Sign in

Danielkennedy74

@danielkennedy74.bsky.social
226 followers 133 following 48 posts

- Cybersecurity industry analyst. - Professional listener to CISOs, occasional skeptic of vendors. - Former CISO. - Opinions mine, data-backed when possible.

PostsRepliesMedia
Danielkennedy74 @danielkennedy74.bsky.social · 12/05/2026
The recent announcement of the capabilities of the Mythos AI model have raised concerns about the cybersecurity implications of ever more powerful AI tools. @scott-crawford.bsky.social and I return to the podcast to debate the impact with host Eric Hanselman: www.youtube.com/watch?v=fl2r...
youtube.com
Mythos and Security
YouTube video by S&P Global Market Intelligence
000
Danielkennedy74 @danielkennedy74.bsky.social · 29/04/2026
RSAC2026 considered agentic AI in situations where the price of hallucinations may be a wrong or destructive autonomous action in a live production environment. - www.spglobal.com/market-intel...
spglobal.com
010
Danielkennedy74 @danielkennedy74.bsky.social · 17/04/2026
AI’s impact in security and its application are not always aligned - blog.451alliance.com/ais-impact-i...
000
Danielkennedy74 @danielkennedy74.bsky.social · 02/04/2026
For the past three years, one of the highlights of my week at #RSAC2026 has been joining Matthew Schwartz in the ISMG News studio to talk about the intersection of my research and the security themes we’re seeing emerge at the conference: www.bankinfosecurity.com/multi-cloud-...
bankinfosecurity.com
Multi-Cloud Security Is Straining CISO Teams
Cloud security and gen AI governance are stretching security teams thin, warned Daniel Kennedy, principal research analyst at 451 Research, S&P Global Market
000
Danielkennedy74 @danielkennedy74.bsky.social · 02/04/2026
"It's going to get much worse. Just look at generated code, right? I mean, pull requests are getting bigger. The vulnerability mix is changing. It's not going down. How do we deal with that? How do we let people safely generate code from prompts?" www.databreachtoday.com/blogs/agenti...
databreachtoday.com
Agentic AI Uncertainty Dominates Dialog at RSAC Conference
Reflecting the current state of cybersecurity, uncertainty dominated at this year's annual RSAC Conference in San Francisco, as advances in artificial intelligence, including agentic artificial intelligence, now pose risks experts never saw coming. It's a disorientating state of affairs for all involved.
010
Danielkennedy74 @danielkennedy74.bsky.social · 20/03/2026
𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗳𝗼𝗿 𝗔𝗜 𝗶𝘀 𝗰𝗿𝗲𝗮𝘁𝗶𝗻𝗴 𝗮𝗻 𝗲𝘅𝗽𝗲𝗿𝘁𝗶𝘀𝗲 𝗽𝗮𝗿𝗮𝗱𝗼𝘅 - blog.451alliance.com/security-for...
011
Danielkennedy74 @danielkennedy74.bsky.social · 18/03/2026
Next in Tech | Ep. 259: The RSAC Conference – Agents on The Loose. www.spglobal.com/market-intel...
spglobal.com
000
Danielkennedy74 @danielkennedy74.bsky.social · 14/01/2026
Transition from isolation to exposure brings evolving threats to IoT and OT systems - blog.451alliance.com/transition-f...
000
Danielkennedy74 @danielkennedy74.bsky.social · 17/12/2025
Any SecOps capabilities that can be automated or simplified represent opportunities for security services providers to dramatically streamline and improve MSS delivery. blog.451alliance.com/genai-is-str...
000
Danielkennedy74 @danielkennedy74.bsky.social · 05/11/2025
"Automating aspects of detection, analysis or response, including outside tool coordination and data retrieval, can streamline repeatable incident response tasks in chronically understaffed security operations centers (SOCs)." blog.451alliance.com/organization...
020
Danielkennedy74 @danielkennedy74.bsky.social · 10/10/2025
Recent attacks amplify the need for software supply chain security - blog.451alliance.com/recent-attac...
blog.451alliance.com
Recent attacks amplify the need for software supply chain security
The 451 Alliance shares recent survey findings on all things application security, including pain points cited by security professionals.
