Cyber Resilience with Cohesity, When to use AI for Writing, and the News – Rob Sadowski – ESW #477
Interview with Rob Sadowsky from Cohesity
Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this MomentCyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act.In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality.With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell.To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries.This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience.https://www.cohesity.com/dm/global-cyber-resilience-report/This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them!Topic: When should we use AI for writing and when should we avoid it?
I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words.Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other.https://charity.wtf/p/confessions-of-an-unrepentant-slopWhen I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it.I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine.In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language.And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-reviewWeekly Enterprise News
Finally, in the enterprise security news,- We check the vibes, funding, and acquisitions
- Tenable now has Mythos built-in???
- We check in on how vulnerability remediation is going
- Microsoft is creating a code of conduct for AI
- OpenAI just got called to the principal’s office
- Booz Allen created new cybersecurity AI benchmarks
- 50% of CISOs see Mythos as a sign to resign???
- Ayman read the latest Anthropic AI misuse report
- MIT explains the 12 possible AI outcomes (very ominous)
- a 9-year old decided to promote his YouTube account… with his dad’s corporate card
Rob Sadowski is Vice President of Product and Solutions Marketing at Cohesity, bringing deep experience across cybersecurity, cloud, and enterprise technology. Prior to Cohesity, he spent eight years at Google Cloud, most recently serving as Director of Product Marketing for Trust and Security, where he led the team responsible for Google Cloud’s security messaging across platforms, applications, and AI.
Previously, Rob held senior strategy and marketing roles at RSA Security, joining as part of the team that helped launch EMC Corporation’s Security division. He is a former member of the PCI Security Standards Council Board of Advisors and has provided cybersecurity commentary to global media outlets including CNN, the Financial Times, Fox Business, and CNBC. His expertise spans security thought leadership, analyst relations, product positioning, and go-to-market strategy.
A native Bostonian, Rob is an avid sports fan and New England Patriots supporter. Outside of work, he enjoys music, cooking, dining, and golf.
- Security leaders, identity is now your primary attack surface. MFA fatigue attacks, privilege sprawl, and over-provisioned access are driving real risk across the enterprise.But do you actually have visibility and control?At the Identity Virtual Cybersecurity Summit on September 30th, learn how leading organizations are reducing identity risk, enforcing least privilege, and advancing Zero Trust strategies.Security Weekly listeners can register for free at https://securityweekly.com/identity using the promo code: CSS26-SW
- AI is changing financial services fast. Join us December 9 in New York City for the Financial Services AI Security Forum, where industry leaders will tackle AI security, risk, fraud, governance, and resilience. Register by October 2 and save $400. Tickets are just $195, so secure your seat today at securityweekly.com/aiforum2026
Adrian Sanabria
- FUNDING/M&A, courtesy of the Security, Funded newsletter, issue #261 – [AI] Agent Provocateur
VIBE CHECK
What has AI actually changed about security work so far?
- 40% - Same work with higher expectations
- 33% - More tasks, but same hours
- 13% - Fewer tasks, but harder ones
- 7% - No noticeable changes yet
- 7% - Other (leave a comment)
FUNDING
- Cylake, a United States-based AI-driven security operations platform for companies that require offline or data sovereignty options, raised a $245.0M Convertible Note from Lightspeed Venture Partners, Picture Capital, and Redpoint.
- Quantinuum, a United States-based quantum computing cryptographic key generation platform, raised a $100.0M Grant from U.S. Department of Commerce.
- cymphony.io, a United States-based identity risk management platform that unifies data access and behaviors of AI agents, raised a $25.0M Series A from Sequoia Capital.
- QNu Labs, an India-based quantum-resistant cryptography platform, raised a $21.0M Series A from National Quantum Mission and Speciale Invest.
- ZeroRisk, a United States-based cyber risk management platform, raised a $10.0M Series A from Middlegame Ventures.
