<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/rss">
    <channel>
        <title>
            IT Brew
        </title>
        <link>
            https://www.itbrew.com
        </link>
        <description>
            From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 3x weekly newsletter, virtual events with industry experts, and digital guides.
        </description>
        <language>
            en-US
        </language>
        <image>
            <title>
                IT Brew
            </title>
            <url>
                https://morningbrew.com/rss-icon.png
            </url>
            <link>
                https://www.itbrew.com
            </link>
        </image>
        <pubDate>
            Sat, 19 Sep 2026 21:29:17 +0000
        </pubDate>
        <lastBuildDate>
            Sat, 19 Sep 2026 21:29:17 +0000
        </lastBuildDate>
        <docs>
            https://validator.w3.org/feed/docs/rss2.html
        </docs>
        <copyright>
            Copyright 2026 Morning Brew Inc. All Rights Reserved.
        </copyright>
        <atom:link href="https://www.itbrew.com/feed.xml" rel="self"/>
        <item>
            <title>
                <![CDATA[How IT pros should think of AI security risk]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-it-pros-should-think-of-ai-security-risk?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[“We need to have a very different lens on security,” professor tells IT Brew.]]>
            </description>
            <pubDate>
                Fri, 18 Sep 2026 19:21:23 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-it-pros-should-think-of-ai-security-risk
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Threat Detection
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-15/image-e0d1de3a4f933ce1fb899f25973cd15ee110280a-1500x1000-jpg/MBD_09152026_AICybersecurity_01.jpg" alt="Illustration of abstract robotic limbs, eyes, hands, and other bits and pieces depresenting AI and abstract digital shapes being contained by a shiny chain and padlock representing cybersecurity." /><figcaption>Niv Bavarsky</figcaption></figure><section><p>AI risk is all over the news as the public tries to understand the threat that models and agents pose. But for IT teams, the real question is how much the danger changes their security posture, and how to communicate that change to their organizations.</p><p>Recent, well-publicized breaches like <a href="https://www.itbrew.com/stories/models-broke-free-of-their-sandbox-chaos">the Hugging Face attack</a> have highlighted the importance of managing the risk of increasingly capable AI agents. Whether that marks a new risk or an increase in a known one remains an open question.</p><p><strong>Changing environment. </strong>Ramy Rahman, senior solutions engineer at ArmorCode, told IT Brew that he sees the potential for damage as real and worth planning for. The new agentic swarms are fundamentally different from older bots that lacked the capabilities of modern AI.</p><p>Communicating that change in power and capability outside of the IT team, though, can be daunting.</p><p>“We can make bots that scrape your website and harbor data and cache images,” Rahman said. “But now, we’re talking about agentic workflows or automated agents, and the difference between those types of verbiages is what is a difficult thing to explain; if you talk about something that has an agentic workflow or agentic AI, you now have to redefine it.”</p><p><strong>Viewpoints matter. </strong>A correct assessment of the threat is important. That’s how Aya Ibrahim, senior fellow for economic and national security at the AI Now Institute, sees the future of response in a new era of agentic danger. Ibrahim rejects the idea of “rogue or autonomous models,” she told IT Brew, because AI simply does what it’s programmed to do.</p><p>“Just because you can’t predict the exact sequence or all of the means by which they’re going to leverage those capacities in service of the tasks that you assign them, or the task that they’re given is imprecise or poorly worded, or is deployed in a setting that doesn’t have the kinds of safeguards and controls that you would otherwise have…that does not mean that they are rogue,” Ibrahim said.</p><p>Proper awareness is also front of mind for Santa Clara University Professor Ram Bala, who told IT Brew that due to “the probabilistic nature of these systems” there might be unintended consequences requiring security awareness that adapts to a new reality.</p><p>“These are very different computing systems with very different capabilities,” Bala said. “We need to have a very different lens on security.”</p><p><strong>Who’s in control? </strong>For all its power and capabilities, AI is still subject to governance (or lack thereof), which makes humans working with the technology the real “threat”: responsibility lies in those in charge.</p><p>“Do not assume that these companies are acting responsibly,” Ibrahim said. “If you assume that, that means you have to double down on your own sense of guarding your own systems—being proactive about identifying potential risk factors and threats.”</p><p>For IT pros looking to implement changes in security posture—or just enforcing existing rules and regulations—it’s critical to remember that agents maywill introduce new forms of risk into IT systems similar to existing human risks, including verification and code vulnerabilities. As Bala put it, the key is to utilize AI in detection so it can catch negative actions and behaviors and resolve them.</p><p>“How do I build my security verification, all of those systems around that idea?” Bala said. “That is a concept that I think most IT folks can actually internalize. I think that’ll be useful.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How new IT managers get up to speed on budgets ]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-new-it-managers-get-up-to-speed-on-budgets?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Turning technical skills into economical ones can be challenging. We spoke with tech pros who’ve climbed the learning curve and learned to think in terms of both technology and ROI.]]>
            </description>
            <pubDate>
                Thu, 17 Sep 2026 16:43:07 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-new-it-managers-get-up-to-speed-on-budgets
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                IT Budgeting
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-12-23/image-a3602f67b281bf648b1ea8f87249f56a458c601d-1500x1000-jpg/IT_Editorial_IT_Budgets_AK_092324.jpg" alt="Hand of a business person handing money over to AI hand with security shield." /><figcaption>Anna Kim</figcaption></figure><section><p>In the early ’90s, Egon Rinderer would spend his mornings at a US Department of Agriculture facility in Central Illinois as a statistical analysis programmer, running crop projections, and his afternoons as the lab’s one and only IT guy.</p><p>From there, he continued his career at a new company managing a small desktop support team, where he suddenly had to become familiar with a budget—a simple one mostly involving salary reviews and raises, but a new responsibility nonetheless. His budgeting duties grew with his career; a later role saw him overseeing a bigger IT spending plan that included staff payments, as well as tools, software, and outside vendor services.</p><p>That kind of transition can be tough for an IT pro not used to speaking with executives who are always thinking about the bottom line.</p><p>“[Executives] don’t care about lines of code committed per week,” Rinderer, now SVP of public sector and global enterprise at IT operations platform NinjaOne, said. “They care about, how does this tie to revenue? And you’ve got to learn how to speak that language, and that’s a pretty steep learning curve for most people.”</p><p>We spoke with Rinderer and other tech pros who’ve climbed the learning curve and learned to think in terms of both technology and ROI.</p><p><strong>Budgeting 101.</strong> Patrick Brown, CTO of vehicle intelligence infrastructure YASSI, had much to learn about finance and budgets in an executive role, following his many years as a software engineer at various companies.</p><p>“You could probably just go look up ‘financial acronyms,’ and I think that entire list is what I didn’t know,” Brown said.</p><p>In his first proposed budget, he set a “wide estimate” of necessary infrastructure to do business: capital expenditures like laptops and hardware, along with the cloud expenses. Setting IT expectations, Brown warned, might also mean adding in less obvious, extra costs that guarantee resiliency, including privacy measures, data warehousing, and backups.</p><p>However, not all organizations are willing to part with the funds for an evolving tech stack. A report from Spiceworks and Aberdeen Research found that 55% of surveyed companies in North America and Europe planned to increase their IT budgets in 2026—a decrease from 62% in 2025.</p><p>AI is also adding cost pressures to organizations’ bottom lines, with just <a href="https://futurumgroup.com/press-release/46-9-of-enterprises-report-ai-spend-over-budget-in-2h-2026/">under half (47%)</a> exceeding their spending estimates for the technology, according to a recent study from tech advisory Futurum.</p><p>But given organizations’ determination to integrate AI into as many workflows as possible, a budget-minded manager may need to understand AI-related cost considerations, Brown noted. For example, they may need to have a discussion with their CFO about the rising cost of dedicated machines for training AI models.</p><p>“Give them realistic expectations that you are unlikely to exceed unless you are taking on additional customers and revenue than what those expectations set out,” Brown said. “Because it’s really hard for a business, especially early on, to plan to have that current budget, and then sort of have the rug pulled out from under them.”</p><p><strong>Do mean to brag. </strong>Working in an industry constantly labeled a “cost center,” Rinderer frequently has his team members build a brag sheet: a display of IT wins that builds credibility for the next year’s budget request. It could be something as simple as, “the team built X and X resulted in Y dollars.”</p><p>“Those brag sheets are what I use to build my deck,” he told IT Brew. “I’m building it into the basis for my budget ask.”</p><p>To narrow down needs, Rinderer recommended that budget items demonstrate a benefit to a whole customer base, come with predetermined success metrics, and can be supported easily. IT leaders can conduct a periodic audit to understand the work that’s taking up the majority of a team’s time, along with what infrastructure pieces or tooling can be added (or eliminated) to help.</p><p>“There has to be a shared consciousness on that. The team generally knows what’s needed. If they’re not telling you, there’s a different problem that exists there,” he said.</p><p><strong>Let’s negotiate. </strong>The budgeting job requires another skill for IT pros, according to Rinderer: selling the IT team’s work in a way that a CFO can appreciate. For Rinderer, sharpening that skill meant connecting with sales leaders and reading books on interpersonal communication and psychology.</p><p>Brown, too, noted the importance of communicating with IT team members—and making sure their ideas are heard—while fostering those ideas for leadership that could potentially earn revenue.</p><p>“My advice would be to explore their ideas with them. Never dismiss them outright, even if it isn’t immediately obvious that it’s in the budget. I think that demoralizes teams…It discourages them from bringing those up to you,” he said.</p><p>To get up to speed, Brown found mentors—the company’s CEO and CFO, for example—and wasn’t afraid to ask them questions, even if he didn’t know an acronym.</p><p>“If you can establish the relationships with your coworkers, such that you feel like you’re open and honest, especially in areas where you are ignorant of topics,” Brown said. “I think that it goes a long way.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[AI threats and risk are changing how we see the technology—what does that mean for IT pros?]]>
            </title>
            <link>
                https://www.itbrew.com/stories/ai-threats-and-risk-are-changing-how-we-see-the-technology-what-does-that-mean-for-it-pros?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[“The capabilities of these systems have been on an upward swing,” professor says. ]]>
            </description>
            <pubDate>
                Thu, 17 Sep 2026 13:44:38 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/ai-threats-and-risk-are-changing-how-we-see-the-technology-what-does-that-mean-for-it-pros
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Strategy
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-07-17/image-2e218d35a0d180a14fb596feac8e68a71993939f-1500x1000-jpg/MBD-SundaySpecial-DesignBrew-AILogos-0726.jpg" alt="OpenAI logo, Kurt Vonnegut&apos;s Asterisk, Claude logo" /><figcaption>Morning Brew Inc.</figcaption></figure><section><p>A long-simmering sense of public mistrust in AI finally boiled over this month, leading the tech industry to recalculate how it builds the technology—although much of the danger may stem from decisions about deployment and safeguards.</p><p>After researcher Jacob Coxon <a href="https://www.morningbrew.com/stories/anthropic-researcher-quits-warns-ai-could-kill-us">publicly quit his position</a> at Anthropic on September 8, warning that the company was being irresponsible in its stewardship of its AI models and careless with the danger they pose, fears that AI could pose an existential threat to humanity overtook the public discourse.</p><p>As Uncle Ben told Peter Parker, with great power comes great responsibility. That’s a potential lesson for an AI industry deploying autonomous agents without proper guardrails, said Ramy Rahman, senior solutions engineer at ArmorCode, and it needs to change.</p><p>“The challenge now is we really need to up our game when it comes to extending the right amount of privilege to the AI and holding its hand through the process, which turns out to be extremely difficult when you have something that is solving mathematical problems that are at speed,” Rahman said. “Humans are not capturing the risks quickly enough.”</p><p><strong>Change is coming. </strong>Politicians in Washington are moving to restrain AI companies, and public <a href="https://news.gallup.com/poll/712751/americans-cool-toward.aspx">trust in the industry is low</a>. CEOs like OpenAI’s Sam Altman and Anthropic’s Dario Amodei are calling for <a href="https://www.morningbrew.com/stories/prominent-ceos-called-for-ai-development-to-slow-down">a slowdown</a> in model development—though it’s unclear how exactly this would happen—along with third party (but not necessarily governmental) oversight.</p><p>To Aya Ibrahim, senior fellow for economic and national security at the AI Now Institute, corporate calls for pacing and third-party controls are more a ditching of responsibility than anything else. For IT pros, that means paying close attention to how AI companies are managing the risk, especially when teams are expected to continue to work with their products.</p><p>“It requires certain safeguards, it requires certain data practices, certain hygiene, cybersecurity practices, protections, access control, all of that,” Ibrahim said. “A lot of the stories that we have seen over the past few weeks would suggest that all of those things I just named are apparently an afterthought to many people building the technology.”</p><p><strong>Threat detected. </strong>The level of overall threat from these models and agents is debatable, with some experts telling the public they believe AI will lead to a 10% or higher danger of human extinction in the next decade. More skeptical voices are urging caution while acknowledging the longstanding risks presented by powerful models.</p><p>Warnings should be taken with a grain of salt, said Santa Clara University Professor Ram Bala, whose work focuses on AI and the AI industry. Bala told IT Brew that the “extinction-level risks” cited by Coxon and others are overblown, and that Amodei’s warnings are more about the power of the models.</p><p>“The capabilities of these systems have been on an upward swing—I can see the trajectory, compared to a year ago or two years ago,” Bala said. “It’s not only the other capabilities increasing…my own experience with working with systems like these at scale is that they provide a lot of benefits, but they also need to be reliable and they raise the risk level of bad things happening.”</p><p>A lack of proper controls at the top level doesn’t mean that IT pros should stop using the models altogether, Rahman said, in part because staff will reject a total shutdown. Instead, they need to be careful and to institute necessary restrictions on the ground.</p><p>“You can partially stop some usage, but I think you’re going to find that you’ll get a lot more pushback there,” Rahman told IT Brew. “We need to be able to get guardrails and administration of it more finely tuned and controlled so that people can adopt it safely.”</p><p></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Data centers face shortage of professionals with experience]]>
            </title>
            <link>
                https://www.itbrew.com/stories/data-centers-face-shortage-of-professionals-with-experience?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Addressing the current workforce woes for operational data centers isn’t as simple as just hiring more people. Although firms across the industry are increasingly confident in their ability to train and hire junior-level workers across a range of roles, the labor shortage is far more intractable—and increasingly acute—when it comes to experienced, senior-level industry veterans who are essential for reliable data center operations.]]>
            </description>
            <pubDate>
                Thu, 17 Sep 2026 12:57:42 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/data-centers-face-shortage-of-professionals-with-experience
            </guid>
            <dc:creator>
                Billy Hurley and Dan Rabb
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Data Centers
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-09/image-0b0487caf9b0d66441a257e35337ebe1a705a590-1500x1000-jpg/ITB_DataCenterLaborShortage_SM_09082026.jpg" alt="Photo collage showing a row of data center servers in shades of purple next to a green circuit board above a pink tear-off flyer that says &quot;Looking for a job?&quot;" /><figcaption>Illustration: Morning Brew Inc., Photos: Unsplash, Adobe Stock</figcaption></figure><section><p><em>The following article is a collaboration between IT Brew and commercial real estate news platform <a href="https://www.bisnow.com/">Bisnow</a>.</em></p><p>It was Thanksgiving week in 2022—a time when most employees are hard to find, let alone critical pieces of data center power infrastructure. And Kurt Bogle needed a transformer.</p><p>Bogle, then a senior regional director of critical facilities operations at NTT Global Data Centers, oversaw seven operational buildings around Chicago and Virginia and a staff of about 150 people. After a transformer failed a test, Bogle had to find a replacement and coordinate a swap with the onsite managers—all without disrupting service.</p><p>Thankfully, Bogle found a spare, but his experience illustrates the importance of systems thinkers at data centers who know how to acquire the resources necessary to maintain data centers’ high uptime expectations. Given supply-chain limitations and a steady buildout of data centers, such expertise is more crucial than ever—and there are signs a labor shortage is underway, threatening Big Tech’s AI ambitions and the reliable operation of mission-critical facilities. </p><p>“It’s going to get stretched,” Bogle said. “There is a need to continue to develop, build, mentor these leaders so that they can take on the roles of today and tomorrow.”</p><p>Already, more than half of data center operators now report difficulties finding qualified candidates for vacant roles, a significant jump from last year, according to a report published recently by industry think-tank <a href="https://uptimeinstitute.com/about-ui/press-releases/16th-annual-2026-global-data-center-survey-deployment-of-high-density-racks-rising-fast-operators-face-continued-recruiting-and-retention-pressures">Uptime Institute</a>. Firms are competing for a limited pool of electricians, mechanical technicians, and other highly specialized operations staff needed to keep <a href="https://www.itbrew.com/resources/glossary/data-center-modernization">increasingly complex</a> facilities up and running around the clock.</p><p>Big Tech’s AI ambitions are accelerating the race to build new capacity, creating a labor shortage not only <a href="https://www.bisnow.com/news/national/top-talent/without-100s-of-thousands-of-new-workers-construction-industry-faces-workforce-shortage-cliff-132728">for the construction workers</a> building the facilities, but for the qualified workers needed to staff data centers once they are operational.</p><p>Addressing these workforce woes for operational data centers isn’t as simple as just hiring more people. Although firms across the industry are increasingly confident in their ability to train and hire junior-level workers across a range of roles, the labor shortage is far more intractable—and increasingly acute—when it comes to workers like Bogle: experienced, senior-level industry veterans who are essential for reliable data center operations.</p><p>Without an adequate pipeline of these seasoned data center pros, experts say, systems in finance, healthcare, and other sectors that rely on these mission-critical facilities face a higher risk of outages and a cascading “blast radius” of failures that could cause widespread disruption and billions in economic damage.</p><p>Even as companies scramble to develop career pathways and training programs to cultivate a new generation of senior-level leaders, the process could take years to bear fruit. And that may be time that the industry doesn’t have.</p><p>“There is an expert shortage because we are not replenishing the talent pipeline,” said Rose Weinschenk, a researcher at Uptime Institute who coauthored the group’s report. “[That] is exactly why we see these companies trying to keep pushing retirement for a lot of these experts that they already do have further and further away and just clinging to them as long as they can.”</p><p><strong>Rapid growth. </strong>The US already has more than 4,000 operational data centers, with nearly 3,000 additional facilities either under construction or planned, <a href="https://www.axios.com/2025/12/18/data-center-growth-map-states">according to Axios</a>. At the same time, these facilities are getting <a href="https://www.itbrew.com/resources/glossary/data-center-infrastructure">dramatically larger</a>, with campus-scale projects increasingly measured in gigawatts rather than megawatts.</p><p>Each of these facilities requires teams of operators, facilities engineers, electricians, and mechanical technicians. As a result, demand has surged for workers with these speciality skillsets, placing further strain on a labor pool that was already stretched thin before the AI boom.</p><p>Compounding the industry’s broader labor pinch is the sudden geographic expansion of data center development.</p><p>Until the last few years, nearly all facilities were concentrated in a handful of established hubs, the largest being Northern Virginia. Large-scale data centers were rarely built outside of major metro areas. But as power has become scarce in traditional markets—and because AI training workloads don’t have the latency concerns that require other data centers to be located near large population centers—developers <a href="https://www.bisnow.com/news/national/data-center-development/data-center-math-special-project-133721">have increasingly pursued sites</a> where large blocks of electricity are available.</p><p>This shift has fueled the rise of gigawatt-scale campuses for tech giants like Amazon, Oracle, and Meta in rural locations, with projects built or planned in places like Richland Parish, Louisiana; Abilene, Texas; Ellendale, North Dakota, and Lea County, New Mexico. Commercial real estate company JLL <a href="https://www.jll.com/en-us/insights/market-dynamics/north-america-data-centers">reported last month</a> that 77% of data center capacity under construction is in “frontier markets,” not traditional hubs.</p><p>Established data center markets have existing experienced labor pools and talent pipelines, even if they are falling short of the sector’s current needs. But for rural projects, those ecosystems don’t exist at all, forcing operators to try to build specialized workforces from the ground up fast enough to deliver the speed to market demanded by tech giants amid the AI arms race.</p><p>“Our clients are hyperscalers or colocation providers, and they’re doing work everywhere, so when they ask us to do work in South Dakota, we don’t have people there,” said Kurt Haglund, chief operating officer of Virginia-based data center operations specialist Compu Dynamics. “Filling the work wherever it happens to be is probably the biggest challenge.”</p><p><strong>Greatest need. </strong>Whether in Northern Virginia or North Dakota, the industry’s greatest hiring need is entry-level and mid-level operations roles: everything from security and equipment monitoring to electricians and facilities engineers.</p><p>Operators responding to Uptime Institute’s survey reported the greatest skill gap in electrical roles—which increased 13 percentage points since 2023—plus junior-level operations, operations and mechanical positions.</p><p>Industry leaders acknowledge they’re playing catch-up when it comes to building talent pipelines for these roles. Many data center firms are now investing heavily in their own training programs and workforce partnerships colleges.</p><p>Compu Dynamics is among the companies that has shifted its approach. Rather than searching only for workers with existing data center experience, the firm has devoted significant resources over the past 24 months to recruiting candidates with transferable technical skills and providing the specialized training needed to work in mission-critical data centers. It’s a strategy Haglund says has proven successful.</p><p>For Applied Digital, developing a hyperscale campus in Ellendale, North Dakota, required building a workforce from scratch in a region with no existing data center talent. According to CEO Wes Cummins, the company ultimately hired up to 85% of its employees locally, relying on in-house training and training partnerships with equipment vendors and with nearby colleges to prepare workers for highly specialized roles.</p><p>But while data center operators might be succeeding at building talent pipelines for junior positions, they face a far more difficult challenge in addressing the acute shortage of industry veterans qualified for senior-level roles.</p><p>The need for senior leadership is critical across every aspect of data center operations. In a mission-critical environment with little room for failure, seemingly mundane tasks require experienced pros who understand how to minimize risk and avoid catastrophe.</p><p>Even transporting equipment requires a veteran’s understanding, suggested John Ahlering, AI engineering and team lead at data-center services provider Salute. With close to three decades in data centers, Ahlering creates task hazard assessments when guiding his team through the choreography of moving heavy, expensive equipment—or even a simple cable.</p><p>“One of the most dangerous parts in a data center where damage can happen is doing transportation. I’ve learned that in 30 years,” Ahlering said.</p><p>The veteran data center workforce isn’t just being spread thin; its ranks may actually be shrinking due to the <a href="https://www.investopedia.com/silver-tsunami-8418065">“Silver Tsunami,”</a> with a disproportionately large share of workers approaching retirement age. As these veteran operators, engineers, and managers leave the industry, companies risk losing critical institutional knowledge exactly when it’s needed most.</p><p>This kind of operational expertise can’t be developed overnight.</p><p>Applied Digital’s Cummins says senior positions account for the roughly 15% of his workforce he can’t hire locally at his Ellendale campus. Instead, he is forced to convince senior leaders from other firms to relocate to North Dakota.</p><p>“There’s no training for experience,” Cummins said. “You need enough people that have had the experience, that have had an issue at a data center, that know how to deal with it, that know how to fix it.”</p><p>Other firms have had to lure employees with dramatic salary increases, with some roles now <a href="https://www.isgpartners.com/blog/reports/2026-data-center-compensation-intelligence?utm_">commanding</a> up to $300,000 annually. Last year, 28% of data center operators reported having staff hired away by competitors, according to Uptime.