Author name: Scott Bly, Director, Security Technologies

Before You Trust a Local LLM, Test It Like an Attacker Would

More teams are running open-weight models locally — for cost, for data sovereignty, for workloads that can’t touch a third-party API. Fewer are testing those models the way they’d test anything else before putting them near production. A benchmark score tells you how well a model writes code or answers trivia. It doesn’t tell you […]

Before You Trust a Local LLM, Test It Like an Attacker Would Read More »

The Hidden Blind Spot in AI Security Testing (And the Open-Source Tool That Found It)

Most AI security evaluations test the model. They don’t test the stack — the hardware, drivers, quantization, and routing decisions sitting underneath it. That gap is exactly what Scott Bly, SIS Cyber Director of Security Technologies, stumbled into while trying to cut cloud costs by running local AI models, and it led him to build

The Hidden Blind Spot in AI Security Testing (And the Open-Source Tool That Found It) Read More »

Why Vendor AI Benchmarks Don’t Protect Your Stack

And What We Found When We Tested It Ourselves Here’s what’s going on. Every major AI vendor publishes benchmark scores. Every hardware vendor publishes performance numbers. And every security team making a model procurement decision trusts those numbers to mean something about their deployment. They don’t. At least not the way most teams think. A

Why Vendor AI Benchmarks Don’t Protect Your Stack Read More »

The API Trap: Security in the Age of AI‑Generated Integrations

AI is accelerating how applications are built, but it’s also accelerating API sprawl and expanding attack surfaces faster than most security programs can keep up. In this webinar, ‪@SISCyber‬ teamed up with ‪@Heeler-Security‬ to unpack how AI‑assisted development is reshaping API risk, why many organizations no longer have clear visibility into what APIs are running

The API Trap: Security in the Age of AI‑Generated Integrations Read More »

The Reality of “Shift Left” (And How to Fix It)

The concept of “shift left” was supposed to be the silver bullet for application security. Yet, the reality is that most DevSecOps programs are fundamentally broken, leaving critical gaps that attackers are exploiting much faster than security teams can deploy patches. In this deep dive with Scott Bly, SIS Cyber Dir. of Security Technologies and

The Reality of “Shift Left” (And How to Fix It) Read More »

Scroll to Top