Sign in

Phil Venables

@philvenables.bsky.social
308 followers 0 following 56 posts
PostsRepliesMedia
Phil Venables @philvenables.bsky.social · 29/05/2026
Power of Community: Seven Steps to Fast-Track Your Security Career. www.philvenables.com/post/the-pow...
010
Phil Venables @philvenables.bsky.social · 02/05/2026
High Frequency Trading and Lessons for Agentic AI www.philvenables.com/post/high-fr...
031
Phil Venables @philvenables.bsky.social · 04/04/2026
Stop Selling, Start Securing: The Real Role of the Field CISO Attributes of success are, of course, sheer competence but also a huge amount of customer empathy from having real lived experience of being in a security leadership role before being a Field CISO. philvenables.com/post/the-rea...
000
Phil Venables @philvenables.bsky.social · 07/03/2026
Cybersecurity’s Need for Speed & Where To Find It www.philvenables.com/post/cyberse...
philvenables.com
Cybersecurity’s Need for Speed & Where To Find It
As we talked about in the last post, a world going through a massive AI-driven transition means speed becomes vital. This is the speed of adapting to change and the speed of dealing with a world of th...
020
Phil Venables @philvenables.bsky.social · 21/02/2026
Things Are Getting Wild: Re-Tool Everything for Speed In the end, despite the short term pessimism, I remain wildly optimistic for the future. www.philvenables.com/post/things-...
000
Phil Venables @philvenables.bsky.social · 24/01/2026
CISO: Watchmaker or Gardener? www.philvenables.com/post/the-cis...
philvenables.com
The CISO's Craft: Watchmaker or Gardener?
Some time ago I saw a comment about the distinction between acting like a “watchmaker” or a “gardener” when undertaking organization transformations. I misplaced the original reference so, unfortunate...
020
Phil Venables @philvenables.bsky.social · 10/01/2026
Top Posts of '25 www.philvenables.com/post/2025-ye...
010
Phil Venables @philvenables.bsky.social · 27/12/2025
Security Leadership Master Class 7 : Contrarian Takes - The curse of binary thinking - Ceremonial security - Caricatures of security people - You just might be a ̶r̶e̶d̶n̶e̶.....security professional www.philvenables.com/post/securit...
020
Phil Venables @philvenables.bsky.social · 13/12/2025
Security Leadership Master Class 6 : When Disaster Strikes - Capabilities beat just plans - Engineering resilience - Building crisis management muscle memory - Learning from events - Shrines of failure - and more….. www.philvenables.com/post/securit...
011
Phil Venables @philvenables.bsky.social · 15/11/2025
Taking your established security program to the next level. Preventative maintenance, risk quantification, navigating the uncanny valley, continuous assurance, architectural choices to reduce whole classes of risk and more. www.philvenables.com/post/securit...
010
Phil Venables @philvenables.bsky.social · 04/10/2025
Security Leadership Master Class - Part 1: Leveling up your leadership philvenables.com/post/securit...
040
Phil Venables @philvenables.bsky.social · 23/08/2025
Everyone Has A Plan Until They Get Punched In The Face. Resilience is about capabilities not just plans. www.philvenables.com/post/everyon...
philvenables.com
Everyone Has A Plan Until They Get Punched In The Face
Apparently what Mike Tyson actually said in a 1987 interview was, "Everybody has plans until they get hit for the first time". In any case this is still a variant of the common theme of “No plan survi...
031
Phil Venables @philvenables.bsky.social · 26/07/2025
Decoding Cybercrime's True Scope: Beyond the Trillion-Dollar Hype A new NASEM report reveals the truth about #cybercrime stats: our data is fragmented, inconsistent, & underreported. We can't fight what we can't accurately measure. www.philvenables.com/post/decodin...
philvenables.com
Decoding Cybercrime's True Scope: Beyond the Trillion-Dollar Hype
As security specialists, we regularly see claims about the escalating scale of cybercrime, often hearing staggering claims that it’s a "multi-trillion dollar problem." I’ve never seen any comprehensiv...
010
Phil Venables @philvenables.bsky.social · 12/07/2025
The Don't Fire Me Chart A lot of premature CISO turnover is caused by the security program uncovering previously unknown risks and issues. So, paradoxically, the best CISOs make the situation *seem* worse before it then *actually* gets better. www.philvenables.com/post/career-...
031
Phil Venables @philvenables.bsky.social · 28/06/2025
Cyber Insights Needed & Delivered My analysis of the recent Cyentia Institute report. Things are getting worse in absolute terms but it’s not clear (my take) they are getting worse relative to what the situation might be. www.philvenables.com/post/cyber-i...
