It’s largely automated. I have a collection of Python scripts in a Jupyter Notebook that scrapes Meetup and Eventbrite for events in categories that I consider to be “tech,” “entrepreneur,” and “nerd.” The result is a checklist that I review. I make judgment calls and uncheck any items that I don’t think fit on this list.
In addition to events that my scripts find, I also manually add events when their organizers contact me with their details.
What goes into this list?
I prefer to cast a wide net, so the list includes events that would be of interest to techies, nerds, and entrepreneurs. It includes (but isn’t limited to) events that fall under any of these categories:
Programming, DevOps, systems administration, and testing
Tech project management / agile processes
Video, board, and role-playing games
Book, philosophy, and discussion clubs
Tech, business, and entrepreneur networking events
Toastmasters and other events related to improving your presentation and public speaking skills, because nerds really need to up their presentation game
Sci-fi, fantasy, and other genre fandoms
Self-improvement, especially of the sort that appeals to techies
Here’s a video that isn’t from the place where I work (NetFoundry), but from someone works in a different part of AI security. Yet somehow they ended up at the same question that we at NetFoundry ask: How confident are you that your current tools can defend against the new threats brought about by AI?
The video features an interview that took place at the recently-concluded Black Hat 2026 in Las Vegas, and the interviewee is Daniel Bardenstein, CEO of Manifest Cyber.
While NetFoundry focus on identity-based security, Manifest’s focus is on the AI supply chain:
Manifest’s approach to security is knowing what’s actually inside the models and software you build and buy. They’re paying particular attention to provenance: training data you didn’t source, open-weight models pulled from a public hub, what’s “under the hood” of your agents.
NetFoundry approaches AI security from the other end: what’s outside the models and software you build and buy, and what’s allowed to reach it. We’re about machine identity, service-to-service access, and attack surface.
Watch the video; it’s got some notable stuff, including:
Open-weight adoption is about to accelerate, and the reason is control. Bardenstein argues that with a frontier model you have zero control over the system prompt, the training data, or what some provider (or government) decides to change under you. With an open-weight model, you control the whole chain: prompt, data, deployment, guardrails. If you’re already self-hosting models behind OpenZiti, this is the security-side justification for it, from someone who isn’t us.
The Hugging Face incident he describes is darkly funny. A lot of people say that the risk with AI models is that they’re non-deterministic, but the HF situation happened because the sandboxing was weak and guardrails (which really means “ordinary software security”) were missing. Then, when HF pointed its own AI at the forensics, its guardrails read the request as “too cyber” and refused to help,. HF had to fall back to an open-weight model.I’m going to start saying this regularly: AI fails like software because it is software!
“AI has its own supply chain and you inherit it.” Every model off a public hub and every third-party dataset is a dependency you didn’t build and can’t fully vet. Bardenstein notes public datasets have shipped with everything from PII to, in documented cases, outright illegal content nobody caught until after training. As the people on the Antiques Roadshow TV show will tell you, provenance is important.
The Log4Shell framing is the one I’d steal (in fact, I’m doing that right now). Bardenstein built Manifest after the Pentagon Log4Shell vulnerability (a.k.a. CVE-2021-44228) scramble. The issue boiled down to a simple, embarrassing question: “Where is this one piece of code running across everything I’ve built and bought?” Even having seen what happened five years ago, if you told a CISO a model or dataset was poisoned, they’d likely not be able to tell you where it’s deployed, who owns it, or which vendors are affected without a lot of phone calls, emails, spreadsheets, and gnashing of teeth.
99% of CTOs/CISOs at orgs with 1,000+ employees admit they lack full visibility into their AI deployments.
54% named new AI-specific services like MCP servers and LLM gateways as fresh attack surface.
8% think their identity systems are sufficient for non-human workloads.
Pair our observations with Bardenstein’s supply-chain point and the full failure mode is bleak. An agent you can’t identify, running a model you didn’t vet, reaching services over credentials nobody rotates. That’s three unknowns stacked on top of each other.
My read (not Bardenstein’s or NetFoundry’s report’s) is that giving an agent its own OpenZiti identity solves the “reach” half of the problem. You know what the system or service can talk to and every log line means something.
What it doesn’t do is handle the composition half, or to put it another way, it doesn’t account for what’s inside the thing you just handed an identity to.
