<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Caleb Sima — Writing</title>
    <link>https://calebsima.com/writing</link>
    <atom:link href="https://calebsima.com/rss.xml" rel="self" type="application/rss+xml" />
    <description>Essays on cybersecurity, AI, building companies, and investing. Also published as the Glitch newsletter.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 12 Jun 2026 15:01:34 GMT</lastBuildDate>
    <item>
      <title>Least Privilege Was Built for Humans</title>
      <link>https://calebsima.com/writing/least-privilege-was-built-for-humans</link>
      <guid isPermaLink="true">https://calebsima.com/writing/least-privilege-was-built-for-humans</guid>
      <pubDate>Fri, 12 Jun 2026 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>Least privilege assumes you're a person: a stable role, predictable tasks, quarterly reviews. Agents break every assumption, and the missing authorization signal is intent. The practical place to start is using agents to map your humans' privileges first.</description>
    </item>
    <item>
      <title>The Agent is Commoditized. The Value is the Harness</title>
      <link>https://calebsima.com/writing/the-agent-is-commoditized</link>
      <guid isPermaLink="true">https://calebsima.com/writing/the-agent-is-commoditized</guid>
      <pubDate>Mon, 18 May 2026 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>AI agents moved through three phases since early 2024. We're now in Phase 3, where the value isn't the agent — it's the harness around it. Whoever owns the harness owns the feedback loop.</description>
    </item>
    <item>
      <title>The Brain Becomes Portable</title>
      <link>https://calebsima.com/writing/the-brain-becomes-portable</link>
      <guid isPermaLink="true">https://calebsima.com/writing/the-brain-becomes-portable</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>AI makes intelligence portable. For the first time, the enterprise can supply its own brain. You don't need the vendor to be smart anymore — and that changes the entire industry.</description>
    </item>
    <item>
      <title>The Era of the Zombie Tool</title>
      <link>https://calebsima.com/writing/the-era-of-the-zombie-tool</link>
      <guid isPermaLink="true">https://calebsima.com/writing/the-era-of-the-zombie-tool</guid>
      <pubDate>Tue, 02 Dec 2025 12:00:00 GMT</pubDate>
      <category>Security Leadership</category>
      <description>Why 'Buy vs. Build' is more critical than ever. Your 'free' internal tool is about to become your most expensive liability.</description>
    </item>
    <item>
      <title>A CISO's Guide to Vetting AI Security Vendors</title>
      <link>https://calebsima.com/writing/a-cisos-guide-to-vetting-ai-security-vendors</link>
      <guid isPermaLink="true">https://calebsima.com/writing/a-cisos-guide-to-vetting-ai-security-vendors</guid>
      <pubDate>Fri, 29 Aug 2025 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>A practical, no-nonsense framework for vetting AI vendors — built with Edward Wu from Dropzone AI. Three pillars: The Problem, The Proof, and The Practicality.</description>
    </item>
    <item>
      <title>Intent Over Tactics: A CISO's Guide to Protecting Your Crown Jewels</title>
      <link>https://calebsima.com/writing/intent-over-tactics-crown-jewels-strategy</link>
      <guid isPermaLink="true">https://calebsima.com/writing/intent-over-tactics-crown-jewels-strategy</guid>
      <pubDate>Wed, 30 Jul 2025 12:00:00 GMT</pubDate>
      <category>Security Leadership</category>
      <description>A practical guide to protecting your most critical assets when budget, head-count, and political capital are tight.</description>
    </item>
    <item>
      <title>AI Security: The Next Frontier</title>
      <link>https://calebsima.com/writing/ai-security-the-next-frontier</link>
      <guid isPermaLink="true">https://calebsima.com/writing/ai-security-the-next-frontier</guid>
      <pubDate>Fri, 27 Dec 2024 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>After 25 years in security, nothing compares to what AI is about to do to our field. Most people are asking the wrong question.</description>
    </item>
    <item>
      <title>Why I Still Build</title>
      <link>https://calebsima.com/writing/why-i-still-build</link>
      <guid isPermaLink="true">https://calebsima.com/writing/why-i-still-build</guid>
      <pubDate>Sat, 30 Nov 2024 12:00:00 GMT</pubDate>
      <category>Career</category>
      <description>The question I get asked most: &quot;Why are you still doing this?&quot; Building is who I am. It's not what I do — it's what I am.</description>
    </item>
    <item>
      <title>My Security Investment Thesis for 2025</title>
      <link>https://calebsima.com/writing/my-security-investment-thesis-for-2025</link>
      <guid isPermaLink="true">https://calebsima.com/writing/my-security-investment-thesis-for-2025</guid>
      <pubDate>Tue, 19 Nov 2024 12:00:00 GMT</pubDate>
      <category>Investing</category>
      <description>Every few years, the security landscape shifts fundamentally. We went from network security to endpoint security to cloud security. Each shift created massive companies.</description>
    </item>
    <item>
      <title>Mythbusting AI Security Incidents</title>
      <link>https://calebsima.com/writing/mythbusting-ai-security-incidents</link>
      <guid isPermaLink="true">https://calebsima.com/writing/mythbusting-ai-security-incidents</guid>
