<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ai-research on Chris Farris</title>
    <link>https://www.chrisfarris.com/categories/ai-research/</link>
    <description>Recent content in ai-research on Chris Farris</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 23 May 2026 09:37:34 +0000</lastBuildDate>
    
	<atom:link href="https://www.chrisfarris.com/categories/ai-research/rss.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>The Many Faces of the Security Poverty Line</title>
      <link>https://www.chrisfarris.com/post/security-poverty-cliff/</link>
      <pubDate>Sat, 23 May 2026 09:37:34 +0000</pubDate>
      
      <guid>https://www.chrisfarris.com/post/security-poverty-cliff/</guid>
      <description>&lt;p&gt;Wendy Nather coined the Security Poverty Line in 2011. Fifteen years later, the field still thinks in binary — haves or have-nots, the cyber 1% or everyone else. That leaves the entire middle invisible: a Security Upper Middle Class that mostly just shows up to BSides and gets back to work, and a Security Valley of Death that&amp;rsquo;s the most populated tier in the industry and the least discussed. This post builds a five-tier model by mapping economic class theory onto security maturity — and borrows Michael Green&amp;rsquo;s Valley of Death framing to explain why mid-market programs keep failing despite real investment.&lt;/p&gt;
&lt;p&gt;This is mostly research from Claude, but reflects my framing of the issue&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>