Discussion about this post

User's avatar
Mike Schlottman's avatar

Thank you for making the detection layer concrete. Self-reporting fails here for the same reason vendor security questionnaires fail: you are asking people to report legal events they never experienced as legal events. In third-party risk work, the honest witnesses were never the survey responses; they were the expense reports, the SSO logs, and the API keys, exactly as you lay out. My prediction is that the AI register converges with IT asset management within a few years, because the only inventories that stay true are the ones fed by systems that do not care how the answer looks.

1 more comment...

No posts

Ready for more?