      <pubDate>Tue, 29 Oct 2024 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>Our analysis of 243 documented AI security incidents reveals a surprising truth: most of these aren't AI-specific attacks at all.</description>
    </item>
    <item>
      <title>Building a Comprehensive AI LLM/ML Ops Marketecture</title>
      <link>https://calebsima.com/writing/building-comprehensive-ai-llm-ml-ops-marketecture</link>
      <guid isPermaLink="true">https://calebsima.com/writing/building-comprehensive-ai-llm-ml-ops-marketecture</guid>
      <pubDate>Tue, 01 Oct 2024 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>A comprehensive architecture framework for understanding the AI/ML operations pipeline — from model training through deployment — and the security considerations at each layer.</description>
    </item>
    <item>
      <title>Predicting AI's Impact on Security</title>
      <link>https://calebsima.com/writing/predicting-ais-impact-on-security</link>
      <guid isPermaLink="true">https://calebsima.com/writing/predicting-ais-impact-on-security</guid>
      <pubDate>Mon, 17 Jun 2024 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>From BSides and RVAsec keynotes — a framework for understanding AI's real impact on cybersecurity through the lenses of coverage, context, and communication.</description>
    </item>
    <item>
      <title>In a GenAI World, Only Identity Matters</title>
      <link>https://calebsima.com/writing/in-a-genai-world-only-identity-matters</link>
      <guid isPermaLink="true">https://calebsima.com/writing/in-a-genai-world-only-identity-matters</guid>
      <pubDate>Thu, 08 Feb 2024 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>As GenAI enables anyone to generate sophisticated attacks, traditional detection fails. The only reliable security signal left is identity — who is doing what, and should they be?</description>
    </item>
    <item>
      <title>Personal Privacy &amp; Security for CISOs</title>
      <link>https://calebsima.com/writing/personal-privacy-security-for-cisos</link>
      <guid isPermaLink="true">https://calebsima.com/writing/personal-privacy-security-for-cisos</guid>
      <pubDate>Tue, 22 Aug 2023 12:00:00 GMT</pubDate>
      <category>Privacy</category>
      <description>After years as a CISO dealing with threats, I decided to lock down my own personal security and privacy. Here's my framework for personal digital protection — from disappearing online to securing your home network.</description>
    </item>
    <item>
      <title>Demystifying LLMs and Threats</title>
      <link>https://calebsima.com/writing/demystifying-llms-and-threats</link>
      <guid isPermaLink="true">https://calebsima.com/writing/demystifying-llms-and-threats</guid>
      <pubDate>Wed, 16 Aug 2023 12:00:00 GMT</pubDate>
      <category>AI &amp; Security</category>
      <description>A comprehensive primer on how Large Language Models actually work under the hood, and the real security threats they introduce — from prompt injection to training data poisoning.</description>
    </item>
    <item>
      <title>From Founder to CISO: My Unconventional Journey and the Road Ahead</title>
      <link>https://calebsima.com/writing/from-founder-to-ciso-my-unconventional-journey</link>
      <guid isPermaLink="true">https://calebsima.com/writing/from-founder-to-ciso-my-unconventional-journey</guid>
      <pubDate>Sun, 23 Apr 2023 12:00:00 GMT</pubDate>
      <category>Career</category>
      <description>After departing as CSO of Robinhood, I reflect on my 5-year experiment going from cybersecurity founder to CISO across three very different companies — and what comes next.</description>
    </item>
    <item>
      <title>What I Learned at Capital One</title>
      <link>https://calebsima.com/writing/what-i-learned-at-capital-one</link>
      <guid isPermaLink="true">https://calebsima.com/writing/what-i-learned-at-capital-one</guid>
      <pubDate>Thu, 01 Aug 2019 12:00:00 GMT</pubDate>
      <category>Career</category>
      <description>Three hard-won lessons from my time at Capital One — security is genuinely hard, fundamentals beat fancy tools, and good engineering is the foundation of good security.</description>
    </item>
    <item>
      <title>How We Got Started Automating Software Security</title>
      <link>https://calebsima.com/writing/how-we-got-started-automating-software-security</link>
      <guid isPermaLink="true">https://calebsima.com/writing/how-we-got-started-automating-software-security</guid>
      <pubDate>Tue, 01 May 2018 12:00:00 GMT</pubDate>
      <category>Engineering</category>
      <description>How we built a security code orchestration platform at Capital One to automate software security scanning across thousands of applications and hundreds of development teams.</description>
    </item>
    <item>
      <title>How I Protected My Home Network</title>
      <link>https://calebsima.com/writing/how-i-protected-my-home-network</link>
      <guid isPermaLink="true">https://calebsima.com/writing/how-i-protected-my-home-network</guid>
      <pubDate>Sun, 01 Apr 2018 12:00:00 GMT</pubDate>
      <category>Privacy</category>
      <description>A practical guide to home network security using Thinkst Canary tokens and Fingbox — because the cybersecurity professional's home network should be as monitored as the enterprise.</description>
    </item>
  </channel>
</rss>