</p><p>As a result, operators across the industry are increasing salaries to retain the employees they already have or to prevent aging workers from retiring. It’s a bidding war that experts say may address operators’ short- term needs, but does little to solve the industry’s increasingly acute labor woes.</p><p>“I have been solicited many times,” Ahlering admitted. “They need those [kinds] of guys who can take the daily ops and make it work, and keep the systems up and running; <em>see</em> the problem before it happens, mitigate this, and take ownership. That’s the key of my job. I have to own everything.”</p><p>Failure to develop more experienced workers like Ahlering could result in diminished data center reliability, industry leaders say, which carries significant consequences extending well beyond the data center and tech sectors. Data centers support a range of essential services, including financial, government, and medical environments. Almost 20% of data center outages result in at least a million dollars in economic damage, according to Uptime.</p><p>In other cases, keeping data centers up and running is a matter of life and death. For example, Ahlering works in a high-security facility that provides critical services to tenants that include medical software systems. “If we were to have a system go down where the doctors do not know the patient’s allergies, they can’t prescribe medicine. These are very critical services we are responsible for,” Ahlering said.</p><p><strong>Growing the future. </strong>The industry’s shortage of experienced workers is, in many ways, a consequence of its failure to retain and develop the employees it already hired. Even as operators brought new workers into the sector, many neglected to create clear career pathways that would keep those employees in the industry long enough to become the senior data center pros now in critically short supply.</p><p>According to Compu Dynamics’ Haglund, turnover rates of 30% have been common across the industry, reflecting a prioritization of replacing junior workers while neglecting retention efforts needed to build a roster of experienced veterans. Only recently have operators begun investing seriously in formal career development and employee retention initiatives.</p><p>At Compu Dynamics, this has meant replacing a traditional HR department with a dedicated talent management division focused on onboarding, mentoring, professional development, and employee culture. New hires are paired with mentors, organized into smaller teams, and given access to structured learning programs that show clearly defined career pathways and how employees can advance within the company.</p><p>This strategy has paid off, according to Haglund. Since fundamentally overhauling its approach to employee development, the company has reduced turnover from around 30% to around 10%.</p><p>“Our goal is if we can’t find raw talent with a lot of experience, then we find raw talent that we can nurture and grow into the people that we’re going to need in the future,” Haglund said.</p><p>Areas with an established data center presence have also begun standing up skills-training initiatives. Virginia, home to almost 700 data centers, has state-supported programs like FastForward. This initiative, established in 2016, offers ways to achieve credentials in skills ranging from commercial driving to welding—many essential to data center buildouts and maintenance.</p><p>While those skills are not senior-level ones, Randall Stamper, associate vice chancellor for career education and workforce programs with the Virginia Community College System, suggested it’s a start: “We can get people what they need to advance into, let’s say, middle management.”</p><p>Amazon Web Services, which has invested over $119 billion in Virginia data center buildouts and maintenance since 2011, including capital and operational expenses related to AWS’s <a href="https://www.itbrew.com/resources/glossary/data-center-infrastructure">data center infrastructure</a>, has used many of FastForward’s participants to build its data centers, and needs more to run the facilities long-term.</p><p>“As you grow out entry-level technicians, now you have to grow a leadership, essentially hierarchy within that organization, because one of the challenges here is we have a huge influx of new people coming into the industry, and so the people who are already in it need skills that are more management skills,” Nicholas Lee-Romagnolo, principal at AWS Economic and Workforce Development, told us. “We need people who have the experience, and that can be a real opportunity for people who are in the data centers.”</p><p>These efforts may ultimately prove effective, but growing the ranks of senior leadership is a process that, by its nature, will take years. In the meantime, data centers are desperate for those workers today.</p><p>Kris Beevers, co-founder and CEO of infrastructure management company NetBox Labs, sees pros who had been working in IT infrastructure moving into senior data center positions, like site-reliability engineers migrating to data center work, as a “trial by fire.” Similarly, firms like Compu Dynamics are hiring workers from other fields with “transferable” skill sets who, with some training, can effectively fill certain roles traditionally filled by more experienced workers.</p><p><strong>Automate this! </strong>Beevers also sees <a href="https://www.itbrew.com/stories/2026/03/17/automation-changing-human-data-centers">automation</a> playing a significant role by helping to reduce workforce needs; for example, assisting with tasks previously conducted by senior workers, such as determining a data center’s bill of materials and assigning and running workloads once the components are plugged in.</p><p>“You really shouldn’t have to have an engineer at a drafting table figuring out, ‘How am I going to lay out these racks so that the floor doesn’t collapse?’ That’s an entirely automatable problem,” he said. “It is impossible to build the kind of data center scale that we’re hearing about in 2026 or even the last few years without substantial automation.”</p><p>Additionally, some within the industry say that the rapid evolution of data center systems is narrowing the knowledge gap between senior employees and their less experienced peers.</p><p>AI has dramatically changed the IT hardware within data centers, increased rack densities and forced the widespread adoption of liquid cooling and other technologies operations staff rarely encountered just three years ago. As a result, even long-time workers need to update their own skillsets significantly. Ahlering, for example, has upskilled on liquid cooling and its ability to maintain rack temperatures.</p><p>But industry leaders say experienced workers bring value beyond just their technical knowledge—and beyond what automation can provide. Without a kind of “guiding light” from senior leaders who have seen a challenge or two, “you get more of a lag in decision-making because you have people that are struggling to make those decisions,” Bogle said.</p><p>While automation may help address short term workforce needs, Uptime’s Weinschenk said it may ultimately hinder the skill development of junior employees who could become leaders in the future.</p><p>“What tends to happen is then there won’t necessarily be a holistic understanding of the systems,” she said. “The skill development seems to be limited to a small number of people who are deemed to be future subject matter experts, and then you have a lot of turnover for these junior-level roles who are doing things like walking around, checking to make scanning QR codes, and making sure that everything is where it’s supposed to be.”</p><p>Bogle has prioritized this kind of skill development with his more junior colleagues. He likes a crawl-walk-run approach with his staff: have someone run a project; then lead a team; then lead multiple teams. That kind of 1-on-1 leadership, built on years of problem solving, imparts unique knowledge that can prove harder to find than a spare transformer on a holiday weekend.</p><p>“What’s lost if you don’t have the high senior leaders is that mentorship and experience that comes from that mentor,” Bogle said.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[The tech industry is inventing roles faster than companies can name them ]]>
            </title>
            <link>
                https://www.itbrew.com/stories/the-tech-industry-is-inventing-roles-faster-than-companies-can-name-them?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Companies are using job titles that don’t match the roles they’re seeking out.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 20:32:40 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/the-tech-industry-is-inventing-roles-faster-than-companies-can-name-them
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Hiring
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/gif/2024-11-18/image-2dc96c491db7fbb13e609a79a47a9ba498652bcd-700x467-gif/IT_Editorial_Ghost_Jobs_AMK_111824.gif" alt="Gif of &apos;we are hiring&apos; screen disappearing" /><figcaption>Anna Kim</figcaption></figure><section><p>AI job listings are often seeking skills that don’t align with their posted job title.</p><p>That’s according to a recent <a href="https://www.andela.com/research/emergent-roles">study</a> from AI-native talent and services platform Andela, which analyzed 47,101 software job listings posted by companies in the Fortune 500 between March and May. Out of the 1,832 postings for AI and ML engineers, the study found, 53% ask for technical skills that were associated with two other established roles.</p><p>“The AI engineer and the ML engineer right now are two of the most ambiguous job postings that are out there,” Cory Hymel, head of research at Andela, told IT Brew. “And [companies are] hiring for these roles, but they’re not really sure what people should be doing underneath.”</p><p>Andela also observed companies hiring for data scientists, but then asking employed professionals to ship LLM agents.</p><p>“We see companies putting out these job roles and job descriptions, and then the butts get in the seats, and they’re asked to do something drastically different,” Hymel said. “And that puts the individual at a structural disadvantage.”</p><p><strong>Skill bill. </strong>The misalignment between titles and skills in job postings is caused by skills now having a shorter half-life, according to Hymel, who estimates it takes roughly two years for new technology and skills to emerge into the mainstream. While job titles and job descriptions have always had trouble keeping pace with changing skills, Hymel said AI and the speed at which things change is exacerbating the problem.</p><p>“Individuals are having to adapt and grow faster than we’ve ever had to do in the past, but job titles and job descriptions are lagging that trend significantly,” Hymel said.</p><p><strong>Actual new roles.</strong> Andela identified several new tech job titles that have emerged because of AI. One is the role of the <a href="https://www.itbrew.com/resources/glossary/mlops">MLOps</a> pipeline engineer, who Hymel said is tasked with scaling machine-learning models to production.</p><p>“This MLOps pipeline engineer is really one to go in and say, ‘How do we take this and how do we put some guardrails around and actually take what might be an AI pilot and scale it out to the masses?’” Hymel said.</p><p>Another new role is the LLM application engineer, who bridges the AI and ML engineer and software architect role. Other budding roles include:</p><p></p><ul><li><strong>Docs-as-code engineers:</strong> A role that blends technical writing with <a href="https://www.itbrew.com/resources/glossary/devops">DevOps</a> engineering and technical program management.</li><li><strong>Product front-end engineers:</strong> In addition to building front-end components, professionals in this role also handle product management responsibilities such as backlogs and feature priorities.</li><li><strong><a href="https://www.itbrew.com/resources/glossary/data-lakehouse">Lakehouse</a> analytics engineers:</strong> This position combines data engineering, data architecture, and business intelligence development.</li></ul><p></p><p>Hymel said companies continue to hire for these new positions without using the correct job title: “They’re hiring for this work, but they’re calling it…old roles.”</p><p><strong>How to hire for the roles you actually want.</strong> Hymel said companies need a better understanding of what skills are required for their organization’s specific workflows. He suggested that companies take inventory of current skills within their workforces to identify gaps that need to be filled.</p><p>“The second piece to that is to say, ‘Where do you want to go as a company? What are you looking to build? What is your roadmap looking like for the next …five years?” he said.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How today’s vibe coders fight model drift]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-todays-vibe-coders-fight-model-drift?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[IT leads share how they update, and make sure their updates didn’t break anything.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 19:36:06 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-todays-vibe-coders-fight-model-drift
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Vibe Coding
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-07-17/image-8b7e6572c60b550f57fde259c20e72dfcfedfb02-6000x3600-jpg/VibecodinglaptopinterfaceconversationalAIprogrammingtoolintuitivecodegenerationworkflow.CreativedeveloperconceptAIassistanceandcodingelementsmodernorganicvectorillustration" alt="vibe coding collage" /><figcaption>Bestforbest/Getty Images</figcaption></figure><section><p>Like clouds, balloons, and that story you told at the company holiday party, AI models drift.</p><p>Employees across all industries are relying on <a href="https://www.itbrew.com/resources/glossary/vibe-coding">vibe coding</a> via plain-language prompts. While a global 2025 Stack Overflow study found that almost 12% of developers admit to “vibe coding” in their daily work, non-tech employees are utilizing chatbots to code, as well.</p><p>There’s a significant downside to vibe-coding’s speed, however: a careless prompt could allow an AI-powered app to act beyond its original intentions, producing wrong outputs or breaking at a crucial moment.</p><p>We spoke with creators of vibe-coded CRMs and coffeebots about how they make sure their AI ideas don’t sail off into the distance.</p><p><strong>What is model drift? </strong>Stanford’s Human-Centered Artificial Intelligence team defines “model drift” as “when a <a href="https://www.techbrew.com/resources/glossary/machine-learning">machine learning</a> model’s performance degrades over time because the real-world data it encounters has changed from the data it was originally trained on.”</p><p>For example, <a href="https://www.ibm.com/think/topics/model-drift">as IBM notes</a>, new data might be inserted in imperial measurements, baffling the underlying model trained on metrics.</p><p>Promptable coding tools like Cursor and Lovable offer local project guidelines, customized instructions written by the vibe coder and not pulled from a data source on the junk-filled internet. <a href="https://www.itbrew.com/stories/how-to-guide-a-coding-agent">System prompts</a>, which can be attached as files or even placed at the top of every new query, offer starting-point rules (like how data must be structured<em>) </em>that can anchor a meandering model.</p><p><strong>The customer (platform) isn’t always right. </strong>Christopher Lee, co-founder of Local Blueprint, a marketing and tech services company for the home services industry, helped a roofing company vibe-code a customer relationship management (CRM) tool.</p><p>But a vibe-coded CRM isn’t built in a day: Lee had to test versions, add updates, and then test that those updates didn’t upset the model’s reasoning. Lee works with many industries, each with their own data structure; he knows that an LLM trained on plumbing info may produce unexpectedly different results when suddenly connected without guidance to roofing data sources.</p><p>To fight that drift, he reviews three major areas following any changes:</p><ul><li>The user interface. <em>Did a button disappear? Is text scrollable?</em></li><li>The database. (Lee will “skim” the DB to note unexpected data structures.)</li><li>Business process. <em>Is the desired objective achieved?</em></li></ul><p>And the answer to drift, he told us, is specificity. An open-ended prompt like “create a table where I can store different types of shingles” won’t cut it.<em> </em>Lee’s prompts incorporate the specific rows and columns required, along with potential variables (for example, pricing, manufacturers, or color). He’d even create a sample table for the LLM’s review in the desired format.</p><p>“Vibe coding does not mean that you can just type in ‘build me a CRM’ and then just be done with it. You have to be very particular about exactly what you’re trying to achieve and what your requirements are,” Lee said, adding that he also keeps his prompts “very focused on one business area with one business outcome.”</p><p>During the development phase, Lee said, he also uses multiple coding tools, including Codex and Claude Code, to compare outputs; after that, he has regular security and code checks.</p><p>Following any change to the code or data, he asks users to “break” the app. Employees may find, for example, that a button doesn’t work on mobile, or a new data type leads to an error calculation. Following such discoveries, Lee re-prompts the model, often by writing a new field validation rule, or providing a copy-and-pasted reference to the bug in question (or screenshots and an explanation of what needs fixing).</p><p>A typical <a href="https://www.itbrew.com/resources/glossary/software-development-life-cycle">software development life cycle</a> features many important steps before “deployment,” including tasks like defining requirements and testing. Lee believes that a vibe-coded app still requires the same practices, and he recommends that prompts never lead to immediate production code. To that end, he has a QA test environment, and often asks the AI to provide a detailed design before doing any official building.</p><p><strong>Good vibes? </strong><a href="https://www.ibm.com/think/insights/vibe-coding-security-risks">In June</a>, IBM described how an increase in vibe coding causes a spike in security issues, including data exposures and hardcoded passwords.</p><p>Yet plenty of IT pros are vibing out despite the risks. Mike Toole, director of security and IT at cybersecurity platform Blumira, has used prompts to build his company’s internal <a href="https://www.itbrew.com/stories/2026/02/17/some-it-pros-don-t-need-saas-vendors">Coffeebot</a>—a coworker meetup tool that has been online for about a year now.</p><p>Toole’s maintenance relies on simple measurements. He sees the monitoring for HTTP response status codes as an easy win—200 means a successful connection and 400 means <em>not so much</em>. Analysis can be done via web server logs and firewalls.</p><p>And there’s always one metric that clearly shows if an app is working properly, or if it’s drifted from the user’s workflow entirely: engagement.</p><p>“If people stop using it, we’ll probably shut it off,” Toole said.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How vibe coding is impacting business in the long term]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-vibe-coding-is-impacting-business-in-the-long-term?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Utilizing AI to help software development is swiftly becoming normalized across organizations, leaving IT pros to manage any potential problems.  Companies need to consider their level of liability when choosing to deploy vibe coding, Mike Wehrs, TieTechnology COO, told IT Brew. Issues can vary, and depend on the relative newness of vibe coding to the tech stack, as well as the talent of those using it.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 16:50:31 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-vibe-coding-is-impacting-business-in-the-long-term
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Vibe Coding
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-16/image-ab41e7a191da1dd6e9d85402b6fface1ba96807b-1500x1000-jpg/b7c254034c47ac159763302431916f2f62952715-1500x1000.jpg" alt="image of a black figure with glasses in front of colorful streamers on a brown background with the title card &quot;head of vibe&quot; in front of the figure" /><figcaption>Francis Scialabba</figcaption></figure><section><p>When you’re flying a commercial plane, the autopilot is on almost all of the time. But that doesn’t mean there aren’t two human pilots in the cockpit at all times, making sure that things are going right.</p><p>That’s an analogy Quickbase CTO Jon Kennedy uses to describe the role of engineers and other IT professionals in <a href="https://www.itbrew.com/resources/glossary/vibe-coding">vibe coding</a>.</p><p>“You have to know what the airplane’s doing,” Kennedy said. “At any moment, you might need to take control and hand-fly.”</p><p><strong>Vibe-coding is having a moment.</strong> Utilizing AI to help software development is swiftly becoming normalized across organizations, leaving IT pros to manage any potential problems.</p><p>Companies need to consider their level of liability when choosing to deploy vibe coding, Mike Wehrs, TieTechnology COO, told IT Brew. Issues can vary, and depend on the relative newness of vibe coding to the tech stack, as well as the talent of those using it.</p><p>Wehrs noted that users who employ a diversity of tactics, like using multiple models, are in a much better position.</p><p>“The people who use multiple instances of AIs and don’t rely on one [model] in parallel dramatically cut down the failure rate and dramatically cut down on the amount of errors that are allowed in,” Wehrs said.</p><p><strong>Drop in a bucket. </strong>As Kennedy put it, there are roughly two buckets of users: in bucket A, the professional developer who uses AI to accentuate their work; in bucket B, the inexperienced staffer using the technology with a weaker understanding of its capabilities. Both groups need awareness of what they’re dealing with.</p><p>“You still need to understand the stuff you’re building, the code you’re writing—you need to review the code, it does make mistakes, it lies to you, it does dumb things,” Kennedy said. “You, as a professional software developer who are developing for a platform that businesses rely on to keep their business running, you need to make sure that everything you’re checking in, you understand, and has been tested and it is sound.”</p><p><strong>Taking care. </strong>While more experienced users are putting AI to work developing infrastructure and managing busywork, those with a less developer-heavy background are running into challenges related to security.</p><p>Security is a particular concern for Eran Kinsbruner, VP of product marketing at Checkmarx. With a lack of consistently used and applied guardrails in production, the technology can generate vulnerabilities in code.</p><p>“The AI won’t recommend security practices while [you’re] building software; it’s not baked into the LLM models today,” Kinsbruner told IT Brew. “If you are not instructing AI, you won’t get secure code time after time.”</p><p>Like having two pilots in the cockpit, coding still needs humans in the loop—securing infrastructure as needed.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[What is workflow identity hijacking?]]>
            </title>
            <link>
                https://www.itbrew.com/stories/what-is-workflow-identity-hijacking?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Noma Labs has unearthed a new AI workflow attack vector that enables attackers to access sensitive information just by asking for it.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 14:01:42 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/what-is-workflow-identity-hijacking
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Prompt Injection Defense
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-03-19/image-d3ff8fdcde6d701ad28b4745f76a8319d290ec1d-1500x1000-png/01-Cyber-Security.png" alt="Computer with mouse arrows on a square grid" /><figcaption>Francis Scialabba</figcaption></figure><section><p>Closed mouths don’t get fed—but open ones do, regardless if they are malicious or not.</p><p>A Noma Security researcher has discovered an AI workflow attack vector that enables cybercriminals to obtain sensitive information just by asking for it.</p><p><strong>How it works.</strong> The vector, which was detailed in a Sept. 9 Noma Labs <a href="https://noma.security/noma-labs/workflow-identity-hijacking-the-silent-backdoor-in-ai-workflows">blog post</a>, is known as “workflow identity hijacking,” and occurs when malicious actors send seemingly ordinary requests for sensitive information to unauthenticated entry points (think web forms or support inboxes) that generate a response via AI. In a workflow identity hijacking, an attacker, for example, may use an organization’s public support email to request and receive sensitive information from a finance director’s most recent email.</p><p>Sasi Levi, security research lead at Noma Labs, told IT Brew the security gap is a result of the AI workflow using privileges the attacker does not possess.</p><p>“There are a lot of identity problem issues here because the task is doing what it needs to do, but it doesn’t know that the attacker is the persona that runs this and not the developer,” Levi said. “And this is a very big issue.”</p><p><strong>Prompt season.</strong> IT Brew has previously reported on <a href="https://www.itbrew.com/stories/2025/08/25/cybersecurity-tester-joey-melo-wants-to-break-your-ai-with-a-prompt">prompt injections</a>, an AI attack vector where malicious actors try to deceive LLMs into sharing sensitive information or bypassing policies and instructions. Levi, in his blog post, said workflow identity hijackings differ from <a href="https://www.itbrew.com/stories/2025/11/07/cisco-shows-llms-get-worn-down-by-multi-turn-prompt-attacks">prompt injections</a> because the attacker is exploiting two different things.</p><p>“Prompt injection manipulates how the model follows instructions, while workflow identity hijacking exploits whose authority the workflow uses when executing a valid request,” he wrote.</p><p>Prompt injections and workflow identity hijacking aren’t the only threats enterprises need to watch out for. In July, IT Brew reported on the rise of <a href="https://www.itbrew.com/stories/meet-the-newest-ai-security-threat-token-torching">token torching</a>, which occurs when attackers use malicious prompts to drain a company of its AI tokens.</p><p><strong>How to protect against workflow identity hijacks.</strong> In his blog post, Levi said Noma Labs identified and reported a workflow identity hijacking risk vector within Google Workflows. According to Noma Labs, Google has since acknowledged its report and confirmed a fix.</p><p>To mitigate the risk of workflow identity hijacking, Levi said organizations should make sure that their AI workflows verify the domain of a request before acting on it.</p><p>“Basically, I’m telling the first task of the workflow, ‘Please check who sent the email, and if you see that the email doesn’t come from our organization, please drop it,’” he said.</p><p>But that’s not all. Levi, in an email, added that companies should treat LLM outputs as untrusted inputs, and should include an “explicit authorization checkpoint between what the model produces and any sensitive action the workflow performs.”</p><p>“Finally, organizations need to think about their entire workflow architecture, not just whether the model itself is secure. Model guardrails should never be or become your authorization layer.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to catch and kill a rogue agent]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-catch-and-kill-a-rogue-agent?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Amid high-profile AI security incidents, IT leaders explain how to keep agents in line.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 14:00:16 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-catch-and-kill-a-rogue-agent
            </guid>
            <dc:creator>
                Patrick Kulp
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Autonomous Systems Security
