Discussion about this post

User's avatar
Bryce Boland's avatar

Good piece John. You make the key point that fixing is organisational, not computational. I'd push it one step further. These are two separate cost curves, and AI is pulling them apart. Discovery falls fast because it is computational. Remediation stays flat because writing the patch was never the expensive part - the cost lives in ownership, verification, regression testing, and someone signing off on the risk. The gap between those curves is the attacker's margin. So a security economy optimised to find more, faster, may be industrialising the cheap half of the problem while the expensive half stays stubbornly human. Linus's Law told us more eyeballs make bugs shallow. It said nothing about who has to dig the patch.

No posts

Ready for more?