Sign in to view James’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view James’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Raleigh, North Carolina, United States
Sign in to view James’ full profile
James can introduce you to 3 people at Latio
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
22K followers
500+ connections
Sign in to view James’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with James
James can introduce you to 3 people at Latio
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with James
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view James’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Courses by James
-
Application Security Posture Management: Security from the Supply Chain to Cloud Runtime1h 56m
Application Security Posture Management: Security from the Supply Chain to Cloud Runtime
By: James Berthoty
-
Microservices Security Workshop: From Build to Production2h 21m
Microservices Security Workshop: From Build to Production
By: James Berthoty
1,959 viewers
Activity
22K followers
-
James Berthoty shared thisToday we’re launching the Latio AI Assistant, allowing teams to quickly find the most relevant security tool for their use case. The original Latio application was created out of a frustration with existing marketplaces, which often have irrelevant data and mismatched tools. AI has only made this problem worse, as data quality is driven by whatever marketing materials a vendor makes available. As a practitioner and buyer, I never found these resources helpful, and wanted something that gave me relevant information, as I needed it. Latio now lists well over 350 vendors, accurately categorized by hand, and over 200 pages of reports, also written by humans. Our AI Assistant feature allows teams to quickly add their existing stack, and works alongside them to find the most relevant solution. It’s now available in beta to everyone, for free. https://lnkd.in/d7QVipgy
-
James Berthoty shared thisHaving had the opportunity to see the product, here's why I'm excited about Act's launch today. While "proactive cloud security" has existed as a category, it's largely been around deploying and managing SCP across multi-cloud environments; in other words, helping organizations adopt permission and data boundaries at scale. Act stands out due to how much deeper across every layer of the stack they go - mapping identities, application, network, and data layers - helping organizations establish true boundaries between modern applications, and even their on-premise footprint. These capabilities are only going to grow in importance as AI powered attacks force enterprises to assume breach as zero days run rampant. Proper segmentation and runtime protection are essential as AI's ability to take advantage of misconfigurations is becoming nearly instantaneous. Congrats to the team on executing on product and launch!
-
James Berthoty shared thisOne of the most significant emerging trends in "AI SOC" is the investment teams are making in running detections on ingest rather than the traditional scheduled search approach. Historical search has long been the standard way to write a detection, one example being, “Alert me when x event happens.” This runs a retroactive search every 5 minutes against the logs that have been ingested. The problem is that it assumes all of the necessary logs are in a single place. Many AI SOC startups flipped this common practice, and instead sit in front of log storage not only to normalize and route logs, but to fire detections as soon as they happen. This allows them to augment detection capabilities, consolidate detection opportunities, and route logs to the location where they're the most cost effective to store. By firing alerts as logs are ingested, they're able to support any long term data storage preferences an organization may have. Detecting on ingest allows these vendors to increase their customer's detection potential, without the friction that attempting to support, transition, or create federated searches can cause. Next week I'll post about the other approach that has its own benefits. You can checkout what capabilities teams are taking bets on in our SOC report: https://lnkd.in/ertJcqA6
-
James Berthoty shared thisThis is an incredible framework for datacenter security, and a series of actionable steps to investigate for on-premise footprints!James Berthoty shared thisToday, we’re releasing FORGE, an actionable security framework for data centers and AI infrastructure. Modern data centers span countless vendors, infrastructure layers, and disconnected tools. As these environments become more complex, valuable, and exposed, the security blind spots only grow. We developed FORGE with CISOs, neocloud experts, researchers, and infrastructure leaders to help teams identify and reduce risk across the stack. Proud of Michael Katchinskiy 🌋, the rest of the Lava team, and all the incredible reviewers who helped bring this framework to life. Link: https://lnkd.in/dGJ-DT9A
-
James Berthoty shared thisOver the last few weeks, several initiatives have been announced with grandiose ambitions to save open source from the impending vulnpocalypse. A few security researchers and practitioners asked what we thought about it. To be frank, these initiatives have pros and cons to them, and they have an opportunity to make vulnerability management better and worse. These trends also continue privatization pressure that's been growing across vulnerability management. In this article, we breakdown what's happening, the risks involved, and how these initiatives can change things for the better. https://lnkd.in/ejvBphHu
-
