<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>The Tinkering CISO</title><description>Security, AI, and the systems behind them — what actually works in practice.</description><link>https://tinkeringciso.com/</link><item><title>Security theater is expensive</title><link>https://tinkeringciso.com/articles/security-theater/</link><guid isPermaLink="true">https://tinkeringciso.com/articles/security-theater/</guid><description>The performance has a budget, a cast, and a recurring booking. The question is whether anyone in the audience is actually safer.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>strategy</category><category>governance</category></item><item><title>Friction is a bug</title><link>https://tinkeringciso.com/articles/friction-is-a-bug/</link><guid isPermaLink="true">https://tinkeringciso.com/articles/friction-is-a-bug/</guid><description>When the secure path is the hard path, people route around it. Friction is not a virtue signal — it is a defect report.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>ux</category><category>zero-trust</category></item><item><title>We don&apos;t have a system of record for security</title><link>https://tinkeringciso.com/articles/system-of-record/</link><guid isPermaLink="true">https://tinkeringciso.com/articles/system-of-record/</guid><description>Your security posture is whatever your data hub says it is. If the record is wrong, every downstream decision inherits the error.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>data</category><category>identity</category></item><item><title>Security creates work. Let&apos;s stop.</title><link>https://tinkeringciso.com/articles/security-creates-work/</link><guid isPermaLink="true">https://tinkeringciso.com/articles/security-creates-work/</guid><description>Most security work is the residue of decisions made elsewhere. The interesting question is what it costs the people who have to live inside the control.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>ai</category><category>operations</category><category>governance</category></item></channel></rss>