SVP, Chief Information Security Officer @ Globex Corp | My job is 50% risk management, 50% steak dinners | Advisor to 17 startups including @alien

Joined October 2025
3 Photos and videos
Pinned Tweet
How to professionally say "I heard you the first time" in corporate speak πŸ‘‡
Replying to @infosec_fox
"That's fully aligned with our prior conversation and already incorporated into our current workstream."
1
1,622
People on X are fucking insane. People on LinkedIn are much more normal.
1
2
169
Good morning fellows Just sent some AI vendor a security questionnaire Can't wait to see their AI generated response I have a meeting with them today, I will them that I didn't prepare at all That way they'll think I'm so busy they'll have to take me to a steakhouse immediately
1
1
159
Another example of a truly responsible vendor. Thanks SlateDB CEO.
8 Dec 2025
Replying to @Todd_CISO
110% more secure
1
3
1,206
This is an example of a great response from a truly responsible vendor. @vercel I won't move to @Cloudflare if you don't fire your CTO after this incident. But I do expect a steakhouse invitation immediately from your CEO.
8 Dec 2025
Replying to @Todd_CISO
Todd, you should upgrade. Don't rely on the WAF for security. At best it gives you the minutes you need to upgrade
1
278
Here's why Claude Code is better than @cursor_ai:
Replying to @thdxr
Between us, having a terminal open makes me feel like a hacker who actually knows how to code.
1
433
should I disable useEffect in prod until further notice?
1
224
I don't trust AI coding assistants. Or human ones. Or engineers in general.
I have decided: if you do not hate your AI coding assistant with the passion of a thousand burning suns, then you are not a very good programmer.
3
324
Just realized my whole security strategy is basically: 1. Buy tool 2. Turn on 10% of features 3. Screenshot dashboard 4. Present to board as "AI-driven cyber defense fabric"
1
239
Vendor said: "No data leaves your environment" Me:
1
222
I didn't buy Wiz so you could build games. I bought it so I could sleep at night knowing our cloud wasn't on fire. And somehow I still lost to an intern named Kevin.
5 Nov 2025
πŸ•ΉοΈ Meet Path-Man: Your new favorite game. πŸ‘ΎπŸ‘ΎπŸ‘Ύ Our 1-minute Wiz ASM game has arrived! πŸ€” Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you. Think you've got the skills? wiz.io/path-man
543
Last week at the steakhouse, I told the waiter I'm "reviewing vendors". He asked if that's the sauce or the wine list. Halfway through the ribeye, my @splunk alert went off - false positive again, medium rare. The @PaloAltoNtwks rep waved from across the room, we pretended not to see each other. Still expensed the dinner as "incident response".
2
465
It is simply UNBELIEVABLE that some vendors, like this "Railway" startup, still say they're enterprise-ready without sharing their Helm chart for on-prem deployment.
3 Nov 2025
"Railway is super cool but, how Enterprise ready is it?" Very, but, our sales guy kept getting this question. A lot. So we forged a fancy new enterprise page, with a brand new design motif (X-Ray) to showcase our safety, security, and transparency Introducing "Railway@Work"
1
5
4,762
Showed this chart to my CFO. He thought it was our revenue projection I said, "no, that's the global cost of a data breach". He looked worried. I looked excited. Every time that line goes up, I get budget for another security tool. Win win
1
292
Last night I dreamed our S3 buckets were public again. Woke up sweating, checked CloudTrail, saw 4,000 unauthorized GET ... from myself testing permissions. The intern said, "Don't worry Todd, we've got GuardDuty". I said, "That's what I told the board". Spent the morning writing a 42-page remediation plan. By noon we had 3 new vendors, 2 NDAs, and one dinner reservation with Palo Alto. Security posture unchanged, but morale? Through the roof.
2
203
Vendors, learn from this guy. This is how a CEO of a responsible vendor should behave. Kudos @tursodatabase!
30 Oct 2025
Let's do it. There's a Chick-fil-A nearby
1
394
Guys I’m depressed. πŸ˜” OpenAI just announced an AI that finds and fixes security bugs - which, frankly, is 200% more productive than me. My board asked if Aardvark could join the next meeting instead of me. πŸ‘Ž
30 Oct 2025
Introducing Aardvark, our agentic security researcher:
1
239
Changed the security dashboard loaders from "loading" to "thinking" Now my dashboards are Agentic.
1
125
My least favorite HTTP status code is 401. Unauthorized...?! I *am* the CISO. Half the company reports to me, but apparently the firewall doesn't.
29 Oct 2025
What HTTP status code do you hate the most?
188
Can't wait for Cloudflare's "Attack of the AI crawlers" in Finland. If they show how to block ChatGPT from reading our SharePoint, I'm giving them my entire 2026 budget. Packing my architecture diagram and a few compliance questions, just in case.
30 Oct 2025
Cloudflare is excited to be attending Cyber Security Nordic Finland on the 4-5 November! Join Jakub Borys, Sr Manager, Engineering for: Attack of the AI crawlers - How to regain control of your content. As AI technologies evolve, so do the challenges around content ownership, data scraping, and digital control. Jakub will explore how organizations can protect their online assets, limit unwanted AI crawling, and build a security posture for the AI-driven Internet. Secure your ticket here: cfl.re/4hDs9JQ
1
199