top of page
© 2035 by The Clinic. Powered and secured by Wix
All Posts
Compliance Was Always Risk Management. We Just Stopped Treating It That Way
For nearly thirty years I have looked at organizations the way an attacker looks at them, and the most important thing I can tell any leader right now has nothing to do with a specific tool or a specific threat. It is this. The upheaval is not temporary. We keep waiting for things to settle, for the disruption to pass, for some return to a calmer baseline. That baseline is not coming back. Whether you are staring at AI, at your IT controls, at the financial system, at crypto,

Lindsay Timcke
Jun 247 min read
What a Real AI Control Environment Actually Looks Like
The discussion is over, AI, like it, don’t like it, it’s reality, so get on board and start incorporating AI environment into your Risk Registry and get busy building out those controls and processes and stop thinking it’s going away. Everyone wants an AI policy. Almost no one has built the control environment that makes the policy mean anything. A policy is a promise. Controls are the proof. And right now, most firms have one or two controls (at best) and call it governance.

Lindsay Timcke
Jun 242 min read
The Incentive Crisis: How AI Is Quietly Breaking Professional Services
The debate about whether AI is “good or bad” is over. The market has already committed. But while everyone is celebrating productivity gains, a far more dangerous trend is emerging, and it’s coming from the largest consulting and accounting firms in the world. They are now tying bonuses, raises, and promotions directly to AI usage. This isn’t theory. It’s happening. PwC evaluates staff on AI adoption as part of performance reviews. KPMG introduced AI‑enabled productivity KPIs

Lindsay Timcke
Jun 242 min read
My Top Ten AI Attack Vectors
Everyone is watching the IPOs, the mega mergers, and the giant data centers. I have been in those conversations as much as anyone. For months the argument was whether AI security was a real concern. That argument is over. Two weeks later it is the main one. It is time to design the defense perimeter, agree on how we defend it, and be honest about what the attack vectors even are. You cannot protect what you have never mapped. So here is my starting point. For firms up to th

Lindsay Timcke
Jun 242 min read
The AI debate is stuck on the wrong question.
Everyone is arguing the same two points. Should we use it. Is it good or bad. Meanwhile almost no one is handing people what they actually need: a way to start governing it. So I built one, and I am sharing it - my next two posts are these two docs. Here is what I keep seeing. Teams open the conversation by asking which framework is best. SOC 2? ISO 42001? NIST? The EU AI Act? That is the wrong question, and asking it is a tell. Those four are not competitors. They do four di

Lindsay Timcke
Jun 242 min read
The Labor Shortage That Isn’t: Reading the AI Layoff Loop by the Numbers
Jeff Bezos says AI will create a labor shortage, not mass unemployment, and I would take that more seriously if Amazon had not just cut roughly 30,000 corporate roles, 14,000 last October and 16,000 in January, about 9 percent of its corporate staff, with leadership openly tying the reductions to generative AI and automation. When the company shedding people tells you the real risk is too few people, you are not hearing a forecast, you are hearing a justification. So, look

Lindsay Timcke
Jun 242 min read
The Familiar Stranger Attack
Most organizations obsess over cyber controls, but their physical environments run on something far more fragile: pattern recognition. People don’t verify badges, they verify familiarity. They trust what “looks normal.” They trust rhythm, not rules. That’s the weakness I targeted. Phase 1 — I Became Background Noise I didn’t tailgate. I didn’t clone badges. I didn’t impersonate IT. I simply became ambiently familiar face. For two weeks, I walked the perimeter at the same time

Lindsay Timcke
Jun 242 min read
Stop Calling It Analysis. Last Week It Was Touting
Let me say the quiet part out loud. A lot of what passed for IPO analysis last week was not analysis, it was a sales pitch with a press pass. SpaceX priced at 135, opened at 150, closed near 161 and blew past two trillion dollars in a day. Fine. Then came the parade of 400 and 1200 dollar targets on a company that lost nearly five billion dollars last year and trades at roughly ninety five times revenue, where Google went public near seven and Facebook near twenty. New Stree

Lindsay Timcke
Jun 242 min read
AI Got Dangerously Good at Attacking You. The Version You Are Purchasing To Defend You, Did Not
AI is not breaking the commodification of security work, it is pouring rocket fuel on it. IT audits, penetration tests, infrastructure reviews, vulnerability scans, configuration assessments, control testing, risk assessments, the whole catalog is being repackaged into a leasing model where you do not buy expertise, you rent a subscription to a tool that runs on a schedule. Here is the part the sales deck leaves out. AI is now dangerously good at offense. It is finding novel

Lindsay Timcke
Jun 242 min read
P-card/CC Loss and Controls
A corporate card is the most convenient fraud tool ever handed to an employee, and most companies audit them about as often as they replace the smoke detector batteries (when it starts chirping because there is an issue). Here are the numbers that should change that. The typical organization loses 5% of its revenue to fraud every single year. The latest ACFE study tallied more than $3.1 billion in losses across roughly 1,900 cases, with a median hit of $145,000 and an averag

