Meaning in the Signal

Meaning in the Signal

Writing on security, leadership, AI, and the search for signal in the noise.

What Good Looks Like: Building a Meaning-Centric Security Organisation

A whole series spent diagnosing the meaning deficit earns one obligation: to say what the alternative looks like. Not a maturity model but a set of deliberate inversions of what the industry currently optimises, across measurement, people, process, technology, and culture.

*By Julian Brownlow Davies | Meaning In the Signal, Week 11 | 7 July 2026*

security operationssecurity strategymeaningorganisation designleadershipcomprehension
Read more

The Crowdsourced Advantage

Crowdsourced security carries more meaning than automated scanning, and the reason has nothing to do with headcount. A thousand scanners are not a crowd; they are one perspective run at volume. The advantage lives in cognitive diversity, not in scale.

*By Julian Brownlow Davies | Meaning In the Signal, Week 10 | 22 June 2026*

crowdsourced securitycollective intelligencecognitive diversitybug bountysecuritymeaning
Read more

Security Investment Through the Lens of Meaning

Security budgets are still buying coverage when the constraint has moved to comprehension. The metric missing from every board report is not what we have found - it is what we understand well enough to act on.

*By Julian Brownlow Davies | Meaning In the Signal, Week 9 | 6 June 2026*

securityinvestmenttheory of constraintscomprehensionboard reportingciso
Read more

AI Won't Save You (But It Might Save Meaning)

AI deployed to accelerate detection is adding fuel to a fire whose problem is not the fuel supply. The question worth asking is not whether AI can detect better - it demonstrably can. It is whether AI can comprehend better.

*By Julian Brownlow Davies | Meaning In the Signal, Week 8 | 20 May 2026*

aidetectioncomprehensionhuman-in-the-loopsecuritymeaning
Read more

The SOC Meaning Crisis

The meaning deficit hits hardest in the SOC. What we call alert fatigue is, I believe, something considerably more serious: learned helplessness, systematically induced by institutions optimised for throughput rather than comprehension.

*By Julian Brownlow Davies | Meaning In the Signal, Week 7 | 5 May 2026*

socalert fatiguelearned helplessnesssecurity operationssecuritymeaning
Read more

Drowning in Green Ticks: When Compliance Obscures Risk

Compliance measures process, not risk - and the signal it generates competes, often successfully, with the signal that actually matters.

*By Julian Brownlow Davies | Meaning In the Signal, Week 6 | 23 April 2026*

compliancerisk managementgovernancesecuritymeaning
Read more

Intent Is Not in the Feed

Most threat intelligence programmes answer what an adversary is capable of with considerable precision. They are rather less clear on whether that adversary has any particular interest in what you have. That gap is the one that matters.

*By Julian Brownlow Davies | Meaning In the Signal, Week 5*

threat-intelligenceadversaryintentsecuritymeaning
Read more

Attack Paths, Not Attack Surfaces

The attack surface management industry optimised for the wrong question. Attackers don't think in surfaces — they think in paths. Until defenders do the same, billions in ASM investment will produce signal without meaning.

The attack surface management market will be worth several billion dollars by the time you read this. Dozens of vendors, a wave of acquisitions, a category that went from niche to mainstream in less time than most security programmes take to complete a risk assessment. The...

securityattack surface managementattack pathsexposure managementsignalinvestment
Read more

Crown Jewels Are a Strategy Problem, Not a Security Problem

Most organisations identify their critical assets badly, once, or not at all. Crown jewel analysis is a strategy exercise masquerading as a security exercise — and getting it wrong means every downstream decision is built on sand.

There is an exercise that most security programmes conduct at some point, usually early in a maturity uplift or in the aftermath of a breach that concentrated minds. Someone, typically the CISO or a consulting partner, gathers the relevant stakeholders into a room and asks a...

securitystrategycrown jewelsVRINcompetitive advantageprioritisation
Read more

The Constraint Moved and Nobody Noticed

The cybersecurity industry solved for detection. The constraint is now comprehension — and most organisations haven't redirected their investment accordingly.

Eliyahu Goldratt had a gift for stating things that sound obvious in retrospect but are, in practice, almost universally ignored. His Theory of Constraints (Goldratt, 1984) rests on a single deceptively simple observation: in any system, there is always one constraint that...

securitytheory of constraintsvulnerability managementcomprehensioninvestment
Read more

Meaning In the Signal: What Five Talks at [un]Prompted Taught Me About the Future of Cybersecurity

Five uncoordinated presentations at a new AI security conference converged on the same question — and revealed the defining challenge of modern cybersecurity.

[un]Prompted is a brand new AI security practitioners conference, and its inaugural edition, held in San Francisco on the 3rd and 4th of March 2026, announced itself as something rather different from the events that typically populate the cybersecurity calendar. No vendor...

securityAIunpromptedvulnerability managementthreat intelligence
Read more