Sign in to view Nick’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Nick’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
San Diego, California, United States
Sign in to view Nick’s full profile
Nick can introduce you to 10+ people at Aviso Ventures
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
5K followers
500+ connections
Sign in to view Nick’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Nick
Nick can introduce you to 10+ people at Aviso Ventures
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Nick
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Nick’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
5K followers
-
Nick Galbreath reposted thisWho are the lucky UCLA students that get to spend time with professor Eric Futoran? 😉Nick Galbreath reposted thisA new course at Anderson makes the case that nailing the narrative is essential for company founders. Eric Futoran, co-founder of Embrace, will teach the new Technology Entrepreneurship in the Era of AI course at UCLA Anderson. In a recent Q&A, Eric talks shares his goals for the course, how he translated his founder experience into a syllabus and how Dean Gary Fraser and Terry Kramer helped bring him to UCLA Anderson. Read the full discussion on our website: https://lnkd.in/gcHbtMRS
-
-
Nick Galbreath posted thisWhy doesn’t Google or AWS take on GitHub? TLDR: Culture Matters. No one is getting promoted if it happens, and maybe fired if it doesn’t work out. GitHub’s outages scaling issues are commonplace. Github’s “social coding” moat is eroding with agentic coding now accounting for most new code. Cursor and some others have started offering git code hosting, and going after GitHub. How come Google or AWS aren’t doing it too? While GitHub has a zillion features for enterprise use, having Google or AWS have some open source hosting would seem an easy add-on for them. AWS certainly has the infrastructure. They already have some git experience with their CodeCommit product. Their mantra is (or was) “Your Margin Is Our Business” so why wouldn’t they go after it? Google likewise. They have infrastructure. They have a git product with Cloud Source. They host *fonts* for crying out loud. And Google has the identity piece already. The advantages for both Google and AWS: * It’s basic infrastructure! They use tons of open source stuff, so why pull it in from Microsoft? * Developer goodwill * Gateway drug for the rest of their offerings. More importantly. ** they get access to the code, how it changes, how it’s fixed, for use in training their own AI models. ** So… why aren’t they doing it? Culture Matters. * Both Google and AWS are not particularly good with customer facing products. * Unclear how this product would fit in their current organization. For example with Google, would it be in the Cloud group or the Docs group or the AI group or something else? Its messy. * It’s not likely to be a big money marker, so the current KPIs probably disincentive doing this * If it doesn’t go viral, it will be deemed a failure, a publicly visible failure. It’s easy to think of Google and AWS as "a thing that makes decisions", but inside it’s a person who needs to champion this. Given the messy internal politics, the limited upside, and big downside, no one is going to champion it. The opportunity can make sense for Google or AWS and still make no sense for anyone inside Google or AWS to pursue. The infrastructure is easy. The organizational incentives are hard.
-
Nick Galbreath shared thisToday I bought a used book on skyscrapers at the local library for the kids, not even making the connection to 9/11. The kids got it immediately and asked if the building that “blew up” was in it. Seeing the iconic and beautiful WTC in all its glory … it was just as moving as everything else I’ve read today. Never forget.
