I'm Simon Mullis. I've spent thirty years in cybersecurity. I write here about shipping agentic AI inside organisations that can't afford to get it wrong.
Writing
- Jul 2026 Essay 1994 Design Patterns arrived in October 1994, roughly two decades after the practice it described. We started writing the AI era down in year one, on ground that has not stopped moving since.
- Jul 2026 Essay Three Abstraction Shifts in One Career The web abstracted away distance, cloud abstracted away infrastructure, and AI is abstracting away implementation itself. The third one is different in kind, not just degree.
- Jul 2026 Essay The Botnet With One Member In 2013 I built a botnet with a single member and watched the world's antivirus vendors connect to it. The lesson took thirteen years to matter: when capability gets cheap on both sides, the advantage moves to whoever understands the channel between them, not whoever holds the better tool.
- Jul 2026 Thinking Aloud Darmok, Brown M&Ms, and the Bandwidth of Meaning Shared concepts are the highest-bandwidth channel between two minds, and the easiest place to agree on nothing.
- Jul 2026 Essay Compliance as an Inherited Property Why enterprise AI governance should work like a type system, not an audit queue.
- May 2025 Essay Right Finding, Wrong Fix A correct security finding can still take down the thing it was meant to protect. Severity and blast radius are different questions, and we only built a tool for one.