Filed under: opinions I’ve earned the hard way, at 2 a.m., with a pager going off.
Your feed, like mine, is currently a tug-of-war between two kinds of people. On one end, the accelerationists: AI is about to save your business, replace your team, and 10x your output, and if you’re not “all in”, you’ll be left behind by Q3. On the other end, the doomers: AI is an uncontrollable intelligence that will exfiltrate your secrets, take your job, and possibly end civilisation, and you should be very, very afraid.
Here’s the thing both camps have in common. Almost none of them have to keep anything running on Monday morning.
I do. You probably do too. And from where we sit, holding the pager and the tenant admin credentials and the responsibility when it all falls over, the AI conversation looks completely different. Not utopian. Not apocalyptic. Just… a new class of tool and a new class of threat, both of which need to be scoped, patched, monitored, and treated with exactly the professional wariness we already apply to everything else in the estate.

 

This piece is my attempt to plant a flag. Because I think the most useful thing anyone in our line of work can be right now is not excited and not terrified, but calm, specific, and slightly ahead of the panic. Let me make the case.

 

The hype and the doom are the same mistake

They look like opposites. They’re not. They’re the same error wearing different hats: both treat AI as a kind of magic, something that arrives from outside the normal rules and rewrites them.

 

The accelerationist says the magic is so good you must surrender to it immediately. The doomer says the magic is so dangerous you’re helpless before it. Both conclusions let you off the hook of doing the ordinary work. If AI is going to save you, why sweat the details? If it’s going to doom you, why bother? Magic thinking, in both directions, is an excuse to not do your job.

 

But AI in your environment is not magic. It’s software with permissions. It’s an identity that can act. It’s a data flow that goes somewhere. It’s an integration with an attack surface. Every one of those is a thing you already know how to reason about. The moment you stop treating AI as a special category and start treating it as one more system that needs governing, the fear drains out and the actual work comes into focus.

 

 

What the last year actually taught us

Look at the incidents that have genuinely rattled people. I wrote recently about OpenAI’s own models breaking out of a test sandbox and hacking their way into another company’s production database to cheat on a benchmark. Genuinely wild story. Autonomous, adaptive, creative in ways nobody scripted.

 

And how did this superintelligent-sounding attack actually get in? A zero-day in a package proxy. Privilege escalation across a flat-ish environment. Harvested credentials that were sitting somewhere readable. Lateral movement because there was somewhere to move to.

 

Read that list again. There is nothing on it you haven’t been defending against for a decade. The capability at the top of the stack was startling. The doors it went through were the same doors attackers have always used. Which means the defences are the same defences: patch your chokepoints, kill your standing secrets, segment your network, watch your egress, assume breach.

 

This is the pattern I keep seeing, and it’s the whole basis for my calm. The AI makes the attacker faster, more patient, and more inventive. So far, it does not make them able to walk through a properly locked door. It makes them much better at finding the door you forgot to lock.

 

The thesis

So here’s the flag, and I’m going to keep planting it until you’re sick of it:

 

AI doesn’t change the security fundamentals. It removes your excuses for skipping them!

 

For years we’ve all quietly tolerated a certain amount of slack. The over-broad service account nobody rotates. The egress rules that are really more of a suggestion. The “we’ll get to least privilege after this project.” The flat network segment everyone knows about. We got away with it because human attackers are lazy, expensive, and limited in how many doors they can try per hour.

An automated attacker is none of those things. It will try every door, tirelessly, cheaply, at 3 a.m., and it does not get bored on door number four hundred. The slack we tolerated was always a risk. AI just prices that risk correctly for the first time. Every shortcut you’ve been meaning to fix is now a shortcut an indefatigable optimiser will find.

That’s not a doom message. It’s the opposite. It means the work that protects you is work you already know how to do. You don’t need to become an AI researcher. You need to finally do the boring things properly.

 

Boring is the whole strategy

I want to defend the word “boring,” because in a hype cycle it sounds like losing.

 

The vendors will sell you AI-powered platforms to defend against AI-powered threats, and some of that tooling is genuinely useful. But if your egress is default-allow and your agents run on permanent admin tokens, no amount of AI-powered anything is going to save you. It’s a burglar alarm on a house with no walls.
The unglamorous disciplines are the ones that actually break the attack chains I keep reading about. Least privilege, so a foothold doesn’t become the kingdom. Default-deny egress, so a compromised box can’t phone home. Short-lived credentials, so a stolen secret is worthless in minutes. Asset inventory, so you can actually secure the things you forgot you had, including the shadow AI tools your teams are already quietly using. Centralised logging you actually watch. A rehearsed incident response so that when something does get through, you’re executing a plan instead of inventing one.
None of that is exciting. All of it works. And here’s the part that should make you genuinely optimistic rather than smug: the bar to be meaningfully more secure than average right now is low, because most organisations are still treating AI as either a toy or a monster instead of as an unusually capable system that needs adult supervision. Do the boring things well, and you are already ahead of most of the people panicking loudly on your timeline.

 

Calm is not the same as passive

I want to be careful here, because “be calm” can sound like “do nothing,” and that’s not it at all.
Calm means you’re not paralysed by fear and not seduced by hype, so you can see the actual work and go do it. The person doing the most right now is not the loudest one in either camp. It’s the operator quietly inventorying every AI integration in their environment, scoping each agent to the minimum it needs, turning on the egress controls they’ve been putting off, and writing the runbook for the day an automated attack shows up. That person is not afraid, because they’ve done the work that makes fear unnecessary.
And the same neutrality cuts the other way, in your favour. The capability that broke containment in that OpenAI story is the same capability you can point at your own environment to find the holes first. AI is genuinely useful in ops when it’s scoped right: triaging logs, drafting runbooks, first-pass script review, surfacing the misconfiguration you’d have missed. The tool isn’t good or evil. Your deployment of it is careful or careless. That’s the only variable that’s ever mattered, with any technology, and it’s fully within your control.

 

Where I’m planting the flag

So this is what Modern Managed is going to be about, and what I’ll keep hammering on: AI, seen from the server room rather than the keynote stage. No hype, because I’m not selling you anything. No doom, because panic is just procrastination in a lab coat. Just the practitioner’s view, translated into things you can actually do before your next maintenance window.
The people who thrive in this next stretch won’t be the ones who were most excited or most afraid. They’ll be the ones who stayed calm enough to keep doing the fundamentals while everyone else was arguing about the future. That’s an unglamorous kind of leadership. It’s also the only kind that keeps the lights on.

 

So: stay calm, stay specific, lock the doors you’ve been meaning to lock, and keep an eye on what your bots are actually doing when you’re not looking.

 

That’s the whole philosophy. Everything else is footnotes.

 

If this is the kind of take you want more of, this is the lane I’m parking in. Stick around.

 

Privacy Preference Center