Two separate disciplines that happen to share a root cause: You can’t govern what you can’t see, whether “it” is a network path or a model’s provenance.
813 Tech Day happens in Tampa this Thursday, and whether you plan to attend (I’ll be at the Hotel Haya and Sapphire events) or observe from afar, keep this word in mind: Scenius.
What is scenius?
Scenius is a portmanteau of the words scene and genius, and it was coined by musician, music producer, and visual artist Brian Eno to describe the extreme creativity that groups, places, or “scenes” can generate.
Eno came up with the term as a way of countering the pervasive mythoftheLoneGenius: the idea that innovation comes from a small, select set of Chosen Ones:
Brian Eno. Creative Commons photo by Algemene Vereniging Radio Omroep (AVRO). Tap the image to see its source.
“Just as genius is the creative intelligence of an individual,” he says in the video, “scenius is the creative intelligence of a community.”
Here’s Eno’s expanded definition of scenius, courtesy of Eno:
“Scenius stands for the intelligence and the intuition of a whole cultural scene. It is the communal form of the concept of the genius.”
…I thought that originally those few individuals who’d survived in history – in the sort-of “Great Man” theory of history – they were called “geniuses”. But what I thought was interesting was the fact that they all came out of a scene that was very fertile and very intelligent.
So I came up with this word “scenius” – and scenius is the intelligence of a whole… operation or group of people. And I think that’s a more useful way to think about culture, actually. I think that – let’s forget the idea of “genius” for a little while, let’s think about the whole ecology of ideas that give rise to good new thoughts and good new work.”
Historical examples of scenius
Here are some examples of scenius, where the collective smarts, creativity, and passion of a group of people coming together to do great things is greater than the sum of its parts:
The Lunar Society of Birmingham: a dinner club run between 1765 and 1813 in Birmingham, England, and attended by industrialists, scientists, and thinkers who changed science and engineering forever. Their regulars included Boulton and Watt (steam engines and their applications to manufacturing), Erasmus Darwin (biology, inventions, and grandfather of Charles Darwin), Keir (industrialist, chemistry, inventions), Priestly (chemistry, philosophy), Small (Thomas Jefferson’s professor at the College of William and Mary), Stokes and Withering (early heart medicine), Wedgewood (industrialized pottery, pretty much invented modern marketing, including the concepts of direct mail, money-back guarantees, self-service, free delivery, buy one get one free, and illustrated catalogs), Whitehurst (geology).
A then-NYU student named Rick Rubin was there networking, and in a couple of years before he’d co-found Def Jam. A young Madonna performed there before her career took off, and Run-DMC and New Edition played some of their first shows on that stage.
The Roxy also attracted people from New York’s art/punk scene, including Jean-Michel Basquiat, Keith Haring, Andy Warhol, Debbie Harry (who ventured into hip-hop with 1980’s Rapture, which was the first rap tune to make it to #1 on the U.S. charts; it also mentions Fab 5 Freddy), and to complete the scenius circle… John Lydon of the Sex Pistols.
Silicon Valley: Your iPhone and Android are direct descendants of the scenius that was born when the “Traitorous Eight” left Shockley Semiconductor to form their own company, Fairchild, and the “Fairchildren” who then left Fairchild to form their own companies, and so on, creating a cross-pollenating scene that we now know as “The Valley”.
Mutual appreciation: Risky moves are applauded by the group, subtlety is appreciated, and friendly competition goads the shy. Scenius can be thought of as the best of peer pressure.
Rapid exchange of tools and techniques: As soon as something is invented, it is flaunted and then shared. Ideas flow quickly because they are flowing inside a common language and sensibility.
Network effects of success: When a record is broken, a hit happens, or breakthrough erupts, the success is claimed by the entire scene. This empowers the scene to further success.
Local tolerance for the novelties: The local “outside” does not push back too hard against the transgressions of the scene. The renegades and mavericks are protected by this buffer zone.