020
Danielkennedy74 @danielkennedy74.bsky.social · 11/09/2025
blog.451alliance.com/agentic-ai-c...
blog.451alliance.com
Agentic AI complicates the picture around non-human identities
What are the specific pain points around identity security facing Security leader’s today? The 451 Alliance shares recent survey findings.
000
Danielkennedy74 @danielkennedy74.bsky.social · 19/08/2025
The annual “security summer camp” that is made up of the Black Hat and DefCon conferences is just past and the security analyst team, Scott Crawford, Dan Kennedy, Justin Lam & Mark Ehr, join host Eric Hanselman to examine what they saw and discuss the implications. open.spotify.com/episode/1itd...
open.spotify.com
Black Hat and DefCon
Next in Tech · Episode
010
Danielkennedy74 @danielkennedy74.bsky.social · 19/08/2025
Reflections from Black Hat USA 2025 - www.linkedin.com/pulse/reflec... #BlackHat
linkedin.com
Reflections from Black Hat USA 2025
Our team’s #BlackHat2025 recap is up on the latest Next in Tech podcast, where Scott Crawford, Mark Ehr, Justin Lam, and I join Eric Hanselman to provide our impressions of the conference. We encourag...
000
Danielkennedy74 @danielkennedy74.bsky.social · 22/07/2025
Use of GenAI security solutions has spiked, continued uptake projected: blog.451alliance.com/use-of-genai...
000
Danielkennedy74 @danielkennedy74.bsky.social · 29/06/2025
Turns out it’s not the company clothing store…
010
Danielkennedy74 @danielkennedy74.bsky.social · 13/05/2025
apiiro.com/blog/webinar...
apiiro.com
Webinar Recap: Reimagining Application Security Posture Management
In a timely discussion hosted by S&P Global Market Intelligence, Principal Research Analyst Daniel Kennedy sat down with Idan Plotnik (Founder of Apiiro) and Jason Espone (Global Head of Application S...
000
Danielkennedy74 @danielkennedy74.bsky.social · 05/05/2025
I had the opportunity again this year at #RSAC to discuss my latest end user security research with @mathewjschwartz.bsky.social at the ISMG studio. Full interview: www.databreachtoday.com/ai-delivers-...
databreachtoday.com
AI Delivers AppSec Gains, but Ransomware Overconfidence Persists
Cybersecurity leaders are embracing generative AI for its practical value in security operations and application security. But as ransomware tactics evolve, S&P's
010
Danielkennedy74 @danielkennedy74.bsky.social · 03/05/2025
#RSAC 2025 - www.youtube.com/watch?v=F7GX...
youtube.com
RSA Conference Preview
YouTube video by S&P Global Market Intelligence
000
Danielkennedy74 @danielkennedy74.bsky.social · 30/04/2025
Thank you to all who joined our 451 #RSAC breakfast this year, it was great catching up, however briefly.
000
Danielkennedy74 @danielkennedy74.bsky.social · 28/04/2025
As the RSA Conference kicks off this week, listen to our conference preview on the Next in Tech podcast: www.spglobal.com/market-intel... #rsac2025
spglobal.com
000
Danielkennedy74 @danielkennedy74.bsky.social · 22/04/2025
I recently had the opportunity to sit down with a couple of folks who have spent significant time working out real world challenges in enterprise application security programs, catch the replay here: event.on24.com/wcc/r/490723...
000
Danielkennedy74 @danielkennedy74.bsky.social · 28/03/2025
How important are information security certifications? Almost half (47%) of respondents to our recent survey note certifications are very important, and they require job candidates to have them. Another 43% note they are somewhat important - blog.451alliance.com/security-tal...
blog.451alliance.com
Security talent gap cannot be expressed in job numbers alone
The 451 Alliance shares key findings from a recent information security study. The topic? Organizational behavior.