011
Phil Venables @philvenables.bsky.social · 14/06/2025
Segmentation Technologies / Zero Trust Thinking about doctrine vs. structure is a useful mental model to validate a technology’s adequacy for a particular task. In short, to know whether we are jamming a square peg into a round hole. www.philvenables.com/post/segment...
020
Phil Venables @philvenables.bsky.social · 31/05/2025
A different taken on the CISO / Cybersecurity Leader Job Description. www.philvenables.com/post/ciso---...
philvenables.com
CISO / Cybersecurity Leader Job Description
There is a plethora of sample job descriptions for security leaders that are often strictly correct but can also be uninspiring or too detailed to capture the actual essence of the role. I developed t...
131
Phil Venables @philvenables.bsky.social · 17/05/2025
Starting a Security Program from Scratch (or re-starting). www.philvenables.com/post/startin...
030
Phil Venables @philvenables.bsky.social · 22/03/2025
Security Leaders’ Reading List Not many security books. Security leader challenges are mostly, well, leadership along with a healthy dose of program mgmt, culture, attention to detail, risk mgmt and more. www.philvenables.com/post/leaders...
071
Phil Venables @philvenables.bsky.social · 08/03/2025
Turning the Security Flywheel This post explores the "flywheel" concept and its application to security, demonstrating how to create self-reinforcing cycles that improve effectiveness. www.philvenables.com/post/turning...
053
Phil Venables @philvenables.bsky.social · 22/02/2025
Cryptanalytically Relevant Quantum Computers (CRQCs) are coming. Perhaps sooner than we think, but we can conservatively (and usefully) assume in the 2032 - 2040 time frame. Beware the snake-oil of non-standard solutions. www.philvenables.com/post/post-qu...
philvenables.com
Post Quantum Cryptography Migration: Time to Get Going
Quantum computing is advancing rapidly. Innovations from Google, Microsoft, IBM and others are pushing the boundaries of not just the numbers of qubits but also their quality. We are well on our way t...
021
Phil Venables @philvenables.bsky.social · 11/01/2025
Keys to Career Success www.philvenables.com/post/keys-to...
011
Phil Venables @philvenables.bsky.social · 28/12/2024
Top Ideas and Posts from 2024 In closing the year let’s take a look at the top 10 posts of 2024 in order of most read. www.philvenables.com/post/top-ide...
philvenables.com
Top Ideas and Posts from 2024
I managed to keep up the pace of 1 post every 2 weeks throughout 2024. Just when I think I might be running out of ideas, and the backlog of topics is running low, then something always manages to com...
000
Phil Venables @philvenables.bsky.social · 24/12/2024
Want to know more about cyber-physical resilience & why leading indicators like software reproducibility & cold-restart time are more effective than just focusing on lagging indicators? Then take a listen to the 2024 season finale of the cloud security podcast. cloud.withgoogle.com/cloudsecurit...
031
Phil Venables @philvenables.bsky.social · 23/12/2024
Cloud CISO Perspectives for end of Dec ’24 is up covering: - Year end review from AI to Threats - Forecast for 2025 - AI ISO certifications - NIS2 compliance - Threat intel. program development - Detection as code - and much more…. cloud.google.com/blog/product...
cloud.google.com
Cloud CISO Perspectives: From gen AI to threat intelligence: 2024 in review | Google Cloud Blog
To close out the year, our CISO Phil Venables shares the top Google Cloud security updates in 2024. There’s a lot of AI, of course, and a few surprises.
011
Phil Venables @philvenables.bsky.social · 22/12/2024
Remember, as security professionals we are defending the free flow of ideas and capital that are essential for human progress. Defending lives and livelihoods. That's the mission. Happy Holidays. sketchplanations.com/the-three-br...
010
Phil Venables @philvenables.bsky.social · 14/12/2024
The Maintenance Paradox. luca-dellanna.com/posts/mainte...
luca-dellanna.com
The Maintenance Paradox
Maintenance never makes sense in the short term, yet it is indispensable in the long term.
010
Phil Venables @philvenables.bsky.social · 14/12/2024
Leadership: One Day at a Time, One Step at a Time. www.philvenables.com/post/leaders...
000
Phil Venables @philvenables.bsky.social · 12/12/2024
Proud to see @googlecloud as the first cloud service provider to partner with the @GRFederation and its affiliates to help further strengthen the manufacturing industry's cyber resilience. Read more on what this means here: cloud.google.com/blog/product...
cloud.google.com
Google Cloud first CSP to join BRC, MFG-ISAC, and affiliates to advance security | Google Cloud Blog
Google Cloud is proud to be the first cloud service provider to partner with the GRF Business Resilience Council and its affiliates. Here’s why.