Austin Kleon By Larry D. Moore, CC BY 4.0
Here’s what Austin Kleon, a writer and artist whose ideas have been adopted by the tech community, has to say about scenius:
Under this model, great ideas are often birthed by a group of creative individuals—artists, curators, thinkers, theorists, and other tastemakers—who make up an “ecology of talent.” If you look back closely at history, many of the people who we think of as lone geniuses were actually part of “a whole scene of people who were supporting each other, looking at each other’s work, copying from each other, stealing ideas, and contributing ideas.” Scenius doesn’t take away from the achievements of those great individuals: it just acknowledges that good work isn’t created in a vacuum, and that creativity is always, in some sense, a collaboration, the result of a mind connected to other minds.
What I love about the idea of scenius is that it makes room in the story of creativity for the rest of us: the people who don’t consider ourselves geniuses. Being a valuable part of a scenius is not necessarily about how smart or talented you are, but about what you have to contribute—the ideas you share, the quality of the connections you make, and the conversations you start. If we forget about genius and think more about how we can nurture and contribute to a scenius, we can adjust our own expectations and the expectations of the worlds we want to accept us. We can stop asking what others can do for us, and start asking what we can do for others.
How do we grow Tampa’s scenius?
The short answer is: By showing up and participating in events like 813 Tech Day!
While the elements of scenius are in place for Tampa Bay’s tech scene, there’s still some way to go before Tampa can match places like Nashville (whose tech scene is biggerthanyoumightthink) never mind places like Austin, Charlotte, Indianapolis, and Raleigh.
The success or failure of Tampa’s tech scenius depends on us, the Tampeños who work in tech, creative, and related industries.
While the city did launch some initiatives to change this, what truly made the difference was Toronto’s own tech community stepping up and organizing. We held events of all sizes, from regular meetups and user group meetings at pubs and lecture halls to independent conferences like Mesh, RubyFringe and FutureRuby to tech “camp” events to big corporate gatherings put on by the likes of the Canadian subsidiaries of IBM and Microsoft. We built places to get together, from hackerspaces such as Hacklab.TO (where I met Chris Olah as a young teenager; he’d go on to co-found Anthropic)…
…and Site3 coLaboratory to the MaRS Centre. In my work as a developer evangelist for Microsoft, I’ve met many students at Toronto’s fine universities and colleges, and they’re eager to crank out the ‘wares, both hard and soft, and they’re bright as all get-out. We built a great community bound together by cooperation, a strong social media scene and good old-fashioned face-to-face meetings. We got stuff done, and the stuff we did traveled far and wide. We built Toronto’s tech scenius, and it put the city on the map.
Can Tampa do the same? I believe so; it’s just up to us.
And now, 813 Tech Day!
Thursday, August 13, or 8/13, is 813 Tech Day. Brought to you by the folks behind Tampa Bay Tech Week and 727 Tech Day, it’s one day of sessions, discussions, workshops, get-togethers, and networking for Tampa Bay’s tech community, held in Tampa.
There’ll be value in what the presenters show and what the panelists say, but the real gold will be in simply showing up and meeting other people you might not have otherwise met and gaining ideas and inspiration you might not have otherwise had.
Here’s a fun little contradiction to start your week with: NetFoundry asked 200 CISOs and CTOs whether they feel pressure to secure the AI they’re deploying. Unsurprisingly, and to my considerable relief, every single one said “yes”.
We then asked how confident they are that their current tools can actually handle the new risks, and 15% said “very.” 15% is very slightly less that the odds for rolling six on a 1d6. More specifically, among the CISOs, whose entire job is to be the professional pessimist in the room, that figure dropped to 10%.
That’s the current situation: Universal pressure, near-universal doubt.
I work at NetFoundry as a developer advocate, and NetFoundry commissioned this report. So yes, this is a vendor survey, and you’re correct to raise an eyebrow. (I’d be worried if you didn’t).
In our defense, we did the thing you’re supposed to do: the survey itself was run by an independent research firm (Global Surveyz), the respondents were 200 US-based security and technology leaders at companies with 1,000+ employees, and it was fielded this past May and June.
I’m going to try and separate what the survey found from what I think it means. The first category is data. The second category is me, a guy on the internet, having opinions, which won’t always be the same as NetFoundry’s Marketign department (it happens). I’ll flag which is which.
The number that reframed the whole thing for me
Of everything in here, this is the one I keep coming back to:
Security leaders are nearly 10x more likely to worry about securing machine-to-machine workloads than human access to applications.
