
About Elena
Elena writes about governance, compliance, and the real cost of alert backlogs. She interviews CISOs weekly and it shows.
Elena covers autonomous and semi-autonomous remediation with a bias toward the boring questions: who approves the change, what gets rolled back, and who is accountable when an agent is wrong.
Worked on security automation and SOAR tooling before it was called agentic, and has spent the last few years testing where human review still earns its cost.
Latest by Elena Brandt

65% of cloud risk is misconfiguration. Handing it to an AI agent is still a bad idea
65% of cloud security incidents stem from misconfigurations, but letting AI agents fix them autonomously risks breaking production through non-deterministic errors and dependency blindness.

Auto-remediation gets turned off in 90 days. Here is what breaks first
Automated scripts for cloud security often fail in production because they lack operational context. Most teams disable them after the first outage, leading to a resurgence of the remediation backlog.

Inside the AI agent that fixes cloud findings without touching production blind
Enterprises are adopting modular AI agents that map dependencies and calculate blast radius to prevent production outages during security fixes.

Where autonomous remediation stops and a human has to sign off
Autonomous security agents offer speed, but production stability requires human oversight for high-impact IAM and network changes.

What an AI agent must prove before you give it production write access
Automated remediation promises to clear the CNAPP backlog, but granting AI write access to production requires more than a prompt. Trust depends on context, rollbacks, and human oversight.