010
Phil Venables @philvenables.bsky.social · 10/12/2024
Cloud CISO Perspectives for early Dec '24 is up covering: - Forecasting 2025: Notes from the Field - Open source security patch validation - C2 in browser isolation environments - Every CTO should be a CTSO - and more...... cloud.google.com/blog/product...
cloud.google.com
Cloud CISO Perspectives: Our 2025 Cybersecurity Forecast report | Google Cloud Blog
Google Cloud security experts don their forecasting hats to gauge what’s coming in 2025, in our newest CISO newsletter.
010
Phil Venables @philvenables.bsky.social · 06/12/2024
Oops! 5 serious gen AI security mistakes to avoid cloud.google.com/transform/oo...
cloud.google.com
Oops! 5 serious gen AI security mistakes to avoid | Google Cloud Blog
Pitfalls are inevitable as gen AI becomes more widespread. In highlighting the most common of these mistakes, we hope to help you avoid them.
010
Phil Venables @philvenables.bsky.social · 02/12/2024
How has the development and adoption of AI changed over the last year? Dive into the current landscape in this issue of the Dialogues magazine, from @Google and @atlanticrethink for insightful perspectives on the transformative power of AI. Read here: www.theatlantic.com/sponsored/go...
theatlantic.com
The “Eureka!” Moment
We asked 20 scientists and thought leaders to recall when they realized AI had the potential to change the world.
000
Phil Venables @philvenables.bsky.social · 30/11/2024
Regulatory Harmonization - Let’s Get Real Most cyber controls are relatively aligned. Calls for action on harmonization are really induced by obligations from other technology risk domains or broader. Focusing on reducing compliance toil is the right approach. www.philvenables.com/post/regulat...
philvenables.com
Regulatory Harmonization - Let’s Get Real
Every few months some association or other learned group of professionals makes a fresh call to action for cybersecurity regulatory harmonization. The logic being that cybersecurity professionals are spending more time showing adherence to compliance obligations or dealing with the toil due to differences in regulation than they are actually mitigating risk.I do have some sympathy with this sentiment but I would push back on this being as big a problem as people generally assert. However, as we
010
Phil Venables @philvenables.bsky.social · 27/11/2024
It's here. Benedict Evan's annual presentation. Predictably it's all about AI. Well worth a read. www.ben-evans.com/presentations
ben-evans.com
Presentations — Benedict Evans
Every year, I produce a big presentation exploring macro and strategic trends in the tech industry. For 2024, ‘AI, and everything else’.
010
Phil Venables @philvenables.bsky.social · 25/11/2024
Cloud CISO Perspectives Blog for end of Nov '24 is up, covering: - Ransomware and cyber insurance - Workload identity federation - Reducing toil of audit compliance - Gemini AI for malware analysis - and much more.... cloud.google.com/blog/product...
cloud.google.com
Cloud CISO Perspectives: Ending ransomware starts with more reporting | Google Cloud Blog
Cyber-insurance can play a big role in stopping ransomware — if we let it, say this month’s guest columnists Monica Shokrai and Kimberly Goody.
000
Phil Venables @philvenables.bsky.social · 16/11/2024
Lessons in Crisis Management - Top 10 Disaster Movies Which ones am I missing? www.philvenables.com/post/lessons...
010
Phil Venables @philvenables.bsky.social · 02/11/2024
Risk Appetite & Tolerance - A Practical Approach Defining risk appetite should support business decision making - ensuring risk taking is for strategic objectives while capping downside. Risk tolerance expression should permit choices and measurement. www.philvenables.com/post/risk-ap...
philvenables.com
Risk Appetite and Risk Tolerance - A Practical Approach
If you work for a large organization, especially public or otherwise regulated companies, then you may well have faced the prospect of developing a risk appetite statement. You might have been enthusi...
020
Phil Venables @philvenables.bsky.social · 05/10/2024
The Top 10 Attributes of Great Security Leaders 1. Curiosity 2. Influence 3. Moral Courage 4. Persistence 5. Collaboration 6. Critical and Logical Thinking 7. Broad Technical Understanding 8. Culture Alignment 9. Strategic Mindset 10. Team Building www.philvenables.com/post/job-int...
philvenables.com
Job Interviews: Part 2 Conducting the Security Interview - The Big 10
This is the second of two posts about interviews (the first post is here). In this one I’ll focus on interviewing candidates and the main attributes to look for when selecting potential security leade...