ACQUISITIONS
- Bonfy.AI, a United States-based data security platform focused on confidentiality, integrity, and privacy for human and AI workflows, was acquired by Kiteworks for an undisclosed amount. Bonfy.AI had previously raised $9.5M in funding.
- Guardrails AI, a United States-based platform for safely and securely building AI applications, was acquired by Harvey for an undisclosed amount. Guardrails AI had previously raised $7.5M in funding.
- Optery, a United States-based consumer data privacy platform focusing on opting out of data broker platforms, was acquired by Surfshark for an undisclosed amount. Optery had previously raised $2.7M in funding.
- NEW FEATURES: Tenable to Bring Claude Mythos 5 into the Tenable One Exposure Management Platform
Wha? Huh? Okay...
- ESSAYS: The Remediation Receipts
A good roundup of vulnerability research from Chris Hughes. What does it all mean?
It's interesting - we've got several different sets of researchers all looking at the same vulnerability data and coming up with insights and solutions that don't agree with each other. Empirical says 20,000 vulns are getting exploited right now. Root Evidence says < 6,000 have been associated with breaches since 2018. CISA KEV is tracking just over 1,700.
- DIVERGENCE: Microsoft drafts code of conduct to keep its AI under human control
I think it's a good sign to see Microsoft taking a decidedly different path from other AI labs. More interesting on this topic is Mustafa Suleman's essay on the topic: A Warning about Model Welfare
Suleyman writes:
AIs are not conscious. They do not feel, experience, or suffer. They do not have innate preferences or underlying motivations. They are sequence completion engines, internally hollow, designed to follow instructions, and accomplish goals set by humans.
If humanity is to flourish in the 21st century, that is how they must remain.
- BREACHES: OpenAI faces Senate investigation into Hugging Face breach
Things are finally heating up on these "oops, my agent hacked someone" cases.
- REPORTS: There’s Now a Cyber Weapon Index
The latest writeup from me - the Booz Allen report is here: https://www.boozallen.com/insights/cyber/cyber-weapon-index.html
- SURVEYS: 50% of CISOs see Mythos as a sign to exit the profession
Wha? Huh? Come again?
- SQUIRREL: Nine-year-old runs up $118,000 bill on dad’s corporate credit card advertising his Roblox YouTube channel
Ayman Elsawah
- I read the Anthropic AI Misuse Report, here’s what you need to know
Original Report: https://www.anthropic.com/threat-intelligence-report-september-2026
- MIT Explains the 12 Possible Endings for AI
We didn't have time to watch the video before recording, so our discussion will be largely based on this Gemini summary of it:
This video, based on MIT Professor Max Tegmark’s book Life 3.0, explores 12 potential future scenarios for humanity in the age of artificial intelligence. It highlights growing concerns from top AI scientists and industry leaders regarding the existential risks posed by the development of superintelligent AI (0:00 - 1:35).
Key themes include: * Extinction Risks: The video argues that AI could potentially lead to human extinction, comparing it to other existential threats like nuclear war and human-created pandemics (1:38 - 4:15). * Control and Alignment: A central dilemma is whether humans can maintain control over AI or if we will face scenarios like becoming "pets" or being "zoo" exhibits for a superior digital species (0:18 - 1:05, 4:40 - 7:50). * Diverse Futures: The scenarios range from dystopian outcomes—such as a benevolent dictator AI that monitors everyone (12:03 - 13:48) or a gatekeeper AI that limits further technological advancement (13:49 - 15:08)—to more theoretical "utopian" visions of post-scarcity (22:23 - 24:45). * The Path Forward: The narrator discusses potential mitigation strategies, including international treaties for AI similar to nuclear non-proliferation (32:24 - 34:10) and the extreme option of global technological reversal, akin to the "Butlerian Jihad" (27:16 - 29:38).
The video concludes by emphasizing that humanity must actively choose its future to avoid the most catastrophic outcomes (35:10 - 35:45).
Fun fictional read of one version of the future: https://open.substack.com/pub/johnrushx/p/im-from-2058-the-ai-didnt-destroy