Think Big Newsletter #34 - Security as innovation enabler, Vibe coding for executives, Lenny's product pass, and RSI
AI, Innovation and Business Value
Welcome to the Think Big Newsletter, where we explore how business leaders can create value with AI and innovation. In each issue, I’ll share practical strategies, real-world case studies, and actionable frameworks that help you navigate the AI wave without getting lost in the hype.
I’d love to hear your thoughts, challenges, and suggestions for future editions.
In this issue:
Leadership Principles in the Age of AI - Security as an innovation enabler
Business Value with AI - Vibe coding for executives
AI Tool Spotlight - Lenny’s product pass
One New Term at a Time - RSI - Recursive self-improvement
#1 - Leadership Principles in the Age of AI
Security as an innovation enabler
A new definition of CISO
Spring is event season in Stockholm. Every day, and every afternoon there is a conference, a hackathon, a meetup, an afterwork. It’s a great opportunity to learn, to meet new people, and to hear new ideas.
Last week I attended an Miro’s Midsommar Drinks: Team AI-mplification. We heard from two startup founders who got acquired by Miro - Jakob Knutzen (Butter co-founder) and Florian van Schreven (co-founder Uizard), and from two leaders and H&M and Postnord, on how Miro and specifically its AI features are enabling faster innovation. But the most interesting for me were the conversation I had and the session with Mark Strande - Miro’s CISO. We shared many perspectives- for example the innovation principles he took with him from his time at Klarna, which are very much built on Amazon Working Backwards methodology,
But the most interesting observation he made was how he sees the new definition of CISO as Chief Innovation and Security Officer. He is asking himself and his team - how can we make all other team able to move and innovate faster. He goes further and models this innovate behavior by experimenting and building prototypes to to accelerate solutions.
So how can you do that?
How can you both push for innovation AND keep your security posture strong? Miro works with many enterprise and public sector customers, and obviously must have high security standards. The leadership principle that comes to mind is Insist on the Highest Standards, which read as follows:
Leaders have relentlessly high standards - many people may think these standards are unreasonably high. Leaders are continually raising the bar and drive their teams to deliver high quality products, services, and processes. Leaders ensure that defects do not get sent down the line and that problems are fixed so they stay fixed.
Specifically - the line about “deliver high quality products, services, and processes” is the mindset which can help security leaders and security teams enable fast and safe innovation. This is a time for CISOs to rethink their role and their ways of working, and to build new mechanisms that accelerate innovation. I have been using Miro with customer for some time now, and can testify that I have seen their pace of innovation grow tremendously, even as they introduce more and more AI features and capabilities. I’ve mentioned their Miro AI back in November 2025, but since they keep introducing more and more, and now I understand better how they do it.
A new security and innovation mindset
The chat with Sounil Yu, CISO and Head of Research at JupiterOne, provides some good ideas on how to have a innovation enabler mindset. He explains that as a security function you can reduce vulnerability, threat, or impact, and that previously we used to focus on the first two ones, but now you should focus more on reducing impact. The metaphor he suggest that rather the putting locks on a car, we should allow people to drive faster by putting breaks on a car.
He further demonstrates how to weave innovation thinking into security by applying the SIT (Systematic Inventive Thinking) methodology to security with methods such as subtraction, multiplication, and division. I really like listening to that part, as SIT has been a major asset in my innovation toolbox for many years.
Your action step
If you are in a role responsible for security in your organization, start establishing new mechanisms that focus more on reducing the impact of security incidents, and not just on reducing vulnerability.
If you are a functional leader or a CEO that needs your CISO to be more of an innovation enabler, open up the conversation with them on how you might do that together. Offer a security and innovation workshop or hackathon to explore new enabling technologies, so that you may increase velocity dramatically.
#2 - Business Value with AI
Executives vibe coding
More than 6 months, in issue 6, I mentioned the term Vibe Coding. Originally I was teaching vibe coding when working with product teams, subject matter experts and functional team who wanted. In the past few weeks I have had more and more sessions with executives on vibe coding, its implications, and actual hands-on and tips for the executives themselves to try it out. As one of the CEOs told me as we were planning this session for his leadership team - “Building is believing”.
Although I have already vibe-coded live production apps such as Castifai, Jazz in Stockholm, and others, I will not focus on those right now. Instead, I want to highlight the immediate things you and your team can use vibe coding for in a relatively simple way, to grab some lower-hanging fruit.
How to create business value with vibe coding?
Three immediate use cases for vibe coding in an organization include the following:
Prototyping: now you don’t need to make hard choices about which ideas to invest development resources in for getting a prototype in front of users so you can test your assumptions. Tools such as Base44, Lovable, and a bunch more, allow product managers, individuals and even CISOs and other executives to spin up prototypes quickly so they can get early input and feedback - before investing scarse resources into building a production-ready application
Internal workflows: if you have been following this newsletter for some time, you should recall one of the three buckets of creating value with AI as boosting productivity. Vibe coding allows us to create AI-generated and AI-powered applications that connect to different systems, are custom-built for our unique team’s or industry requirements, and remove the dependency and pressure on IT to create and support them. Essentially lowering the threshold for solving business problems.
