Todd A. Jacobs | Pragmatic Cybersecurity

65 Followers
90 Following
173 Posts
Executive Director, Theia Institute ✪ Chief Information Technology Officer, CodeGnome Consulting ✪ AI Governance ✪ Cybersecurity ✪ Strategic Policy ✪ Board & C-Suite Advisories ✪ Keynote Speaker ✪ Panel Facilitator
Verificationhttps://gist.githubusercontent.com/todd-a-jacobs/280f046b804df6da00ce260eb8db7024/raw/41ca3ef349d71f2c8073c610b3b6c28c9557c933/infosec_exchange_verification.html
Theia Institute™ Think Tankhttps://www.theiathinktank.com/
LinkedIn, Personalhttps://www.linkedin.com/in/todd-a-jacobs/
LinkedIn, Company Pagehttps://www.linkedin.com/company/theia-institute-think-tank
CodeGnome Consultinghttps://www.codegnome.com/

Define Your AI Use Cases Before Your Metrics

Companies need to start reframing #AI #metrics like utilization rates of specific AI systems (which they often think of as #COTS tools anyway) based on #use_cases, not as a one-to-many tech solution for every problem domain. There'd be a lot fewer corporate implementation failures if they thought of AI systems as "hammers and screwdrivers" suited to particular tasks rather than as Swiss Army knives that are generically suited to an arbitrary and/or ill-defined set of objectives.

Celebrating New Credential

I'm celebrating a new credential. I'm also celebrating the people who made it possible.

I'm proud to have received my Theia Institute Founder's Badge yesterday. It demonstrates two years of work with some truly brilliant and inspiring people, all of whom are not only "Emerging Technology Thought Leaders" but also deserving of the title of "Visionary Founder."

Sharing Credit with Others

While I still work for Theia Institute, I don't consider this my honor. The real honor is in standing on the shoulders of giants like my friends and colleages there including (in LinkedIn's pseudo-alphabetical order): Barak Engel, Daniel Kinon, Doug Shannon, Lisa Palmer, Jim Desmond, and Q. Wade Billings.

A lot of credit also goes to donors, business leaders, conference organizers, educators, journalists, and others who not only believed in Theia's mission, but have actively supported us over the years. That list would be too long for this post, but they each deserve their day in the sun too. I hope everyone who made took part realizes the real honor is theirs.

Related Links

The new #IBM_Granite 4.0 #Micro_AI model is now available for #beta_testing. First impressions: it's decent for its intended use case, but unsuitable for novices because it requires pre- and post-processing to avoid silly typo-induced hallucinations about imaginary products like "IBM Branite" even at Q8_0. Here's an easy fix for power users:

---
system_prompt:
coherence:
preprocess: [autocorrect_input, fix_spelling]
postprocess: check_coherence

https://huggingface.co/ibm-granite/granite-4.0-micro

ibm-granite/granite-4.0-micro · Hugging Face

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

I boosted several posts about this already, but since people keep asking if I've seen it....

MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for a whole lot of other uses. There isn't really anyone else left who does this, and it's typically been work that is paid for and supported by the US government, which is a major consumer of this information, btw.

I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.

https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015_7001_70RSAT20D00000001_7001

MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, https://github.com/CVEProject

Yosry Barsoum, vice president and director at MITRE's Center for Securing the Homeland, said:

“On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE as a global resource.”

USAspending.gov

The Artificial Intelligence and Data Act (AIDA) – Companion document

Table of contents Introduction Canada and the global artificial intelligence (AI) landscape Why now is the time for a responsible AI framework in Canada Canada's approach and consultation timeline How the Artificial Intelligence and Data act will work High-impact AI systems: considerations and sys

I will be moderating an executive round table via Zoom from 3:00-4:30pm US/Eastern tomorrow for The Ortus Club. The topics are ones I’m always passionate about: #cybersecurity & #businessresilience.

This is a peer-driven round table. No one’s pitching anything. The goal is to bring a broad spectrum of industry luminaries together to share their experiences, insights, and collectively brainstorm about ways to future-proof our security strategies.

The round table is open to IT & cybersecurity leaders in North America. Space is limited, but there are still a few no-cost seats remaining for the #thoughtleaders in my extended network. You can sign up at the link below, but the clock is ticking.