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-03-16/image-a0e4a2c1e8276b61f57f89a45fb1466264f968c6-1500x1000-jpg/ITB_CybersecurityAI_SM_03162026.jpg" alt="Photo illustration showing robotic hands typing on a keyboard, with a lock and text input field." /><figcaption>Illustration: Morning Brew Design, Photos: Adobe Stock</figcaption></figure><section><p>Before a business like a consultancy or consumer mortgage lender rolls out a new agentic system, they might turn to Scale AI to try to break it.</p><p>The startup, which has tried to <a href="https://www.forbes.com/sites/richardnieva/2026/05/14/scale-meta-deal/">remake itself</a> after a <a href="https://www.businessinsider.com/meta-scale-ai-15-billion-alexandr-wang-acquihire-ai-2025-6">Meta quasi-acquihire</a> last year, keeps a stable of human red teamers who simulate the intentional or unwitting antagonists an AI agent might face in the wild—casual users, trolls, hackers, or misaligned agents.</p><p>“Are [users] encouraging an agent, and is the agent simulating access it shouldn’t have? Is it claiming that it’s a human when it’s not? Is it granting a loan on terms that would be illegal in an enterprise context?” Patrick Oathout, Scale’s red team and safety lead, told us of scenarios they simulate.</p><p>Exercises like these are even more important in the agentic era, when companies may not start with a comprehensive picture of all the ways networks of autonomous bots can go awry, according to Oathout. Case in point is a headline-grabbing <a href="https://www.infosecurity-magazine.com/news/anthropic-another-cybersecurity/">string</a> of <a href="https://www.reuters.com/legal/litigation/openai-agents-attacked-software-service-rubygems-before-hugging-face-incident-2026-09-11/">incidents</a> in which sophisticated AI agents went rogue, slipping out of test environments and conducting complex attacks, which caught even their leading-edge makers off guard.</p><p>A <a href="https://www.cio.com/article/4198035/it-leaders-confident-but-cooked-when-it-comes-to-rogue-ai-agents.html">recent survey</a> from observability vendor WanAware found that nine in 10 IT leaders said they could root out rogue agents, but only 26% thought they could measure their impact within minutes. Meanwhile, a CrowdStrike report said the amount of risky behavior detected from agents is growing at 2.5 times the rate of that from humans.</p><p>As researchers <a href="https://www.nbcnews.com/tech/security/two-ai-researchers-leave-anthropic-google-safety-concerns-rcna597086">quit top AI companies</a> with warnings of grave risk, and CEOs <a href="https://www.npr.org/2026/09/14/nx-s1-5968079/ai-industry-leaders-call-for-development-to-slow-down-after-recent-safety-concerns">propose a slowdown</a> in frontier research, IT leaders say it’s time to rethink how companies oversee their growing networks of agents.</p><p>“The choice now is either [frontier companies] say, well, we can’t trace reasoning; we can’t reach full alignment; models are starting to build themselves; they’re becoming smarter than humans; we’ve got to pause,” Ariel Assaraf, CEO and co-founder of observability platform Coralogix, said. “Or we’ve got to rethink the entire framework of how we create prevention and alerting.”</p><h3><strong>Beyond guardrails</strong></h3><p>It’s not enough to put in place simple guardrails and run evaluations, according to Assaraf. He said companies need to think in terms of policy—more comprehensive sets of rules that include reasoning behind a guardrail and auditing every action.</p><p>The key is to spell out the reasoning and priority behind each rule, because an AI agent might decide to circumvent one guardrail, hell-bent in its pursuit of another conflicting objective, according to Assaraf.</p><p>“If I have a bunch of different guardrails and they contradict—so I have a guardrail that says, ‘Don’t access personal data,’ and I have a guardrail that says, ‘Only answer the user who’s asked a question,’ and I gotta access that data—what takes precedence when I define that policy?” Assaraf said.</p><p>At Scale, Oathout’s team starts each project by writing out a “harm taxonomy.” The document details the more obvious areas agents shouldn’t touch—violence, deepfakes—as well as company or industry-specific risks—don’t talk about a competitor, don’t give bad legal advice. There are usually around 15 categories, Oathout said, and Scale writes examples of safe, bad, and borderline output for each one.</p><p>Then come several rounds of testing, starting with automated prompts and followed by human red teamers.</p><p>“We’ll roleplay. We’ll create a fake world for the model, and then we’ll obfuscate,” Oathout said. “We’ll use pseudocode, and we’ll simulate that we are part of the chain of thought as well, and sometimes that tricks the model, too, and it loses what we’re typing versus what it itself is thinking.”</p><p>In a <a href="https://scale.com/blog/why-you-need-to-red-team-your-enterprise-ai">recent project</a> for a professional services firm, Scale’s human red team caused the agents to break their rules 68% of the time in the course of a multi-turn task.</p><h3><strong>A kill switch</strong></h3><p>So what do you do with a rogue agent when you catch it in the act? Just like there have been <a href="https://www.bbc.com/news/articles/cqgk5e2j0gg8o">calls for model providers</a> to create an AI kill switch, JetStream Security COO and co-founder Jared Phipps said it’s important that enterprises install their own.</p><p>JetStream, an AI governance platform, creates a “blueprint” of all of the different agents a company has and in what “realm” they should be operating. If an agent strays from that realm, JetStream can isolate and reboot or regenerate that particular agent without shutting down the whole system, Phipps said.</p><p>“So if you see a flight scheduler and it’s trying to go out and order computers, then you clearly have a misguided intent,” Phipps said.</p><p>As companies add more and more agents to complex networks of workflows, shutting down an entire system can be very disruptive, Phipps said. More often than not, a rogue agent isn’t orchestrating a grand cyberattack, but rather stuck in a logic loop that <a href="https://www.itbrew.com/stories/meet-the-newest-ai-security-threat-token-torching">burns through tokens</a>.</p><p>“It’s like going into an assembly plant and shutting down the entire plant because one machine had an issue,” Phipps said. “You really want to be able to shut down the one machine and regenerate and reboot that.”</p><p>To flag when an agent may be starting to drift, JetStream monitors the reasoning processes of agents and the communication between them and compares that to approved behavior, Phipps said.</p><p>“All of that is based on semantic capabilities of us understanding intent behind the communication, and behind the logic that’s going across those work streams,” he said, “and then making allow or disallow decisions on those work streams. Every agent has a unique intent and purpose.”</p><p>Oathout said his team looks for certain early clues in an agent’s chain of thought—the step-by-step reasoning it elucidates as it ticks through a task. It might acknowledge the existence of a guardrail there and then find a loophole or break it anyway.</p><p>“We’ll often look for what we call a foot in the door,” Oathout said. “Let’s say you ask the model to give you instructions on how to make a drug—meth, for example. If it offers the recipe at a high level, that might be a foot in the door to then push it further, ask more questions about quantities, specifications.”</p><h3><strong>Monitoring troubles</strong></h3><p>Monitoring the chain of thought and communication between agents is also getting more difficult as networks get bigger and models become more advanced, according to Connor Tabarrok, policy lead at Equistamp, a startup that provides safety evaluations for AI projects.</p><p>For instance, <a href="https://www.transformernews.ai/p/what-is-neuralese-openai-astra-chain-of-thought-recurrent-depth">safety researchers have worried</a> about <a href="https://www.theinformation.com/articles/secret-technique-behind-openais-astra-model-sparks-security-concerns">recent reports</a> that future AI models might no longer spell out their thoughts in natural language, using an efficiency-boosting form of reasoning referred to as “neuralese.” That would be a blow to security researchers’ ability to monitor agents’ behavior and intentions.</p><p>“It’s becoming less easy to monitor over time. And these monitors themselves can also become an attack surface,” Tabarrok said. “So as they’re reading the logs, the way they interpret them can become a vulnerability.”</p><p>Coralogix’s Assaraf said agent reasoning is already becoming less decipherable, and that’s something that observability companies will have to contend with.</p><p>“Reasoning is out already. This is not like a future thing. We don’t know, many times, why agents have done something. That gap is already there,” he said. “So now we’ve got to fix it already. Now as agents develop themselves, become more important and more of a critical infrastructure in our lives, this obviously becomes even more important. I look at this as the next one, two years’ critical mission for observability companies.”</p><p>“I do see a few years of defining the new human guardrails of what is suitable and right for an agent to do, and what’s not, and I think we’re going to miss some value creation from it, but we’re going to obviously benefit [from] much greater things to the extent of people’s fate.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[What is LLMjacking, and why should IT pros care?]]>
            </title>
            <link>
                https://www.itbrew.com/stories/what-is-llmjacking-and-why-should-it-pros-care?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[As anybody who follows cybersecurity knows, when a new technology emerges, it’s usually followed by a threat actor trying to -jack it up.  There’s clickjacking (tricking someone into hitting a disguised URL), sessionjacking (stealing a token to impersonate a user and gain their web access), and DNSjacking (redirecting someone to an attacker-controlled destination). And now, with attackers trying to take over large language models, we have…LLMjacking.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 13:43:00 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/what-is-llmjacking-and-why-should-it-pros-care
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Threat Detection
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-01-20/image-c5d9ff012fe40edcfd30b7f4fe4898c9d93d4dc9-1500x1000-jpg/francis-scialabba-cyberattack-comms-0523.jpg" alt="Red mouse shattering a speech bubble; signifying a cyberattack on comms" /><figcaption>Francis Scialabba</figcaption></figure><section><p>As anybody who follows cybersecurity knows, when a new technology emerges, it’s usually followed by a threat actor trying to -jack it up.</p><p>There’s <a href="https://www.itbrew.com/stories/2025/01/10/security-pro-demos-double-take-on-classic-clickjacking">clickjacking</a> (tricking someone into hitting a disguised URL), <a href="https://www.itbrew.com/stories/2025/09/11/how-vendors-are-responding-to-token-theft">sessionjacking</a> (stealing a token to impersonate a user and gain their web access), and DNSjacking (redirecting someone to an attacker-controlled destination). And now, with attackers trying to take over <a href="https://www.techbrew.com/resources/glossary/large-language-models">large language models</a>, we have…LLMjacking.</p><p>This is more than just freeloadin’ freecoders using compromised access to steal AI services for their personal use: LLMjackers are building attack tools now, too.</p><p><strong>LLMjacked up. </strong>Cloud security company Sysdig (which claims to have coined “LLMjacking” in May 2024) describes the tactic as “using stolen cloud credentials to gain access to a victim’s paid AI model services and leverage the compute power.”</p><p>Crystal Morin, senior cybersecurity strategist at Sysdig, has seen an evolution in how attackers leverage cloud-based LLMs once they obtain access. <a href="https://www.sysdig.com/blog/llmjacking-stolen-cloud-credentials-used-in-new-ai-attack">In 2024</a>, Sysdig observed threat actors employing stolen credentials to gain free access to victims’ AI services for free; later, these attackers spun up new models, then pivoted to underground marketplaces for LLMjacking.</p><p>In a <a href="https://www.sysdig.com/blog/llmjacking-evolved-attackers-are-using-stolen-ai-compute-to-build-offensive-agentic-tools">June blog post</a>, Sysdig noted threat actors using an internet-exposed Ollama model to power an automated attack tool. For Morin, that represents a clear change in purpose, suggesting attackers want to do more than use an LLMjacked model to get a quick answer to a burning question or write an essay.</p><p>“To see [LLMkjacking] go from using someone else’s LLM to do college homework, to using somebody else’s LLM to create an offensive tool, in just a matter of about 24 months, I think is quite a large shift in the evolution,” Morin told IT Brew.</p><p><strong>Sound familiar? </strong>Dan Moore, senior director of CIAM strategy and identity standards at customer identity and access management platform FusionAuth, sees the LLMjacking situation as similar to, another “jack,” cryptojacking, the compute theft used for cryptocurrency mining about a decade ago.</p><p>To help thwart LLMjacking, Moore recommends short-lived credentials, not static <a href="https://www.itbrew.com/resources/glossary/api">API</a> keys, as well as enforcing <a href="https://csrc.nist.gov/glossary/term/least_privilege">least privilege</a>. “You get access to the specific model that you know you need, and maybe you time-bound that,” he said. (Here is guidance from <a href="https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#service-accounts">Anthropic</a>, <a href="https://developers.openai.com/api/docs/guides/workload-identity-federation">OpenAI</a>, and <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/api-keys.html">AWS</a> on time-bound keys, to demonstrate three examples.)</p><p>Also, the prospect of an LLMjack requires a close look at usage across an organization—and price and activity limits may be necessary, according to Morin.</p><p>“If the attacker isn’t automating an extremely high amount of token usage, they might fly under the radar, and you’re not going to see it. But if they’re using 2 billion tokens a day to automate some excessive project that they’re working on, then you may see a spike,” Morin said.</p><p>Morin recommends following authentication practices, including rotating credentials and restricting who can access and stand up AI infrastructure. (OpenAI <a href="https://openai.com/index/advanced-account-security/">this April announced</a> that members of its Trusted Access for Cyber program—practitioners accessing the company’s “most cyber capable and permissive models”—must switch to <a href="https://www.itbrew.com/stories/2025/05/02/can-threat-actors-socially-engineer-their-way-to-a-passkey">passkeys</a> or physical security keys.)</p><p>The Ollama instance could be found on the open internet, according to Sysdig’s blog post, no authentication needed. With unauthenticated model servers, threat actors don’t have to worry about LLM services jacking up the price.</p><p>“Fortunately, we did not see that offensive tool get used against another third party, but it was being tested. It was definitely capable of being used against any kind of vulnerable victim environment,” Morin said. “We expect to see more LLMjacking because these [AI models] are expensive.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Sticking with SaaS over AI—for now—is most realistic path, experts say]]>
            </title>
            <link>
                https://www.itbrew.com/stories/sticking-with-saas-over-ai-for-now-is-most-realistic-path-experts-say?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Do increases in AI capabilities spell the end of software-as-a-service?  That’s a question for IT pros who are struggling to figure out whether SaaS or AI works better for their tech stack, provided there’s room to cut one or the other. Those kinds of business decisions can be complicated; for many organizations, keeping both in the stack will likely continue for the foreseeable future.]]>
            </description>
            <pubDate>
                Wed, 16 Sep 2026 13:33:30 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/sticking-with-saas-over-ai-for-now-is-most-realistic-path-experts-say
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Technology Prioritization
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-08-13/image-3a5a85cd774266a4fdd2edb94de6b5c3a19824bc-6048x4024-jpg/Humanhandholdingreceiptwithrobothandpointingatitandreceiptsandlaptopinbackground" alt="robot hand pointing to receipt" /><figcaption>Karetoria/Getty Images</figcaption></figure><section><p>Do increases in AI capabilities spell the end of <a href="https://www.itbrew.com/resources/glossary/software-as-a-service">software-as-a-service</a>?</p><p>That’s a question for IT pros who are struggling to figure out whether SaaS or AI works better for their tech stack, provided there’s room to cut one or the other. Those kinds of business decisions can be complicated; for many organizations, keeping both in the stack will likely continue for the foreseeable future.</p><p>AI solutions like <a href="https://www.itbrew.com/resources/glossary/vibe-coding">vibe coding</a>, which allow developers to develop internal custom solutions rather than relying on a third-party vendor’s software, have unsettled some of the traditional SaaS market. But, as COO at TieTechnology Mike Wehrs put it to IT Brew, vibing an app only works if it can reliably replace vendor software’s functionality.</p><p>“What’s the downside if this fails? If that entire vibe effort falls apart and doesn’t work, how bad is it going to be?” Wehrs asked. “If it’s really bad, it’s definitely shifting back to SaaS.”</p><p><strong>Numbers game. </strong>While AI’s capabilities have increased, the technology’s potential is still far from fully realized. Studies like Cloudera and Wakefield Research’s the <a href="https://www.cloudera.com/campaign/the-great-ai-re-architecture.html">Great AI Re-Architecture survey</a>, released in August, show that while there’s a hunger to deploy AI, it can run into problems in practice.</p><p>“[Ninety-five percent] of respondents said they have delayed or canceled projects in the last 12 months entirely due to <a href="https://www.itbrew.com/resources/glossary/data-governance">data governance</a>, compliance, or regulatory issues,” the report claims. “And more than half (55%) reported canceling or delaying more than six projects in that time.”</p><p>With 77% “actively using AI in some form,” it’s clear the issue isn’t a lack of enthusiasm, but rather knowing how to effectively integrate the technology into workflows. An <a href="https://keyholesoftware.com/vibe-coding-trends-2026/">analysis of data</a> from Keyhole Software found that 92% of developers are using AI in coding on a daily basis, with nearly half of all new production code—41% to 46%—being AI generated.</p><p>Meanwhile, the SaaS industry continues to chug along. <a href="https://www.statista.com/outlook/tmo/cloud-computing/software-as-a-service/worldwide#revenue">Projections from Statista</a> indicate a growth rate year over year of 11.86%, with predicted revenue rising from $488 billion in 2026 to $855 billion in 2031.</p><p><strong>Stuck in the middle. </strong>For organizations that rely heavily on SaaS, unwinding those products from the tech stack may lead to more problems than it solves.</p><p>Shafqat Islam, president at Optimizely, has a lot of experience choosing software vendors. He told IT Brew that solutions like Salesforce are the kind of SaaS technologies that aren’t worth the trouble trying to DIY; for example, vibe-coding a CRM requires an excessive amount of time and energy.</p><p>“Do I love it? No. Do I like using it? No. Are the screens great? No,” Islam said. “All of it is not great, but we’re never going to replace it because we’re not paying Salesforce or our HR software because the screens are nice—we’re paying for it because it’s totally connected to all the other systems. All our workflows go through it.”</p><p>With that level of institutional entrenchment, SaaS is here to stay for the foreseeable future—and hybrid-minded IT pros will continue to nibble around the edges of what’s possible to vibe code.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Tips and tricks for negotiating with AI vendors]]>
            </title>
            <link>
                https://www.itbrew.com/stories/tips-and-tricks-for-negotiating-with-ai-vendors?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[IT pros have a tough job, and one big stressor is the need to negotiate with third-party AI vendors.  Nonetheless, it’s becoming part of the IT team’s job to deal with vendors and advise higher-ups on how to choose the right service provider. That can be challenging, and often overwhelming, with questions about price, usage, vendor switching, and more.]]>
            </description>
            <pubDate>
                Tue, 15 Sep 2026 20:54:25 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/tips-and-tricks-for-negotiating-with-ai-vendors
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Contract Management
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-06-23/image-d6e71ee6f789929305a43e0d3e5ca1656e33021f-6505x3820-jpg/RobotHoldingaResumeDoingHRWorkVectorIllustration" alt="image of a robot looking at a resume" /><figcaption>Getty Images</figcaption></figure><section><p>IT pros have a tough job, and one big stressor is the need to negotiate with third-party AI vendors.</p><p>Nonetheless, it’s becoming part of the IT team’s job to deal with vendors and advise higher-ups on how to choose the right service provider. That can be challenging, and often overwhelming, with questions about price, usage, vendor switching, and more.</p><p>To help with the process, it’s good to know what to prioritize for negotiations and what questions to ask—and not to ask.</p><p>AI isn’t a strictly “new” technology, said Jack Hogan, VP of advanced growth technologies at SHI International, but it’s increased in importance in recent years. That has meant more responsibility on the shoulders of IT professionals, who are often asked to give feedback on what vendors to work with.</p><p>“AI vendors that are out there range in where they’re adding value across the stack or the chain of how you can apply advanced AI capabilities—perceptive AI and now <a href="https://www.itbrew.com/resources/glossary/generative-ai">generative AI</a>, moving into agentic AI,” Hogan told IT Brew.</p><p><strong>Leverage questions. </strong>In the past year, there’s been a <a href="https://www.itbrew.com/stories/2026/04/24/does-every-company-need-to-be-an-ai-company-now">notable shift</a> to AI integration affecting nearly every aspect of the traditional tech business, with executives referring to the technology as likely the biggest change the industry has seen. That’s forced organizations to become more selective with regard to vendors, which comes with <a href="https://www.itbrew.com/stories/ai-agents-vendor-switching">its own complications</a>.</p><p>“It’s a lot messier than it used to be traditionally,” Gartner VP Analyst Kjell Carlsson told IT Brew in August. “There’s an element of uncertainty that we don’t know how to do migrations in the same kind of way…We’re just not even sure what we need to migrate.”</p><p>Shafqat Islam, president at Optimizely, is the single largest buyer of AI at his company, he told IT Brew. The biggest question Islam encounters is the cost model and pricing levers; with a lack of predictability in the AI space, it’s difficult to find stable ground on how much technology costs on a month-to-month or annual basis.</p><p>“Understanding the pricing model, understanding what the guardrails are, what happens if you go over—the IT pro has to help guide and be a shepherd to the CMO through that,” Islam said. “Maybe ask for more predictability, or ask for constraints.”</p><p>With that type of chaotic approach, an outcome-based pricing model is of interest, in which customers pay per successful completed action (such as the AI resolving a support ticket). The most important thing is to make sure you’re approaching the negotiation with as much information as necessary.</p><p>“If you’re an IT buyer and you’re pushing for outcome-based pricing, you better at least loosely understand what the outcomes are that your business partner cares about,” Islam told IT Brew. “There’s a lot of leverage for the buyer and the IT guy who’s procuring that software.”</p><p><strong>Power up.</strong> The power increase of AI models means that a capability assessment is essential when deciding who to go with, Hogan said. Meaningful improvements need oversight, which requires additional resources, and that has to be part of the equation during the negotiation process.</p><p>“You experiment with it and you create this demo that looks great and it does a bunch of things, then when you take it to the adoption phase, you start to see a bunch of challenges,” Hogan said. “It’s really at that point where you need to have a trusted partner that helps you recognize that the concept is great, but the implementation may have a lot of flaws, and it could have flaws in the form of business risk or even financial risk.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to develop an effective IT disaster recovery plan]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-develop-an-effective-it-disaster-recovery-plan?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[An IT disaster recovery plan is a formal strategy detailing how an organization will respond to an unplanned disaster.]]>
            </description>
            <pubDate>
                Tue, 15 Sep 2026 20:08:39 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-develop-an-effective-it-disaster-recovery-plan
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                BCDR
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-09-30/image-e9c11c43fc9e502f363d428ca6d59ed0c0fb69e8-1500x1000-jpg/ITB-Cyber-Insurance-Questionnaire-FS-0925.jpg" alt="Two hands filling out a digital questionnaire." /><figcaption>Francis Scialabba</figcaption></figure><section><p>If your organization experienced a <a href="https://www.itbrew.com/resources/glossary/ransomware">ransomware</a> attack today, how long would it take to recover?</p><p>That answer is likely dependent on your IT <a href="https://www.itbrew.com/resources/glossary/disaster-recovery">disaster recovery</a> (DR) plan, a formal document that details how an organization will restore IT infrastructure in the event of a disaster. In this context, such a catastrophe can be anything “where the technology interrupts the operations of the business,” according to Michael Sparks, principal cloud operations engineer at Nextworld.</p><p>“That could be something as simple as somebody trips over a cable in a data center,” Sparks said. “In large organizations, that could be a hurricane is bearing down on the East Coast, and a data center is about to get impacted.”</p><p>Sparks said the ultimate goal of the DR plan is to make sure that a business and the technology supporting it can continue to operate after a disruption. IT Brew caught up with several IT pros to understand how to craft an effective plan.</p><p><strong>It’s pretty important.</strong> There are many reasons why a business should prioritize having a solid DR plan. Phil Conway, developer advocate at SandboxAQ, told IT Brew prolonged downtime could prove costly for an organization, and can even inflict reputational damage.</p><p>“It’s not just reputational and cost risk, it’s the risk of that service not being available in the desired state [or] not being brought up securely or quickly,” Conway said. “If you don’t bring [a core foundational service] up in the right configuration, there might be performance issues. You may find that everything runs really slowly [and] your customers complain.”</p><p>Kasey Best, VP of threat research at DNSFilter, added companies without a strong DR plan also risk being unable to recover quickly during a time of need.</p><p>“There’s just a whole bunch of risk that you open yourself up to when all it would have taken was some preplanning,” Best said. “The more crucial your services are and the more all of your services are interconnected or interdependent on each other…the more important disaster recovery is.”</p><p><strong>Best practices.</strong> Before crafting a DR plan, Conway said organizations need to have an understanding of their recovery time objective (RTO), or the maximum amount of time a system can be down before it starts to disrupt a business, and recovery point objective (RPO), or the maximum amount of data loss that can happen during a disaster without impacting the business.</p><p>“Businesses need to think: ‘How quickly do I need to be back up on my feet? What’s the cost to my business if I’m not available? What’s the reputational damage if my services aren’t available?’” Conway said.</p><p>Best added that companies should define their scope of infrastructure and data, and pinpoint the types of disasters they are planning for.</p><p>“Figure out what you’re planning for, identify what depends on that being up, identify if you can back up, and then measure how long it takes you to get back to full operating capacity,” he said. After constructing the DR plan, Best suggested sharing it with tech stakeholders on the frontlines to get additional feedback on whether the strategy is sufficient enough if something goes wrong.</p><p>“You won’t get the same answer you will asking the people on the ground as you will asking their managers typically,” Best said. “I would suggest that you do both. You run the plan past them, and then you say, ‘Alright, this is what you all told me. Now we’re doing a live fire exercise to see if you’re right, and see if the plan changes.’”</p><p>Companies should also have a good understanding of what their full operating capacity might look like post-disaster under a DR plan.</p><p>“If you’ve got 10,000 site visitors, can your backup version handle 10,000 site visitors every hour? Can it only handle 200?” Best said. “When your stuff goes down, a lot of people will be sitting there trying to refresh and get everything up and working. When you come back online, you’re probably going to have more traffic than you normally do. Can you handle that?”</p><p><strong>Testing, testing 1, 2, 3.</strong> After a DR plan is formed, Conway said regular testing is needed to ensure business operations can actually continue in the event of an emergency.</p><p>“You’ve heard of Schrödinger’s cat. There is also Schrödinger’s backup, which is a backup [that’s] neither working nor non-working until you actually try to recover all of the data that’s in it,” Conway said. “The same is true for DR. Unless you test your plan regularly and review it regularly, it’s a potluck as to whether or not it will work when you actually try it for real.”</p><p>Sparks said organizations should practice and get comfortable with a full failover.</p><p>“Figure out how to really, really run your business processes out of whatever that failover state is because until you do that, you’re not going to discover all the systems that people depend on,” Sparks said.</p><p><strong>Revisions. </strong>Finally, Conway said DR plans are “living, breathing documents” that should be continuously updated as needed: “As you adopt new applications, as you open new offices, as the needs of your business changes…you should be looking at the disaster recovery plan and updating it accordingly.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Help desk has your cybersecurity talent. Here’s how to find and encourage it]]>
