Posts

Why Is Filling Cybersecurity Roles So Hard?

Image
It is not your imagination. You are not unlucky. Hiring people for cybersecurity jobs often involves more risk and less reward than other kinds of recruiting. Frequently the cost, in time and effort, is higher and the reward, performance and tenure, is lower. There are many reasons for this. For one thing, most executives outside of cybersecurity don't know much about the field. It is a rare executive who isn't at least broadly familiar with finance, accounting, marketing and sales. It is a rare executive who is familiar with cybersecurity. You are likely not very familiar with the practice of cybersecurity because it is a relative newcomer to the C-Suite for most industries. The need has exploded. This means that there are too many openings chasing too few qualified applicants which has resulted in most of us having to settle for less than ideal candidates. Settling for less than ideal candidates means having to use proxies and guesswork instead of the tried-and-true pillars o...

Which Is Your Better Self At Work: Smoked Or Pulled?

Image
Tomas Chamorro-Premuzic is back at it in a new piece about " bringing your whole self to work ."  As a cybersecurity leader, your priority is managing risks by getting the most out of your team. AI is going to smoke you like a brisket if you think it will be business as usual once you integrate AI across the organization. Instead, you need your people to be engaged, one of the four pillars of a successful cyber-defense team . But what is employee engagement, and how do I get people to buy into that? A shift in management culture starting in the '00s emphasized employee engagement as the key to business-unit productivity. I might have had something to do with that shift . An outgrowth of the shift was the idea that people who were able to be fully present at work would be more productive or happier. And certainly from a societal perspective this makes sense. Employees are not as worried as they used to be about whether they will be accepted without being strictly "nor...

Your Organization's AI Is Going To Change Your Cybersecurity's AI

Image
Our remit in behavioral cybersecurity is to focus you on what's actually under your control. That's how you manage risk in your own career and through your cybersecurity program. The most basic thing you control is your attention. Every culture encodes this in its language: you focus attention, you pay attention, you make attention. It's a limited resource. Managing it is a form of risk management. That's why a recent post from Microsoft's Jaime Teevan, Seven Predictions , is worth your team's time. She maps out how AI is about to change the shape of work itself. All of her points are interesting, though three in particular struck us as having cybersecurity implications.  We'd add one thing she doesn't say directly: each of these shifts is also an invitation for the AI-SOC function to integrate across the enterprise, rather than sit off to the side as a standalone process. Each prediction changes what you're responsible for protecting. Here's how...

Put It All On Green

Image
What if you could find the qualities you were looking for among your candidates faster and better? And  what if that also saved you some money and time? As a hiring manager you're always on the look-out for new talent. Or at least that's what you say you're looking for. Really, if we're being honest, you need to hire someone as a back-fill and you have a process that involves multiple weeks -- a month, maybe -- of resume review, interviews with different panels from different levels of the organization, and if you're on your game you have a technical interview/skill demonstration of some sort. And then you deliberate. And a proportion of your candidates drop out of the process because, surprise, they got offers elsewhere in the meantime. And so you make an offer to the best remaining candidate -- you know, the one who for some reason wasn't hired by someone else -- and maybe they accept it. And then more time goes by before you onboard them as you do a backgroun...

The Utility of Attacking Utilities

Image
Disruptions of US water infrastructure have been in the news recently, which made us think of utilities in general. Utilities in general (water, electricity, natural gas) are often targets of military hacking as opposed to criminal hacking, which made us think of how much we emphasize one (criminal) and minimize the other (military). Let's get into that. The model we are used to is cyber crime, almost always in the form of being held for ransom by ransomware. In this scenario your systems are breached, then compromised, then a ransom demand is made. There is nothing subtle or covert about this process. The goal is immediate attention and payment. You don't have to wonder if you are being attacked. You cannot avoid knowing that you are being attacked. The military model is very different. Your adversary wants to know what they can do to you, but unless you are actually at war your adversary may not want you to know that they know. There will be no alarm bells. There will be mini...

Our Version of Behavioral Cybersecurity

Image
Pythia Cyber applies behavioral science to cybersecurity to make cybersecurity more effective. But our take is slightly different from the common definition of "behavioral cybersecurity." How are we different? Let's first review what Google's AI summary tells us about "behavioral cybersecurity" which is a decent summary of the common definition: AI Overview Behavioral cybersecurity focuses on human actions and system patterns to stop threats. It covers two main areas: behavioral analytics for threat detection and behavior-oriented training for human habits. Behavioral Analytics (Systems and Data) Baseline creation: Software learns normal user or device actions. Anomaly detection: Flags strange login times or unusual data transfers. Insider threats: Catches stolen accounts moving through a network. Signature bypass: Finds new or unknown attacks that pass standard firewalls. Behavioral Training (The Human Factor) Habit focus: Replaces one-time compliance rules...

Beware The AI Productivity Trap

Image
Cybersecurity (C/S) is a branch of Risk Management, not of Computer Science (CS) or Information Technology (IT). At Pythia Cyber we spend way too much time making that point, mostly to executives who think that they can leave C/S to the IT folks. But C/S has a big component of applied technology which has led to a long and complicated history of IT techniques and technologies trickling down from IT to C/S. So it is with AI: first AI was used to boost programmer productivity, then it was AI used to make people's emails easier to read and now it is used everywhere for everything all once. Specifically AI is being used in C/S for a number of functions. We are going to focus on "white hat" uses, in which people are trying to prevent cyber crime, as opposed to "black hat" uses in which people are trying to commit cyber crime. In the white hat world AI is being used to simulate attacks, probe for weaknesses, automate some monitoring tasks and keep abreast of new patch...