James Berthoty shared thisThe nature of SIEM tools is changing, but the architectural tradeoffs can be complicated to decipher. In our 2026 Security Operations Report, we wanted to do three things when laying out the SIEM market: 1. Make the architectural differences in vendor approaches clear 2. Map use cases to the architectural strategies 3. Highlight approaches that enable flexible storage This led to our mapping of SIEM's based on how portable the detections and underlying data structures are. Most startups in the SIEM space need to have flexible underlying architectures in order to accomodate the reality that they are unlikely to be an organization's only data source. Conversely, larger EDR vendors tend to push towards integration, while larger traditional SIEM vendors push towards a more federated model. It's important to note that this graph is not "top right = best;" rather it highlights the degree of vendor lock-in someone will experience when using the tools, which itself has pros and cons. Additionally, there's an ongoing discussion on whether the underlying detection language matters at all, as AI can quickly translate complicated queries between providers For the full breakdown on the approaches, see page 21 of our SOC report here: https://lnkd.in/enWHgw9H
-
James Berthoty shared thisShifting left promised to fix the developer/security relationship, but in many ways it made it worse. Unfortunately, for many teams shifting left became two functionalities: blocking builds when vulnerabilities are discovered, and nagging developers in as many places as possible to fix issues. To be clear, scanning often and early for security issues is a great investment; however, too many teams failed to convert scans into fixes. It was great teaming up with Or Chen 🍀 and the likeminded team at Clover Security to cover why shift left failed to fix the developer/security relationship, and how better use of AI can remediate some of the gaps that shifting left created. Read the article here: https://lnkd.in/eQVWUFUq
-
James Berthoty shared thisOver the last year we've been covering the rapid evolution of Datadog's security capabilities. This week I attended Dashcon and was impressed by the continued smart approaches to new features, AI and otherwise. Here are some takeaways on why I continue to like Datadodge: 1. Coolest new features: network hop mapping for hybrid cloud environments and database query optimization. Mapping network traffic is a nightmare in production, and this brings major value. The database query optimization testing against a mirror of your database was also extremely cool. 2. Most surprising feature: productizing their ai coding agent guardrails. Datadog has a number of open source malware detection projects, and I'm excited to see these work their way into the product. 3. Most hyped changes: Datadog has invested a ton into making the "AI SRE" promise a reality - giving code level changes for fixing production outages, or pushing fixes in realtime. I'll be excited for this approach to get rolled into security use cases like patching more over time. Overall, at Datadog's scale, the investment into building their own models has allowed them to roll out AI for customers with much less rate limiting and gating than many other providers. It remains to be seen if the outputs can stand up in production, but if they do the investment will pay off.
-
James Berthoty shared thisThis was a lot of fun to make and this Guardle game from Act is really fun - I've been doing it more often than I care to admit to test my SCP skills! https://guardle.io/awsJames Berthoty shared thisToday's Guardle is not for the faint of heart. We handed the design over to James Berthoty (Latio). He decided to not let folks off easy. Five attempts. RCP or SCP. Same Guardle rules, tougher than usual. Solve it, then go check whether that guardrail is actually live in your own cloud. That part depends on you 🙃 Post your score, tag Act and James Berthoty. First solver today wins AirPods Pro🎧 Link in the first comment ⬇️
-
James Berthoty liked thisJames Berthoty liked this9,764 #CVE published in July. Just under 10,000 in a single month. Call it #vulnpocalypse. Call it coverage finally catching up with reality. Or argue that a CVE is not a vulnerability and this number undercounts what is actually out there. All three are defensible and none of them changes what lands on your plate Monday. The part that is not arguable - every one of these was already in the software. July did not create 9,764 vulnerabilities. It published them. Yes, most of them score low on #EPSS. I wrote yesterday why that is a property of the instrument rather than a verdict on the year - age is the strongest single vulnerability characteristic in the model, and a CVE published this month has almost no record behind it yet. #KEV additions have stayed roughly flat year over year for four years, while publication volume climbed in every one of them. I do not read that as #exploitation being flat. I read it as the teams writing exploit signatures being at capacity. The Hugging Face postmortem is the other half of it. What caught that intrusion was correlating more than 17,000 individually unremarkable events into one timeline. That is the defender's job now - and the same volume is going straight into attacker automation on the other side. So my first test for a #CVE is not whether it is exploitable. It is whether it is in my environment at all. Exploitability is the second question and it keeps moving. Presence is the first one, and it is answerable today. The chart is the major #CNA who are mostly also major software vendors, which is about as much context as fits in one picture. Oracle went from 241 to 1,108 on the July CPU. Microsoft, VulnCheck, Wordfence, #WPScan, Apple, Red Hat, IBM and #Apache all posted their biggest month in the window. One genuinely good sign in there: MITRE has come down every month since April. https://lnkd.in/dnNUNyvU #informationsecurity #vulnerabilityassessment #vulnerabilitymanagement
-