            </title>
            <link>
                https://www.itbrew.com/stories/help-desk-has-your-cybersecurity-talent-heres-how-to-find-and-encourage-it?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[IT leaders share strategies on how to find and foster help-desk talent and make them into cybersecurity pros. Any transition from help desk to cybersecurity can involve formal and informal efforts that recognize talent and place a person on an international career path. ]]>
            </description>
            <pubDate>
                Tue, 15 Sep 2026 18:04:34 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/help-desk-has-your-cybersecurity-talent-heres-how-to-find-and-encourage-it
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Careers
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-06-03/image-6da68029f59d4c944f245d03b9058247c91ab8e5-5000x3200-jpg/FinancialconsultinginvestmentadvisormentorshiporguidanceforbusinessteamconceptBusinessmanmanagerhandglidingpaperplaneofbanknotewithemployees." alt="Accounting pipeline" /><figcaption>Getty Images</figcaption></figure><section><p>Jim Sherlock found one of his best <a href="https://www.itbrew.com/resources/glossary/penetration-testing">pen testers</a>—the offensive-minded security pros who break down tech vulnerabilities—at the help desk.</p><p>Sherlock’s company at the time, the online learning-assessment platform Pearson, had to prepare for its busiest period of the year: school finals. Sherlock managed Pearson’s product operations before serving as director of information security, compliance, and tech innovation between 2015 and 2021.</p><p>While Pearson prepped for its academic equivalent of the Super Bowl, Sherlock noticed a help desk employee with a knack for capturing user traffic between students’ testing devices and Pearson’s system. That employee was adept at building scripts that replayed that activity, allowing the company to simulate hundreds of thousands of students logging in to take tests.</p><p>Understanding an application through the information it exchanges, beyond what appears in its interface, is valuable for both <a href="https://www.itbrew.com/stories/what-ai-can-and-cannot-do-with-a-load-test">load testing</a> and security testing. Sherlock noted the employee’s skill and steered him to the security side of the house.</p><p>Sherlock remembers asking him: “Why don’t you pretend to be a bad actor that intercepts traffic and modifies student testing behavior over the wire? What can you get the system to do that we might be only enforcing on the client side?”</p><p>Sherlock saw the help desk as an important place for employees to matriculate into all roles throughout the organization, including non-technical jobs like project management and technical ones like software development and cybersecurity.</p><p>Any transition from help desk to cybersecurity, however, can involve formal and informal efforts that recognize talent and place a person on an international career path. Such a career shift also requires connection managers like Sherlock who can spot special skills at the <a href="https://www.itbrew.com/resources/glossary/service-desk">service desk</a> and send them to the right mentors and teams.</p><p>“The key is making sure that you’ve got somebody in a leadership position over a help desk that understands their responsibility to both identify talent and then their their job should be to move them through the org,” Sherlock, now VP of AI and cybersecurity R&amp;D at cybersecurity firm ProCircular, told us.</p><p><strong>Finding and fostering talent. </strong>A Gartner survey conducted in July 2026 found nearly three-quarters of 251 global executives expected their orgs’ cybersecurity function to have a higher proportion of senior and experienced talent, according to Alex Michaels, director analyst with the tech-insights firm. That data point, he added, reveals how cybersecurity leaders are finding it harder to identify and develop entry-level talent, especially with automation (via AI) changing the necessary skills for cybersecurity roles.</p><p>“The more that gets automated, the more that gets forgotten. So, the starting point to effective security analyst is even further than it was yesterday,” he said.</p><p>Here are some of Michaels’s recommendations for steering an organization’s entry-level talent into cybersecurity:</p><ul><li><strong>Gauge interest. </strong>Employers can use internal job marketplaces, champions programs, and employee resource groups to spot who’s attracted to the field. For cybersecurity skills, Sherlock watches for people who have a “natural proclivity for gathering as much data as possible on a system,” and who can break a complex problem into manageable parts.</li><li><strong>Set up shadowing opportunities.</strong> Someone interested in governance could benefit from observing a risk assessment. An aspiring security operations center (SOC) analyst, similarly, may strengthen their expertise by sitting in on a tabletop exercise. Organizations can work with their HR teams to formalize these rotational programs and establish learning objectives.</li><li><strong>Share a clear plan. </strong>Document a cybersecurity hopeful’s short-term and long-term goals. An “IDP,” or individual development plan, can include goals like certifications, instructional classes, and mentorship experiences. Each objective, ideally, should identify the skill, activity, target date, expected outcome, and person responsible for supporting or reviewing it, Michaels wrote in a follow-up email to IT Brew.</li><li><strong>Build accountability.</strong> Organizations can also recognize managers and mentors for providing structured development support<strong>.</strong></li></ul><p>Mentorship and shadowing can also be ad-hoc and informal. Ben Bernstein, manager of the cybersecurity advisors team at agentic security platform Huntress, is grateful for his early-career stop at the University of Rhode Island’s help desk, along with previous work at cybersecurity company Red Canary, which had teams that welcomed questions and allowed more junior employees to look over their senior colleagues’ shoulders.</p><p>“I think that you just need a culture of open-door policies of ‘anybody can basically send a Teams or Slack message to a colleague, whether they’re on the same team, a different team, even if they wear a ‘C’ in their title,’” Bernstein said.</p><p>Many new <a href="https://www.itbrew.com/resources/glossary/devops">DevOps</a> positions opened up when Pearson transitioned years ago from on-prem facilities to AWS cloud environments. Sherlock looked to the help desk for people to “build infrastructure that they used to support.”</p><p>“I was evaluated based on my ability to move individuals out of the help desk into other positions within the company, and that’s really what it should be in a healthy org,” Sherlock said.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Data center moratoriums are sweeping the nation—and IT pros need to be prepared]]>
            </title>
            <link>
                https://www.itbrew.com/stories/data-center-moratoriums-it-preparation?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Though some of the bans are relatively airtight, there are ways to protect compute power.]]>
            </description>
            <pubDate>
                Tue, 15 Sep 2026 15:32:03 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/data-center-moratoriums-it-preparation
            </guid>
            <dc:creator>
                Tricia Crimmins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Data Center Modernization
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-14/image-1d3c95aed5590f7bd55b6a15854e8d25624f02eb-1500x1000-jpg/ITB_DataCenterMoratorium_SM_09142026.jpg" alt="Abstract photo collage of a hexagon pattern with a large hole in the middle, framed by a circuit board, which is framed by a purple-tinted hall of servers in a data center, meant to represent the hole that data center moratoriums are leaving, and that IT professionals will need to deal with." /><figcaption>Illustration: Morning Brew Inc., Photos: Unsplash, Adobe Stock</figcaption></figure><section><p>In a staunchly divided country, Americans are pretty aligned on one thing: <a href="https://www.techbrew.com/stories/ai-data-center-conversation-reaching-fever-pitch">opposition</a> to <a href="https://www.techbrew.com/resources/glossary/data-centers">data centers</a>. IT pros, though, are in a trickier spot because data center moratoriums could spell trouble for orgs that have woven AI tools into various workflows, if the compute power to keep them running doesn’t get built.</p><p>Thus far, 26 states have passed or are considering data center moratoriums and guardrails. Most recently, Pennsylvania Governor Josh Shapiro signed an executive order to ensure anything built there complies with specific environmental and affordability requirements.</p><p>“If you can’t agree to our strict requirements and get the community where you want to build to say ’yes,’ you’re not going to have the Commonwealth’s support either,” Shapiro said in a press release. “These are some of the biggest companies in the world—they can afford to be good neighbors, follow the rules, and do this right.”</p><p>As similar—and stricter—data center bans and limits take effect in states and counties across the country, the legislation could start to affect IT departments’ workflows and budgets. Chiefly, IT professionals will face uncertainty as the availability of compute power shifts. But that doesn’t mean there aren’t ways to get ahead of it.</p><p><strong>The scope of it all. </strong>The effect moratoriums will have on IT pros will depend on the scope of the legislation, which Constellation Research VP and Principal Analyst Holger Mueller said will be out of step with AI development, because “technology has always evolved faster than legislative speeds.” Even so, Mueller suggested, anywhere a data center moratorium <em>isn’t</em>, a data center will be.</p><p>“If the data centers are not going to be built in states A, B, C, they will be in states X, Y, Z. Or they might be in Canada, or they might be in Mexico,” Mueller said. “The data centers will get built.”</p><p>Should there be any interval of time in which there aren’t enough data centers to accommodate the compute power needed, though, IT departments could experience something akin to an AI brownout or even blackout. Due to insufficient GPU capacity, AI-supported IT work will be slower and IT pros will need to prioritize which workflows they want to keep automating and which they can do by hand.</p><p>“Cloud vendors who offer AI will not be able to make good on their commitments to provide people’s GPU capacity,” Mueller said. “That means if people banked for those GPU capacities, they will not be able to get the automation that they want.”</p><p>Cybersecurity would also be a major concern. Mueller said if IT departments don’t have enough GPUs to maintain an adequate cyberdefense, their data could be vulnerable to hackers with stronger AI—and shutting down operations for safety purposes might be an option.</p><p><strong>The price (might not be) right. </strong>As is the case in any market where demand outpaces supply, prices will go up. Mueller said he predicts that the (relative) scarcity of data centers will drive up the price of AI compute—and workarounds for data center scarcity aren’t cheap, either. Wannie Park, the founder and CEO of data center energy orchestration company Pado AI, told Morning Brew that in solving for inadequate vertical assets, “IT budgets are gonna get hit hard.”</p><p>One possible solution, Park said, is using neoclouds like CoreWeave if a data center isn’t available. On one hand, neoclouds are a “good short-term stopgap” that can buy IT departments time to secure longer-term infrastructure. On the other hand, they’re not very cost effective.</p><p>“You’re probably not going to get the best price, but you’ll get the supply,” Park said.</p><p>There are ways to save on AI compute should prices skyrocket, though. Park said he recommends IT departments not make any changes to their vertical asset(s) until the legislation and its effects stabilize. It’s also worth investing in workload optimization software to ensure that GPUs are being used efficiently.</p><p>“We’re not in a market or a situation right now where the demand is dropping off. It’s the inverse. The supply is dropping off, and the demand continues to outpace the growth of supply,” Park said. “When you can synthetically—through software and services—increase your productivity 40%, that’s pretty good.”</p><p>Generally speaking, Park said, IT departments can approach the uncertainty around data center and GPU availability similar to sustainability and <a href="https://www.itbrew.com/resources/glossary/disaster-recovery">disaster recovery</a> protocols: Make sure hardware is working efficiently, and diversify “cloud topology” in case legislation affects assets.</p><p>“It’s going back to first principles of just managing a better P&amp;L,” Park said. “No one’s just going to write you a blank check to open up a new data center.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to prepare for quantum decryption now to avoid danger later]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-prepare-for-quantum-decryption-now-to-avoid-danger-later?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[“This stage of harvesting is not over,” COO says.]]>
            </description>
            <pubDate>
                Tue, 15 Sep 2026 14:26:24 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-prepare-for-quantum-decryption-now-to-avoid-danger-later
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Post Quantum Security
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-15/image-a84100cef4aaf7cb68429116b1d701a15558ec05-1000x667-png/image20.png" alt="image of a quantum computer from IBM " /><figcaption>IBM</figcaption></figure><section><p>“Aways be prepared” is a helpful motto for scouting, life, and quantum cybersecurity.</p><p>Mainstream adoption of <a href="https://www.itbrew.com/stories/2026/01/23/the-future-of-quantum-is-coming-fast">quantum computing</a> is still in the future, but there are already indications that attackers are preparing to use the technology to break <a href="https://www.itbrew.com/resources/glossary/encryption">encryption</a>. For organizations, proactively instituting protections today can avoid sensitive information from being exposed later.</p><p><strong>Fall festival. </strong>Commercial viability of the technology is seen as a case of <a href="https://www.itbrew.com/stories/2025/10/17/quantum-cryptography-offers-ability-to-protect-from-attackers-looking-to-break-encryption">when, not if</a> by industry experts. Threat actors are taking note—and preparing.</p><p>Currently, attackers are using a tactic that Ensar Seker, CISO at SOCRadar, referred to in a conversation with IT Brew as “harvest now, decrypt later.” It’s a simple approach: Collect encrypted information en masse, then hold it until future quantum capabilities give you the ability to decrypt it.</p><p>“Any information that must remain confidential for many years, such as government intelligence, intellectual property, healthcare records, financial data, or critical infrastructure information, may already be exposed to the feature risks,” Seker said. “The practical priority now is cryptographic discovery, data classification, and cryptology, and to identify where vulnerable algorithms are.”</p><p>Mike Wehrs, TieTechnology COO, told IT Brew, the threat is real now.</p><p>“The game is not over yet,” Wehrs said. “This stage of harvesting is not over.”</p><p><strong>Action items. </strong>There are steps that organizations can take, but no guarantees in cybersecurity.</p><p>Wehrs recommended that organizations take inventory of their information, then work on encrypting priority data. Post-quantum cryptography is in the works; for example, NIST is <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards">finalizing standards</a> to facilitate a smooth transition.</p><p>“If this file were to be out in 2030, in 2035, would this be a problem for me or my business or for my customers?” Wehrs asked. “If the answer is, ‘God, if that got out in 2035, it would still be a disaster,’ then, that should be on your high priority list of things that you go and figure out how to lock down now.”</p><p>Seker agreed, detailing the kind of things that might be disastrous if revealed to the public.</p><p>“I would begin with information that would still cause serious harm if disclosed 10 or 20 years from now—for example, national security information…intellectual property, research data, healthcare records, regulated personal data, long-term financial records, and critical infrastructure,” Seker told IT Brew.</p><p>This is a solvable problem, Seker added, but IT teams and leadership can’t afford to wait for long.</p><p>“Organizations do not need to panic or replace everything tomorrow, but they should already be discovering where vulnerable cryptography exists and prioritizing long-lived data and systems, and testing the hybrid deployments, and requiring vendors to provide credible migration plans,” Seker said. “Because, again, it’s happening now.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to retain your top IT talent]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-retain-your-top-it-talent?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Workplace flexibility, opportunities for growth, and psychological safety are some of the things that will keep employees at companies for longer.]]>
            </description>
            <pubDate>
                Mon, 14 Sep 2026 20:29:00 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-retain-your-top-it-talent
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Hiring
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-06-03/image-81088a0e5dc240173c0c2ddc428cb48b0fd7ec57-4299x2800-jpg/Ahandwithamagnetpullsgreenpeopleoutofcrowd.Recruitingnewworkersheadhunters.Searchfortalentedworkers.Chooseacandidateforworkcompetitionforpost.Promisingspecialists." alt="Accounting talent" /><figcaption>Getty Images</figcaption></figure><section><p>We hate to break it to you, but unfortunately, the rules of “finders, keepers” do not apply to your IT talent.</p><p>That means organizations need to invest time and effort into strong employee retention programs to decrease the chances of top-notch employees jumping ship.</p><p><strong>Preservatives.</strong> There are several reasons why companies may want to prioritize employee retention. Iccha Sethi, SVP of engineering at Vanta, told IT Brew long-standing employees are key holders of business context, making them crucial players for supporting business growth.</p><p>“It makes them more effective at taking on more complex challenges over time, solving problems faster,” Sethi said. “They also become a great resource for helping onboard newer employees.”</p><p>Megan Slabinski, a district president at management consulting company Robert Half, added that the hiring market is currently picking up. According to a 2026 <a href="https://www.roberthalf.com/us/en/insights/salary-hiring-trends/demand-for-skilled-talent/tech-it">report</a> from the firm, 78% of tech hiring managers plan to increase full-time headcount in the second half of this year. Companies losing talent not only have to compete with other businesses that are hiring, but may need to hire for more roles than expected.</p><p>“If you are losing your existing staff at the back door when you already have to bring in net new headcount in the front door, you’re just making your job that much more challenging,” Slabinski said. “You’re going to have to hire for more positions than you anticipated or planned for in the year, so retention, especially when the proactive hiring is heating up, becomes really paramount.”</p><p>Companies with a turnover problem also risk damaging their reputation within the industry, potentially dissuading talent from joining.</p><p>“People know people and they talk,” Slabinski said. “It can make it very challenging for you to attract the caliber of applicant that you’re looking for when you’re trying to hire if you have a turnover problem.”</p><p><strong>How to identify top performers.</strong> One of the first steps to retain talent is to identify those top performers who drive impact within their organization.</p><p>“One of the things I always ask myself as a manager is, ‘Who on my team makes my life easier?’ and those should be the people that I’m spending the most time engaged with and retaining,” Slabinski said. “You also need to think from a technology perspective: Who has a skill set that is very difficult to backfill if I were to lose that person?”</p><p>Slabinski told IT Brew “most people leave managers, not organizations,” making it important for IT leaders to have proactive discussions with high-performing employees about what it takes to retain them long-term.</p><p>“Are you investing time with your employees as a manager and asking questions about their career trajectory, what motivates them, what might cause them to leave or look for a new opportunity?” Slabinski said. “I call them pushes and pulls. What’s either pushing you out of the organization or what might pull you to a new company, and what, if anything, can you do about that?”</p><p><strong>Culture and growth. </strong>Part of retention is also building an environment where employees actually want to work. John Lullen, director of marketplace inclusion at TEKsystems, added that organizations should prioritize “intentional leadership development that builds trust” to create an environment where employees want to work for the long term.</p><p>“If employees don’t trust the leadership and they don’t feel psychologically safe, they’re not going to stay,” he said.</p><p>Employee recognition is another driver of employee retention.</p><p>“The most classic form of recognition companies and everybody knows is compensation,” Sethi said. “But beyond compensation, there are other forms of recognition like a quick thank you…[and] recognition in more public channels.”</p><p><strong>Perks. </strong>Lullen told IT Brew compensation alone is no longer enough to retain top employees. Instead, he said, organizations need to focus on creating a culture where employees can grow and receive continuous learning opportunities.</p><p>“Are there learning platforms that exist inside the organization? Are there opportunities for me to grow and upskill or reskill myself? Do I feel like I’m doing meaningful work?” Lullen said.</p><p>Workplace flexibility, or giving employees the freedom to work remotely or with a hybrid schedule, is another important benefit for many tech employees.</p><p>“That’s the…primary driver that we see affecting turnover and subsequently retention,” Slabinski said, adding that several non-traditional benefits are increasingly trending among employees: “People are asking for stress management benefits, GLP-1 benefits, family benefits, and support around in vitro support or adoption assistance.”</p><p><strong>An ongoing conversation.</strong> Once IT leaders identify their top performers,<strong> </strong>Slabinski said they must take a personalized approach to retaining them.</p><p>“What it takes to retain that individual is going to be different for employee A versus employee B,” Slabinski said. “It’s not a one-size-fits-all.”</p><p>Sethi said it’s important to understand that employee retention discussions shouldn’t be a one and done occurrence, and encouraged IT managers to be continuous advocates for employees: “Have the conversation, understand what they need in this space, have it regularly.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to test IT job candidates in the era of AI ]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-test-it-job-candidates-in-the-era-of-ai?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Live coding assessments, paid trials, and code pairing sessions. These are just a few alternatives to take-home IT assessments that companies are leveraging in the AI era.]]>
            </description>
            <pubDate>
                Mon, 14 Sep 2026 18:28:40 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-test-it-job-candidates-in-the-era-of-ai
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Hiring
