Writing

From the Blog

Thoughts on application security, AI-assisted testing, DevSecOps, and the gap between what vendors promise and what practitioners actually need.

The CISO's Blind Spot: You're Testing for Yesterday's Attacks

Most organisations test their security posture once or twice a year. Their attack surface changes every day. That gap isn't a resource problem — it's a mental model problem. The shift every CISO needs to make isn't in tool selection; it's in expectation.

Read on LinkedIn →

The Model Isn't the Agent: What GPT-5.5 Actually Changes for Security

GPT-5.5 is now part of XBOW's production stack — and the reactions split cleanly into two camps, both missing the point. A better model is necessary. It's not sufficient. Here's what actually changes, and what practitioners need to care about.

Read on LinkedIn →

Before You Replace Your SAST Tool With an AI Model: Three Questions Nobody Is Asking

The last few weeks have been loud. Anthropic's research found thousands of unknown vulnerabilities in weeks. The hype cycle is in full swing. But before you rip out your SAST tooling and replace it with an AI model, there are three questions the conversation keeps skipping — and they matter more than the headlines.

Read on LinkedIn →

The Myth of Self-Healing Code: Why Claude Code Security Isn't Replacing Application Security

Anthropic recently launched Claude Code Security — an AI-powered vulnerability scanner that can analyse your codebase, trace data flows across files, find bugs, and even propose patches. It represents a meaningful advance in how developers can get security insights earlier in the development process. But does a smart scanner replace an AppSec programme?

Read on LinkedIn →