<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyber Machines</title>
    <link>https://cybermachines.io/</link>
    <description>Essays on security automation: detection engineering as a software discipline, alert triage, automated response guardrails, severity scoring, and asset inventory.</description>
    <language>en</language>
    <atom:link href="https://cybermachines.io/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Tools That Survive Contact With Your Environment</title>
      <link>https://cybermachines.io/tools-that-survive-your-environment/</link>
      <guid isPermaLink="true">https://cybermachines.io/tools-that-survive-your-environment/</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <category>Procurement</category>
      <description>Security tooling is usually evaluated on capability and fails on integration. The questions that predict whether a product will work are mostly about your estate, not the product.</description>
    </item>
    <item>
      <title>Machine Speed Attacks, Human Speed Decisions</title>
      <link>https://cybermachines.io/machine-speed-attacks-human-speed-decisions/</link>
      <guid isPermaLink="true">https://cybermachines.io/machine-speed-attacks-human-speed-decisions/</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate>
      <category>Strategy</category>
      <description>The tempo gap between automated attacks and human response is not closed by hiring. It is closed by deciding in advance, which means the real work happens before the incident.</description>
    </item>
    <item>
      <title>Asset Inventory Is the Security Programme</title>
      <link>https://cybermachines.io/asset-inventory-is-the-security-programme/</link>
      <guid isPermaLink="true">https://cybermachines.io/asset-inventory-is-the-security-programme/</guid>
      <pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate>
      <category>Foundations</category>
      <description>Every security capability silently assumes a correct inventory. When the inventory is wrong, detection, vulnerability management and response all degrade in ways that are hard to attribute back to the cause.</description>
    </item>
    <item>
      <title>What a Severity Score Actually Tells You</title>
      <link>https://cybermachines.io/what-a-severity-score-tells-you/</link>
      <guid isPermaLink="true">https://cybermachines.io/what-a-severity-score-tells-you/</guid>
      <pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability Management</category>
      <description>A CVSS base score describes a vulnerability in isolation, by design. Treating it as a priority queue is the most common and most expensive misreading in vulnerability management.</description>
    </item>
    <item>
      <title>Automating Response Without Automating Mistakes</title>
      <link>https://cybermachines.io/automating-response-without-automating-mistakes/</link>
      <guid isPermaLink="true">https://cybermachines.io/automating-response-without-automating-mistakes/</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate>
      <category>Automation</category>
      <description>Automated response fails in a specific way — it executes a wrong decision faster and more consistently than a human ever could. The design problem is bounding blast radius, not writing the playbook.</description>
    </item>
    <item>
      <title>The Alert Nobody Reads</title>
      <link>https://cybermachines.io/the-alert-nobody-reads/</link>
      <guid isPermaLink="true">https://cybermachines.io/the-alert-nobody-reads/</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <category>Operations</category>
      <description>Alert fatigue is usually described as a volume problem. It is closer to a precision problem, and the fix is unpopular because it means deleting detections you spent money building.</description>
    </item>
    <item>
      <title>Detection Engineering Is a Software Discipline</title>
      <link>https://cybermachines.io/detection-engineering-is-software/</link>
      <guid isPermaLink="true">https://cybermachines.io/detection-engineering-is-software/</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Detection</category>
      <description>Detections are code that runs in production against hostile input. Teams that treat them as configuration keep rediscovering why software engineering invented tests, review and version control.</description>
    </item>
  </channel>
</rss>
