The Next Two Years of Software Engineering

Extreme TLDR: Software engineering faces AI's impact on junior roles and coding skills by 2026. Junior hiring may decline as AI automates tasks or grow with new industries needing devs. Core programming skills may wither or become crucial, shifting focus from coding to oversight. Developer roles may shrink to auditing AI outputs or expand to orchestrating AI systems. Versatile “T-shaped” engineers who adapt are favored over narrow specialists. Education shifts towards practical skills over degrees as companies embrace non-traditional training pathways. Continuous learning and human creativity remain essential amidst change.

https://addyosmani.com/blog/next-two-years/

Why Cybersecurity Cannot Hire Its Way Through the AI Era

Cybersecurity faces a talent shortage; AI can help manage risks effectively. Automation is vital for handling modern threats, and AI enhances productivity despite job displacement. Organizations must focus on prioritizing significant risks and reskilling personnel. AI may create new roles while improving processes. The Risk Operations Center (ROC) framework shifts from reaction to proactive risk management. Continued scrutiny is necessary for AI-generated coding risks. Embracing AI's potential is essential for cybersecurity resilience and growth.

https://cyberscoop.com/cybersecurity-talent-shortage-ai-risk-operations-center-2026-op-ed/

What Makes a Successful CISO?

CISO's role shifts from technical focus to business leadership; their purpose is to align cybersecurity with business objectives. Discussions on defining CISO roles highlight the need for both technical knowledge and strategic vision, emphasizing that organizations must clarify expectations for CISOs. The evolving landscape necessitates CISOs to foster business resilience, communicate in business language, and collaborate across departments, especially as AI transforms security dynamics.

https://cisoseries.com/what-makes-a-successful-ciso-2/

Coder Unveils AI Governance Tools for Developers

Coder.com launched a suite of AI governance tools for developers, enhancing self-hosted workspaces with AI coding agents. The platform includes AI Bridge for centralized model access, Agent Boundaries for security controls, and Coder Tasks for workflow automation. This structure aims to provide enterprises control over AI use, reducing risks associated with fragmented systems. As organizations adopt AI more deeply in development, Coder.com emphasizes the need for a unified governance model.

https://itbrief.co.uk/story/coder-unveils-ai-governance-tools-for-developers

The State of Trusted Open Source

TLDR: Chainguard's report on the open source software supply chain reveals key insights: AI is reshaping the stack, risks mostly lie in lesser-known “longtail” images, and compliance drives software choices. Popular images don't correlate with security risks—98% of vulnerabilities are outside top projects. Chainguard remediated critical CVEs in under 20 hours, emphasizing the need for fast response across all software components, not just popular ones. As open source complexity grows, addressing risks in less visible areas is crucial for security and compliance.

https://thehackernews.com/2026/01/the-state-of-trusted-open-source.html

PCI DSS Compliance Is a Business Essential, Not an IT Task

PCI DSS compliance is essential for businesses, not just IT, to mitigate risks from data breaches, avoid fines, and maintain customer trust. It's vital for any entity handling cardholder data. Compliance should be ongoing, not a yearly task, as failure could halt operations and lead to financial losses. Certification signals commitment to security but must be part of continuous operational discipline to manage threats effectively. PCI DSS standards evolve to address new challenges in payment processing.

https://www.engineeringnews.co.za/article/pci-dss-compliance-is-a-business-essential-not-an-it-task-2026-01-08

Passwords Are Where PCI DSS Compliance Often Breaks Down

Extreme TLDR: PCI DSS compliance often fails due to poor password practices, like reuse and insecure storage. Enhanced training on password management and using password managers can improve compliance. These tools support key requirements, reduce risky behaviors, and should be integrated into employee onboarding to make secure practices routine. Compliance becomes easier when secure password handling is a default behavior.

https://www.helpnetsecurity.com/2026/01/08/passwords-pci-dds-compliance/

Cybersecurity CEO: Is Your Company Selling Or Storytelling?

Cybersecurity companies must transition from traditional selling to storytelling in marketing. Microsoft emphasizes this by hiring a director for narrative and storytelling, crucial for building trust and elevating its brand amid shrinking earned media. With projected cybersecurity spending reaching $522 billion in 2026, storytelling could differentiate companies. Effective narratives are more persuasive than aggressive sales tactics, as highlighted by experts like George Kurtz and Adam Keown, stressing that understanding and connecting with clients is essential for success.

https://cybersecurityventures.com/cybersecurity-ceo-is-your-company-selling-or-storytelling/

The Future of Cybersecurity Includes Non-Human Employees

Future cybersecurity hinges on non-human identities (NHIs) like AI, bots, and service accounts. NHIs' security, now as crucial as human accounts, lacks traditional oversight, increasing vulnerabilities. Organizations must adopt zero-trust security, implementing least-privilege access and automated credential rotation to manage these risks effectively, ensuring NHIs receive equal protection to human users to prevent cyber threats.

https://thehackernews.com/2026/01/the-future-of-cybersecurity-includes.html

Scroll to Top