000
Phil Venables @philvenables.bsky.social · 07/09/2024
6 Truths of Cyber Risk Quantification 1. Risk Quant vs. Risk Comms 2. Risk = Hazard + Outrage 3. Experience and Judgement Eats Data for Breakfast 4. A Tree Falls in the Forest 5. All Risk Quantification is Wrong 6. Multi-Disciplinary or Nothing www.philvenables.com/post/6-truth...
philvenables.com
6 Truths of Cyber Risk Quantification
I wrote the original version of this post over 4 years ago. In revisiting this it is interesting to note that not much has actually advanced in the field. Yes, there have been more products and tools ...
020
Phil Venables @philvenables.bsky.social · 24/08/2024
Ethics and Computer Security Research - Stakeholder Perspectives and Considerations - Respect for Persons and Informed Consent - Beneficence - Justice - Respect for Law and Public Interest www.philvenables.com/post/ethics-...
010
Phil Venables @philvenables.bsky.social · 27/07/2024
33 'Computer Programs' That Changed the World - OS/360 - Multics - VAX/VMS - Linux - Python - Git - IBM VTAM (in SNA) - Netscape Navigator - RSA BSAFE - Borg - SecDB - and more........ www.philvenables.com/post/33-comp...
philvenables.com
33 Computer Programs That Changed the World
This is a slight departure from my normal security and risk management topics, but is something I’ve been getting more interested in. There are now a myriad of books like “A History of the World in 10...
110
Phil Venables @philvenables.bsky.social · 13/07/2024
Why Good Security Fails: The Asymmetry of InfoSec Investment. www.philvenables.com/post/why-goo...
philvenables.com
Why Good Security Fails: The Asymmetry of InfoSec Investment
One of the many paradoxes of security is that when you have invested appropriately (sometimes at significant expense) and you have less and less incidents, then some time later, someone somewhere migh...
010
Phil Venables @philvenables.bsky.social · 15/06/2024
Going Faster: Isochrones and “Time to Hello World” We need more metrics to see if we're moving faster. Isochrones to watch for fast(er) paths to actions and measuring variants of Time to Hello World may well be useful. www.philvenables.com/post/going-f...
000
Phil Venables @philvenables.bsky.social · 18/05/2024
Crucial Test of Security Leadership: A-grades vs. Pass/Fail Great teams know what needs to be done really well vs. simply ok, that is A-grade vs. Pass - and also make sure that A-grade goals are what give most leverage not just the evidently critical. www.philvenables.com/post/the-cru...
philvenables.com
The Crucial Test of Security Leadership: A-grades vs. Pass/Fail
A major success marker of great security leaders and their teams is one simple prioritization technique: the ability to know what needs to be done really well vs. what needs to be simply ok. In other ...
000
Phil Venables @philvenables.bsky.social · 04/05/2024
Where the Wild Things Are: Second Order Risks of AI. 1. Human Misunderstanding Mediated by AI 2. Complex Agent Interactions 3. Deskilling 4. Everything Has an API 5. Augmented Reality 6. AI Replacement of Humans in Dual Control Situations www.philvenables.com/post/where-t...
000
Phil Venables @philvenables.bsky.social · 20/04/2024
Security and Ten Laws of Technology. - Moore’s Law - Murphy’s Law - Conway’s Law - Hyrum’s Law - Metcalfe’s Law - Wirth’s Law - Cunningham’s Law - Hyponnen’s Law - Kryder’s Law - Venables’ Law www.philvenables.com/post/securit...
000
Phil Venables @philvenables.bsky.social · 06/04/2024
A Letter from the Future. www.philvenables.com/post/a-lette...
000
Phil Venables @philvenables.bsky.social · 23/03/2024
InfoSec Hard Problems. - Distributed Policy Specification and Enforcement - Protecting and Assuring Security and Trust in AI  - Data Level Entitlement Policy Enforcement : Rules, Roles, Rights, Requests - and more...... www.philvenables.com/post/infosec...
000
Phil Venables @philvenables.bsky.social · 09/03/2024
DevOps and Security DevOps practices drive organization performance and security. AI is showing early signs of performance increase. Looking at our DORA report through a security lens. www.philvenables.com/post/devops-...
000
Phil Venables @philvenables.bsky.social · 25/02/2024
The Power of Community: 5 Steps to Fast Track your InfoSec Career. Many professions have societies and hierarchies. InfoSec is more diffuse so be deliberate: 1. Start focused 2. Join and engage 3. Be helpful 4. Lead and connect 5. Level up www.philvenables.com/post/the-pow...
000