<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://coachciso.com/</id><title>Coach CISO</title><subtitle>Blog from Simon Goldsmith, a Chief Information Security Officer and a lifelong student of leadership and building high performing teams. Simon believes in security as both a profession and craft - one that requires relentless curiosity, the humility to listen to those in the code, and the agility to adapt to the unique complexity of the organisations and people we serve.</subtitle> <updated>2026-05-23T01:14:37+02:00</updated> <author> <name>Simon Goldsmith</name> <uri>https://coachciso.com/</uri> </author><link rel="self" type="application/atom+xml" href="https://coachciso.com/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://coachciso.com/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Simon Goldsmith </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Why inspection failed</title><link href="https://coachciso.com/posts/what-appsec-should-do-next/" rel="alternate" type="text/html" title="Why inspection failed" /><published>2026-05-22T02:00:00+02:00</published> <updated>2026-05-22T23:51:49+02:00</updated> <id>https://coachciso.com/posts/what-appsec-should-do-next/</id> <content src="https://coachciso.com/posts/what-appsec-should-do-next/" /> <author> <name>Simon Goldsmith</name> </author> <category term="Articles, Cybersecurity, Software" /> <summary> Why inspection failed — and what AppSec should do next A plan for software security in the age of AI-generated code The hidden factory Every software organisation runs two factories. The first is the one leadership sees: feature roadmaps, sprint velocity, deployment frequency, revenue. The second is invisible. It exists solely to fix things that were not done right the first time. Your develo... </summary> </entry> <entry><title>The wrong race</title><link href="https://coachciso.com/posts/the-wrong-race/" rel="alternate" type="text/html" title="The wrong race" /><published>2026-04-16T02:00:00+02:00</published> <updated>2026-04-16T02:00:00+02:00</updated> <id>https://coachciso.com/posts/the-wrong-race/</id> <content src="https://coachciso.com/posts/the-wrong-race/" /> <author> <name>Simon Goldsmith</name> </author> <category term="Articles, Cybersecurity, Software, Resilience" /> <summary> The wrong race Two Numbers In January 2026, two security researchers pointed AI agent swarms at Windows kernel drivers from AMD, Intel, NVIDIA, Dell, Lenovo, and IBM. In thirty days, for $600, they found over 100 exploitable vulnerabilities. Cost per bug: four dollars. In the same month, CrowdStrike published a number that should concern anyone who has approved a security budget in the past f... </summary> </entry> <entry><title>Welcome to my new blog !</title><link href="https://coachciso.com/posts/welcome-to-my-new-blog/" rel="alternate" type="text/html" title="Welcome to my new blog !" /><published>2026-04-01T02:00:00+02:00</published> <updated>2026-04-01T02:00:00+02:00</updated> <id>https://coachciso.com/posts/welcome-to-my-new-blog/</id> <content src="https://coachciso.com/posts/welcome-to-my-new-blog/" /> <author> <name>Simon Goldsmith</name> </author> <category term="Articles" /> <summary> Hello everyone, I have previously used LinkedIn articles to blog. I have had some time and want a more permanent (and more sovereign) place to write in long form about things I’ve worked on recently. My goal is to at least publish one entry in the blog per week. I want to write about cyber security (big surprise) but also about other software, AI, leadership, and resilience engineering topics... </summary> </entry> </feed>