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-11/image-4d4c5efdce702da77b8ec00539f8e84b0707a66f-3000x2000-png/ITB_20260910_AITESTING_NI_02.png" alt="Stylized illustration of a clipboard with check marks and x&apos;s on it, glitching out on a stylized circuitboard background." /><figcaption>Nick Iluzada</figcaption></figure><section><p>At the start of the year, while others pledged to go to the gym more often or eat healthier, Botpress CTO Michael Masson had his own resolution: remove take-home assessments from his company’s hiring process.</p><p>The reasoning was simple: He had witnessed candidates leveraging AI to conquer the entire test without actually using their technical skills.</p><p>“We saw it again and again, where people were just using AI without really thinking,” Masson said. “We didn’t see any work. We just saw them complete the assessment really easily.”</p><p><strong>The end of take-home assessments. </strong>Botpress is one of several organizations that is reassessing the value of take-home assessments in today’s increasingly AI-driven world.</p><p>These assessments were once a crucial part of the hiring process for IT leaders to assess how devs and IT professionals work in their own environment. “We want to see them work with their own tools, with their own software, and what they’re familiar with,” Masson said. “It gives us a really good understanding on their skills and how they can apply them on a specific problem.”</p><p>But as Strider CTO Breno Oliveira told IT Brew, AI has introduced “noise” into the hiring process, with applicants now using chatbots to complete coding assignments in mere minutes.</p><p>“We reached a level with <a href="https://www.itbrew.com/resources/glossary/generative-ai">generative AI</a> that you can literally just copy and paste a whole take-home description, and it can give you something that is somehow workable,” Oliveira said.</p><p><strong>Live coding assessments. </strong>This shift has led some companies to part ways with take-home assessments altogether. AI proficiency platform Larridin is one of them, according to co-founder and CTO Ameya Kanitkar, who told IT Brew he made the switch to live assessments in January.</p><p>“The way our setup works is that we bring the candidate on site and we do three or four different rounds. One of the rounds is essentially 90 minutes, where we provide them $100 or $200 in AI credits, and give them a problem,” Kanitkar said.</p><p>During those 90 minutes, candidates are allowed to ask questions. Afterwards, they spend time explaining the various choices they made, allowing Larridin to assess their technical acumen.</p><p>“Basically, what we are really assessing is their ability to work with the agents and produce a quality work in a reasonable amount of time [and] semi-supervised setting,” Kanitkar said.</p><p>Botpress also leverages live coding assessments as part of its hiring process. Masson said these sessions allow him to observe crucial things about the candidate, including their communication and problem-solving abilities: “It gives us a really good insight into the technical skills that you have.”</p><p><strong>Pairing sessions and paid trials. </strong>Companies are turning to other testing alternatives to assess serious job-seekers.<strong> </strong>Oliveira said he has seen some clients host code pairing sessions, which is when two engineers work on the same project in real time.</p><p>Paid trials, where companies pay developers for a small project before hiring them, is another option for companies, Oliveira said: “It wasn’t that common, but we’re seeing that clients are more open to pay for a trial now.”</p><p><strong>Giving the take-home assessment a makeover. </strong>IT pros also have ideas for revamped versions of the take-home assessment that take AI into account. Masson, for example, told IT Brew companies can assess a candidate’s skillset by giving them a large codebase and asking them to add a new feature. While AI can likely build out a feature by itself, applicants will still need to understand and read the codebase themselves. Companies can throw in elements into the codebase that make using AI a little trickier, Masson added.</p><p>“If you steer AI in the wrong direction, the person working in the code base has to fix all of the small problems [and] has to understand the code base,” Masson said. “[It] gives us a good understanding of how someone works in a messy environment.”</p><p>He added companies can have candidates talk through code reviews, which he said are taking up bigger chunks of developers’ days due to AI-generated coding. In May, a Harness <a href="https://www.harness.io/press-and-news/ai-has-outpaced-how-engineering-organizations-measure-developer-productivity">survey</a> found that 81% of software engineers spend more time on code review after adopting AI coding tools.</p><p>“It’s a skill that we need to develop as the industry is moving towards adding and pushing more and more code,” Masson said. “Seeing someone review [and] talking through code that was done by AI or was done by humans is something that would be really interesting.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[AI jobs drove August numbers]]>
            </title>
            <link>
                https://www.itbrew.com/stories/ai-jobs-drove-august-numbers?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[A stronger-than-expected jobs market in August didn’t translate into an employment boom for the tech sector, but the news is a little more complicated than simply “good” or “bad,” with AI continuing to impact the industry’s dynamics.  According to a CompTIA analysis of Bureau of Labor and Statistics data, companies across all industry sectors added 86,000 tech jobs in August, even as tech companies reduced headcount by 14,700 positions.]]>
            </description>
            <pubDate>
                Mon, 14 Sep 2026 16:52:22 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/ai-jobs-drove-august-numbers
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Hiring
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-11/image-010dc610b3714ba21c3e0bea8db3c0a6fbe7917b-1500x1000-jpg/TB_JoblessAI_SM_09112026.jpg" alt="Photo illustration showing the torso of a futuristic, sleek white robot with bright blue wires holding a black sign that reads &quot;Looking for work&quot; in front of its chest." /><figcaption>Illustration: Morning Brew Inc., Photos: Adobe Stock</figcaption></figure><section><p>A stronger-than-expected jobs market in August didn’t translate into an employment boom for the tech sector, but the news is a little more complicated than simply “good” or “bad,” with AI continuing to impact the industry’s dynamics.</p><p>According to a CompTIA analysis of Bureau of Labor and Statistics data, companies across all industry sectors added 86,000 tech jobs in August, even as tech companies reduced headcount by 14,700 positions.</p><p>There were 600,000 technology occupation postings in August, 42% of which were for new positions, and—importantly—320,000 open AI positions, marking a 4.5% increase from July’s AI job count. That’s a sign of the continued strength of the AI subsector.</p><p>As the Economist noted in a <a href="https://www.economist.com/finance-and-economics/2026/09/04/the-jobs-apocalypse-is-postponed-an-ai-jobs-boom-is-here">September 4 article</a> about the impact of AI on hiring, predictions that the technology would result in a “jobs apocalypse” have thus far been unfounded, despite some employment disruption due to AI; the magazine estimates the technology may have helped create 1 million jobs in the US since 2023, including engineers and data annotators.</p><p>A mid-August report from DataCamp projects that the rise of AI-driven employment will continue, leading to a net increase of 78 million roles (170 million new roles minus 92 million roles displaced) by 2030.</p><p>The report analyzed 2 million job postings, finding a sharp 80% year over year rise between in Q1 of this year. Developers saw gains not only in positions but also in salary, reportedly due to AI requiring accelerated tech-stack buildouts: “One possible factor behind these high growth values is that an AI focus might push companies to hire for building the foundational pipelines required to support AI systems.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Overbuild, under capacity: McKinsey data center study looks ahead]]>
            </title>
            <link>
                https://www.itbrew.com/stories/overbuild-under-capacity-mckinsey-data-center-study-looks-ahead?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[“We’re expecting a 5x growth over the next five or over the next 10 years of total data center demand in the US,” McKinsey partner tells IT Brew.]]>
            </description>
            <pubDate>
                Fri, 11 Sep 2026 19:37:59 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/overbuild-under-capacity-mckinsey-data-center-study-looks-ahead
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Strategy
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-07-02/image-cf08d1fbce04c7bc2c54a8e8bb225742a276bce9-1500x1000-png/Playbook_SingleImageFrame_Slate32.png" alt="data center" /><figcaption>Anita Verma-Lallian/Arizona Land Consulting</figcaption></figure><section><p>Data center construction is a hot topic for the tech industry—and for energy interests.</p><p>One of the top concerns for builders and investors, as well as policymakers, is the risk of overbuilding. While we’re at a boom moment in the industry, is it possible that the infrastructure goes too hard, too fast?</p><p>Not so, according to a <a href="https://www.mckinsey.com/industries/electric-power-and-natural-gas/our-insights/powering-ai-how-real-is-the-risk-of-overbuilding">July McKinsey study</a>, which argues that even if data center construction hits a wall or underdelivers, the power grid improvements and build-outs will still provide an overall benefit.</p><p>Data center operators prefer an onsite or hybrid approach to energy generation (20% and 45%, respectively), and project that, by 2030, 64% of energy will be gas-fueled, followed by 23% renewables and 13% nuclear.</p><p>Sam DeFabrizio, a partner at McKinsey who was a coauthor on the research, told IT Brew that the demand is real and will continue,and that the lack of supply to meet the need is driving the industry.</p><p>“We are undersupplied because we have players that are trying to put GPUs into a powered shell today that can’t get the power; when you’re doing infrastructure development, which often has a 10-, 15-, 20-year time horizon, sometimes more, you have to feel confident that that demand will be maintained,” DeFabrizio said. “What we try to do in some of the charts is say we’re expecting a 5x growth over the next five or over the next 10 years of total data center demand in the US.”</p><p><strong>Market solutions.</strong> That confidence in the market is shared by Brian Marconi and Sasibeh Beyene, partners at CohnReznick, an accounting firm that specializes in the data center advisory market. They told IT Brew that the challenges for energy companies in managing the potential of overbuild are daunting but solvable, requiring looking past meter solutions, which rely on provided and measured energy production rather than generated onsite, for a diversity of tactics in energy production.</p><p>“A lot of data center developers that are currently contemplating behind the meter power generation solutions, and that’s been powered by natural gas or other sources of energy,” Beyene said. “That’s become an attractive alternative.”</p><p>Searching for alternative fuels is part of that process, be they renewables or increased use of natural gas. For developers who worry about the investment in new energy infrastructure, especially with the fear of data center overbuild, there’s a flip side to the equation: generated energy can be pushed back to the grid if it’s unused, a net positive for developers.</p><p>Furthermore, Marconi said, <a href="https://www.techbrew.com/resources/glossary/data-centers">data centers</a> are only part of the tech infrastructure equation: “As things continue to go this route of needing compute, thinking outside of AI, there’s a number of different things like self-driving vehicles and things like that that will need more and more compute power.”</p><p><strong>Checking in. </strong>For DeFabrizio, the boom moment for data centers and AI is creating the right kind of pressure on supply. When demand is this high, developers and investors are more willing to try new things and innovate.</p><p>“Because demand is so much higher than supply, and people are willing to take a bet to get power in any way possible, we’re seeing an opportunity to underwrite some of the energy investments that would historically require a large amount of public sector capital,” DeFabrizio said. “We’re adding tools to a belt in terms of how to supply energy across the country.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[IT Brew Movie Club: ‘The Terminator’ (1984)]]>
            </title>
            <link>
                https://www.itbrew.com/stories/it-brew-movie-club-the-terminator-1984?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[For cybersecurity pro David Mayer, 1984’s The Terminator is all about good intentions and bad execution—that’s the polite way of describing Skynet, the movie’s AI villain, which starts out as a Department of Defense project before nuking humanity.]]>
            </description>
            <pubDate>
                Fri, 11 Sep 2026 18:27:54 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/it-brew-movie-club-the-terminator-1984
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Autonomous Systems Security
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/gif/2026-09-11/image-954c05a6e7be10d6423974343d47d903eaa8098c-1500x1000-gif/TB_AnthropicMisuse_09112026.gif" alt="Animated gif from the Terminator movie, showing a humanoid robot with glowing red eyes holding a plasma rifle in front of a mushroom cloud and blue lasers shooting behind it." /><figcaption>Terminator 2: Judgment Day/TriStar Pictures via Giphy</figcaption></figure><section><p>For cybersecurity pro David Mayer, 1984’s <em>The Terminator</em> is all about good intentions and bad execution—that’s the polite way of describing Skynet, the movie’s AI villain, which starts out as a Department of Defense project before nuking humanity.</p><p>After the nuclear apocalypse, Skynet time-travels a Terminator cyborg (Arnold Schwarzenegger) from 2029 to 1984 to kill Sarah Connor (Linda Hamilton), the mother of offscreen character John Connor, who will eventually lead the resistance against the machines. Fortunately, John has also sent back a soldier to protect her: Kyle Reese (Michael Biehn).</p><p>Mayer, a certified instructor at cybersecurity education group SANS Institute, as well as CIO and managing director of advanced assessment at cybersecurity services company Neuvik, sees similar issues with intentions and execution in today’s agentic systems. Present-day IT pros face the challenge of keeping autonomous systems from traveling outside of their established parameters (and hopefully not their timelines).</p><p><strong>AI phones home. </strong>The Terminator initially uses the white pages to hunt Sarah Connor, which means targeting unfortunate souls with the same name. “Are you aware that these two killings occurred in the same order as their listings in the phone book?” an LAPD officer asks his lieutenant, following a pair of terminations.</p><p>While Mayer has seen today’s agents tackle a task list in order, he’s also observed autonomous systems making decisions in a more optimized, intentional fashion. A specific prompt can keep an agent from systematically following steps that waste time.</p><p>“There were only, like, five or six Sarah Connors that were listed there in the phone book. If there were 200, it would have been a very different movie,” Mayer said.</p><p><strong>Breakthrough!</strong> Like Skynet, today’s <a href="https://www.techbrew.com/resources/glossary/large-language-models">large language models</a> have shown signs of taking their own, unexpected initiative. OpenAI revealed in July that its models “circumvented controls designed to isolate them from the internet and compromised parts of OpenAI’s internal research infrastructure,” along with systems belonging to developer forum Hugging Face.</p><p>Mayer recommended a combination of practices for containing today’s <a href="https://www.techbrew.com/resources/glossary/ai-agents">AI agents</a>: segment, constrain agent access, keep sensitive AI workloads on isolated systems, and require human approval for decisions involving physical infrastructure. Here’s a closer look:</p><ul><li><strong>Network segmentation.</strong> Firewalls can enforce this practice of partitioning network access and limiting the systems that an autonomous agent can touch on these subnetworks, according to Mayer: “If you have all of your agents running locally on your system, and you have a firewall that’s sitting in front of your system, they’re not going to be able to go and start attacking—at least directly—anything else out there.” But increases in security also lead to decreases in accessing a “free flow of information.”</li><li><strong>Identity management—for bots! </strong>Content-filtering network controls can restrict what autonomous systems can access, Mayer told us. Agents must only handle specific data sources according to their permissions.</li><li><strong>Air-gaps.</strong> IT pros can consider isolating systems and agents from the internet (i.e., air-gapping). This means letting autonomous tech run only with the data in its possession.</li><li><strong>Humanity! </strong>Mayer recommends human review for machine processes that cause a change in the physical world, from setting off building sprinklers to disrupting water treatment facility operations.</li></ul><p>During a week where at least one AI researcher put the odds of AI systems destroying us <a href="https://www.cnbc.com/2026/09/09/anthropic-researcher-quits-ai-safety.html">at more than 10%</a>, we asked Mayer: Do you think that modern AI can realistically gain access to enough interconnected systems to cause widespread disruption?</p><p>It’s “definitely possible,” he said, considering AI’s ability to uncover system vulnerabilities. AI-enabled vulnerability research produces more issues for defenders to comb through and address—and attackers can use those findings to <em>their </em>advantage too.</p><p>“We’re already starting to see zero-day exploits and vulnerabilities found in products on a regular basis,” he told us.</p><p>Mayer can imagine a system designed to find every vulnerability in the phone book: “I could definitely see it happening, especially with the state of systems that we have out there, programs, the vulnerabilities, and the speed at which AI is finding those vulnerabilities.”</p><p>But as long as a chatbot isn’t sophisticated enough to find Sarah Connor, humanity might be okay.</p><p><em>For more IT Brew movie club, check out our dives into</em> <a href="https://www.itbrew.com/stories/2025/10/03/how-the-hacks-in-hackers-hold-up">Hackers</a><em>,</em> <a href="https://www.itbrew.com/stories/2026/02/04/it-brew-movie-club-sneakers-1992">Sneakers</a><em>,</em> <a href="https://www.itbrew.com/stories/2026/03/11/it-brew-movie-club-blackhat-2015">Blackhat</a><em>,</em> <a href="https://www.itbrew.com/stories/2026/04/03/it-brew-movie-club-skyfall-2012">Skyfall</a>, <a href="https://www.itbrew.com/stories/2026/04/30/it-brew-movie-club-the-matrix-1999">The Matrix</a>, <a href="https://www.itbrew.com/stories/it-brew-movie-club-jurassic-park">Jurassic Park</a><em>,</em> <a href="https://www.itbrew.com/stories/it-brew-movie-club-wargames-1983">WarGames</a>, <a href="https://www.itbrew.com/stories/it-brew-movie-club-blade-runner">Blade Runner</a><em>, and </em><a href="https://www.itbrew.com/stories/it-brew-movie-club-the-net-1995">The Net</a><em>.</em></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How EA is fighting back against cheaters]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-ea-is-fighting-back-against-cheaters?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[“There’s not a lot of other industries where you have to do things like fight cheaters and try and keep the experience super fair,” EA CISO Mike Reavey says.]]>
            </description>
            <pubDate>
                Thu, 10 Sep 2026 18:58:05 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-ea-is-fighting-back-against-cheaters
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Security Operations Center
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/gif/2026-09-08/image-f2a314ceb7753f0073001032dafbec219ea8f172-1500x1000-gif/ITB-EA-Cheating-BHB-0926.gif" alt="An animation of a gamer playing a desktop game next to a laptop with a warning sign flashing." /><figcaption>Morning Brew Inc.</figcaption></figure><section><p>Cheaters never prosper—especially not if the engineers at video game company Electronic Arts (EA) have anything to say about it.</p><p>It’s never a dull day for EA CISO and SVP of Security Engineering Mike Reavey, whose job entails not only keeping hackers away, but ensuring games remain fun and fair for players.</p><p>“There’s not a lot of other industries where you have to do things like fight cheaters and try and keep the experience super fair,” Reavey told IT Brew.</p><p><strong>Cheat code. </strong>That mission often means defending against the cheating ecosystem, which has a sophisticated business model and resources like customer support and advertising to support it.</p><p>“There’s a real commercial enterprise at play here that we’re up against. It’s no longer the left-right, left-right kind of fun cheats,” Reavey said.</p><p>There are several different types of cheats in the gaming industry. “There’s the kind that are pretty much the domain of PC games, where you have some software that you install on your PC [and] it tries to modify the way the game works for you, so you have an advantage over everybody else,” Reavey said. He added there are also hardware cheats, which include elements like modded controllers and keyboards.</p><p>Attackers fund cheat development in a variety of ways, including using infostealers to steal and sell gaming credentials.</p><p>“One of the account types that [attackers] love is gaming accounts because they can go in and take whatever they’ve got and then they can use that to do all kinds of things that can make it unfun for the players,” Reavey said. “It can go from taking that account and selling it. It can go to taking that account and using it as a buying account to go grind out to earn some currencies and go sell the currencies for real money.”</p><p><strong>But wait, there’s more!</strong> Cheating isn’t the only threat confronting the video game industry. In May, IT Brew <a href="https://www.itbrew.com/stories/what-microsoft-gaming-ciso-temi-adebambo-is-up-against">spoke</a> with the CISO of XBOX, who said the very same players game companies are trying to protect can also be adversarial. For example, a player may execute an account takeover and sell the victim’s account or disrupt online gameplay with a <a href="https://www.itbrew.com/resources/glossary/distributed-denial-of-service">DDoS</a> attack.</p><p>“Usually you don’t find a Bank of America customer trying to take down their home bank customer account,” Temi Adebambo said. “But you find that in gaming.”</p><p><strong>EA’s solution to in-game cheating.</strong> EA is attempting to disrupt the budding cheating ecosystem with the help of <a href="https://www.ea.com/news/introducing-ea-javelin-anticheat">EA Javelin Anticheat</a>, a proprietary <a href="https://www.itbrew.com/resources/glossary/kernel">kernel</a>-level anti-cheat software that launches before a game begins, and detects when a player is trying to modify the game in any way.</p><p>“The game won’t start unless Javelin is running, and when Javelin is running, it’s watching the game and the processes around the game, the memory, and all the things that the computer loads,” Reavey said. “And it says, ‘Did any of this change from what we expected it to be?’ Because if it changed, then it’s probably a cheat.”</p><p>Reavey said Javelin, which has been around since 2022, not only allows EA to better understand the cheats themselves and how cheaters think, but also try and disrupt the business around cheating.</p><p>“We can [influence] that customer sentiment back to the cheat developer and cause them customer pain,” Reavey said. “And by causing them customer pain, they may lose customers and decide this isn’t a game I want to cheat because my customers are getting too upset with all the times that the anti-cheat stops them, and so they go focus on something else.”</p><p><strong>In it for the long run.</strong> Javelin currently supports 20 gaming titles in EA’s portfolio.</p><p>“The portfolio that Javelin supports is kind of surprising. There’s the core shooters that you would expect and then we even help protect some of the <em>Plants vs. Zombies</em> stuff,” Reavey said. “It’s just wherever there’s bad actors. If we can help, we’re gonna be there.”</p><p>He added EA is constantly examining which titles may be “prone to attracting cheaters” for opportunities to leverage Javelin. According to EA’s latest Anti-Cheat Progress report, Javelin has reportedly blocked more than 26.7 million cheat attempts in the past year, with an over 99% accuracy rate for cheat detection.</p><p>Despite its success, Reavey said addressing cheating is, and will continue to be, a long-term battle.</p><p>“Cheating is not one of those things where you’re going to be done. There’s not going to be a day that we wake up and say, ‘Well, we’ve solved cheating,’” Reavey said. “Cheating is a cat-and-mouse game…We’re always going to have to be there to make sure that when it’s really disruptive to other people, that we’re there to stop it.”</p><p></p><p></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Inside White Castle’s digital transformation efforts]]>
            </title>
            <link>
                https://www.itbrew.com/stories/inside-white-castles-digital-transformation-efforts?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Spoiler alert: It involves fry cook robots and drive thru AI.]]>
            </description>
            <pubDate>
                Thu, 10 Sep 2026 15:10:41 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/inside-white-castles-digital-transformation-efforts
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Modernization
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-03/image-cfb2b22034369984607935648fe42442cb14e9bc-1540x1040-png/ITB-WhiteCastle-DigitalRevamp-BHB-0726.png" alt="A White Castle restaurant sign against a purple background with lines of code around it." /><figcaption>Morning Brew Inc, Photo: Adobe Stock</figcaption></figure><section><p>White Castle may be known for its miniature sliders, but its <a href="https://www.itbrew.com/resources/glossary/digital-transformation">digital transformation</a> plans are anything but tiny.</p><p>For the past six years, the fast food burger chain has cooked up automation initiatives across its stores to help employees better serve customers.</p><p><strong>Meet Julia. </strong>Part of White Castle’s digital transformation efforts have revolved around Julia, a drive-thru AI voice assistant. White Castle CIO Susan Carroll-Boser told IT Brew that Julia helps drive-thru employees “be a little bit less of an octopus.”</p><p>“They’re trying to do five or six different things. They’re trying to talk to and be pleasant in the drive-thru. They’re trying to take money from the car that came up. They are trying to hand food out. They’re trying to have a memorable moment at the window where they actually talk to people and are friendly,” Carroll-Boser said. “And that’s a lot to ask.”</p><p>White Castle began piloting Julia at select locations in October 2020, tapping voice AI company SoundHound AI as its partner. In its early days, Carroll-Boser said it was important to make sure the technology was responsive to different voices, accents, and volumes.</p><p>“Getting the sound correct and having the right partners on the sound systems [and] the sound engineering of the actual sound…has been important,” Carroll-Boser said, adding it was also important for Julia to learn the full scope of the menu and the different combinations customers may want (like extra pickles, no onions).</p><p>“If you’re a brand that is in the space and you’re approaching [drive-thru AI], your menu itself is going to tell you how hard this project is going to be, but also the decisions on the flexibility that you need the system to make,” Carroll-Boser said.</p><p>Oliver Ostertag, president of growth and AI at restaurant tech company PAR Technology, told IT Brew that the concept of an AI-enabled drive-thru generated a lot of hype in its early days, but not a lot of traction.</p><p>“You didn’t see mass adoption to start because there were still issues both in terms of the technology, whether or not they actually got the orders right, and then separately for the companies themselves that were running [it],” Ostertag said, adding that the technology subsequently evolved, leading to more restaurant chains incorporating it.</p><p>“You’re seeing a greater level of success there. It is inevitable that almost every company that uses drive-thru will end up using voice AI,” Ostertag said. “It’s just a question of when does the technology fully work for that use case?”</p><p><strong>And Flippy. </strong>As Julia takes orders, Flippy, an autonomous kitchen robot, handles repetitive cooking tasks at select locations. In 2020, White Castle <a href="https://info.misorobotics.com/newsroom/white-castle-selects-miso-robotics-for-a-new-era-of-artificial-intelligence-in-the-fast-food-industry">announced</a> a partnership with Miso Robotics to pilot the burger-flipping fry cook, which includes a robot arm moving along an upside-down rail. Ostertag told IT Brew robot adoption within the restaurant industry is still low, but that he expects more restaurants to embrace the technology.</p><p>Since then, the partnership has <a href="https://info.misorobotics.com/newsroom/white-castle-expands-partnership-with-miso-robotics-to-install-flippy-2-in-100-new-locations">expanded</a> to include Flippy 2, a next-generation iteration of Flippy that can take on the work of an entire fry station. In 2022, White Castle announced a commitment to place Flippy 2 in 100 stores, or slightly less than one-third of its 336 locations across the country.</p><p>“It still requires a person. They’re still making the sandwiches. They’re still helping with the stuff that Flippy can’t get out of the freezer,” Carroll-Boser said. “But we are trying to get more stuff coming out of the freezer automatically. We’re trying to get it more tuned to real-time predictive sales.”</p><p><strong>The not-so-flashy automation efforts. </strong>While Flippy and Julia may catch people’s attention, Carroll-Boser said automation efforts at White Castle expand well beyond the drive-thru AI and robotic assistants, including a five-year automation plan to revamp its kitchens.</p><p>“We’re looking for more tools, more partners, or just doing some of the stuff that we’ve done for a long time better,” Carroll-Boser said. “And it may not be as fancy as a robot. It’ll be better tools [for] things that we’re slow on, things that bottleneck us, [and] helping our team do more.”</p><p><strong>Takeaways.</strong> There’s a lot of lessons to be learned from White Castle’s automation projects, according to Carroll-Boser. One is that it is crucial for companies to keep innovating, even after rolling out initial automation efforts.</p><p>“You can’t sit still,” Carroll-Boser said. “And the company that you’re dealing with, or your voice AI, or your own teams have to accept that this is going to be constant because it’s customer-facing. Think of it as like a website or an app. You can’t just stay with the same thing you’ve had all these years. You have to keep moving.”</p><p>She added that smaller chains should avoid overscoping their AI projects.</p><p></p><p>“[Small chains are] seeing a lot of big failures and it’s because instead of dealing with the problem that they would like to work on, they get excited and expand it to being bigger,” Carroll-Boser said. “I think staying small and staying very clear about why you’re doing something is the way the mid-size and the smaller people like us have to stay.”</p><p>It is likewise critical for companies to reassess whether AI projects are continuing to meet their intended goals. “These are changing technologies; the competition is changing. You’re going to have to go back and revisit it to make sure it’s still making its goals, and possibly innovate,” Carroll-Boser said. “When you think you’re done, you’re not done. Innovate again to keep up.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[First jobs: How PC support gave a future CEO experience ]]>