-
Nick Galbreath posted thisThe Fed is also Watching AI Token Pricing -- Chairman Warsh at Jackson Hole. Everyone and every company is watching AI token pricing. Even the US Federal Reserve. Here's the AI part of Chairman Warsh's speech at Jackson Hole. The last paragraph is particularly telling where he wonders on the "equilibrium price of tokens". Such an economist lol. My take is that is tokens are always getting cheaper. --- Capital and labor have combined to create the large language models at the heart of AI. Users buy tokens to gain access to the models. Reports put annualized token sales for the two leading labs alone at more than $100 billion—an increase of 500-plus percent from a year ago. The Fed watches all of this attentively. We recognize that AI is a new variable—potentially a new factor of production—that will have consequences for both the economy and the conduct of monetary policy. It opens some major lines of inquiry: Will the application of AI cause a significant, sustained rise in productivity across the economy? And if so, when? Will token usage be complementary or competitive to labor? Will the next generation of AI models demand even greater capital intensity, or will the models themselves help devise a capital-light solution? Among the other yet unknowns is the resulting market structure. It's not obvious where the returns on capital will land or on what timescale. Early on, how much of the surplus goes to owners of scarce assets—AI labs, chipmakers, energy producers, and cloud providers? Over time, how much of that value accrues to businesses and consumers? What are the broad implications for workers and for the employment side of the Fed's mandate? Likewise, we don't yet know the equilibrium price of the tokens. Might there be a heterogeneity of tokens, such that growing sums will be paid for access to the best models at the frontier? Will token prices for older models fall to the level of their marginal cost? ---
-
Nick Galbreath posted thisGitHub, AI, and the End of Social Coding Agents have no pride. That's the problem for GitHub. Its dominance was built on three things: making git usable, great design, and social coding (stars, followers, pull requests, profile pages, a news feed for programmers, etc). That last one mattered most. It turned a dry technical tool into a place developers wanted to be seen. None of that works on an AI-first internet. Agents call git directly with using the browser or some other middle layer. Heavy web design is dead weight when every page fires API calls no agent uses. And AIs infer popularity from usage data, not star counts. Take away the audience that wanted to be seen, and the utility of the social layer diminishes. "Social Coding" and GitHub's moat isn't gone, but it's eroding. What's left is commodity infrastructure — speed, storage, uptime. And that's letting competitor move in. PostScript: I remember many years ago at Etsy when I told Kellan Elliott-McCrea I had some projects on Google Code, a no thrills code hosting platform. His response was "Nick, all the cool kids have their projects on GitHub." Google Code is long gone. Maybe they should have kept it around after all.
-
Nick Galbreath shared this“AI makes starting easy…. Finishing is a different skill”Nick Galbreath shared thisI spent part of this week polishing a small Mac app I originally built for myself. AI made the first version surprisingly easy. The rest still required the usual work: fixing edge cases, recovering failed dictations, testing text insertion in different apps, signing the build and getting it notarized by Apple. That got me thinking about the phrase “AI makes building easy.” It makes starting easy. You can turn an idea into a rough prototype in an afternoon. That matters, because you can test ideas that would previously have stayed in a notebook. Finishing is a different skill. 𝟭. 𝗗𝗲𝗰𝗶𝗱𝗶𝗻𝗴 𝘄𝗵𝗮𝘁 𝗴𝗼𝗼𝗱 𝗹𝗼𝗼𝗸𝘀 𝗹𝗶𝗸𝗲 AI can generate ten solutions. You still need to choose the one worth keeping. 𝟮. 𝗛𝗮𝗻𝗱𝗹𝗶𝗻𝗴 𝘁𝗵𝗲 𝗯𝗼𝗿𝗶𝗻𝗴 𝗰𝗮𝘀𝗲𝘀 A demo works once. A useful product also works after a failed recording, a strange permission setting or an unexpected app update. 𝟯. 𝗦𝘁𝗼𝗽𝗽𝗶𝗻𝗴 When changing the product becomes cheap, adding one more feature is always tempting. Shipping requires deciding that today’s version is useful enough. My weekend experiment for anyone curious about building with AI: → Pick one small annoyance in your own day → Build the simplest fix you could use on Monday → Spend as much time finishing it as generating it AI has made prototypes abundant. Finished, useful things are still rare. If you’re curious about my app. It’s called LocalFlow and it’s a private secure and fully local dictation app for Mac. Https://localflow.eu.com #AI #AIBuilding #BuildInPublic #LocalAI