Specifically: 69% said machine workloads (service-to-service, API-to-API, agent-to-whatever) are where they’re least confident today. Just 7% said human user access. The remaining 24% said “both equally,” which I read as “please don’t make me pick.”
That tracks perfectly, and it’s a compliment to the last decade of security work. Think about what we spent the 2020s doing. COVID sent everyone home, remote access became the whole ballgame, and the industry poured an enormous amount of money and brainpower into VPNs, Zero Trust access, and all sorts of security measures for a world that was suddenly more online that ever. It worked, and hman access to applications is, comparatively, a solved-ish problem. We got good at authenticating people. (I should know; it was during that time that I worked at Auth0!)
The issue of identity
The catch is that all of that machinery is built on one quiet assumption: that the thing connecting to your app is a human being with a unique identity. You authenticate the person, then you grant the access.
My late former coworker, Vittorio Bertocci, has forgotten more about identity than I will ever learn, and he was starting to look very deeply into identity in the age of AI.
Agents and models don’t work like that. They don’t have identities the way humans do. So the tooling we built for the last problem doesn’t cleanly transfer to this one, and the volume is going the wrong direction, fast. Machine traffic is now growing several times faster than human traffic year over year. We got really good at guarding a door that fewer and fewer of the visitors are actually using.
A few more stats worth your attention:
100% agree their attack surface is growing. Not a plurality. Not a strong majority. Everyone. The average projected increase was 14% over the next 12 months, and that figure only counts AI deployments already underway or planned. 14% is probably the minimum.
93% are concerned about the new risks AI introduces, but only 15% are highly confident their current tools can handle them. That’s the gap I opened with. When the level of concern and the level of confidence are that far apart, something structural is going on.
99% admit they don’t have full visibility into their own AI deployments. That remaining 1%, which would have to be one respondent? I would like to buy that person a coffee (or beer! or bourbon!) and ask them a lot of questions.
90% are worried about shadow AI, the unsanctioned tools employees adopt on their own because the approved options don’t cut it. This is not a technology problem, it’s a human-nature problem. I will neither confirm nor deny my own contributions to the shadow AI at previous organizations, but in my defense, I was getting things done! When a tool is genuinely useful, people use it, memo or no memo.
Only 8% call their current identity systems “very sufficient” for non-human workloads. 85% are now actively evaluating or exploring new approaches. That second number is the tell. When five out of six organizations are shopping for a new approach at the same time, that’s teh surest indicator that the industry is collectively coming to the realization that the existing tools weren’t built for this.
Oh, and it’s slow. 55% cited risk and compliance review as a top contributor to delays in the network changes AI deployments need, and those changes add an average of 8 days from request to implementation. And that’s now, while AI-specific scrutiny is still warming up.
My read (this part is me, not the data)
In this section, I’m switching from reporting to speculating.
I think almost every number above traces back to one root cause: machines don’t have real identities. They have internal names so that developers and devops people can talk about them, but when it comes to having reasonably canonical identities like we humans do (full name, usernames, an email address, a government-issued unique ID number), we haven’t really created these for machines.
In the absence of machine identities, we have workarounds. On the less secure end, we have IP addresses; on the (relatively) more secure end, there are shared secrets, API keys, long-lived service-account credentials. As with most workarounds, they quietly rot. The credentials we give machines tend to carry more permission than they need. They rarely get rotated. After a while nobody’s entirely sure which agent a given key even belongs to, or why it exists.
Once you’re in that world, everything downstream gets harder. Visibility is hard because you can’t tell one agent’s actions from another’s. Access control is hard because a secret isn’t an identity, it’s some piece of data that happens to belong to a robot (and all too easily duplicated). Auditing is hard for both of those reasons at once. The identity gap is the root problem of most of the other security problems in the AI age.
NetFoundry — who are made of some very smart people, a few of whom are literal greybeards! — obviously has opinions about how to close that gap, and the report gets into them. That’s the vendor part, and you can take it or leave it.
In case you saw the em-dashes in the paragraph above and thought “Aha! AI!’, I assure you that I typed them in myself, because this is my relationship with AI:
Entering em-dashes is dirt simple on macOS: option-shift-minus. On Windows it’s a little more work: alt+0151. On Linux: control-shift-U, then release and type 2014, then return/enter.
