Teams are connecting Claude to Jira to summarize issues, draft tickets, and answer sprint questions in seconds. The productivity gains are real, but so is the security risk. The problem is simple: a direct connection gives Claude the same permissions as the person who set it up. If that user can view confidential projects or delete issues, so can Claude. There's no business logic in between deciding what AI should and shouldn't touch. Most organizations don't want to ban AI.
If you’ve managed Jira for a while, you've probably seen permissions grow more complex over time. You might have accounts that were granted temporary access during a migration but are still retaining it today. Or maybe contractors whose access was never revoked. You can clean that up. But with hundreds of users and projects, it’s going to take forever. Things become even more complicated when you're preparing for a SOC 2, ISO 27001, or SOX access review.
Framework choice isn’t really about syntax or GitHub stars. It’s a multi-year commitment that shapes architecture, team habits, hiring, and how painful your next migration will be. Frameworks decide your architecture by default, whether you choose it or not. Some frameworks default to synchronous request handling; others assume non-blocking IO from day one. Some nudge you toward a monolith; others push you toward services that split naturally.
Avni Wala, Principal Developer – Arctic Wolf Laura Ellis, SVP Artificial Intelligence – Arctic Wolf Merin Eralil, Security Partner Solutions Architect – AWS Tim Sitze, Solutions Architect – AWS AI didn’t just make defenders faster. It made attackers faster too. The moment both sides got access to the same speed, speed stopped being the advantage. With speed no longer separating attackers from defenders, the deciding factor moved somewhere else.
There's a widespread assumption in enterprise security that identity is a problem IAM programs know how to solve. Provision the right access, enforce least privilege, audit the credential chain, and you've addressed the identity risk. For human users and traditional service accounts, that's approximately correct. For coding agents, it misses two-thirds of the problem. Coding agents don't have a single identity. They operate across a layered identity surface, and each layer carries its own risk profile.
Attackers are learning to target the moments when organisations are trying to be helpful, restoring access quickly while proving who deserves to be trusted again. Ajay Biyani, Senior Vice President, APJ, Securonix Identity conversations usually begin with the login because that is the moment everyone can see. It is where organisations concentrate passwords, MFA, device checks, and risk signals.
A board meeting agenda gives the CISO ten minutes to talk about AI. Walking in with a shadow AI tool count or a list of blocked prompts does not answer the question directors probably have: what happens if this goes wrong, and who is accountable when it does? Boards increasingly carry direct exposure for AI oversight failures, from regulatory scrutiny to shareholder litigation.
Managing hybrid cloud environments is complex due to fragmented tooling and policies. Learn why consolidated and consistent policy management is crucial for security and efficiency.
In a recent announcement, the U.S. Department of Defense (DoD) suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. Since we’ve received questions from our customers about the announcement's impact, I’ve recapped the latest updates below. Remember to always consult your DoD contracts for the latest provisions and review these program updates with legal counsel, technology consultants, and third-party CMMC assessors, as appropriate.