AI is making commodity software nearly free to produce, exposing security vendors without real moats. Feature lists stopped being a reliable signal of which products will hold their position as commoditization sorts the market. If you were anxious about "SaaSpocalypse," here's a practical way to understand and handle it:

A seven-dimension rubric from Ben Vierck scores software products from 1 to 3 across each dimension. Three cybersecurity-specific dynamics raise scores for products with compounding defensibility. For example, an EDR platform with a shared data layer can score 20 out of 21 because its dimensions reinforce each other. Enterprise buyers generate telemetry that sharpens detection, which strengthens the compliance posture that attracts the next buyer.

Product managers and founders can apply the rubric to their own product, while buyers can apply it to their vendor shortlist. A low score names a dimension that needs investment, or a vendor likely to be bundled, absorbed, or replaced. Running the exercise honestly identifies the gaps worth examining.

https://zeltser.com/scoring-security-product-strategy

#cybersecurity #infosec #productmanagement #AI #securityleadership

Scoring Your Security Product Strategy in the AI Era

AI has made commodity software easy to produce, leaving traditional SaaS exposed. Applied to cybersecurity, a seven-dimension rubric scores security product strategies to help leaders identify weaknesses and strengths.

Lenny Zeltser

Now you can receive my blog posts via email. Go ahead and sign up: https://zeltser.com/newsletter

I've enjoyed writing more frequently and deeply than I have in recent years, and I'm glad to have more ways to get those articles in front of readers who want them.

All of my posts will continue to reside on my site, but I want to make it easy for people to read them in a way that works for them, whether on social media, in their RSS reader, or in their email inbox.

I decided to maintain my own website and newsletter platform rather than using services such as Medium and Substack so I can shape the reading experience and keep it free of paywalls and ads.

#infosec #cybersecurity #securityleadership

Lenny Zeltser's Newsletter

Subscribe to get new posts by email. Cybersecurity, mostly.

Lenny Zeltser

Nothing weakens a security culture faster than executive shortcut syndrome.๐Ÿ’ก

#CyberSecurity #InformationSecurity #Infosec #Compliance #GRC #CyberRisk #CyberAwareness #SecurityLeadership #ISMS #CISO

We invest hours analyzing a security risk, and that effort makes us overvalue the recommendation. An executive who hasn't shared that analysis weighs the same risk differently, and they might be right.

https://zeltser.com/rejected-security-recommendations

#cybersecurity #securityleadership #CISO #infosec

When Executives Reject Your Security Recommendation

A rejected security recommendation feels personal, but it often reflects competing demands the security team doesn't fully see. Knowing how to act on that reality helps the CISO become someone the business trusts with its priorities.

Lenny Zeltser

As we automate more security work, stakeholders trust what they can see. Making them feel secure is as much our job as making them secure.

https://zeltser.com/importance-of-feeling-secure

#cybersecurity #infosec #securityleadership

The Importance of Feeling Secure

Security teams that focus only on being secure, without making protections visible, risk losing stakeholder confidence. Nobody trusts what they can't see, whether that's automated defenses, AI-driven tools, or competent but quiet leadership.

Lenny Zeltser

When DevOps overwhelmed security reviews, the same velocity let teams patch in minutes instead of waiting for quarterly releases. Vibe coding by non-developers is the next shift where that speed works in our favor.

https://zeltser.com/security-governance-vibe-coding

#cybersecurity #infosec #securityleadership #AI

Security Governance at the Speed of Vibe Coding

Employees who've never written code now build production apps using AI, without security review, dependency scanning, or enterprise oversight. The SaaS and DevOps transitions give security teams a starting governance approach for this.

Lenny Zeltser

๐Ÿง Turn your team into threat hunters, one dice roll at a time ๐Ÿ’ฅ

๐ŸŽฒ ๐——๐—จ๐—ก๐—š๐—˜๐—ข๐—ก๐—ฆ & ๐——๐—ฅ๐—”๐—š๐—ข๐—ก๐—ฆ: ๐—ง๐—›๐—˜ ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—œ๐—ง๐—ฌ ๐—ฃ๐—ข๐—ช๐—˜๐—ฅ ๐—ง๐—ข๐—ข๐—Ÿ ๐—ฌ๐—ข๐—จ ๐——๐—œ๐——๐—กโ€™๐—ง ๐—ž๐—ก๐—ข๐—ช ๐—ฌ๐—ข๐—จ ๐—ก๐—˜๐—˜๐——๐—˜๐—— - Klaus Agnoletti ( @klausagnoletti ) & Glen Sorensen ๐Ÿ›ก๏ธ

Roleplaying isnโ€™t just for nerds, itโ€™s a proven method for building real security muscle. This talk reveals how structured tabletop roleplaying games unlock deeper learning, improve team cohesion, and turn abstract security concepts into lived experience. By simulating incident response, threat modeling, and zero-trust design through narrative-driven play, teams develop adaptive thinking, shared mental models, and faster decision-making under pressure.

Klaus Agnoletti https://www.linkedin.com/in/agnoletti/ is a freelance storytelling cyber security advisor, co-founder of BSides Kรธbenhavn, neurodiversity advocate, and architect of playful security transformation through narrative and gamification.

Glen Sorensen https://pretalx.com/bsidesluxembourg-2026/speaker/J3PRCC/ is a Solutions Engineer at DeleteMe, former vCISO, and incident master for HackBack Gaming. 20+ years in security engineering, GRC, and operations. Passionate about OSINT, AI-powered social engineering, and using tabletop games to train real-world response.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #GamifiedSecurity #CyberTraining #IncidentResponse #RolePlaying #SecurityLeadership #InfosecEducation #PlayToLearn

We adapted security governance to SaaS adoption and DevOps velocity. Vibe coding by non-developers is the next comparable shift, and those transitions give us a starting approach, even though the timeline is shorter.

https://zeltser.com/security-governance-vibe-coding

#cybersecurity #infosec #securityleadership #AI

Security Governance at the Speed of Vibe Coding

Employees who've never written code now build production apps using AI, without security review, dependency scanning, or enterprise oversight. The SaaS and DevOps transitions give security teams a starting governance approach for this.

Lenny Zeltser