CISOOnline

Whatever happened to the 36-month IT security roadmap?

Those agent findings spurred McManus to add control audits and system segmentation to the open-source observability company’s roadmap. Neither had been part of the plan a few months earlier.

Planning beyond a year is close to “an exercise in futility,” McManus says, given how quickly the landscape changes, especially with cheap, capable AI now available to nearly anyone. Cloud security, in his view, is largely a solved problem at this point. The open questions revolve around shadow AI and shadow code, and the integrations citizen developers build on their own.

Grafana still keeps a two-year “goal map.” But the second year gets reprioritized as the threat landscape shifts. And the team has abandoned long threat-modeling engagements with full code reviews in favor of weekly, tactical sprints with six-week turnarounds. Security, McManus adds, has no end state.



Source link