-
Nick Galbreath shared thisThe parallels of AI exploit development and AI generated mathematical proofs. Terence Tao, "many regard as the finest mathematician of his generation." (NYT), wrote a paper titled "Mathematics in the Age of AI" The field of mathematics is having the same crisis that the security industry is having with the #vulnpocalypse. If you don't care about mathematics, jump to Section 7: """ • AI-generated proofs [exploits] will accumulate faster than they can be verified; • verified AI-generated proofs [exploits] will accumulate faster than they can be given a readable write-up; [CVE overflow] • AI-generated proofs [exploits], even those required to be both correct and well written, will overwhelm a traditional peer review system that depends on volunteer expert labor; [OSS maintainers] • and even the published proofs [exploits] will be too numerous for the community to work into definitive form. [OSS packaging, back ports, patch collisions, exploit naming] In short, we will transition from an era of proof [exploit] scarcity to an era of proof [exploit] abundance. Most of our institutions ... were designed under the assumption of scarcity, and it should not surprise us if they behave poorly under abundance. """ Sound familiar? It concludes with """ ... we will need to take the initiative on AI usage, and define best practices for incorporating these tools into our workflows on our own terms rather than on terms set for us by vendors. We will also need new workflows and new infrastructures to complement our traditional ones. """ Which is exactly what is needed in software engineering. While exploit development and mathematical proofs aren't identical, the article should appeal to anyone in software development or mathematics. It's also a great introduction to "what do mathematician do". https://lnkd.in/gVveV2WRMathematics in the age of AIMathematics in the age of AI
-
Nick Galbreath shared thisCal Newport, of Digital Minimalism and Deep Work fame, published a bit of a confusing article this week, "AI Coding and Its Discontents." But it illustrates the point that writing code with AI is a skill, and like all skills, takes time to master. The article opens with a senior engineer writing to Newport, converted after trying Claude Code: he now "exclusively uses" it, a week's work down to two days. Months later, he writes back that the AI's code crashed production twice, and his boss threatened to fire him. His new policy: write the code by hand, and use AI only for narrow, low-stakes tasks like tests and throwaway scripts. That's what you'd expect from onboarding a junior engineer. You don't hand a new hire the keys to production on day one, you scope what they touch, review everything, and expand their responsibility as they earn it. Skip that process and get burned, and the lesson isn't "junior engineers are useless." It's "I undersupervised them." The same logic applies to a tool that writes plausible-looking code without the judgment to know when it's wrong. The fix isn't less AI, it's improving the environment where reliable code gets produced. Test suites, linters, review gates, staged rollouts turn raw code into dependable output, whether it comes from a junior engineer or a language model. https://lnkd.in/ge8c6paY
-
Nick Galbreath liked thisNick Galbreath liked thisInteresting. Google's "AI Mode" uses Gemini 1.5 Pro, a model from early 2024! 1B MAU with query volume doubling every quarter. Insane numbers on a 2.5yo model. A great example of using the right model for the task. Why do they stick to this model? 1. It excels at retrieval accuracy. Plucking a needle from the webpage haystack. 2. It's a sparse model. Only parameters related to your query are activated, saving compute. 3. It's hardened. It has a known and battle-tested safety profile. Lots of lessons here for production-scale inferencing.
-
Nick Galbreath liked thisNick Galbreath liked thisI’m excited to be speaking at the #Boston Cybersecurity Summit! AI will continue to shift the cybersecurity landscape in 2026. We'll explore how modern tools can enhance detection, response, and decision making while introducing new risks tied to generative systems, data integrity, and fast moving threat innovation. 🎟️ Register today and receive FREE admission with code: CSS26-SPEAKER #OfficialCybersecuritySummit #CRAEvents #Cybersecurity https://lnkd.in/gwhWMRDQ
-
