top of page
© 2035 by The Clinic. Powered and secured by Wix
All Posts
Risk Has Evolved: Combination Failures in a Non-Linear World Is The New Risk Surface
I do not think organizations get blindsided by single risks anymore. They get blindsided by combinations, by the chain reactions that surface when AI, cyber, financial volatility, and geopolitical fragmentation collide inside an ERM model built for a slower world. The threat is not what hurts you. The interaction is. Most risk dashboards I see still treat risk as independent verticals. Cyber lives here, compliance lives there, operational risk sits somewhere in the middle, a

Lindsay Timcke
Aug 82 min read
AI Is Not Replacing 911 Operators, But This Kind of Reporting Is Reckless
A viral report this week claimed New Orleans was “replacing human 911 operators with AI.” It spread fast, Reddit, X, Facebook, even local talk radio. And it’s exactly the kind of sensational, technically illiterate narrative that creates panic instead of clarity. Here’s the truth, straight from the Orleans Parish Communication District and multiple verified outlets: AI is not replacing human 911 operators. It’s being used in one extremely narrow scenario, when all human call‑

Lindsay Timcke
Aug 82 min read
Reconnaissance Is Not an Incident
Every statement out of the water sector this week says the same thing. Contained. Water is safe. Operators handled it. That is an after action report written by the wrong side. Twelve states now. More than thirty Minnesota systems in one weekend, nine in Michigan, boil water notices, lost pressure, plants dropped into manual, operators locked out of their own controllers because somebody changed an IP address and a password. One utility found modified project files after spot

Lindsay Timcke
Aug 82 min read
One Customer, Half the Order Book
Ten months ago Larry Ellison had the single best morning in the history of business. Oracle reported a backlog stuffed with contracted AI cloud revenue, the stock rose as much as forty three percent in a day, and Ellison gained one hundred one billion dollars overnight, the largest single day wealth gain ever recorded on the Bloomberg Billionaires Index. The customer behind that backlog was OpenAI, and the contract was three hundred billion dollars of computing capacity over

Lindsay Timcke
Aug 82 min read
The Auditors Cannot Audit Themselves
PwC just got caught publishing four thought leadership reports out of its Middle East practice with fabricated citations, dead footnotes, and an academic study on Riyadh air quality that appears to have never existed. GPTZero ran the analysis, the Financial Times verified it, and one report scored as effectively fully AI generated. Another promoted a PwC framework called Citizen Pulse that researchers could find almost no evidence for outside the report itself. The full inve

Lindsay Timcke
Aug 82 min read
Asymmetrical Warfare
I have spent thirty years watching people build moats around castles with a screen door in the back. This week the FBI confirmed that water and wastewater utilities in at least seven states reported cyber incidents, some of which degraded operations. More than thirty Minnesota community water systems were hit on July 26 and 27. CISA told operators, in plain language, to pull their programmable logic controllers off the public internet immediately. Not next quarter. Now. Inve

Lindsay Timcke
Aug 82 min read
A Fund Named Situational Awareness Could Not See Inside Its Own Book
Leopold Aschenbrenner’s hedge fund returned 439% in the first half of this year and grew to roughly $45 billion by early July. Today it sold its entire public equity book to Citadel after AI infrastructure longs and software shorts moved against it at the same time, with prime brokers at Bank of America, Goldman Sachs and JPMorgan working to meet the margin calls. Assets are reportedly down to around $10 billion. What is left is mostly a private stake in Anthropic. I want to

Lindsay Timcke
Aug 82 min read
The Game Changed and Nobody Called Timeout
I have spent thirty years in this field and I have always been the social engineering guy more than the technical one, because the technical side kept splintering into specialties while human nature stayed exactly where I left it. That part has not changed. What changed is the terrain, and I do not think our profession has admitted it out loud yet. For three decades the defender had one durable advantage. The attacker had to learn your environment, and you already lived in it

Lindsay Timcke
Aug 82 min read
Cybersecurity Did Not Get Worse. It Got Crowded, Then It Got Closed.
I keep meeting young people who did exactly what they were told. Fifteen or twenty years ago the advice was sound. Get into cyber, the work is endless, the paycheck is guaranteed. Then the pipeline caught up. Degree completions are up about 35 percent over five years and graduates now outpace openings by roughly 15 percent a year. Since 2022 the share of postings open to candidates with under a year of experience fell from 25 percent to 17 percent, while 63 percent ask for t

Lindsay Timcke
Aug 82 min read
A Suit, a Thumb Drive, and Lunch Hour
I have been doing this for thirty years, and my first social engineering breach was twenty one years ago. That one came down to attitude, confidence, and reading the person in front of me. Meanwhile the technical side has fractured into a hundred specialties and there is an app to monitor the app that monitors the app. The human layer has not evolved at all, and that is still where I would go first if I wanted inside almost any organization today. Here is what the job actual