No matter how well-attended these events are, it’s always more fun with a friendly face or two in the crowd. I hope yours will be one of them, and look forward to seeing you there!

https://www.linkedin.com/posts/todd-a-jacobs_why-legacy-cybersecurity-is-putting-your-activity-7310488468139200512-nodq

Why Legacy Cybersecurity is Putting Your Business at Risk—And How to Build… | Todd A. Jacobs

I will be moderating an executive round table via Zoom from 3:00-4:30pm US/Eastern tomorrow for The Ortus Club - Executive Knowledge Sharing. The topics are ones I’m always passionate about: #cybersecurity & #businessresilience. This is a peer-driven round table. No one’s pitching anything. The goal is to bring a broad spectrum of industry luminaries together to share their experiences, insights, and collectively brainstorm about ways to future-proof our security strategies. The round table is open to IT & cybersecurity leaders in North America. Space is limited, but there are still a few no-cost seats remaining for the #thoughtleaders in my extended network. You can sign up at the link below, but the clock is ticking. No matter how well-attended these events are, it’s always more fun with a friendly face or two in the crowd. I hope yours will be one of them, and look forward to seeing you there! https://lnkd.in/ePaFaJDs

Not a single Republican is going to say anything about POTUS's shameful treatment of veterans? Especially those most in need? All cowards. This is hard to read without wincing, and it's an utter disgrace for the United States to treat its veterans this way.

"Late in February, as the Trump administration ramped up its quest to transform the federal government, a psychiatrist who treats veterans was directed to her new workstation — and was incredulous."

"She was required, under a new return-to-office policy, to conduct virtual psychotherapy with her patients from one of 13 cubicles in a large open office space, the kind of setup used for call centers. Other staff might overhear the sessions, or appear on the patient’s screen as they passed on their way to the bathroom and break room."

"The psychiatrist was stunned. Her patients suffered from disorders like schizophrenia and bipolar disorder. Treating them from her home office, it had taken many months to earn their trust. This new arrangement, she said, violated a core ethical tenet of mental health care: the guarantee of privacy."

"When the doctor asked how she was expected to safeguard patient privacy, a supervisor suggested she purchase privacy screens and a white noise machine. “I’m ready to walk away if it comes to it,” she wrote to her manager, in a text message shared with The New York Times. “I get it,” the manager replied. “Many of us are ready to walk away.”

"Scenes like this have been unfolding in Veterans Affairs facilities across the country in recent weeks, as therapy and other mental health services have been thrown into turmoil amid the dramatic changes ordered by President Trump and pushed by Elon Musk’s Department of Government Efficiency."

"Among the most consequential orders is the requirement that thousands of mental health providers, including many who were hired for fully remote positions, now work full time from federal office space. This is a jarring policy reversal for the V.A., which pioneered the practice of virtual health care two decades ago as a way to reach isolated veterans, long before the pandemic made telehealth the preferred mode of treatment for many Americans."

"As the first wave of providers reports to offices where there is simply not enough room to accommodate them, many found no way to ensure patient privacy, health workers said. Some have filed complaints, warning that the arrangement violates ethics regulations and medical privacy laws. At the same time, layoffs of at least 1,900 probationary employees are thinning out already stressed services that assist veterans who are homeless or suicidal."

"In more than three dozen interviews, current and recently terminated mental health workers at the V.A. described a period of rapid, chaotic behind-the-scenes change. Many agreed to speak on the condition of anonymity because they want to continue to serve veterans, and feared retribution from the Trump administration."

"Clinicians warn that the changes will degrade mental health treatment at the V.A., which already has severe staffing shortages. Some expect to see a mass exodus of sought-after specialists, like psychiatrists and psychologists. They expect wait times to increase, and veterans to eventually seek treatment outside the agency."

https://www.nytimes.com/2025/03/22/us/politics/veterans-affairs-mental-health-doge.html

Trump and DOGE Propel V.A. Mental Health System Into Turmoil

A chaotic restructuring order threatens to degrade services for veterans of wars in Vietnam, Iraq and Afghanistan.

The New York Times

Mozilla flamed by Firefox fans after promises to not sell their data go up in smoke

Open source browser maker ties itself up in legalese and explanations Mozilla this week asked Firefox users to abide by new Terms of Use, and updated its Privacy Notice as well as an FAQ – only to quickly issue a clarification that it isn’t actually claiming ownership of user data.…
#theregister #IT
https://go.theregister.com/feed/www.theregister.com/2025/03/02/mozilla_introduces_terms_of_use/

Mozilla flamed by Firefox fans after promises to not sell their data go up in smoke

: Open source browser maker ties itself up in legalese and explanations

The Register

#FrameChallenge: #ShadowAI is no different from any other form of #ShadowIT.