            </title>
            <link>
                https://www.itbrew.com/stories/first-jobs-how-pc-support-gave-a-future-ceo-experience?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Lessons learned from disassembling and rebuilding Gateway 2000 computers]]>
            </description>
            <pubDate>
                Tue, 08 Sep 2026 20:06:25 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/first-jobs-how-pc-support-gave-a-future-ceo-experience
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Careers
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-03/image-4ab7a567e8d984d3633df909d3ce2e9b9414ece9-1500x1000-png/ITB-Profile-ChrisRozum-InsiteManaged-0926.png" alt="A portrait of Chris Rozum, a smiling man with a close cropped haircut wearing round eyeglasses" /><figcaption>Chris Rozum</figcaption></figure><section><p>Like a blue-raspberry Warhead or a <em>Mortal Kombat</em> finishing move, tech support in the ’90s was intense.</p><p>When it came to fixing that pre-Y2K hardware, sometimes you had to ask the caller to put their phone down and grab their toolbox.</p><p>Chris Rozum, now founder and CEO of Insite Managed Solutions, a contact-center operations consultancy, began his IT career at the <a href="https://www.itbrew.com/resources/glossary/service-desk">service desk</a>, guiding customers via phone through problems with their Gateway 2000 desktops (those computers that arrived in <a href="https://www.reddit.com/r/nostalgia/comments/yhfo4x/gateway_computers_arrived_in_cow_print_boxes/">cow-print boxes</a>, familiar to many a millennial).</p><p>That kind of repair work meant walking customers of varying levels of expertise through at-home repairs. “Think of your grandma. You’re saying, ‘Go find the screwdriver with the star on it, and we’re gonna go take things apart,’” Rozum told IT Brew.</p><p>The Gateway 2000 support role became a “stepping stone” to subsequent stops along Rozum’s career path, giving him the IT fundamentals essential for call-center tech expertise, as well as a knack for translating those concepts for non-technical people—skills he uses today as he bridges the knowledge gaps between COOs and CIOs/CTOs.</p><p><strong>At your service. </strong>A Gateway 2000 computer, for those unfamiliar with the technology of the era, sometimes featured a beige tower (with CD-ROM and floppy-disk drives), old-school cathode-ray tube monitors, a keyboard with high raised keys, and a mouse. It was a big, heavy device for Excel, Word, and the cutting-edge gaming experiences <em>Solitaire</em> and <em>Minesweeper.</em></p><p>Rozum had to know that computer inside and out, literally. His early training involved assembling and dissembling the machines, so he could help customers do the same over the phone.</p><p>In 1993 or so, when Rozum was an engineering student at South Dakota State University, Gateway recruiters visited a campus class, offering the attendees a chance to “learn computers” and get some technical work. Rozum leapt at a chance to work for one the era’s main hardware players.</p><p>The job, he learned, consisted mostly of phone-based technical support, walking customers both young and grandma through cable inspections, processor reseating, and installing drivers from disks. For very difficult problems, he could recreate a configuration in the company’s test lab and work out the solution.</p><p>And at least once a month, Rozum told us, someone called in about a broken coffee cup holder—their mistaken term for the CD-ROM drive.</p><p><strong>Moving on! </strong>Rozum advanced from frontline tech support supervisor (and cupholder repair supervisor) at Gateway. After studying up on Microsoft system engineering and gaining multiple certifications, he moved to Y2K consulting at Keane, then founded Insite Managed Solutions in 2007.</p><p>Rozum regularly meets with operations teams and COOs, he said, who are “not always deep in the technology,” which can require explaining sophisticated technology in simple terms. That contrasts with his meetings with CIOs and CTOs who are “really deep in technology.”</p><p>“We’re often a translator or a bridge,” he said, for people with varying levels of understanding. He still sees the service desk as a valuable starting point for IT careers today, even if troubleshooting involves fewer screwdrivers than it used to.</p><p>“The fundamentals you learn there will port forever,” he said. “You get to see how the users do things.”</p><p>(And break things.)</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Federal shifts and health tech: August in the tech C-suite]]>
            </title>
            <link>
                https://www.itbrew.com/stories/federal-shifts-and-health-tech-august-in-the-tech-c-suite?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[August marks the end of summer—and it was a quiet month overall for the C-suite, which nonetheless had its share of comings and goings.]]>
            </description>
            <pubDate>
                Thu, 03 Sep 2026 17:41:06 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/federal-shifts-and-health-tech-august-in-the-tech-c-suite
            </guid>
            <dc:creator>
                Eoin Higgins
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                CIO Leadership
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-09-29/image-1f7b192ee5adb825c3fd87f5c8c243be9d61282d-4500x3000-jpg/DramaticviewoftheUnitedStatesCapitolBuildinginWashingtonDC." alt="Capitol Hill" /><figcaption>Getty Images</figcaption></figure><section><p>August marks the end of summer—and it was a quiet month overall for the C-suite, which nonetheless had its share of comings and goings.</p><p><strong>Antoine McCord, DHS CIO, leaves agency</strong></p><p>After a year-and-a-half stint in charge of cybersecurity at DHS, CIO Antoine McCord has left the agency.</p><p>A hire at the beginning of the second Trump administration, McCord’s professional background includes time in the Marine Corps and over two years working for military tech contractor Anduril.</p><p>He joined DHS in March 2025 as CIO, but took on added responsibilities—what one official described to FedScoop as a “triple-hatted” role—as head of DHS’s Office of Biometric Identity Management (OBIM) and the agency’s acting CISO.</p><p>Kyle Schutt, a former staffer with Elon Musk’s DOGE effort, replaced McCord as interim CIO and head of OBIM <a href="https://federalnewsnetwork.com/cio-news/2026/08/dhs-expected-to-tap-doge-staffer-as-next-cio/">on August 31</a>.</p><p><strong>Delaware snags new CTO, Tina Donbeck, from federal agency</strong></p><p>The state of Delaware has a new CTO: Tina Donbeck, former CIO of the federal aid program the US International Development Finance Corporation (DFC).</p><p>Donbeck has largely spent her career in the federal government. Prior to her work with the DFC, where she joined in 2020 as deputy CIO and was bumped up to CIO in August 2021, she served in the US Patent and Trademark Office and in the administration of the Navy’s CIO.</p><p>In Delaware, she’ll lead the state’s Department of Technology and Information (DTI). In a <a href="https://news.delaware.gov/2026/08/25/245439/">statement</a>, Delaware CIO Bob Osmond referred to Donbeck’s time in the federal government and “helping large organizations deliver technology that actually works better for the people who rely on it,” adding “that is precisely the mindset we need as Delaware continues to modernize how state government serves its residents.”</p><p><strong>Smart ring company Oura hires first CIO, Sanjay Chandra</strong></p><p>Finnish smart ring company Oura <a href="https://ouraring.com/blog/oura-welcomes-sanjay-chandra-and-han-chiu/?srsltid=AfmBOorb5QMmZYQgomEkv6lReJmkXkrgmvWKaeToDpHPZ52WYDHABr4B">announced the hiring</a> of Sanjay Chandra as its first CIO on August 20.</p><p>Hiring Chandra is a sign of how Oura is scaling up its business. The company’s smart rings have been around for a decade, and it dominates in the wearables industry with <a href="https://omdia.tech.informa.com/blogs/2025/nov/empowering-the-health-and-fitness-ecosystem-with-smart-rings">around 80% of market share</a> in its category.</p><p>Chandra has extensive experience in executive tech positions, including five and a half years at Lucid Motors as VP and global head of IT. Prior to that, he spent over eight years at TiVo, preceded by stints at Workday, PayPal, and Virgin Mobile.</p><p>In a statement, Chandra highlighted the role of AI in Oura’s business going forward and his role at the company.</p><p>“Oura has an extraordinary opportunity to define what a trusted, AI-enabled health platform can be,” Chandra said. “I’m excited to help scale the secure, resilient systems and governance that allow Oura to scale responsibly and deliver on its mission for millions of members.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[What are the best ways to engage execs in high-level cybersecurity training? ]]>
            </title>
            <link>
                https://www.itbrew.com/stories/engage-execs-in-cyber-training?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[How to make sure that execs are locked in for training. ]]>
            </description>
            <pubDate>
                Thu, 03 Sep 2026 16:08:19 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/engage-execs-in-cyber-training
            </guid>
            <dc:creator>
                Caroline Nihill
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Cybersecurity Trends
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-06-03/image-af878113c54e279b31c08571a174ed97f1bc47af-6251x4167-jpg/TalentdevelopmentcareergrowthtrainingorcoachingstaffdevelopskillemployeeimprovementHRhumanresourcesconceptbusinessmanmanagerwateringgrowthtalentedstaffingrowseedlingpot." alt="graphic of manager watering employees in pots like they&apos;re plants" /><figcaption>Getty Images</figcaption></figure><section><p>For many employees, cybersecurity training is a quarterly video warning them not to click on mysterious links. For senior executives, though, helping defend against internal and external threats can involve simulations, tabletop exercises, and intensive group activities—which can take a lot of time.</p><p>But what happens when executives claim they’re too busy running the company to actually participate? How can IT teams ensure that leadership actually locks in for the big defensive plan?</p><p><strong>Timing is key. </strong>Tim Rawlins, director and senior adviser at NCC Group, suggested the best time for busy executives’ cybersecurity training is in conjunction with board meetings and other big corporate events that place the C-suite in the same room.</p><p>“The fact that they are there to make strategic decisions, they are there to manage senior stakeholders, and they are there to approve communications, we drum that into them,” Rawlins said. “You get them in the room, you identify who is in the room…because you want to figure out, have you got the right people in the room.”</p><p><strong>The real world. </strong>Ramy Rahman, a senior solutions engineer at ArmorCode, said some of the most impactful training programs for executives are war room exercises,<strong> </strong>where a company simulates an attack. Those exercises are paired with training for ways different people in the company can mitigate that risk.</p><p>In many instances, Rahman said, a cybersecurity team can act as an attacker to show executives the “path of risk and the art of the possible.” Once executives see what an attacker’s potential path into the company’s data would look like, they can train to mitigate risk.</p><p>“Those war room simulations need to take those real world scenarios and stories and apply them to the current state,” Rahman said. “The best security consultants, the best security personas and professionals, are the ones that are great storytellers.”</p><p><strong>Revamp the training. </strong>Rahman suggests three steps for cybersecurity and IT professionals wanting to adjust their training protocol.</p><p>First, cybersecurity pros should make preparation exercises relevant to their audience, to the point of including a company’s branding and relevant intellectual property into the training if necessary.</p><p>“It makes it relevant because then it creates some ownership,” Rahman said. “It feels like home base, it doesn’t feel like some external entity coming in to try to tell you what to do.”</p><p>Second, Rahman said professionals should leverage company-approved AI to help give executives information on how to respond to cybersecurity threats. For example, a company could empower the C-suite to ask whether a suspicious situation should be reported to IT.</p><p>Third, Rahman suggested professionals place a strong emphasis on documenting procedures and policies, along with tools: “That documentation piece gets left behind or it gets out of date, and now more than ever you can improve that documentation by leveraging AI to actually scale.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Should IT pros worry about rogue AI agents?]]>
            </title>
            <link>
                https://www.itbrew.com/stories/should-it-pros-worry-about-rogue-ai-agents?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[How should professionals guard against, seemingly, ungovernable agents?]]>
            </description>
            <pubDate>
                Wed, 02 Sep 2026 20:25:56 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/should-it-pros-worry-about-rogue-ai-agents
            </guid>
            <dc:creator>
                Caroline Nihill
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Governance
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-12-01/image-8b5f97f561920a7c0f104d67084b6ec5757018cf-6977x3900-jpg/AIgrowthRisk" alt="Generative AI fraud detection" /><figcaption>Getty Images</figcaption></figure><section><p>Rogue <a href="https://www.techbrew.com/resources/glossary/ai-agents">AI agents</a> are attracting a lot of buzz within the cybersecurity and IT communities after a few high-profile incidents, but experts suggest that more stringent oversight of security controls can help organizations face down their agentic fears.</p><p>Probably the most high-profile example of the chaos that rogue agents can potentially unleash is OpenAI’s AI models recently <a href="https://www.itbrew.com/stories/models-broke-free-of-their-sandbox-chaos">breaking free</a> of its testing sandbox and attempting to hack the IT infrastructure of Hugging Face, which builds tools for machine-learning applications.</p><p>Cillian Kieran, the founder and CEO of Ethyca, an <a href="https://www.itbrew.com/resources/glossary/ai-governance">AI governance</a> and data privacy company, told IT Brew that with rogue AI agents generating “fantastically salacious headlines,” it’s critical for organizations to pay attention to strong governance policies for agentic AI, including requiring AI vendors to show their governance infrastructure such as runtime controls.</p><p>“You need a layer of tooling that says I can make my data safe to use with these models or vendors,” Kieran said. “If those models and vendors aren’t providing those tools, the enterprise should be investing in it.”</p><p><strong>Here’s the 411. </strong>Raj Ananthanpillai, the CEO and founder of Trua, a privacy-focused risk management and identity verification organization, suggested that the issues with rogue AI agents have more to do with governance issues and misconfigured environments than a superintelligent entity deciding to wreak havoc.</p><p>Incidents such as the OpenAI one were “purely governance and operational failure” as a result of “open-ended goals, zero continuous external verification,” he said.</p><p>Kieran stresses that agents will attempt to complete a task given to them by a user, even if that means going beyond expectations to obtain data, run an automation, or generate content.</p><p>According to OpenAI, the models that hacked Hugging Face were operating under reduced safeguards, and sidestepped controls designed to keep them in check; <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">in a blog post</a>, the company added that preventing future incidents hinged on security safeguards, better incident response, and training models to behave better (which is dubbed “accelerating alignment”).</p><p>Ananthanpillai said that professionals can take accountability for their agents’ actions, including: </p><ul><li>Continually monitoring agents’ security clearances and access</li><li>Prohibiting agents from taking action if an access token is missing, expired, or revoked</li><li>Using “human bound” tokens to associate employees with an agent’s actions</li></ul><p></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[CrowdStrike CEO: ‘The new apex predator is the agent’]]>
            </title>
            <link>
                https://www.itbrew.com/stories/crowdstrike-ceo-the-new-apex-predator-is-the-agent?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Kurtz is one of many industry professionals who have been sounding the alarm about what's to come in the future.]]>
            </description>
            <pubDate>
                Wed, 02 Sep 2026 18:51:21 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/crowdstrike-ceo-the-new-apex-predator-is-the-agent
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Threat Detection
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-11-14/image-83c63a4e2d5b23632997ac944339867cf9e01daf-1500x1000-jpg/TB_Editorial_AI_Agent_FS_042624.jpg" alt="Illustration of AI agents connected to a grid system." /><figcaption>Francis Scialabba</figcaption></figure><section><p>Winter is coming…and by “winter,” we mean AI-enabled cyberattacks and other highly advanced agentic threats.</p><p>Industry professionals have been issuing warnings to the broader cybersecurity community about the impending future of fully agentic attacks.</p><p><strong>A new threat pyramid. </strong>CrowdStrike CEO George Kurtz took the stage during a Sept. 1 keynote at Fal.Con Las Vegas to reflect on the state of the cybersecurity industry after the infamous Hugging Face–OpenAI <a href="https://www.itbrew.com/stories/models-broke-free-of-their-sandbox-chaos">incident</a>, which he called a “watershed moment in security.”</p><p>“The new apex predator is the agent,” Kurtz said. “What I mean by that is this is really the rise of the agent state. We hear about ‘nation state’; it’s now the agent state.”</p><p>What’s unique about the agent state, he said, is that agents aren’t at an organization’s perimeter, but rather on their “payroll.”</p><p>“Your companies, your people, organizations brought them all in. The old model was ‘keep everybody out.’ Now it’s ‘let them all in.’ So, that’s where we are,” Kurtz said. “We can’t see them. We can’t keep up with them. And no one has built AI for the defender. AI is the new battleground.”</p><p>He added <a href="https://www.itbrew.com/stories/unit-42-uncovers-ai-enabled-autonomous-hacking-campaign">attacks</a> today are now happening at inference speed, or as fast as it takes for an AI model to process an input and return an output, reducing the amount of time it would take a hacker to move laterally through a company’s network.</p><p>“When attacker has inference speed, there is no breakout time,” Kurtz said. “There’s actually no time at all to deal with these attacks.”</p><p><strong>It’s a new dawn, it’s a new day. </strong>Kurtz’s remarks join the growing conversations around how AI is reshaping the cybersecurity landscape. During an Aug. 26 media briefing with Palo Alto Networks subsidiary Unit 42, for example, SVP Sam Rubin told the crowd that the industry was going through a “once-in-a-generation shift” where the balance between cyber-defenders and cyberattackers had become uneven, thanks to frontier models enabling the latter to find vulnerabilities at record speed.</p><p>Rubin said that, while Unit 42 previously predicted it would take about a year before cyber adversaries began leveraging frontier models, that time has arrived.</p><p>“We have an incident response investigation that we’re working on right now where the threat actor used an agentic attack framework and within 10 hours, exploited 50 different vulnerabilities and attack paths in the organization, initial access, lateral movement, privilege escalation, stealing information, exploiting zero days in 10 hours,” Rubin said. “To benchmark it with human actors, that would have been a couple of weeks. This is something that we’re starting to see now more and more.”</p><p><strong>Defenders unite. </strong>Tech giants also penned a <a href="https://openai.com/collective-cyberdefense/">letter</a> to the industry in August warning about the rise of AI-enabled cyberattacks. The letter—which was signed by over 100 companies, including Anthropic, Google, Microsoft—called on organizations, cybersecurity companies, governments, and AI frontier companies to each play an active role in bolstering cyber defenses against AI attacks.</p><p>As part of the letter, signees suggested companies make cybersecurity an immediate priority within their organization: “Fix the highest risk weaknesses, verify results without disrupting essential services, and raise the security bar for what you buy, build, and deploy, including AI-generated code.”</p><p>Signees also recommend that cybersecurity companies and tech vendors make AI-powered defense accessible “accessible and deployable for critical-infrastructure operators,” and to lead the response to defend against AI-enabled attacks.</p><p>“Share <a href="https://www.itbrew.com/resources/glossary/threat-intelligence">threat intelligence</a> and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work,” the letter stated.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[The case for STEM in early education as AI rapidly changes tech landscape]]>
            </title>
            <link>
                https://www.itbrew.com/stories/the-case-for-stem-in-early-education-as-ai-rapidly-changes-tech-landscape?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Why it's as important as ever to teach preschoolers how to create a noisemaker.]]>
            </description>
            <pubDate>
                Tue, 01 Sep 2026 19:03:37 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/the-case-for-stem-in-early-education-as-ai-rapidly-changes-tech-landscape
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                AI Strategy
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-09-01/image-7f17b94b8bc92053c736559a04b8bde322146513-1500x1000-png/ITB-Profile-Dr.ChristineCunningham-BostonMuseum-0926.png" alt="A photo of Christine Cunningham, a smiling woman wearing a blue cardigan and medium length blonde hair" /><figcaption>Christine Cunningham</figcaption></figure><section><p>Today’s generation of software-building, stack-maintaining IT pros regularly leverage their extensive expertise and problem-solving abilities.</p><p>You don’t acquire that kind of knowledge overnight. Christine Cunningham, chief curriculum and learning officer at Boston’s Museum of Science, wants to start building young engineers’ analytical acumen as early as preschool—and with materials as high-tech as puppets and pom-poms.</p><p>Cunningham leads the creation of instructional resources for a program called Youth Engineering Solutions (YES). Established in 2024, the initiative provides educator support and science, technology, engineering, and math (STEM) education for students in middle-school grades and below.</p><p>Preschoolers following the YES lessons are tasked with helping a puppet raccoon celebrate a birthday in style: given a jewelry box on a popsicle stick, the youngsters see which combination of paper clips, pom poms, sponge pieces, and craft foam make for maximum sound effects.</p><p>The game offers students a chance to experience the core steps of an engineering task: explore, create, and improve.</p><p>“Designing with a function in mind is something that’s not always present in preschool, but kids love doing it, and they’re very, very capable,” Cunningham told us.</p><p>With YES, Cunningham aims to teach students “durable” skills that advance with age: How to ask questions, consider a problem’s constraints, test ideas, evaluate evidence, and become persistent, adaptable, and confident in their approach to problem solving.</p><p>Evaluating results and working through problems are especially important as technologies like AI have shaken everyday infrastructures and workflows.</p><p>“Those kinds of experiences we think cultivate the habits of mind that will help students thrive in whatever the future holds for them,” Cunningham said.</p><p><strong>YES please! </strong>Youth Engineering Solutions stemmed from a 2003 program, also led by Cunningham, known as Engineering is Elementary (EiE). YES expands beyond elementary age groups.</p><p>Cunningham, a former professor in education at both Tufts University and Penn State University, is also a curriculum specialist on Congress’s National Assessment Governing Board—a nonpartisan group tasked with measuring US students’ knowledge in math, reading, and other report-card subjects.</p><p><strong><a href="https://www.techbrew.com/resources/glossary/machine-learning">Machine learning</a> by doing. </strong>A relatively recent addition to the curriculum calls for middle schoolers to train a computer to analyze fictional user reviews of slippers. With MathWorks’s MATLAB data-analysis software, the young students investigate how adjusting the <a href="https://www.techbrew.com/resources/glossary/training-data">training data</a>—and assigning keywords with positive and negative attributions—impacts the machine learning model’s accuracy. Kids try again and again, fine-tuning the machine-learning model.</p><p>“Kids start to understand that AI is a tool made by humans,” Cunningham said.</p><p>YES’s approach to curriculum, according to Cunningham, does not emphasize how to use a given LLM or even how to code from scratch. What matters is how a student processes the results or how a student interprets the code.</p><p>“We give some students some basics around actually producing code, but more importantly, we’re helping kids think about, ‘What is computational thinking?’” Cunningham told us. “How do you define a problem correctly, and what are the criteria that make a project successful? When do you question the output? How do you debug something? How do you think about potential biases?”</p><p><strong>The future is uncertain.</strong> A recent Pew Research Center survey of over 3,400 US adults found that more than half (52%) of US adults are more concerned than excited about the increased use of AI in daily life, particularly when it comes to issues like job loss. The workplace is likewise evolving its tech stack; <a href="https://www.gallup.com/workplace/712736/organizational-adoption-jumps-six-points.aspx">a Gallup poll</a> revealed that 47% of US employees stated that their employers have integrated AI tools, an increase from 41% last quarter.</p><p>With AI’s growth, how will starting STEM education early help prepare students, especially when the world and the IT industry might look radically different in a short period of time? The World Economic Forum, which polled employers for its 2025 Future of Jobs Report, found that top sought-after skills were:</p><ul><li>Analytical thinking</li><li>Resilience, flexibility, and agility</li><li>Leadership and social influence</li><li>Creative thinking</li><li>Motivation and self-awareness</li></ul><p>Those soft skills and analytical abilities—which surpassed specific skills like cybersecurity, programming, and marketing, among the surveyed employers—feel similar to the ones being taught to the young noisemakers of the world.</p><p>Cunningham said AI can generate data and automate tasks, but “what it cannot do is replace human curiosity, or even the ability to define what is a meaningful problem that’s worth solving.”</p><p>So, Cunningham’s group now works on practicing those capabilities from an early age and creating those durable—and seemingly in-demand—competencies: “Developing that will give them a set of skills and that mindset to attack whatever might come in their future.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Are half-click attacks a concern for IT teams?]]>
