Over the past few months, I’ve been knee-deep building an LLM-powered assistant with memory, long-term context, RAG, and the uncanny ability to break every time I so much as look … Continue reading “Tokenization: yet another thing to worry about in your AI stack”
vulnerability management
tl;dr – A Wonk’s Guide to Effective Vulnerability Management
I published a rather lengthy blog post about the importance of patch management to the success of a security program. Due to the length of the post I thought I’d … Continue reading “tl;dr – A Wonk’s Guide to Effective Vulnerability Management”
A Wonk’s Guide to Effective Vulnerability Management
I’m going to cover something that arguably has the greatest impact on the security posture of an organization and is not something that information security is typically responsible for. It’s … Continue reading “A Wonk’s Guide to Effective Vulnerability Management”
Trying to capture cost per vulnerability patched and why I don’t believe it’s a good idea
This post is part experiment, part memorializing a short conversation I had with Sasha Romanosky (one of the creators of CVSS). I have more thoughts on the subject of the … Continue reading “Trying to capture cost per vulnerability patched and why I don’t believe it’s a good idea”