James Berthoty reacted on thisJames Berthoty reacted on thisBallroom culture has long been a place of community, creativity, resilience, and chosen family. It’s also a powerful space for sharing resources, uplifting one another, and promoting wellness. Thanks to support from The Susan Terry Foundation, the Central Florida Ballroom Collective is expanding access to HIV prevention through its peer led PrEP program. By connecting community members with trusted providers and education, this initiative is helping more people access the tools they need to protect their health. When communities lead, meaningful change follows. We’re honored to support organizations that are building healthier futures from within. #CFBallroomCollective #BallroomScene #TampaBay #CANCommunityHealth #TheSusanTerryFoundation
-
James Berthoty liked thisJames Berthoty liked thisCan agents generate code that is secure by design? Coding agents create a HUGE opportunity for software security. For the first time, security expertise can be embedded into every software change as it is being planned and generated. But realizing that opportunity depends on one question: what kind of context actually helps an agent write secure code? Our research team ran 162 controlled experiments across three coding agents and three production codebases. We asked the agents to build features with business-logic flaws hidden in the specifications. We changed only one thing: the security context given to the agent. MD files with security guidelines and threat-modeling skills increased the percentage of flaws prevented from 17% to roughly 33%. Most flaws still shipped. Generic STRIDE or OWASP Top 10 guidance mainly made agents sound more secure. They produced plans that cited the right threats, passing tests, and code that appeared hardened, while the underlying vulnerabilities remained. Only security context built specifically for the feature made a meaningful difference, increasing the average prevention rate to 84%. Read the full research here: https://lnkd.in/giGGwkQi
-
James Berthoty liked thisJames Berthoty liked thisBig news today: DryRun Security just launched an entirely redesigned UI. The whole experience is faster, cleaner, and far more searchable. More importantly, we’ve added a new reporting section that gives security leaders a clear view into the risk entering through pull requests, including what’s being evaluated, what’s getting merged, and how risk is trending over time. The goal wasn’t simply to make DryRun prettier. It was to make the security intelligence we’re already producing easier to understand, explore, and act on. In the video, you'll see a few of the major product updates and how DryRun Security connects with the rest of your development stack. I’m incredibly proud of the team and what they’ve built. This is a major step forward for the product, and there’s a lot more coming. See it in action: https://lnkd.in/g_JErGyN
-
James Berthoty reacted on thisFINALLY. Thank you LinkedIn. We now have what we need to put an end to the #Sloppening.
-
James Berthoty liked thisJames Berthoty liked thisGood feedback is a skill, not a personality trait, and most of us are worse at it than we think. Be specific: "nice job" teaches nothing, but "you slowed down right at the hard part instead of rushing" actually sticks. Separate the behavior from the person so you're critiquing the work, not their worth. And give it close to the moment it happened, feedback from a week ago has already gone stale. Timing and specificity beat good intentions every time. #CivicsEducation #FutureLeaders
-
James Berthoty reacted on thisJames Berthoty reacted on thisMy mom was a hospice nurse who worked nights, weekends, and holidays. As a kid I’d see her bathroom light on in the dark before sunrise as she got ready for her next 7pm - 7am shift. Hospice care is physical, psychological, and emotional labor. It’s feeding, bathing, and clothing another person. It’s blood draws and medication schedules while being gentle and patient. She worked relentlessly and she loved her job. I often referred to her as a “death doula.” Her friend told me she told people they worked in “God’s waiting room.” Hospice care is for people in their final months, days, and hours of their life. Something that would be considered gruesome to many. She, somehow, looked death unflinchingly in the face. She provided physical and emotional comfort to her patients and their families during their hardest moments. She’d come home after every shift and tell me the story of who died that day. She’d tell me what they said as they reflected back on their life. Some people were CEOs who made 100x my mom, some were the parents of those CEOs, some were janitors, some were children. Imagine growing up surrounded by thousands of stories packed with the wisdom of people reflecting back on their lives. As a single mom, she’d also bring me along to work with her. I spent a lot of time in nursing homes as a child playing dominoes and cards with the residents. This relationship to the elderly and death shaped much of my life. I’ve always felt as though death was breathing down my neck. I’ve tried to relentlessly analyze my life through the lens of a life in retrospect. How will I feel about this when I’m 80? Through that lens, I’ve never felt I could work hard or fast enough to achieve all I want to achieve. This consciousness of my own mortality has shockingly been a gift, freeing me to live a life that made her proud. Due to the nature of her work, she could also be morbid and had the darkest, and best, humor. She loved a well written obituary and would often cut them out of the newspaper and send them to me or put them on the fridge. She aspired to be a writer and she loved the poignancy packed into the tiny word count. She had a remarkable ability to notice the individuality in everyone. She liked when obituaries reflected the small things. She thought a lot about psychology and never met someone she wouldn’t call a friend. Now, I hope the obituary I wrote her is good enough. In her final days, I took the lifetime of wisdom and insight she gave me and tried to stare death in the face as bravely as she would. I’m honored to carry her legacy and be my mother’s daughter. And thank you to one of the best PM turned best friend for the beautiful flowers Victoria Fawcett.