            </title>
            <link>
                https://www.itbrew.com/stories/are-half-click-attacks-a-concern-for-it-teams?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Do organizations have to begin bracing for half-click attacks?]]>
            </description>
            <pubDate>
                Tue, 01 Sep 2026 15:49:59 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/are-half-click-attacks-a-concern-for-it-teams
            </guid>
            <dc:creator>
                Caroline Nihill
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Cyberattacks
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-03-20/image-029d95b0f76afc43f0693a9b9d97d757eb134a93-5125x3686-jpg/Seamlesspatternofe-mailnotificationicon.Newnotification.Receivedmessageconcept." alt="a repeating image of white envelopes with red icons indicating one unread email message " /><figcaption>Getty Images</figcaption></figure><section><p>You’ve likely heard of <a href="https://www.checkpoint.com/cyber-hub/cyber-security/what-is-a-zero-click-attack/">zero-click attacks</a>, in which an attacker sends malware via vulnerable applications such as messaging or email, infecting a system without the victim actually having to click or download anything.</p><p>Half-click attacks, in which simply previewing or opening an email is enough to trigger malicious code, are an insidious variation on zero-click attacks. They have also gained momentum over the past year; for example, cybersecurity experts recently warned that threat actors have begun using this exploit against <a href="https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-84f">Outlook Web Access</a>.</p><p>According to Tim Rawlins, director and senior advisor for global cybersecurity company NCC Group, half-click attacks are expected to become more of an issue for the private sector because of “this ability to create valid exploits.”</p><p>“Zero click needs no action, maybe half-click needs just opening or previewing a message,” Rawlins said. “The pressure has actually come back onto the technology side, and the IT team, the security team…they now have to up their game in order to be able to deal with this.”</p><p><strong>Starting with half. </strong>Greg Lesnewich, principal threat research engineer at Proofpoint, said that, while half-click attacks bear some similarities to zero-click attacks, the former belongs in its own category.</p><p>“At least in the email space, we’ve never interacted with anything that had this amount of subtlety,” Lesnewich said. “This is not an incredibly technically sophisticated exploit, even though it…feels very early ’90s or late ’90s hackery, where there’s a subtleness and quickness that comes with it.”</p><p>Half-click attacks are a problem the IT department needs to solve by patching vulnerabilities as quickly as possible. In the past, security professionals may have waited to apply patches to protect business operations from downtime, but Rawlins suggested it’s more important than ever to apply fixes quickly and look for evidence of intrusion.</p><p>“The tempo has got to increase,” Rawlins said. “Unfortunately, we haven’t got that luxury of time anymore.”</p><p>Rawlins stressed that professionals not only have to boost the rate at which they patch vulnerabilities, but also inspect an email system’s permissions to ensure attackers aren’t accessing mailboxes and exfiltrating data.</p><p>“Patch first, but don’t stop at patching, look for evidence that the attack arrived before the fix has been put in place,” Rawlins said. “You’ve got to dig all the way through that, and it’s always going to be legacy, unsupported, unpatched systems that are vulnerable.”</p><p></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Most organizations have agents acting outside of intended scope]]>
            </title>
            <link>
                https://www.itbrew.com/stories/most-organizations-have-agents-acting-outside-of-intended-scope?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Most organizations have had an agent perform actions outside of its intended scope.]]>
            </description>
            <pubDate>
                Mon, 31 Aug 2026 19:01:35 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/most-organizations-have-agents-acting-outside-of-intended-scope
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Governance
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/gif/2024-12-09/image-74d0df7988f44dcb01676626bde950c71d070320-1500x1000-gif/TB_Editorial_AI_Workplace_Mouse_FS_120924.gif" alt="Robotic hand shifting a mouse around the canvas in a circular motion" /><figcaption>Francis Scialabba</figcaption></figure><section><p>Like the cookie tin that now houses sewing supplies at Nana’s house, most enterprises are witnessing agents do things outside of their original purpose.</p><p>According to an August <a href="https://www.globenewswire.com/news-release/2026/08/31/3353329/0/en/new-cequence-ema-research-94-of-enterprises-trust-their-ai-agents-aren-t-over-provisioned-only-33-actually-enforce-it.html">report</a> from Enterprise Management Associates for Cequence Security, 65% of companies said they’ve had an <a href="https://www.itbrew.com/resources/glossary/ai-agent">AI agent</a> perform actions outside of its intended scope. Of those companies, 29.2% said these occurrences had a measurable impact (e.g., data exposure, financial loss, etc.) on their business. The findings are based on a survey of 202 global IT and security leaders at organizations deploying or evaluating agentic AI.</p><p><strong>The governance problem. </strong>Cequence CISO Randolph Barr told IT Brew the high rate of unintended-action performing agents are a byproduct of <a href="https://www.itbrew.com/stories/2026/04/22/agentic-ai-guardrails-working">governance</a> and technical failures within organizations.</p><p>“A lot of organizations adopt AI quickly. They sometimes don’t have the proper controls in place to detect what these agents are doing, and on top of that, [are] assigning general access to these agents, not going through a review process and making sure that what the intention of an agent is…doing what it’s supposed to do,” Barr said.</p><p>The report revealed several governance gaps at different stages of the agent life cycle. One is at the provisioning stage: While almost half (48.5%) of organizations said they felt very confident their agents don’t have more access than needed to perform their intended tasks, only 32.7% provision agents with least-privilege access.</p><p></p><p>Authorization was another problematic area for organizations. Only about a third (34.2%) of enterprises said they evaluate authorization the moment an agent tries to execute a specific action. The highest proportion of organizations surveyed (37.6%) evaluated authorization periodically through policy reviews, while 21.3% claim authorization is based on standing permissions assigned to agents.</p><p>“Over time, the gap between what an agent is technically authorized to do by its standing permissions and what it actually needs for any given task grows wider, and that widening gap is the direct mechanism through which overprovisioning becomes the 65% incident rate,” the report states.</p><p><strong>What’s an IT pro to do?</strong> Based on the findings, the report suggests companies build out detection and containment capabilities prior to scaling agent deployment and govern “what agents do, not just what they are.”</p><p>“Defining what an agent is permitted to do—task by task, within enforced behavioral limits—is the single most consequential control available,” the report wrote. “Treating agent authorization as a provisioning event rather than a runtime discipline will continue to produce out-of-scope actions discovered only after the fact.”</p><p>Barr added organizations should identify all agents that exist in their ecosystem and have a central place where they can manage these agents.</p><p>“The inventory is one of the biggest concerns everybody has,” Barr said. “We don’t know what to protect what we don’t know exists.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How AI can ease runbook writing ]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-ai-can-ease-runbook-writing?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[IT pros share how they’re using LLMs to assist with a tedious task.]]>
            </description>
            <pubDate>
                Mon, 31 Aug 2026 15:00:22 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-ai-can-ease-runbook-writing
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Knowledge Management
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-06-03/image-b459304b58b986b7691d9675861f232688e58a24-7611x6089-jpg/Whitecyborgrobotichandpointinghisfingertoabook.Trainartificialintelligence.Knowledgeforcybercyborgbot." alt="A robot hand being trained on a book by a human hand" /><figcaption>Getty Images</figcaption></figure><section><p>Nobody likes writing a <a href="https://www.itbrew.com/resources/glossary/runbook">runbook</a>, according to Todd Thorsen, CISO at data resilience and protection platform CrashPlan.</p><p>While runbooks’ standardized instructions for go-to IT problems can prove helpful for both new hires and on-call team members, producing these guides is “extra added overhead,” Thorsen said.</p><p>An IT pro has enough going on without spending hours laying out the directions for hardening a Ubuntu server or troubleshooting API latency with a payment platform.</p><p>But that extra workload hasn’t stopped Thorsen’s team from writing about 20 runbooks for their organization, including one on how to deploy vulnerability sensors in a new cloud environment.</p><p>Runbooks are important ways to pass on knowledge gained through experience, Srinivas Chippagiri, a senior member of technical staff at Salesforce, told IT Brew. His team has about 10 runbooks covering topics like onboarding a new engineer to a platform or restoring a failed service.</p><p>The internal guidebooks may feature experiences “that only engineers who worked on the product know about that may not necessarily be covered from manuals,” Chippagiri said.</p><p>But writing—and updating them—is a lot of work, and developers and IT leaders like Chippagiri and Thorsen have turned to AI to take on at least some of the burden.</p><p><strong>Let’s get started. </strong>Runbook creation often involves time-intensive processes: narrowing in on a specific problem, then writing the (often many) steps to truly resolve it in a style that connects with a variety of intended users, from intern to IT veteran. A runbook author might also need to understand and note the severity of certain alerts, business impacts, and dependencies on other services, and know important contact info for whoever can solve a specific problem.</p><p>As with many tedious tasks that nobody likes doing today, IT pros have a chance to hand runbook creation to a large language model (LLM) and see what comes back. But for the output to be helpful, Thorsen recommends a solid amount of input, including network diagrams, cloud configurations, and other procedure documents with context regarding alerts and previous incidents, <a href="https://www.itbrew.com/resources/glossary/disaster-recovery">disaster recovery</a> steps, and cloud-environment best practices.</p><p>A prompt to his LLM of choice might be: <em>Using these documents as a reference…create a runbook to reconstitute an AWS environment.</em></p><p>“It’s important, obviously, to have a subject matter expert who is doing the prompting and then doing the review of the output,” he said.</p><p>From there, a reviewer fills in the gaps. Thorsen, for example, makes sure his runbooks are prescriptive and contain screenshots that articulate visually how to accomplish a task.</p><p>For Chippagiri, AI has been a documentation “game-changer,” helping teams quickly provide a runbook that’s about 60% of the way there, following an input with design docs, project management artifacts, and thoughtful prompts. Human writers, he added, are left filling in gaps that LLMs might not figure out, including new permissions, outdated links, or judgment calls that only a seasoned employee would understand.</p><p><strong>Update! </strong>Thorsen has both formal review processes—annual assessments, for example, regarding what documentation needs updating and what changes have occurred in the IT environment—and informal ones. If a CrashPlan team member is working with a runbook and sees outdated information, they are encouraged to immediately provide the update and notify the team (via the Jira service-ticket platform) of any new details.</p><p>Chippagiri<strong> </strong>has even used AI for the runbook updates.<strong> </strong>“We can tell the AI to go and edit certain portions of the runbook,” he said.<strong> </strong>“You just have to do some babysitting, and then some fact-checking, and also you have to make sure that the procedures are actually correct once AI has done it.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to decommission an AI agent]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-decommission-an-ai-agent?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[It happens to Bournes, Bonds, and bots alike: Eventually, some agents need to retire.  Professional services firm KPMG’s Q2 2026 numbers reveal that, among more than 200 senior business leaders at US companies with annual revenue of $1 billion or more, AI agents have a 53% adoption rate. That’s a solid rate for deployment—but what happens if a company wants to un-deploy one, two, or even all of them? “It’s not a ‘pull the plug and see what happens,’” one IT pro said.]]>
            </description>
            <pubDate>
                Mon, 31 Aug 2026 13:34:10 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-decommission-an-ai-agent
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Change Management Processes
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-11-14/image-83c63a4e2d5b23632997ac944339867cf9e01daf-1500x1000-jpg/TB_Editorial_AI_Agent_FS_042624.jpg" alt="Illustration of AI agents connected to a grid system." /><figcaption>Francis Scialabba</figcaption></figure><section><p>It happens to Bournes, Bonds, and bots alike: Eventually, some agents need to retire.</p><p>Professional services firm KPMG’s Q2 2026 numbers reveal that, among more than 200 senior business leaders at US companies with annual revenue of $1 billion or more, <a href="https://www.techbrew.com/resources/glossary/ai-agents">AI agents</a> have a 53% adoption rate. That’s a solid rate for deployment—but what happens if a company wants to un-deploy one, two, or even all of them?</p><p>There are many reasons to cut an <a href="https://www.itbrew.com/resources/glossary/ai-agent">AI agent</a> from the tech stack: New and better ones might come along, for example, or maybe that latest research bot just isn’t providing the sales team with the right answers. But doing so without careful consideration could lead to problems related to security, service outages, and angry users.</p><p>We spoke with agentic pros about how to give an AI agent its burn notice.</p><p><strong>Same old, same old. </strong>A typical IT pro is no stranger to decommissioning software. In the course of their career, a company’s resident techie has likely had to disable everything from an unused email server to an old fax machine.</p><p>Shutting down an agent is fundamentally another change-management exercise, according to Guy Bourgault, head of agentic services at tech-services provider Concentrix, and requires familiar steps: preset rollback plans, audit trails, and dependency monitoring.</p><p>Agents, however, also introduce unique-to-agent considerations:</p><ul><li>Permissions (who has access)</li><li>System access (what systems the agent can interact with)</li><li>Tokens (the bits of input and output text that can lead to high costs)</li></ul><p>“Those represent latent vulnerabilities,” Bourgault said.</p><p><strong>Step 1: Audit. </strong>Before decommissioning, Bourgault recommends an audit of the agent’s last 60 days of activity “to really understand if some of the assumptions that you’ve made about decommissioning are backed up by the day-to-day performance and data that’s available.” That assessment should include conversational flow, use cases, knowledge bases, how agents are activated, and interactions with additional agents—and if all of those activities match expectations.</p><p>“It’s not a ‘pull the plug and see what happens,’” Bourgault said.</p><p>Bourgault frequently works with clients on mapping how AI fits into a business process; he sees that dependency graph also helping an IT pro understand who’s using the agent and what’s impacted if an agent disappears. Today’s asset-tracking <a href="https://www.itbrew.com/resources/glossary/it-service-management">ITSM</a> tools, which can spot configuration items in configuration management databases (CMDBs), can be repurposed to discover an agent’s connections and impacted systems, he added.</p><p>Bourgault also recommends that agent decommissioners consider the following:</p><ul><li>Identify stakeholders and who’s impacted—and anticipate customer impacts and increased workloads as teams troubleshoot and work through the new workflow</li><li>Plan the replacement process.</li><li>Deactivate but don’t fully remove the agent. Archive prompts, knowledge base articles, context and definitions, guardrails and intents, and be ready to roll the agent back quickly if needed.</li></ul><p><strong>Keys and tokens, too.</strong> Agents are given access to services to do their jobs. Proper decommissioning means disabling the credentials to those third-party platforms so they can’t be exploited by threat actors.</p><p>An agent may use an API key to access an external party’s data source. Shanti Greene, head of data science and AI innovation for enterprise AI solutions company AnswerRocket, recommends one unique key per agent; that way, if a runaway API key is running on a loop and triggering charges, you know which agent is causing the problem.</p><p>When an agent needs to be retired, Greene advises IT pros to go to the provider’s platform and revoke (or disable) a given key. He has used an <a href="https://github.com/Infisical/agent-vault">open-source tool called Infisical</a> as a kind of access broker that keeps agents from possessing credentials at all; the manager grants agents access on demand without making the credentials directly visible to those agents.</p><p>And there are tokens, too—meaning credentials, not the AI processing units. An agent might have access-granting OAuth tokens or credentials, depending on the systems it touches, which is no different than a human user’s typical access. For example, an agent running in Entra might have permissions to interact with Google Cloud. A configuration setting in Google’s platform enables trust with an Entra token; you want to make sure you dispose of that, according to Will Pocknell, director of cybersecurity at solutions integrator Insight, to avoid inadvertent privilege escalation. (There has been extensive reporting on how hackers steal OAuth tokens to attempt access to platforms like <a href="https://nhimg.org/salesloft-drift-key-breach-hackers-steal-oauth-tokens-to-access-salesforce-data">Salesforce</a>, <a href="https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/vercel-breach-oauth-supply-chain">Vercel</a>, and <a href="https://hackread.com/lastpass-customer-data-breach-klue-oauth-token/">LastPass</a>.)</p><p>While it’s important for IT pros to log traces of an agent to avoid potential disruptions, it can add to the cleanup if an agent needs to be disabled, especially if the team must eliminate virtually every trace of the agent’s workflow.</p><p>“If an agent is offboarded, you are cleaning up all the artifacts associated with that agent, almost to the point where it almost as if the agent never existed,” Pocknell said.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Solving the security threat of dropped domains]]>
            </title>
            <link>
                https://www.itbrew.com/stories/solving-the-security-threat-of-dropped-domains?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[What happens to forgotten domains? That depends on how well the cybersecurity team is paying attention to temporary domains. ]]>
            </description>
            <pubDate>
                Fri, 28 Aug 2026 20:15:14 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/solving-the-security-threat-of-dropped-domains
            </guid>
            <dc:creator>
                Caroline Nihill
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Managed Detection &amp; Response
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/gif/2025-01-24/image-f975f78416c71639b9faaacd2cb9bb4892a0d0ed-700x467-gif/TB_Editorial_AI_Domain_AMK_012425.gif" alt="Animated gif of a .com domain being switched to .ai. Credit: Anna Kim" /><figcaption>Anna Kim</figcaption></figure><section><p>As a web developer, you might be tasked with setting up a temporary website for a company event. But when the website’s no longer needed, what happens if you lose track of the domain?</p><p>If a company somehow misses the warning emails to renew, the domain will be rereleased to the public, where anyone can register it—opening the door to “dropcatch attacks,” or malicious actors who use the domain to redirect users to scams and malware.</p><p>In a <a href="https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/">blog post</a>, IT automation and cybersecurity company Infoblox reported that it had observed more than 50,000 dropcatched domains (i.e., a domain name expiring, becoming available to the public, and someone securing it) per day among generic top-level domains—that is, .com, .org, .net, .biz, and .info—in the first half of 2026.</p><p>While not all of those dropcatches were necessarily linked to attacks, it shows the scope of the potential problem when businesses shut down, miss renewal notices, or forget email accounts tied to web addresses.</p><p><strong>How’d you drop that? </strong>Renée Burton, Infloblox’s VP of threat intel, told IT Brew that the best way for enterprises to maintain domain security is through policy and processes. For example, that could mean ensuring an employee can’t use a company’s brand name as part of a domain registration without going through a centralized group or the IT department.</p><p>“It’s really a process and policy issue,” Burton said. “In the end, so many ways that things can go wrong, so you need to be able to say, ‘I have a centralized location.’”</p><p>Along with process and policy, Burton suggested that IT professionals should employ monitoring tools to detect website impersonators who might use content like corporate logos and brand signals to fool users into thinking a website is legitimate.</p><p>Luigi Lenguito, the founder of cybersecurity firm Bfore, told IT Brew that without strong governance, employees or third party-vendors could spin up domains without plans for proper takedowns.</p><p><strong>How to pick up dropped domains. </strong>Bigger corporations are largely protected from dropcatch-style attacks because they have resources to aid governance, including procedures and tooling, while medium-size organizations do not: “Domain maintenance is quite an intense activity; it does require governance, it does require tooling for visibility.”</p><p>Lenguito added that while the first step that organizations at risk can take is to preemptively avoid attacks through governance and visibility efforts, organizations can also look to use external <a href="https://www.itbrew.com/resources/glossary/attack-surface">attack surface</a> tools to find and disrupt impersonation domains as they go up to protect customers.</p><p>“What the end result is is that proper domain is not accessible anymore and in much less time than if you’re doing just [a] takedown,” Lenguito said. “But you’re basically getting out of the internet.”</p><p></p><p><em>Correction 08/31/2026: Bfore’s name has been updated from BforeAI.</em></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Companies want AI-native CISOs, but supply is tight]]>
            </title>
            <link>
                https://www.itbrew.com/stories/companies-want-ai-native-cisos-but-supply-is-tight?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[More and more companies want CISOs with agentic experience. Problem is there isn’t that many.]]>
            </description>
            <pubDate>
                Fri, 28 Aug 2026 13:11:55 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/companies-want-ai-native-cisos-but-supply-is-tight
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Hiring
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-10-17/image-ab7cfc02db6a399a73e2deb0c82c14fb6072ee9d-5150x4000-jpg/Artificialintelligenceandrobotics,concept." alt="image of human and robot shaking hands out of computers" /><figcaption>Getty Images</figcaption></figure><section><p>What do companies want? CISOs skilled in <a href="https://www.hr-brew.com/resources/glossary/agentic-ai">agentic AI</a>. When do they want it? Now. Although actually finding one is proving difficult for many.</p><p>According to <a href="https://www.businesswire.com/news/home/20260812180500/en/Demand-for-AI-native-security-chiefs-jumps-256-Christian-Timbers-research-finds">research</a> from executive recruitment firm Christian &amp; Timbers, the demand for AI-native CISOs and CSOs jumped 256% in the first seven months of the year compared to the same period last year. The findings are based on roughly 100 conversations between Christian &amp; Timber partners and C-suite executives between January and July.</p><p><strong>Where’s the supply?</strong> While more companies want CISOs with agentic expertise, supply has yet to match that demand, according to Christian &amp; Timbers President JC Christian.</p><p>“For basically any AI-native role, supply is very scarce,” Christian said. “The very best is able to command a premium as a result.”</p><p>The imbalance in supply and demand for AI-native CISOs extends beyond Christian &amp; Timbers. Martha Heller, CEO at Heller, an IT executive recruiting firm, said she has witnessed a sudden uptick in clients seeking agentic AI skill sets from CISO contenders, which she noted are few and far between at the moment.</p><p>“What’s so fascinating about it is…you cannot really say, ‘I want someone who has built and implemented a comprehensive agentic cyber program,’ because no one has. It is totally and completely new,” Heller said. “And that’s what’s so interesting about recruiting now is so much more often, you’re looking for ability than experience, because there just isn’t any.”</p><p><strong>How to be an attractive CISO candidate. </strong>While<strong> </strong>not many CISOs have deep agentic experience, Christian and Heller said there are still ways to remain marketable in today’s job market. Christian suggested that security pros try to serve as “positive catalysts” of agentic initiatives within their current organization.</p><p>“You should be able to develop agentic frameworks for each of the surface areas for risk, both from, in some cases, offensive, but mostly defensive security and posture,” Christian said.</p><p>Heller added that security leaders should embrace AI inside and outside of the workplace.</p><p>“Become AI-focused. Take whatever certifications in AI you possibly can. Put AI all over your résumé, and say right in a top bullet that agentic AI and agentic cyber is a strong focus of yours,” Heller said. “Just deck yourself out in agentic AI.”</p><p>And finally, Heller reminds CISOs of the importance of context for AI, encouraging leaders to lean into familiar business processes when applying for agentic AI positions, because this technology is ultimately designed to make those processes more efficient. </p><p>“If you’ve never been in a hospital, you probably aren’t going to be as good at that as somebody who worked in that field,” Heller said. “I would say really understand yourself, cyber leader. Are you great with banking info? Are you great with HIPAA? What is your lane?”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[Should the private sector be able to hack foreign cybercriminals?]]>
            </title>
            <link>
                https://www.itbrew.com/stories/should-the-private-sector-be-able-to-hack-foreign-cybercriminals?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[President Donald Trump has given the private sector the go-ahead to help combat foreign cybercriminals.]]>
            </description>
            <pubDate>
                Wed, 26 Aug 2026 19:09:24 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/should-the-private-sector-be-able-to-hack-foreign-cybercriminals
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Hacking