Nick Galbreath liked thisDid you know that the fabulous An Gaiser is doing the closing keynote at Swiss Cyber Storm on October 20? Be sure to reserve a seat. https://lnkd.in/eQTZ-YGMNick Galbreath liked this🚨 𝗢𝗻𝗹𝘆 𝟯 𝗺𝗼𝗻𝘁𝗵𝘀 𝘂𝗻𝘁𝗶𝗹 𝘁𝗵𝗲 𝗡𝗜𝗦𝗔 𝗖𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲, 𝗯𝗲 𝗾𝘂𝗶𝗰𝗸 𝘁𝗼 𝗰𝗹𝗮𝗶𝗺 𝘆𝗼𝘂𝗿 𝘀𝗽𝗼𝘁! 🕵🏻♀️ ⏱️ 66 days and counting down to the Netherlands Intelligence Studies Association 𝗖𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲 𝗼𝗻 𝟮-𝟯 𝗗𝗲𝗰𝗲𝗺𝗯𝗲𝗿 𝟮𝟬𝟮𝟲 in The Hague, the Netherlands. 📣 Key note speakers include Bart Jacobs (Professor of Security, Privacy and Identity, Radboud University Nijmegen), Rory Cormac (Professor of International Relations, University of Nottingham), Thorsten Wetzling (Head of Research Unit ‘Digital Rights, Surveillance and Democracy, at interface), and Daniela Richterova (Associate Professor in Intelligence Studies at the Department of War Studies, King's College London). 💡Curious what we’ll discuss at the conference? The program is now available (still subject to changes), check it out here 👉🏻 https://lnkd.in/e7YSx3j6 📝 Be there or be square! To register, please send an email from your institutional or organisational email address (students: from your university email address) to conference@nisa-intelligence.nl Rowin Jansen Eleni Braat Jip Boer Sophie Harleman Constant Hijzen Bram Spoor Margaret D. 𝗟𝘂𝗱𝗼 𝗕𝗹𝗼𝗰𝗸 Erik Elgersma Sylvie B.ScheduleSchedule
-
Nick Galbreath liked thisNick Galbreath liked thisWhat makes Claude Projects so interesting is that it handles teams of agents really well, you talk to a main orchestrator agent and it spins up specialists. Basically it creates an organization to solve your issue, mixing expensive and cheap agents depending on your preferences. For example, I asked Fable in Claude Projects to select famous historical mysteries that it could try to resolve. It initiated research agents, selected the mysteries based on data it could access, and spun up eighteen separate threads, each with an agent each focused on one mystery. Then each thread launched additional agents (simulating avalanches, breaking codes) before summarizing those and passing them to still more agents for write up and another set of skeptical agents to fact check. It did this over a day of work, with the central orchestrator agent organizing it all. The results were interesting if you like historical mysteries. They are also for fun and certainly not definitive or guaranteed error-free (but they are also mostly reasonable & grounded in the literature). https://lnkd.in/gsJjPASe
Experience & Education
-
Aviso Ventures
******** *******
-
******
**** ********* ** ***********
-
****** ******** ****
******* * *** * ***
-
********** ** *********
******** ** ******* * ** *********** undefined
-
-
****** **********
****** ** ******* * ** ***********
-
View Nick’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View Nick’s full profile
-
See who you know in common
-
Get introduced
-
Contact Nick directly
Other similar profiles
Explore more posts
-
Hanno Ekdahl
Idenhaus Consulting, LLC • 7K followers
OCR Director Defends HIPAA Updates: "There's a very high cost of doing nothing. A successful cyberattack can cost far more in terms of reputation, potentially paying a ransom, remediation of information systems, protection for those whose PHI was accessed, potential civil lawsuits from harm to individuals, and not to mention my investigators coming and knocking on your door and asking for information and talking about penalties." https://hubs.ly/Q04793ML0
1
-
Phillip Rhodes
Fogbeam Labs • 3K followers
One shortcoming in the #A2A spec, is that the spec assumes that there is a one to one correspondence between a "server" (that is, a "physical server instance" with a port number and some process listening) and an Agent. So if you request http://somehost:8080/.well-known/agent-card.json you get the ONE and ONLY AgentCard for that server... which defines ONE Agent. Now obviously one can serve multiple Agents from a Server, so this seems... sub-optimal. So far all the A2A project people have said is "Put each Agent's AgentCard on a different port" (Uuuuggh... does not scale and is a PITA to manage) or "use different context paths" (which strictly speaking breaks the ".well-known" semantics). There are a variety of proposals out there for how to address this. I'd love to see them simply allow .well-known/agent-card.json to return a array of AgentCards OR at least define .well-known/agent-cards.json or .well-known/agents.json to return such an array. But short of that, a solution I quite like, and am knee deep in implementing, is to simply NOT change the spec at all, and just make the "root" Agent an "AgentListerAgent" if there are multiple Agents on the server. In my vision, this Agent has an AgentCard listing skills like "list_agents", "search_agents", "get_agent_by_name" and so on, which do exactly what they sound like they would do... and in either case, triggering those skills would return an array of AgentCards