Customer-facing applications: sometime there are business needs for customer-facing applications that we never had time or budget to create. These might be a launch of short-lived campaign landing pages, or information regarding an event. Now the functional team and subject matter expert can create these solutions with ease, by just “asking” the vibe coding tool for what they need. Yes - there should be some security and privacy considerations and guardrails, and whoever builds these should get some essential principles and training, but that is again an opportunity to enable, increase velocity and impact, and distribute value creation.
Maor Shlomo, the founder and CEO of Base44, recently shared how they are using this more and more internally - “We keep allocating more and more talent to a role we call "internal builders" – people whose entire job is building internal tools for the team. This makes the gap between "we should pay for this" and "just build it" shrink.”
So what’s the role of our software engineers?
Andrej Karpathy, who coined the term “vibe-coding” has highlighted the implications of this becoming a more common practice of everyday operations, and what is the new role of experienced software engineers in light of that. According to him - they are responsible for “preserving the quality bar in terms of what existied before in professional software, How do we go faster – properly”. Very much like the role of a CISO enabling others to innovate quickly, at scale, while maintaining high standards.
Twitch is an Amazon subsidiary. In the video below, Lauren Kearney, Director of Product there, shares how she is using vibe coding for prototyping. This was especially interesting for me to see, as someone who has led the innovation program at Amazaon Web Services, where writing a PRFAQ document was a key requirement BEFORE writing any line of code. Now an Amazon Director of Products is saying that this is flipping, and that you should create the prototype before writing the doc!
The video includes other valuable advice and insights, similar to things that I share in my sessions, such as that tools matter less than the vibe-coding loop. Tools keep evolving, but we should be establishing new ways of working that apply to any vibe coding tool we happen to have access to.
Your action items
First of all, if you haven’t built with a vibe coding tools in the past 3 months, I urge you to do it right now. Select a subject that you care about. If you are constrained to not use any business-related data or process, take on a project that is important to you personally - such as renovating you house, or building something to help you manage your diet, sports, or your personal finances. You will discover the potential, the challenges, the depth and speed that these tools now enable. You will also appreciate that this is a skill and a mindset that needs to be built for more and more people in your organization.
And maybe more importantly, start to observe and note how this is changes your approach to the value of software - can you now see this as a highly personalized application with a customer-audience of one? is it ok to build throwaway solutions that are only built to last a month or a week? what if you built 5 versions of a solution to the same problem in parallel and did A/B/C/D/E testing to gain learning and feedback?
#3 - AI Tool Spotlight: Lenny’s Product Pass
A cherry on top of the podcast
I have included episodes of Lenny’s podcast in previous issues. It is one of the best product focused podcasts out there. And recently in issue 28, I also mentioned Lennybot as a use case for an AI-powered tools. Now I want to highlight something else of great value to Lenny’s newsletter subscribers.
If you subscribe to Lenny’s newsletter for an annual subscription, you get a package of access to multiple great products for one year, that would otherwise cost you thousands of dollars. I subscribed, and this give me access to tools such as Notion, Granola, Railway, Replit, Gamma, Lovable, Canva, Cursor and several more. If you are experimenting with AI, not only is the newsletter a great value, but the product pass is a cherry on top of that.
Below are a couple of videos on getting the most out of the product pass. To subscribe to Lenny’s newsletter, go here.
and here’s part 2:
#4 - One New Term at a Time: RSI
This week’s term: RSI or Recursive Self-Improvement - the point at which AI systems can design and build their own successors with little or no human involvement, creating a loop where each generation of AI accelerates the development of the next. In the past few weeks, RSI moved to the center of the AI industry’s agenda.
On June 4, Anthropic published a paper called “When AI Builds Itself,” arguing that RSI “could come sooner than most institutions are prepared for”. The evidence comes from their own operations: Claude now writes more than 80% of the code merged into Anthropic’s systems, up from low single digits before Claude Code launched in early 2025, and their engineers ship roughly eight times more code per quarter than they did a few years ago.
OpenAI has gone further and put dates on it. The company set internal goals of an automated AI “research intern” by September 2026 and a fully automated AI researcher by March 2028.
We are not there yet. Researchers like Helen Toner of Georgetown’s CSET point out that engineers using AI heavily is different from classic RSI, where no humans are needed at all. Today’s models still struggle with exactly what a closed loop requires: self-direction, judgment, and managing ambiguous, week-long tasks. But we are getting closer and closer.
The Business Implications
You don’t run an AI lab. But every AI plan you make rests on an assumption about how fast capabilities will improve. Even partial automation of AI research compresses the time between model generations. That means any strategy built on “AI can’t do this yet” will have a short expiry date than you expected.
The key point is that you don’t need to believe in an intelligence explosion or RSI. The pace of change becomes the one assumption in your plans you should revisit most often.
See Matt Baxter’s 15-minute non-technical explainer on how RSI works as a feedback loop and why it could lead to an intelligence explosion.
Think Big Newsletter is written by Amir Elion of Think Big Leaders -