Lindsay Timcke
Jun 242 min read
Why I’d Hack Your Accountant Before I’d Hack You
Here is something that should keep more people up at night. CPA firms are the ones who perform SOC examinations on everyone else. They sign the attestation. They tell the market whether a service organization can be trusted with sensitive data. Private equity firms, in turn, demand SOC 2 reports from their portfolio companies and vendors as a condition of doing business. Yet as far as I can tell, neither industry holds a SOC report between them. Sit with that for a second. T

Lindsay Timcke
Jun 242 min read
The New Failure Mode: When Your Supply Chain Becomes Your Attack Surface
Most organizations still talk about cyber risk as if it lives inside their walls. In 2026, that assumption is no longer just outdated, it’s operationally dangerous. The real exposure now sits outside the enterprise, distributed across vendors, platforms, and AI‑driven dependencies that no one fully controls. The shift is subtle but decisive: IT risk has become a supply‑chain problem first, and a cyber problem second. Agentic AI systems now interact across networks faster than

Lindsay Timcke
Jun 242 min read
When a Fund Gates to Stop a Run, It Usually Starts One - Blackstone
I have spent enough time inside risk functions to know the difference between a warning light and a fire alarm, and what just happened at Blackstone is the alarm. BCRED, the firm’s flagship private credit vehicle, is capping quarterly redemptions at 5 percent after requests hit roughly 10 percent of shares outstanding, the second straight quarter the gate has been tested after Q1 ran near 8 percent. For two years we were told the economy is fine because the small signals st

Lindsay Timcke
Jun 242 min read
Does Your AI Data Center Even Have a SOC Report? And If It Did, It Still Would Not Tell You What You Need
Start with a question almost nobody downstream can answer. Does the AI data center holding your data even have a SOC report. I am not convinced most of them do. The hyperscalers attest, fine, but the flood of neocloud GPU farms and purpose built AI sites that sprang up to soak the demand hyperscale capacity could not meet, I would not assume any of them have been examined at all. People hear AI infrastructure and picture a mature, audited environment. A lot of this is racks

Lindsay Timcke
Jun 242 min read
Phishing To Expanding Privileges
I do not need to be a genius to get inside your network. I need one person to be human for a moment. So I send one believable email. Not a clumsy prince offering millions but a note that looks like it came from your CFO, your vendor, or your help desk. Someone clicks. That click does not hand me the kingdom. It hands me a single chair in a single room. What I do next is what separates a contained incident from a catastrophe. I am now sitting inside the trust boundary your who

Lindsay Timcke
Jun 242 min read
I Was Paid to Break Into a Bank. The Thing That Let Me In Wasn’t a Technical Solution
A client assumed we’d beat their machines, the cameras, the card readers, the alarm system that ate most of last year’s security budget. Not one of those is how we got inside. Long before anyone showed up in person, the whole job was sitting in plain sight online. Their hiring page named the badge vendor. LinkedIn handed us the new hires and whoever ran facilities. A casual break-room photo someone posted had a propped-open fire door sitting right in the background. Nothing

Lindsay Timcke
Jun 12 min read
The Ninety Day Window Your Backups Don’t Survive
When I run red team engagements against mid market companies, the playbook is consistent and the outcomes are predictable. Get in, escalate to domain admin, find the backup infrastructure, and quietly map the recovery posture before doing anything loud. The interesting part is what real attackers do once they own that position. They sit. Sixty to one hundred eighty days is the modern dwell window (IBM says 287 behind your firewall). They exfiltrate continuously for double ex

Lindsay Timcke
Jun 12 min read
The AI Bubble Is a Risk Management Problem Before It Is a Market One
Here is what keeps me up at night, and I say this as someone who leans on AI every day and believes it earns its keep. The four largest hyperscalers plan to spend roughly 725 billion dollars on AI infrastructure in 2026, up 77 percent from last year, with capital intensity now running 45 to 57 percent of revenue, a level that used to be unthinkable, and the debt issued to fund it could top 1.5 trillion dollars over the next few years. Then let’s look at how the revenue gets

Lindsay Timcke
Jun 12 min read
Phishing To Expanding Privileges
I do not need to be a genius to get inside your network. I need one person to be human for a moment. So I send one believable email. Not a clumsy prince offering millions but a note that looks like it came from your CFO, your vendor, or your help desk. Someone clicks. That click does not hand me the kingdom. It hands me a single chair in a single room. What I do next is what separates a contained incident from a catastrophe. I am now sitting inside the trust boundary your who

Lindsay Timcke
Jun 12 min read
Scamming - Public Service Announcement
A text arrived on my phone this morning. Final Warning. Today’s date. Massachusetts Department of Transportation. License suspension if I don’t pay by end of day. A code citation. Five escalating consequences. A payment link. A clever instruction at the bottom, reply “Y” and reopen the message to activate the link. Every element is engineered. None of it is real. Massachusetts has no “Centralized Violation Registry.” There is no Administrative Code 15C-16.003. The RMV does no

Lindsay Timcke
May 222 min read
bottom of page