000
Danielkennedy74 @danielkennedy74.bsky.social · 01/03/2025
From an old hand, step 1 in the 'finding leakers' handbook is...don't announce you're looking for or have found leakers. I know you think it has a deterrence effect, it doesn't. You want folks to make mistakes and leave bread trails, not get better at leaking information. qz.com/meta-fires-2...
qz.com
Meta just fired about 20 employees for leaks
The Facebook parent company fired the workers for sharing confidential information
000
Danielkennedy74 @danielkennedy74.bsky.social · 28/02/2025
Let's see, from what I'm reading you're making some demands here, somewhat impolitely, I just need to check a couple things... - Yup, not in my chain of command, ok, next thing... - You don't add value, either now or project to in the future... And there you go, right on the 'pay no mind' list.
media.tenor.com
a man in a black shirt and tie is writing on a notebook with a pen .
ALT: a man in a black shirt and tie is writing on a notebook with a pen .
000
Danielkennedy74 @danielkennedy74.bsky.social · 11/02/2025
"We have a new guideline in place, if you could just sign the form..." Gotcha, well I apologize, I have a process where I'm not allowed to 'just sign' anything I don't understand or agree with or that lacks the force of law, you understand, can't be upsetting the folks upstairs here at Kennedy Inc.
000
Danielkennedy74 @danielkennedy74.bsky.social · 24/01/2025
"SecOps managers said they were aware of but unable to investigate 43% of alerts they received through security operations center (SOC) tools.It's a number that has remained consistent over the years..." www.techtarget.com/searchitoper...
techtarget.com
Cybersecurity expertise gaps: More than meets the eye | TechTarget
What 10 years of market research data reveals about past improvements in SecOps practices and how to tackle gaps in cybersecurity expertise.
000
Danielkennedy74 @danielkennedy74.bsky.social · 16/01/2025
TikTok replaced Vine, and if it’s banned something will replace it (YouTube shorts and Instagram reels among the options). All of these ‘it will be healthy’ takes…20 million kids aren’t going to walk outside and rub their eyes in the sun, and then ‘play until the street lights come on’.
230
Danielkennedy74 @danielkennedy74.bsky.social · 13/01/2025
Explosive use of GenAI in 2023 results in predictable need to secure it - blog.451alliance.com/explosive-us...
blog.451alliance.com
Explosive use of GenAI in 2023 results in need to secure it
What's in store for 2024? The 451 Alliance asks security professionals about their planned spending for the new year.
010
Danielkennedy74 @danielkennedy74.bsky.social · 06/01/2025
Multicloud multiplies the pain for information security - blog.451alliance.com/multicloud-m...
blog.451alliance.com
Multicloud multiplies the pain for information security - 451 Alliance
The 451 Alliance explores the evolution of cloud security practices in organizations and key pain points identified in securing the cloud.
010
Danielkennedy74 @danielkennedy74.bsky.social · 18/12/2024
"indicating the importance of a resilience-based strategy focusing on backup technologies such as immutable storage" www.databreachtoday.com/blogs/ransom...
databreachtoday.com
Ransomware Defender Risk: 'Overconfidence' in Security Tools
Are your defenses against ransomware good enough to survive contact with the enemy? Don't be so sure. A new study from market researcher 451 Research finds that "overconfidence in security tooling rem...
011
Danielkennedy74 @danielkennedy74.bsky.social · 16/12/2024
Don’t celebrate #ransomware’s decline just yet - blog.451alliance.com/dont-celebra...
011
Danielkennedy74 @danielkennedy74.bsky.social · 12/12/2024
I had the opportunity to sit down with Beth Pariseau on her podcast for a wide ranging discussion on the notion of a cybersecurity skills shortage & the effects of the Crowdstrike outage on a long-running debate about platforms vs best-of-breed: www.podbean.com/media/share/...
podbean.com
The arc of SecOps is long, but bends toward improvement
S&P Global Market Intelligence principal research analyst Daniel Kennedy discusses what the results of his Voice of the Enterprise research project dating back to 2015 reveal about the notion of a...
000
Danielkennedy74 @danielkennedy74.bsky.social · 10/12/2024
Exploring the shifts in attitudes around 'coordinated disclosure': www.veracode.com/sites/defaul...
