I’ve been fortunate to meet some great people through conferences, podcasts, and publications over the years.

Arve Kjoelen

2025 Vulnerabilities in the Model Context Protocol

January 29, 2026

Analysis of MCP-related CVEs published in 2025, comparing and contrasting with vulnerabilities in AI-related software and other vulnerabilities. PDF

Read more →

AI Defense - Gartner 2024 Security and Risk Management Summit

June 05, 2024

At the 2024 Gartner Security and Risk Management Summit, my session focused on defending in the AI Era. Both adversaries and defenders benefit from the use of AI. Defensive use of AI introduces new attack vectors. Offensive use of AI can be defended using traditional methods: As covered in my earlier substack, AI ...

Read more →

Defending in the Era of AI

June 27, 2024

At this week’s North American Information Security Summit, I made the following points under the title “Defending in the Era of AI”: 1. GenAI has the potential to be a net positive for cyber defenders. While GenAI advances adversary capabilities, it can advance defender capabilities even more. AI alignment ef...

Read more →

Law Enforcement - Risks and benefits of AI

April 12, 2024

In this training session for the Dallas FBI, I covered some of the implications of GenAI for Law Enforcement. In addition to areas such as disinformation, we covered practical forensics in connection with malicious AI use. Some slides are reproduced below. The presentation was influenced by Justin Hutchins' ex...

Read more →

Netacea

April 12, 2024

I joined host Andy Ash (CISO at Netacea) to discuss differences in how CISOs are compensated across both sides of the Atlantic, how the role is shifting to account for increased governance and regulations, and the ‘left of boom’ approach to preventative security. We also compare notes on how we first become fascina...

Read more →

Public / private partnership - 2022 RSA Conference

June 09, 2022

The FBI is the primary domestic intelligence agency and law enforcement agency for cyber. I had the pleasure of moderating a discussion at the RSA Conference between the FBI’s head of Cyber, Ron Bushar and Elvis Chan. You can watch the interaction here Thank you to Ed and TAG who continue to post insightful mater...

Read more →

SEC Incident Disclosure Rules - Tag Cyber

April 12, 2024

My conversation with Edward Amoroso at TAG Infosphere about the need to test your process for complying with the new SEC rules for incident disclosure; the potential for “CYA” filings with the SEC; and how to tell you might be CISO at the wrong company. Thank you to Ed and TAG who continue to post insightful materi...

Read more →

We need offensive GenAI for defensive use

December 21, 2023

In this substack article, I argue that AI alignment efforts inhibit defensive capabilities. Read the article

Read more →