@cy-berseb.bsky.social

I do cybersecurity for clients during the day. zero-trust, AI security, the stuff that keeps systems alive. at night I'm building Unifeyn because I got tired of pretending I understood papers I skimmed twice. the internet doesn't know both of these people exist yet.

Every "AI security policy" I read cites NIST AI RMF but stops at GOVERN. The framework is GOVERN → MAP → MEASURE → MANAGE. Without describing your AI system [MAP 1.1], you can't assess its performance [MEASURE 2]. Reviewed 11 policies this year; none had a working MAP, most didn't know it existed.

Most ATT&CK coverage dashboards are superficial. The 7 techniques I've observed in real incidents at small companies: T1078 valid accounts T1190 public app exploit T1059 command interpreter T1567 exfil over web T1486 encrypted data T1489 service stop T1071 application protocol Seb

Many teams have CloudTrail and GuardDuty enabled but lack effective detection and response plans. To improve, enable detailed logs, review top findings weekly, craft three clear rules, and maintain a simple runbook. DM "detect" for a starter guide.

A 50-person SaaS only needs 3 key logs: CloudTrail, auth, DNS. If you can't quickly answer "who assumed what role in the last 24h," you lack detection, only dashboards. The first 90 days of detection involve plumbing, offboarding scripts, and IAM.