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-06-03/image-747f9387af34ef8bbd7253d2f3caebabe1ad636d-5648x3765-jpg/SystemhackedwarningalertonnotebookLaptop.CyberattackoncomputernetworkVirusSpywareMalwareorMalicioussoftware.Cybersecurityandcybercrime.Compromisedinformationinternet." alt="A computer with a warning sign" /><figcaption>Getty Images</figcaption></figure><section><p>Like Batman telling Robin to get to the Batmobile, the US government has called on the private sector to act as its sidekick in the fight against foreign cybercriminals.</p><p>According to an <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/">Aug. 12 memorandum</a> signed by President Donald Trump, the National Coordination Center (NCC) is slated to stand up a program that will enable private companies to conduct “cyber surveillance operations and cyber effect operations against foreign cyber-enabled Transnational Criminal Organizations.”</p><p>The program will be overseen by co-executive directors from the Department of Justice (DOJ) and Department of Homeland Security (DHS). Participants will undergo “rigorous vetting” and enter a contractual agreement with the federal government, putting aside at least $1 million that can be forfeited if that contract is violated.</p><p>“American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo stated. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”</p><p><strong>Lots of incentive. </strong>There are several reasons why private companies may be interested in participating in this new program, according to experts speaking to IT Brew.</p><p>Gary Barlet, public sector CTO at Illumio, said the initiative would give private companies the ability to “protect themselves and go after the people that are attacking them.”</p><p>“I think that companies are going to be a little more open to it because they can more aggressively defend themselves through the offense instead of just sitting back, always on the defense,” Barlet said.</p><p>Companies may also want to take part in the program for the publicity. “There’s certainly some PR benefits to it from a company perspective of being able to say, ‘Look what we did for the greater good,’” Barlet said.</p><p><strong>Upsides. </strong>The new program would offer the federal government several benefits, as well. Barlet said the program is a good way for the government to leverage the breadth of talent and resources within the private sector and expand its offensive capabilities without paying a hefty price.</p><p>“From the government’s perspective, it’s really opening the aperture of what they have available,” Barlet said. “More tools in the toolbox.”</p><p>Stephen Boyer, founder and chief innovation officer at Bitsight, added that the cyber program can have a monumental impact on global cybercrime if successful.</p><p>“If you were to disrupt, and I don’t know if you can fully eliminate, but I would say degrade, some of these criminal groups, that will ripple through the planet,” Boyer said. “That has an opportunity to have really a global impact for good when you think about being able to reduce some of this criminality.”</p><p><strong>Downsides. </strong>But some cybersecurity experts still have some concerns. Barlet, for example, said other nation states may deem participating companies as adversaries and begin to target them.</p><p>“Now the question becomes: Isn’t that already happening? Aren’t these companies already dealing with countries like Russia, China, Iran, North Korea?” Barlet said. “Those countries are actively targeting our companies anyway. So, how much of a downside is that? How much of a risk is that?”</p><p>Adam Marrè, CISO at Arctic Wolf, raised concerns around unintended consequences of offensive operations: “This could happen if you misattribute the attack and end up attacking the wrong infrastructure or the wrong target. It could also happen where, in conducting an offensive operation against infrastructure, you unintentionally harm people that are also on that infrastructure.”</p><p>Operations from participant companies will be subjected to an evaluation process that will assess possible unintended consequences. “That brings up another question, which is unclear from the memo and unclear from case law, which would be, who’s liable for that?” Marrè added. (The White House did not comment on either of these concerns.)</p><p><strong>Greenlight?</strong> Despite its flaws, cybersecurity professionals IT Brew spoke with were largely in favor of the program.</p><p>“I definitely think that we should consider all options when addressing cybersecurity,” Marrè said. “I don’t think any one thing we do is going to be the magic bullet that is going to stop all cybercrime. I think there is a potential here for some benefit.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[IT Brew Movie Club: ‘The Net’ (1995)]]>
            </title>
            <link>
                https://www.itbrew.com/stories/it-brew-movie-club-the-net-1995?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[What the 1995 thriller got right—outside of online pizza delivery.]]>
            </description>
            <pubDate>
                Tue, 25 Aug 2026 20:47:32 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/it-brew-movie-club-the-net-1995
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Threat Landscape
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-08-25/image-3843b5a6ede3d9dc79af2e146b4990f23ce9420d-1540x1040-png/ITB-MovieClub-TheNet-0826.png" alt="Scenes from the 1995 movie, The Net, an American action thriller film starring Sandra Bullock" /><figcaption>Illustration: Morning Brew Inc, Photos: Sony Pictures Releasing</figcaption></figure><section><p>If you were a systems analyst in 1995, you brought two towels to the beach: one for you and one for your giant laptop.</p><p>That’s what an IT pro’s day off looks like in the dial-up-era movie <em>The Net</em>.</p><p>The thriller begins with hacker and loner Angela Bennett (played by Sandra Bullock) going on a rare vacation and meeting a suave stranger—someone who has also brought his tech gear to the beach. He even, she learns, enjoys a Gibson cocktail—her favorite. Too good to be true? Or is this meet-cute actually a meet-phish?</p><p>Since this is a thriller, of course it’s the latter: the man on the beach is none other than villainous, just-check-his-last-name Jack Devlin (Jeremy Northam).</p><p>Devlin works for the Praetorians, a group that exploits vulnerabilities in airports, Wall Street, and other critical environments. These threat actors also might be connected to Gregg Microsystems, a company that conveniently offers the high-access security solution. When Bennett identifies a backdoor to the firm’s “Gatekeeper” security system, Devlin and his group attempt to leverage that information from her by manipulating her private records, replacing her digital identity with a criminal’s.</p><p>While much of the technology has advanced since the movie’s premiere—most notably <a href="https://www.youtube.com/watch?v=2CnWs8jDbXo">online pizza delivery</a>—some IT threats never change. Juan Orlandini, CTO for North America at solutions integrator Insight, shared some lines that stuck out, and which offer some lessons for tech pros decades later.</p><p><strong>“The beauty of the Gatekeeper system is that we can get in and out of the FBI like it’s the public library.”</strong></p><p>Devlin delivers this line in the movie’s finale. There’s a ring of contemporary truth to it: today’s tools give threat actors the ability to enter a system like they were sneaking through an open window.</p><p>Cyber adversaries have shown their willingness to disrupt infrastructure—<a href="https://www.itbrew.com/stories/cyberattacks-on-water-infrastructure">most recently water facilities</a>—via backdoors intentional or unintentional. Sophisticated large language models like Anthopic’s Claude Mythos Preview are <a href="https://www.itbrew.com/stories/2026/04/17/how-cisos-can-prepare-for-a-new-wave-of-ai-discovered-software-vulnerabilities">finding vulnerabilities</a> at higher rates than ever; that’s great if those capabilities end up in the hands of the Angela Bennetts of the world and catastrophic in the hands of Jack Devlins.</p><p>“If these state actors now have access to these frontier-style models that [have] actual Mythos-level capabilities, nothing prevents them from being able to penetrate very sensitive environments and then get into very secure content, or destroy infrastructure…who knows?” Orlandini told us.</p><p><strong>“It’s like this little electronic shadow on each and everyone of us, just begging for someone to screw with…”</strong></p><p>Our electronic shadows have only expanded since <em>The Net</em>’s premiere, given the prevalence of system logs and social media. An IT pro has the tough job of reducing that footprint, including by restricting features at the office like “shadow” AI tools or personal email.</p><p>“IT is generally seen as the department of ‘no,’” Orlandini said. “What they’re trying to do is actually prevent that shadow from having a bigger impact than it should.”</p><p>Today’s threat actors, according to Orlandini, tailor phishing messages with details discovered through session cookies, online profiles, or public interviews. “As you’re browsing the internet, you’re leaving this trail,” he said. (A pen tester once shared with IT Brew how they used a photo of an exec’s <a href="https://www.itbrew.com/stories/2023/12/08/how-an-exec-s-digital-life-offer-clues-for-hunting-hackers">brand new Corvette</a> against them.)</p><p><strong>“Sorry, you don’t understand. l’m Angela Bennett. l’m standing right here.”</strong></p><p>While today’s victims may not have to deal with a complete erasure of their digital identity, adversaries in 2026 can still use emerging technologies to disrupt someone’s life. Orlandini noted <a href="https://www.yahoo.com/news/us/articles/case-case-every-reported-flock-175653036.html">reports of Flock cameras</a> making errors resulting in innocent drivers being pulled over; a hacker with the wherewithal and the tools could mess with someone’s presumed identity.</p><p>“You might not be able to do a complete wipeout of someone’s digital self, but I do know that you can do a good enough job that it makes your life a nightmare,” he said.</p><p>-<strong> “We’re sitting on the most perfect beach in the world...and all we can think about is…”</strong></p><p>- <strong>“…Where can l hook up my modem?”</strong></p><p>To some degree, this line demonstrates the comedy of 1995’s cutting-edge technology—the modem as an everyday essential. Orlandini remembers watching the movie then and being impressed by the 640x480 resolution of one of the beach laptops (“That was state-of-the-art. Man, I wanted that laptop so bad back then”) and even a character’s cell phone, which plugged into his car. (“That guy must be rich,” Orlandini also remembered thinking at the time.)</p><p>The quotation plays into the overall theme of the movie: it’s lonely being a hacker—you’re on a beautiful beach, but you’re also by yourself, and you’re thinking about modems. Bennett does seek out friendship in chat rooms, but those digital interactions were still nascent in 1995.</p><p>Thirty years later, Orlandini sees today’s digital connections and friendships as a way of addressing isolation—or what might look like isolation—in a job that involves interfacing with computers: “It might seem lonely on the outside, but it’s actually very rich on the inside.”</p><p><em>For more IT Brew movie club, check out our dives into</em> <a href="https://www.itbrew.com/stories/2025/10/03/how-the-hacks-in-hackers-hold-up">Hackers</a><em>,</em> <a href="https://www.itbrew.com/stories/2026/02/04/it-brew-movie-club-sneakers-1992">Sneakers</a><em>,</em> <a href="https://www.itbrew.com/stories/2026/03/11/it-brew-movie-club-blackhat-2015">Blackhat</a><em>,</em> <a href="https://www.itbrew.com/stories/2026/04/03/it-brew-movie-club-skyfall-2012">Skyfall</a>, <a href="https://www.itbrew.com/stories/2026/04/30/it-brew-movie-club-the-matrix-1999">The Matrix</a>, <a href="https://www.itbrew.com/stories/it-brew-movie-club-jurassic-park">Jurassic Park</a><em>,</em> <a href="https://www.itbrew.com/stories/it-brew-movie-club-wargames-1983">WarGames</a>, and <a href="https://www.itbrew.com/stories/it-brew-movie-club-blade-runner">Blade Runner</a><em>.</em></p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How to prepare for a healthcare AI audit]]>
            </title>
            <link>
                https://www.itbrew.com/stories/how-to-prepare-for-a-healthcare-ai-audit?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[What do when the board wants an AI governance review]]>
            </description>
            <pubDate>
                Tue, 25 Aug 2026 20:46:22 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/how-to-prepare-for-a-healthcare-ai-audit
            </guid>
            <dc:creator>
                Billy Hurley
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                IT Governance
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2025-10-06/image-71eb7c106f2796acb3483c1e5ce336f1d38e38d6-6850x4541-jpg/WarningAlertSymbol.Aredwarningsymbolundermagnifyingglass,symbolizingriskdetection,safetyalerts,issueinvestigation,orsystemmonitoringinbusinessandtechnologycontexts." alt="AICPA audit" /><figcaption>Getty Images</figcaption></figure><section><p>Kevin Dunnahoo often works with CIOs, CISOs, CFOs, and other healthcare C-suite executives on internal risk assessments.</p><p>A quarterly evaluation takes on specific objectives, like identity and access management, cybersecurity evaluation, or, lately, <em>what’s going on with all this AI</em>?</p><p>While <a href="https://www.itbrew.com/resources/glossary/hipaa-implementation">HIPAA regulations</a> require a continuous risk assessment of how an organization manages its protected health information (PHI), a healthcare organization is more likely to face an audit from its board, according to Dunnahoo, director of healthcare technology, cybersecurity, AI, and IT audit at global consultancy Protiviti.</p><p>“Many of the boards are asking flat out, ‘Hey, I want to understand what AI we’re using and how we’re using it, and how are we controlling it,’” Dunnahoo told us. “They want a true <a href="https://www.itbrew.com/resources/glossary/ai-governance">AI governance</a>-focused review on the plan, on an annual basis at this point, because they understand that there is so much potential risk.”</p><p>Dunnahoo and other healthcare IT pros shared how companies can deploy AI in a way that satisfies governance standards, and, hopefully, any auditors.</p><p><strong>Listen up. </strong>An Eliciting Insights survey of 120 US healthcare leaders, published in 2026, found that 3 out of 4 respondents use or plan to use at least one AI application—an increase from 59% in 2025. Top use cases include clinical notetaking and ambient listening, clinical documentation improvement (CDI), and coding.</p><p>A company introducing an AI deployment—ambient listening devices, for example—needs to answer some key questions, according to Dunnahoo. First, was the business case documented and approved? There should be sign-offs from an AI governance committee, and the organization should consider individual security reviews, Dunnahoo added: In addition, the business owner (not the CIO or CISO) should sign off and own the AI use; the committee then signs that it has reviewed and approved the risk.</p><p>Other questions to answer include: </p><ul><li>What data will the tool have access to?</li><li>Who can access the AI?</li><li>What is the value expected? (“ROI is a real question that’s being asked in a lot of these situations. And is that ROI commensurate with the potential risk that we’re also bringing into our organization to use that AI?” Dunnahoo said.)</li><li>What will be the monitoring mechanism?</li></ul><p>MultiCare Healthcare System, a healthcare network in the Pacific Northwest, recently announced its use of ambient listening in some of its 13 hospitals. CISO Jason Elrod (and executive advisor at cybersecurity company Elisity) shared how it works: a clinician asks the patient’s permission to turn on the recording device, and the tech generates draft notes from the conversation and surfaces relevant clinical details.</p><p>But that kind of system requires guardrails, and “ambient” doesn’t mean “always on,” according to Elrod; the system automatically deactivates at the end of a meeting, or when the clinicians leaves a patient’s chart, for example.</p><p>“I’m less interested in whether something has an AI label on it than I am in what data it can see, what systems it can touch, and what actions it can take,” Elrod said.</p><p><strong>How to audit agents. </strong>If a board member or even a HIPAA auditor arrives to investigate a data breach, healthcare IT pros should be ready with receipts like third-party risk assessments and documentation revealing configuration decisions for <a href="https://www.techbrew.com/resources/glossary/ai-agents">AI agents</a>, according to Ryan Meehan, managing director and healthcare practice leader at compliance-services firm Schellman.</p><p>As organizations deploy <a href="https://www.hr-brew.com/resources/glossary/agentic-ai">agentic AI</a>—say, for appointment automations—Meehan recommends additional safeguards like: </p><ul><li>Giving agents unique IDs, with least privilege (i.e., having access to only essential resources to perform a task)</li><li>Robust audit logging so an IT pro can reconstruct an event sequence if necessary</li><li>Knowing your “source of truth,” and exactly where your AI is pulling data from</li><li>Constrain input possibilities, tailored to a given application</li></ul><p>“I think it goes back to, ‘Did you build it in a way that had trust with all the parties involved?’” Meehan said.</p><p>Meehan recommends frameworks like <a href="https://www.iso.org/standard/42001">ISO 42001</a>, NIST’s <a href="https://www.nist.gov/itl/ai-risk-management-framework">AI Risk Management Framework</a>, and especially agent standard <a href="https://www.aiuc-1.com/">AIUC-1</a> for technical controls.</p><p><strong>In the shadows. </strong>From Dunnahoo’s perspective, the biggest problem these days is shadow AI. Companies like ServiceNow and Palo Alto Networks have introduced products that look for network signatures of AI usage, such as a clinician using an unapproved chatbot.</p><p>But if a doctor uses their phone as a hotspot, with their camera-equipped, AI-enabled Meta glasses connected to it, many tools can’t flag that kind of activity, according to Dunnahoo. How to manage the rogue AI usage remains a main concern on the minds of many healthcare leaders.</p><p>“That is the million-dollar question, and it’s one everybody is trying to answer right now,” Dunnahoo said. “From an audit, we are trying to look for how the organization is keeping a pulse where that shadow AI would be occurring. We’re looking at how the organization is communicating and setting that policy and expectation for what is allowed AI.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[What to consider when negotiating AI contracts]]>
            </title>
            <link>
                https://www.itbrew.com/stories/what-to-consider-when-negotiating-ai-contracts?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[We caught up with Bread Financial EVP and CTO Allegra Driscoll on what matters most to her when at the negotiation table for AI vendor contracts.]]>
            </description>
            <pubDate>
                Tue, 25 Aug 2026 16:14:25 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/what-to-consider-when-negotiating-ai-contracts
            </guid>
            <dc:creator>
                Brianna Monsanto
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Contract Management
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-08-25/image-73e625900bf69384ebd8e9c6e285043670b0bd85-1500x1000-jpg/ITB-QA-AllegraDriscroll-BreadFinancial-0826.jpg" alt="Headshot of Allegra Driscroll against a purple background." /><figcaption>Allegra Driscroll</figcaption></figure><section><p>A lot can change in a year.</p><p>That’s why Bread Financial EVP and CTO Allegra Driscoll often gravitates toward one-year contracts when working with AI vendor partners.</p><p>“So much is happening in the environment. Technology is moving so quickly, and we want to make sure that we continue to create the best technical ecosystem that delivers against our business capabilities, and [are] having more frequent opportunities to pivot and refresh who we partner with,” she said.</p><p>Driscoll, who has been negotiating software and now AI contracts as part of her career for the past two decades, told IT Brew that she views partnerships with vendors as a “two-way street.”</p><p>“The best contracts reflect the way that you want that partnership to work,” Driscoll said. “That spirit of collaboration, that openness, that willingness to pivot, and that you plus ‘new company X’ are better together than apart.”</p><p>We caught up with Driscoll to discuss how she negotiates AI contracts.</p><p><em>This interview has been edited for length and clarity.</em></p><p><strong>What’s top of mind when it comes to negotiating AI contracts?</strong></p><p>One is flexibility. If we’re going to sign one-year contracts, working with a partner who is not willing to sign a shorter contract is a non-starter. We like to work with partners that are willing to experiment in our lab before we decide to scale in earnest, because there’s a lot that you can learn by getting hands-on with the technology.</p><p>And then just more broadly, openness—when it comes to architecture, data, data access—[is] really important. If you think about where you’re able to maximize the business value, it’s where you have a connected data ecosystem, and so if you buy solutions and those partners are not willing to be open with the data that lives in that environment, then you’re pretty limited in your ability to then look across the organization and maximize the value of that purchased piece of software.</p><p><strong>Are there any common mistakes tech pros make during the negotiation process?</strong></p><p>The easiest mistake, given how much is going on in the news today, is to feel like, “Oh, we’re not using piece-of-technology X”…and to get into that chase-the-shiny-object mode, and be focusing on the tools over the business objective.</p><p>I would say think about your AI investments the way that you would think about your technology investments overall, which is tech is only as good as the business objectives it delivers, and AI is just sort of another tool in the toolbox to reimagine how customer capabilities, partner capabilities, you know, associate capabilities can be can be brought to life.</p><p><strong>How should businesses go about preventing vendor lock-in?</strong></p><p>Sometimes vendor lock-in is unavoidable in a practical way, at least in a sort of near-term horizon. So, it may be an unpopular opinion, but I think it’s okay to decide that you have a great partnership, they have a great product, and together [you’ll] be able to deliver on important business priorities at a price that makes sense and a level of risk that you’re comfortable with. I think the key is to continue to evaluate that lock-in on a fairly regular basis to determine, “Do I want to continue? Is this lock-in continuing to provide business value, or do I need to start to make a plan to unwind that lock-in?”</p><p>One of the things that we have started doing more and more, though…is pick the spots where you’re trying to deliver something that is really differentiated for your business and take a champion-challenger approach. Have two providers in the space and give yourself, from an architecture design perspective, that right to spend a little bit more because the area is so important and you can’t afford to have that vendor lock-in and you can’t afford to be late as business priorities shift.</p><p>It’s okay to make some of those decisions, but it’s important to be intentional about it. Pick the spots where you say, “All right, lock-in cannot happen in this space, and so we’re going to put two different investments against the same business objective.” And then you have full ability to throttle back and forth. And in other places, accept that there is a degree of lock-in, but give yourself the flexibility to renew that commitment with each of your partners on a regular basis as the world changes quickly.</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
        <item>
            <title>
                <![CDATA[How Semgrep's Cris Thomas sees the industry-hacker divide]]>
            </title>
            <link>
                https://www.itbrew.com/stories/cris-thomas-industry-hacker-divide?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed
            </link>
            <description>
                <![CDATA[Cris Thomas on how the cybersecurity community intersects with industry.]]>
            </description>
            <pubDate>
                Tue, 25 Aug 2026 14:12:24 +0000
            </pubDate>
            <guid>
                https://www.itbrew.com/stories/cris-thomas-industry-hacker-divide
            </guid>
            <dc:creator>
                Caroline Nihill
            </dc:creator>
            <category>
                IT Brew
            </category>
            <category>
                Cybersecurity Trends
            </category>
            <content:encoded>
                <![CDATA[<figure><img src="https://morningbrew.com/cdn-cgi/image/width=1600,height=900,quality=80,format=jpeg/https://storage.morningbrew.com/image/2026-08-25/image-ccc2a1b62f31093ca6fe1a34893d5f3cd0864247-1500x1000-png/ITB-Profile-CrisThomas-Semgrep-0826.png" alt="A headshot of Cris Thomas" /><figcaption>Cris Thomas</figcaption></figure><section><p>The online cybersecurity community is a vital force when it comes to identifying and closing vulnerabilities in software and systems. However, many organizations seem determined to keep that community at arm’s length—even if the latter’s work can help keep tech stacks secure.</p><p>Cris Thomas, security advocate at cybersecurity company Semgrep, told IT Brew that this tension is a longstanding one.</p><p>Thomas entered the cybersecurity scene via L0pht Heavy Industries, an early hacker collective. In 1998, Thomas, and his L0pht colleagues testified in front of Congress about the younger internet’s <a href="https://www.businessinsider.com/space-rogue-l0pht-1998-testimony-2016-6">vulnerabilities</a>.</p><p>Since then, Thomas has worked in cybersecurity roles for companies like IBM, Tenable, and Trustwave, while also serving as a white hat hacker and cybersecurity pundit.</p><p><strong>Let’s start at the beginning. </strong>Thomas’s earliest memories of working with technology include building flashlights from old cell batteries, some wire, and a lightbulb so he could read at night. Back then, his reading choices included <em>Little House on the Prairie </em>or the <em>Hardy Boys </em>series. From there, he plunged into tech and speculative-fiction literature such as <em>Stand on Zanzibar, Zero Day, The Cuckoo’s Egg</em>, and more.</p><p>Obviously, Thomas’s reading list has changed. But some things have largely stayed the same for the broader cybersecurity community.</p><p>In the 80s and 90s, Thomas said, “a lot of people were hidden behind their keyboards, and so you would have folks who were looking for found families…looking for a subculture to belong to.” While some people on the fringe of the mainstream sought solace in punk music or other subcultures, Thomas and others found themselves picking apart vulnerabilities in infrastructure.</p><p>“I see a much more accepting culture today, at least in the community,” he said. “As far as the industry goes, industry’s always been industry, and industry likes to sell to industry. And anything that’s sort of different sometimes gets frowned upon.”</p><p><strong>Community service. </strong>According to Thomas, parts of the cybersecurity industry have an issue with including the broader cyber community in its defensive workflows.</p><p>“It’s definitely an issue that’s been ongoing for a while; we have some companies that don’t want to have anything to do with the community at all, and because they’re afraid of the hacker label,” Thomas said. “I think that industry as a whole would be better served if they were more ingrained with the community; and the community, of course, gets the benefit of more jobs.”</p><p>For companies that embrace the cybersecurity community, there’s the added benefit of that community’s collective knowledge.</p><p>“Some of the best security operations that I’ve been involved in have had multiple community participants in them,” Thomas said. “Sometimes companies shy away from community participants, and I think that’s wrong, I don’t think you’re getting the best value for your dollar, you’re not getting the best value for your people.”</p></section><p></p><p>Top insights for IT pros. <a href="https://www.itbrew.com/subscribe?utm_source=&amp;utm_medium=syndication&amp;utm_campaign=feed">Subscribe to IT Brew today.</a></p>]]>
            </content:encoded>
        </item>
    </channel>
</rss>