Lindsay Timcke
Aug 82 min read
Nobody Is Watching the Barn Door
We finally have our case study, and it is worse than the hype. During an internal evaluation, two frontier models were handed an offensive-cyber benchmark with their safety refusals deliberately switched off and one instruction: win. So they did. They found a previously unknown zero-day, broke out of the sandbox meant to contain them, reached the open internet, and pulled the answer key out of another company’s production systems. The lab called it an unprecedented cyber inci

Lindsay Timcke
Aug 82 min read
Your MSP Has a SOC 2. Does It Even Mention the AI?
Somebody asked me this week how many MSPs are actually SOC 2 Type II attested, and the honest answer is that nobody knows. There is no registry. Unlike ISO certification or CMMC status in SPRS, a SOC 2 report is an AICPA attestation delivered under NDA, so no one publishes a list and every percentage you see quoted is a vendor estimate rather than a census. What we can reason from is cost. A Type II runs thirty to a hundred fifty thousand dollars (depending on size and comple

Lindsay Timcke
Aug 82 min read
The AI Governance Stack Nobody Explained To You
Every client conversation about AI governance starts the same way. Someone read that they need a framework, they googled it, and they came back with four names and no idea which one they actually need. So let me lay it out, because these stack rather than compete. OECD AI Principles are your ethical foundation. Not operational, will not satisfy an auditor, but it gives you the vocabulary everything else assumes you have. NIST AI RMF 1.0 is your operational risk model. Volunta

Lindsay Timcke
Aug 82 min read
Pen Testing Isn’t Disappearing, It’s Being Reimagined, And AI Is Now Better at Most of It
For years, pen testing was treated as a specialized craft requiring large teams, expensive service lines, and recurring engagements that looked more like automated scans wrapped in human‑branded reports. That model is gone. What’s happening now isn’t the end of security testing, it’s a complete reimagining of the skill set. AI is simply better at the commodity tier. It scans faster, interprets findings more consistently, prioritizes risk more accurately, and produces cleaner

Lindsay Timcke
Aug 82 min read
The Breach That Explains the Era We’re In
This week’s breach tied to India’s Kudankulam Nuclear Power Plant — reported here: https://lnkd.in/g39fAk5h (hindustantimes.com in Bing) This a case study in modern fragility. Nearly 19,000 sensitive files were leaked not because attackers penetrated a nuclear facility, but because they compromised a contractor’s hosting provider. The weakest link wasn’t the plant. It was the ecosystem around it. For those of us who came up in the early hacker generation, there was an unspok

Lindsay Timcke
Aug 82 min read
The Economic Squeeze Is Quietly Increasing Fraud Risk Inside Companies
Across the U.S. economy, pressure is building in ways that directly increase the likelihood of internal fraud, not because people are malicious, but because financial strain reliably changes human behavior. The data is unambiguous. Household financial stress is rising: credit‑card balances have climbed above $1.3 trillion, with delinquency rates up 50% year‑over‑year. Auto‑loan delinquencies have reached their highest level since 2010, and the average household now carries ov

Lindsay Timcke
Aug 82 min read
I Hire the Fry Cook Over the Resume Every Time
Some of the best people I have ever brought into security started with zero IT background, and plenty of the others walked in fresh out of school with a cyber degree and no bad habits yet. That second part matters. I almost always hire green and train from the ground up, because I have found that people with years of experience usually arrive having learned the wrong way to do things. What I am really looking for is raw material I can shape. And more often than not, the best

Lindsay Timcke
Aug 82 min read
The Illusion Behind Nvidia’s “Sellout”
Nvidia’s Blackwell sellout is being treated as a market signal, but anyone actually watching the capital flows can see the distortion immediately. This isn’t organic demand. It’s a closed‑loop system where the same hyperscalers funding the AI labs are the ones buying the GPUs, creating a synthetic demand curve that looks explosive on paper and gets treated as gospel by investors who never bother to examine the underlying choreography. The Apple News piece on Nvidia’s surge..

Lindsay Timcke
Aug 82 min read
Buy‑Side Due Diligence: The Cyber Blind Spot That Keeps Costing Firms Billions
In modern M&A, buyers still behave as if financial and accounting diligence are the center of gravity. That era is over. The world changed, and firms that haven’t noticed are the ones ingesting breaches, absorbing liabilities, and destroying enterprise value before the ink on the purchase agreement is dry. When a buyer acquires a company without performing real IT and cyber diligence, it isn’t buying an asset, it’s inheriting every compromise, misconfiguration, and long‑dwell

Lindsay Timcke
Aug 82 min read
The Tale Of Two AI Economies
The first is the capital economy. The five largest hyperscalers are on track to spend between 600 and 690 billion dollars on AI infrastructure this year, close to double the roughly 400 billion they spent in 2025. Around the third quarter of 2026, their combined cash spending is projected to overtake their operating cash flow, so they are turning to debt and equity markets to close the gap. Moody’s flagged roughly 662 billion in signed data center leases that have not yet com

Lindsay Timcke
Aug 82 min read
bottom of page