for the cases where multiple matches are possible. The downside is that this adds one extra step to the handshake, but the upside is that it requires no change to the existing spec, and natively uses A2A to solve the problem. The other thing about this, is that it also cleanly supports the case where the "AgentListerAgent" can return Agents that are *not* actually hosted on the current Server instance. That is, if it were the front-end to, say, an #AgentRegistry of some sort. Then it would return AgentCards that point to any Agent registered with the Registry. (Note: the description of each individual Agent in its AgentCard defines how to reach it. Of course you could munge that up if you, say, know that the Agent is behind a proxy of some sort and you know the "real" route to the Agent). #AI #Agents #AIAgents #AgentRegistry #AgentCard #MultiAgentSystems
1
-
Reza Rafati
Hendrix Genetics • 6K followers
Website cloning attacks are a form of digital impersonation where threat actors replicate a company’s legitimate website to deceive users, harvest credentials, or redirect payments, often before enterprises even realize a clone exists. These attacks exploit brand trust at scale, turning familiarity into a weapon against customers. Continue reading https://lnkd.in/e5DXPwQy
8
-
John Barger
SPARC • 3K followers
In this episode of IT SPARC Cast - CVE of the Week, Louis Schmidt and I examine a critical Apple security vulnerability patched in iOS, iPadOS, macOS, watchOS, tvOS, and visionOS 26.3. The focus: CVE-2026-20700, a memory corruption flaw in Apple’s dynamic link layer that could allow attackers to break out of the sandbox and achieve remote code execution (RCE). Although exploitation requires physical access, the definition of “physical” in today’s hybrid enterprise world is broader than it sounds. Remote management tools, compromised accounts, lost devices, or improperly secured BYOD endpoints can all create real-world exposure. With Apple’s unified “26” operating system line now spanning every platform, this patch affects: • iOS 26.3 • iPadOS 26.3 • macOS 26.3 • watchOS 26.3 • tvOS 26.3 • visionOS 26.3 Security researchers are classifying this vulnerability as critical/high severity, and enterprises are urged to patch immediately. ⸻ 🔎 CVE-2026-20700 Details • Type: Memory corruption • Impact: Sandbox escape → Remote Code Execution • Exploit Path: Physical or logical device access • Risk Level: High/Critical (no official CVSS published) • Fix: Upgrade to Apple OS version 26.3 ⸻ ⚠ Why This Matters for Enterprise IT 1️⃣ BYOD Risk Surface Bring-Your-Own-Device policies mean iPhones, iPads, and Macs often connect to corporate networks without full administrative control. A vulnerable device on your network increases lateral movement risk. 2️⃣ Physical Access Isn’t Just “Someone in the Room” Remote tools, compromised Apple IDs, or stolen devices expand the meaning of physical access. 3️⃣ Upgrade Hesitation Is Real Apple’s 26 release introduced major UI changes (including the controversial glass interface). Stability concerns have led some users to delay upgrades — increasing exposure time. Security must outweigh aesthetic or usability concerns. ⸻ 🛠 Enterprise Recommendations • Immediately communicate required upgrade to 26.3 • Enforce OS minimum versions where possible • Review BYOD policies and mobile device controls • Audit Apple device access on corporate networks • Educate users about lost/stolen device risk Youtube Episode 25 - https://lnkd.in/ebEw_Zib YouTube Channel - https://lnkd.in/eUFCpk8V Apple Podcast Link - https://lnkd.in/eKDZpm93 Spotify Link - https://lnkd.in/ekEFx_KE Amazon Podcast Link - https://lnkd.in/ekPB4Pqa Acast Link - https://lnkd.in/ehDHfztt
3
-
Colton Porter
SAINT Technology Services • 3K followers
Your security vendor says everything is running smoothly. But how do you actually verify that claim? I've observed a troubling pattern: organizations invest heavily in security contracts, then rely entirely on vendor self-reporting for performance validation. This creates a fundamental conflict of interest. Vendor-neutral oversight changes this dynamic completely. Independent assessment validates whether your security providers are meeting contractual obligations, maintaining required coverage levels, and delivering promised outcomes. It's the difference between hoping your investment is working and knowing it is. The strongest security programs separate vendor management from vendor validation. One party delivers the service, another independently verifies the results. For intelligence-driven vendor oversight: intelligence@greyshieldgroup.com #ThirdPartyRisk #ContractCompliance #SecurityGovernance #SecurityOperations
-
Meisam Eslahi, Ph.D.
