11 min read
What Good Looks Like: Building a Meaning-Centric Security Organisation
A whole series spent diagnosing the meaning deficit earns one obligation: to say what the alternative looks like. Not a maturity model but a set of deliberate inversions of what the industry currently optimises, across measurement, people, process, technology, and culture.
*By Julian Brownlow Davies | Meaning In the Signal, Week 11 | 7 July 2026*
security operationssecurity strategymeaningorganisation designleadershipcomprehension
10 min read
The Crowdsourced Advantage
Crowdsourced security carries more meaning than automated scanning, and the reason has nothing to do with headcount. A thousand scanners are not a crowd; they are one perspective run at volume. The advantage lives in cognitive diversity, not in scale.
*By Julian Brownlow Davies | Meaning In the Signal, Week 10 | 22 June 2026*
crowdsourced securitycollective intelligencecognitive diversitybug bountysecuritymeaning
6 min read
Security Investment Through the Lens of Meaning
Security budgets are still buying coverage when the constraint has moved to comprehension. The metric missing from every board report is not what we have found - it is what we understand well enough to act on.
*By Julian Brownlow Davies | Meaning In the Signal, Week 9 | 6 June 2026*
securityinvestmenttheory of constraintscomprehensionboard reportingciso
11 min read
AI Won't Save You (But It Might Save Meaning)
AI deployed to accelerate detection is adding fuel to a fire whose problem is not the fuel supply. The question worth asking is not whether AI can detect better - it demonstrably can. It is whether AI can comprehend better.
*By Julian Brownlow Davies | Meaning In the Signal, Week 8 | 20 May 2026*
aidetectioncomprehensionhuman-in-the-loopsecuritymeaning
12 min read
The SOC Meaning Crisis
The meaning deficit hits hardest in the SOC. What we call alert fatigue is, I believe, something considerably more serious: learned helplessness, systematically induced by institutions optimised for throughput rather than comprehension.
*By Julian Brownlow Davies | Meaning In the Signal, Week 7 | 5 May 2026*
socalert fatiguelearned helplessnesssecurity operationssecuritymeaning
5 min read
Drowning in Green Ticks: When Compliance Obscures Risk
Compliance measures process, not risk - and the signal it generates competes, often successfully, with the signal that actually matters.
*By Julian Brownlow Davies | Meaning In the Signal, Week 6 | 23 April 2026*
compliancerisk managementgovernancesecuritymeaning
9 min read
Intent Is Not in the Feed
Most threat intelligence programmes answer what an adversary is capable of with considerable precision. They are rather less clear on whether that adversary has any particular interest in what you have. That gap is the one that matters.
*By Julian Brownlow Davies | Meaning In the Signal, Week 5*
threat-intelligenceadversaryintentsecuritymeaning
5 min read
Attack Paths, Not Attack Surfaces
The attack surface management industry optimised for the wrong question. Attackers don't think in surfaces — they think in paths. Until defenders do the same, billions in ASM investment will produce signal without meaning.
The attack surface management market will be worth several billion dollars by the time you read this. Dozens of vendors, a wave of acquisitions, a category that went from niche to mainstream in less time than most security programmes take to complete a risk assessment. The...
securityattack surface managementattack pathsexposure managementsignalinvestment
7 min read
Crown Jewels Are a Strategy Problem, Not a Security Problem
Most organisations identify their critical assets badly, once, or not at all. Crown jewel analysis is a strategy exercise masquerading as a security exercise — and getting it wrong means every downstream decision is built on sand.
There is an exercise that most security programmes conduct at some point, usually early in a maturity uplift or in the aftermath of a breach that concentrated minds. Someone, typically the CISO or a consulting partner, gathers the relevant stakeholders into a room and asks a...
securitystrategycrown jewelsVRINcompetitive advantageprioritisation
5 min read
The Constraint Moved and Nobody Noticed
The cybersecurity industry solved for detection. The constraint is now comprehension — and most organisations haven't redirected their investment accordingly.
Eliyahu Goldratt had a gift for stating things that sound obvious in retrospect but are, in practice, almost universally ignored. His Theory of Constraints (Goldratt, 1984) rests on a single deceptively simple observation: in any system, there is always one constraint that...
securitytheory of constraintsvulnerability managementcomprehensioninvestment
9 min read
Meaning In the Signal: What Five Talks at [un]Prompted Taught Me About the Future of Cybersecurity
Five uncoordinated presentations at a new AI security conference converged on the same question — and revealed the defining challenge of modern cybersecurity.
[un]Prompted is a brand new AI security practitioners conference, and its inaugural edition, held in San Francisco on the 3rd and 4th of March 2026, announced itself as something rather different from the events that typically populate the cybersecurity calendar. No vendor...
securityAIunpromptedvulnerability managementthreat intelligence