Experience & Education
-
Latio Tech
******* * ***
-
*** ***** ***** **********
***** ******
-
*********
******** ******** ***
-
******* ***** **********
********** ** ******* *********** ********** undefined
-
-
*** ******** ******* *********** ********
****** ** ******** * **** ********** *** ********* *******
-
View James’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Licenses & Certifications
Projects
-
Cloud Security List
A quick and trustworthy resource for the top vendors across cloud security, product security, and devsecops domains.
-
Latio Tech
Cloud Security consulting built around trustworthy security reviews, architecture planning, and tool assessments/implementations
-
YouTube Content
All things cloud and product security!
Languages
-
French
Professional working proficiency
-
Greek, Ancient (to 1453)
Professional working proficiency
-
Hebrew
Limited working proficiency
Recommendations received
4 people have recommended James
Join now to viewView James’ full profile
-
See who you know in common
-
Get introduced
-
Contact James directly
Other similar profiles
Explore more posts
-
Rohit Agnihotri
Northwestern Mutual • 9K followers
One thing that matters in security strategy is predictive accuracy: when the model matches reality, it’s worth revisiting the thesis. A few days ago, I wrote about how the pure-play cybersecurity cycle has compressed from ~10 years to ~5. I argued that the new goal isn’t $100M ARR; it’s proving traction fast and exiting before a platform bundles the category. This week, CrowdStrike announced it is acquiring Sgnl: ~$740M outcome. • Founded: 2021 (roughly a 5-year journey). • Stage: Series A (raised $30M in Feb 2025). • Outcome: ~$740M (this looks like a strategic multiple, not a revenue multiple). Sgnl didn’t wait to fight the platform war for a decade. They built undeniable “Best-in-Class” technology (CAEP/JIT) and integrated into a larger ecosystem at the exact moment the math made sense. This isn’t just a big number, it’s a clean validation point that the platform vs. best-of-breed debate is increasingly constrained by bundling economics. Congrats to the SGNL team for exceptional execution and timing. With timing this precise, I might need to go buy a lottery ticket next.
32
3 Comments -
Rohit Agnihotri
Northwestern Mutual • 9K followers
Platforms aren’t killing pure-play vendors. They’re just making the math impossible. Your “Best-in-Class” vendor just became a line item in your cloud provider’s free tier. Now what? We are witnessing an evolving landscape in “pure-play” cybersecurity business model. Not because the products are bad but because platforms discovered they can give away what you sell… and still out-earn you. Because they’re not monetizing ‘identity’ (or SIEM, or endpoint, or DLP). They’re monetizing: compute, storage, data gravity, and everything that gets sticky once you standardize. Here’s the pattern that keeps repeating across categories: The Pure-Play Playbook (2015–2023): - Build a specialized tool (IGA, PAM, SIEM, EDR, DSPM…). - Become “Best-in-Class” through deep features + integrations. - Charge enterprise prices because you “own the category.” - Win analyst reports. Win mindshare. - Scale to IPO… or get acquired. The Platform Counter-Move (2024–2025): - Hyperscalers notice the category is mature. - They bundle a “70% good enough” version into an existing SKU. - The buying question quietly changes from “Is it best?” to “Is it worth paying extra?” That’s the bundling trap. Not “your tool isn’t good.” Not “your competitor is better.” Just: “The incremental value has to be undeniable.” Example: AWS IAM Identity Center. If most workloads live in AWS, “native + included + integrated” becomes a default gravitational pull. So the enterprise conversation shifts to a much harder question: What’s the ROI of the remaining 30%? Not in features. In outcomes: - Audit cycle time reduced. - Access review effort collapsed. - Faster joiner/mover/leaver. - Higher confidence in least privilege. - Measurable blast-radius reduction. The acquisition wave is a symptom, not a strategy. Across the industry, the headlines are all pointing in the same direction: identity, data security, and platform consolidation are compressing time-to-exit. Not because innovation stopped. Because bundling changed the clock speed. Old world: - Build for 7–10 years. - Hit $100M ARR. - IPO or PE at premium multiples. New world: - Build for 3–5 years. - Prove traction fast $10M ARR - Exit before a platform bundles the category So the “Platform vs. Best-of-Breed” debate isn’t really a debate anymore. It’s a constraint. The job is no longer to pick the “best tool.” It’s to: 1) Negotiate the bundle without bankrupting your architecture. 2) Identify the 20% of use cases where bundled tools fail (multi-cloud governance, regulatory edge cases, extreme scale). 3) Justify premiums with hard ROI, not “better features.” Because “70% free” forces everyone to speak in economics. The vendors who survive won’t win on feature checklists. They’ll win by proving they’re worth paying for “even when the platform is good enough” The thing that works in favor of pure play vendors is org complexity. #CISO #Cybersecurity #Identity #IAM #CloudSecurity #Platformization #TheIdentityNavigator
84
19 Comments
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content