Let me have just a couple of em-dashes in my article. Please.
But strip the logo off and the underlying observation stands on its own: we spent a decade giving humans strong identities and largely ignored the machines, and now the machines are the fastest-growing thing on the network. That bill was always going to come due. It’s just arriving faster than most people planned for.
The stat I want ask you about
That 14% attack-surface increase feels low to me. If you’re actually running agents in production right now, watching them spawn sub-agents and reach across cloud boundaries and pick up new tool integrations every sprint, does 14% over a year match what you’re seeing, or is it wildly optimistic?
(That’s a genuine question, not a rhetorical one. I’d rather hear it from people living it than trust my own gut.)
Read the full 2026 State of Secure AI Access report!
Pictured above is my standard AI usage disclosure slide, which I include in all my slide presentations these days. It’s gives the audience a quick overview of how I prefer to use AI when putting a talk together.
Here’s the text:
This strategy presentation was developed using AI assistance (Claude, ChatGPT, and Gemini) for:
Research: Market trend analysis and competitive landscape review
Editing: Grammar, clarity, and flow optimization
Ideation assistance: Testing ideas and generating new ones, because no matter how creative you are, it’s impossible to come up with a list of things you’d never think of.
The main contents — including strategic insights, tactical recommendations, specific positioning, and any em-dashes (option-shift-minus on Mac, alt + 0151 on Windows, Google “em dash” and copy and paste it on Linux) — were developed based on analysis of the interview materials and 15+ years of experience in the industry.
Thursday, 8/13, is the day when we celebrate the techies and tech companies in the 813 area code: 813 Tech Day!
We recently celebrated the 727 area code, which covers Clearwater and St. Pete with a one-day, multi-event celebration of the area tech community, and on August 13th, we’re doing it again for the Tampa side of Tampa Bay. It’s being put together by the good people behind Tampa Bay Tech Week (with HyLo Innovation and W3RTech).
Are you in or near the 813 area code? Do you build systems or software for a living, or do you want to? Then you’ll want to mark Thursday, August 13 on your schedule and free it up for 813 Tech Day.
Vibe: Panels, hands-on workshops, a lot of open networking, and an evening that keeps going
813 Tech Day happens in different places at different times!
813 Tech Day moves around Tampa, and it’s both a feature that lets you see places you might not have seen before and a way for you to get your steps in:
Look, I’m a night owl and a musician, so I’m not likely to be at the Sweat in the City workout event at the start of the day (I tend to work out after my 10 a.m. standup with my NetFoundry teammates). But if you like early morning workouts and want to do one with the Tampa tech scene, go!
Many sessions in the first half of the day happens at Cres Community in the Wellswood area (Rome Ave., south of Hillsborough), a very comfy-looking business event space.
There’s also a big morning session at Hotel Haya in Ybor City, where the 813 Tech Day AI Meetup & Co-working event will take place. I’ll be there.
Then, in the afternoon, the sessions move from Cres Community to Hotel Haya.
Because this is basically a hometown game. 813 Tech Day crams the whole spread of Tampa Bay tech into one day and three venues, and the afternoon block at Hotel Haya is the real flex: cybersecurity in fintech, telecom/IT infrastructure resilience, and manufacturing workforce AI, back to back to back. Fortifying the Digital Frontier and Hyper-Connected Tampa are exactly the kind of conversations I show up for uninvited (don’t worry; I was invited). Zero-trust networking and infrastructure that doesn’t fall over are, not coincidentally, my day job.
The morning’s no slouch either. At Cres Community, there’ll be an AI-and-workforce panel, a founder mental health session that more conferences should be brave enough to program, and a healthtech partnerships talk that’ll be catnip if you’re anywhere near that space. If you like things more freeform, the 813 AI Meetup and Coworking event is happening at Hotel Haya, where I’ll be.
813 Tech Day wraps up at a place I’ve been meaning to check out: The Sapphire Tampa (a pretty stylin’ looking place in an unexpected location on Boy Scout Road) for a networking happy hour and a closing night that, judging by past Tech Week events, does not believe in winding down early.
I’ll be around all day; come say hi! I’m the one with the accordion energy and strong opinions about cybersecurity, AI, zero-trust networking, and the future of computing.
Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, memes, and even videos — I found over the past week. Share and enjoy!