000
Danielkennedy74 @danielkennedy74.bsky.social · 09/12/2024
Managing privileged identities remains a headache for organizations’ security leaders — it is the top-cited pain point in identity management (36%). blog.451alliance.com/privileged-i...
000
Danielkennedy74 @danielkennedy74.bsky.social · 06/12/2024
App Sec and the shift to DevSecOps, a conversation with GitLab: www.youtube.com/watch?v=LFtW...
youtube.com
App Sec and the shift to DevSecOps with 451 Research and GitLab
YouTube video by GitLab
010
Danielkennedy74 @danielkennedy74.bsky.social · 05/12/2024
A discussion on cyber insurance with Eric Hanselman, @scott-crawford.bsky.social and Tom Mason on the 'Next in Tech' podcast: www.youtube.com/watch?v=keg8...
youtube.com
[Ep. 152] Cyber Insurance | Next in Tech
YouTube video by S&P Global Market Intelligence
011
Danielkennedy74 @danielkennedy74.bsky.social · 04/12/2024
Lol, whatever it takes...
000
Danielkennedy74 @danielkennedy74.bsky.social · 04/12/2024
While much has been said about GenAI’s potential to enhance developer productivity by generating usable code in integrated development environments, automating code patches for security vulnerabilities may enable similar efficiency gains in application security. blog.451alliance.com/security-pro...
blog.451alliance.com
Security pros see potential in AI-augmented fixes for security flaws
As generative AI is increasingly applied to information security, a key emerging use case emerges. The 451 Alliance shares key findings.
000
Danielkennedy74 @danielkennedy74.bsky.social · 02/12/2024
The challenges in securing the 'multicloud of madness', a panel discussion with CISOs Mike Johnson and Lora Vaughn: vimeo.com/759687623
vimeo.com
Enterprises and the Multi-Cloud of Madness.mp4
This is "Enterprises and the Multi-Cloud of Madness.mp4" by Fastly on Vimeo, the home for high quality videos and the people who love them.
010
Danielkennedy74 @danielkennedy74.bsky.social · 27/11/2024
“Should I engage a MSSP or bring security in-house?” You should reject the premise of the question, as that is not how the majority of managed security services relationships are set up, as an ‘either-or’.
010
Danielkennedy74 @danielkennedy74.bsky.social · 26/11/2024
Discussing the prevalence of open source in applications today and what risks that poses in the realm of Mergers & Acquisitions (M&A) - www.youtube.com/watch?v=JrJv...
youtube.com
Open Source Security Risk - Managing the Threat in Mergers & Acquisitions | Black Duck
YouTube video by Black Duck
011
Danielkennedy74 @danielkennedy74.bsky.social · 26/11/2024
Cyber insurance remains a sought after risk transference strategy for enterprise security leaders, but the market for acquiring insurance remains complex to navigate. Most of that complexity is due to the shift and growth in ransomware... blog.451alliance.com/cyber-insura...
011
Danielkennedy74 @danielkennedy74.bsky.social · 22/11/2024
'Organizational dynamics in information security': www.brighttalk.com/webcast/1315...
brighttalk.com
Organizational Dynamics of Information Security
Positioning Information Security within the enterprise presents its own set of challenges. Our recent survey data from hundreds of senior security and IT leaders like you uncovered a number of systemi...
120
Danielkennedy74 @danielkennedy74.bsky.social · 21/11/2024
The opening blunder... ;)
140
Danielkennedy74 @danielkennedy74.bsky.social · 21/11/2024
I asked ChatGPT to come up with some new analyst style security product category names for me:
010
Danielkennedy74 @danielkennedy74.bsky.social · 20/11/2024
Approaching Application Security in the Enterprise - A significant percentage of data breaches in the last year came as a result of the targeting of web applications. www.brighttalk.com/webcast/1315...
brighttalk.com
Approaching Application Security in the Enterprise
A significant percentage of data breaches in the last year came as a result of the targeting of web applications. ‘Software’ continues to eat the world, but not all of the code behind it is being cons...
020