Shadow IT is a fancy way of saying "individuals or teams doing stuff without going through channels." It can be a headache for #cybersecurity, #datagovernance, and #riskmanagement groups in heavily-regulated environments. However, self-serve IT is also a great "canary in the coal mine" for identifying areas where a company's processes have failed to deliver value to customers or internal stakeholders, or where current tools and processes are seen internally as blocking innovation or limiting productivity.

Compliance doesn't equal security, and security for its own sake doesn't usually deliver market value—unless you're selling security products or services, of course. So, if people are bypassing routine channels to implement solutions directly rather than requesting new centrally-managed capabilities, it's probably time to review and improve your current policies, standards, and guidelines.

Good reviews address the current friction points of your existing processes. More importantly, they shine a light on the perceived value proposition of the solutions that people are implementing themselves to solve day-to-day work challenges. During reviews, remember that the goal is to facilitate value creation within the organization's risk tolerance, not to avoid adaptation!

The risks of "shadow AI" are absolutely identical to the other risks inherent in data and systems protection, including the risks of #BYOD. These things are inevitable when business units respond to market change faster than the larger organization can adapt. The controls to successfully address those risks are all exactly the same, too.

https://www.linkedin.com/posts/pradeeps_shadow-ai-is-already-inside-your-business-activity-7300883716002693122-36xV

Shadow AI Is Already Inside Your Business, and It’s a Ticking Time… | Pradeep Sanyal | 18 comments

Shadow AI Is Already Inside Your Business, and It’s a Ticking Time Bomb Employees aren’t waiting for IT approval. They are quietly using AI tools, often paying for them out of pocket, to speed up their work. This underground adoption of AI, known as Shadow AI, is spreading fast. And it is a massive risk. What’s Really Happening? • Employees are pasting confidential data into AI chatbots without realizing where it is stored. • Sales teams are using unvetted AI tools to draft contracts, risking compliance violations. • Junior developers are relying on AI-generated code that might be riddled with security flaws. The Consequences Could Be Devastating ⚠️ Leaked Data: What goes into an AI tool does not always stay private. Employees might be feeding proprietary information to models that retain and reuse it. ⚠️ Regulatory Nightmares: Unapproved AI use could mean violating GDPR, HIPAA, or internal compliance policies without leadership even knowing. ⚠️ AI Hallucinations in Critical Decisions: Without human oversight, businesses could act on false or misleading AI outputs. This Is Not About Banning AI, It Is About Controlling It Instead of playing whack-a-mole with unauthorized tools, companies need to own their AI strategy: ✔ Deploy Enterprise-Grade AI – Give employees secure, approved AI tools so they do not go rogue. ✔ Set Clear AI Policies – Define what is allowed, what is not, and train employees on responsible AI use. ✔ Keep Humans in the Loop – AI should assist, not replace human judgment in critical business decisions. Shadow AI is already inside your company. The question is, will you take control before it takes control of you? H/T Zara Zhang | 18 comments on LinkedIn

It's gratifying to see my insights about the #techEconomy—especially #ITlayoffs in #cybersecurity and #softwareDevelopment partly driven by the current #AI hype cycle—amplified by peers & media.

"AI can't support what it doesn't know," says James Stanger, the chief technology evangelist at CompTIA, a nonprofit trade association for the US IT industry…"If you've got toxic companies that are interested in that binge-and-purge, on-and-off hiring of developers, I'm not sure they're going to create very good products." (Hoover)

It supports my own #codingAI #metrics that show a human solving a problem the AI never completed even with 400% more time & expert prompting. Confirmation bias? Possibly. Feeling seen & heard? You bet!

  • Hoover, A. 2025. The career ladder for software engineers is collapsing. Business Insider. https://www.businessinsider.com/career-ladder-software-engineers-collapsing-ai-google-meta-coding-2025-2

  • Jacobs, T.A. 2025. AI can’t replace IT professionals yet. LinkedIn. https://www.linkedin.com/posts/todd-a-jacobs_layoffs-itprofessionals-ai-activity-7298780638222929921-XuOA

  • The career ladder for software engineers is collapsing

    In the age of artificial intelligence, entry-level coders are doomed. But some engineers are thriving.

    Business Insider