EC-Council Global Services • 78K followers
Sick SOC: A Practical Checklist of Symptoms! That SOC that looks operational (alerts, dashboards, tools) but lacks strategy, visibility, and repeatable response, so it quietly fails. Yeah… that’s called a sick SOC. I love the term “Sick SOC” — framed by Reza A. in his article, highlighting key metrics and warning signs that indicate your SOC isn’t operating at its best quality. • Strategic misalignment • Process & governance breakdown • Visibility & detection gaps • Knowledge & capability gaps vs threats • Architecture & technical implementation flaws • People & culture You can’t cure a sick SOC with more alerts; you cure it with clarity, coverage, and capability: https://lnkd.in/g9k63pfF If you want to make that checklist more “complete” and more usable in real SOC assessments, I’d add these categories: • Service management + customer alignment (SOC as a product) • Detection engineering lifecycle • Data quality management (not just “data sources”) • Identity-centric operations (where modern incidents live) • Resilience + readiness • Third-party / supply-chain visibility I don't know what you heard about me! I practice, test, learn in public, and share what actually works ... daily and free! Threat hunting 101 series on YouTube: https://lnkd.in/g7D4pTVk Daily Cyber Drops on Medium: https://lnkd.in/gsekf7kB Nothing Cyber. Keep hunting. #cybersecurity #threathunting #threatdetection #opensource #tips #career #blueteam #soc #socanalyst #skillsdevelopment #careergrowth #IR #dataanalysis #incidentresponse #ai
31
2 Comments -
Cole Kennedy
TestifySec • 6K followers
493 out of 494 SOC 2 reports. Nearly identical. Same paragraphs. Same grammatical errors. Only the company name changed. That was Delve. A $300M compliance producing copied audit reports at scale. Hundreds of companies are now trying to prove to their auditors that their compliance posture is actually real. This is the thing that nags at me. AI is going to write most of the code. And if that's true, the code should be the first thing you interview when building a compliance program. Not your engineers filling out spreadsheets. The code itself. We built TestifySec for this. Version 3.0 shipped last week. It reads your source code, your infrastructure, your CI/CD pipelines. Produces SSPs with citations down to the file and line number. Finds your data stores, identity services, crypto, cloud infra. Classifies boundaries and maps everything to NIST. Your engineers don't get tapped on the shoulder. Every build step is cryptographically attested with Sigstore and Archivista. Policies are enforced before deployment. Multi-provider AI code review (Claude, Gemini, Codex) runs on every PR and blocks merge on critical findings. The platform identifies gaps in your compliance posture and prioritizes them by authorization impact. We partner and integrate with most tools (including OSCAL), for example excel docs can be inputs or outputs. We also support and partner with GRC like Vanta and Secureframe so they get source-of-truth data pulled from your actual code and pipelines. If you got caught up in the Delve situation: send us your SOC 2 documentation. We'll run it against your codebase and show you where your compliance claims match reality and where they don't. 30 days of full platform access. Your auditors shouldn't have to take your word for it. Neither should you.
43
14 Comments -
Daniel Young
Circadian Risk Inc. • 9K followers
Here’s a pattern I’m seeing more often: More sites. More assessments. More reporting expectations. Same headcount. Security teams are being asked to scale output without scaling structure. So what happens? Assessments become episodic. Reporting takes too long. Prioritization becomes subjective. And leaders spend more time translating risk than reducing it. This isn’t a capability issue. It’s an architecture issue. At some point, physical security has to operate with the same operational discipline as finance and IT. Otherwise it stays in permanent catch-up mode. For security people overseeing medium to large portfolios (20+ sites): What’s currently your biggest bottleneck volume, visibility, or validation? And why do you think this is?
5
1 Comment
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top contentOthers named Nick Galbreath in United States
-
Nick Galbreath
Chattanooga, TN -
Nick Galbreath
Westerville, OH -
Nick Galbreath
Ooltewah, TN -
Nick Galbreath
Greater Bend Area
6 others named Nick Galbreath in United States are on LinkedIn
See others named Nick Galbreath