Posts

Cybersecurity As Management Fuction Example: Ransomware

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. At least they pretend to be surprised. We suspect that they really want  C/S to be an IT function because then they  wouldn't have to take any responsibility for it. As we have written about before, part of this reluctance to embrace C/S comes from fear of the unknown: most managers and leaders are quite familiar with accounting, marketing, sales, legal and HR. They are not familiar with C/S. Part of this reluctance comes from fear of the scary way in which C/S is presented, as an arcane dark technological enterprise marrying crime and science. Hooded figures in the dark type away on black keyboards, surrounded by so many monitors, all of which have green text on a black background. As we will see in a subsequent post, this image is the result of laziness and fatigue. In this post we will give a counter example that any business person can understa...

Keeping You In The Race Every Day

Image
As a professional you are always in the race. The bad guys are running hard. Your competitors are innovating. You're getting bogged down in administrivia, your costs are soaring, and your fellow employees see you as the captain of the no-fun team. How do you keep your focus? We saw this piece, " The mile world record holder can teach you about more than just running ," recently on The Athletic (behind paywall). The story is about how Josh Kerr, who recently broke the men's world record time in the mile run at 3 minutes 42.66 seconds (which is nuts), keeps his head in the game. It seemed like something you could benefit from. One reason you could learn from Kerr is that his approach is simple, and simple is best, because you need to keep your head in the game too. 1. Write out your perfect day. That one caught my attention also. What about you? Are you able to write out what your perfect day is? (Presume we keep it in the realm of work- or profession-related.) Are you ...

Who Do You Trust More -- Your Dentist Or Your CISO?

Image
You probably have an appointment schedule with your dental office that gets you there every 6 months. The best case scenario is that these are routine cleaning appointments with 90 seconds of DDS time to tell you that yep everything still looks good. What happens when, well, things don't look so good but you don't have any tooth pain? Do you just do what the doctor says and get the treatment (for maybe thousands of dollars) because after all the doctor is a medical professional with very significant educational experience and credentials that need constant updating? Do you go dental practice shopping because you suspect that your current dentist wants to drill and bill? Do you trust your dentist? What about the CISO of the company you just invested in? Do you just do what the cyber-practice leader says and get the AI-based SOC (for maybe millions of dollars with constant upgrades) because after all the leader is a battle-tested professional with very significant educational exp...

Litany Of The Hacked: August 2026 Wrap-Up

Image
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.  Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities )...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens... We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly. Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is t...

Insider Threats Part 3: Malice

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice. This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. Malice is intentional. Once you determine that the incident was malicious your options become few and obvious: dismissal, criminal prosecution or one of those murky NDA-driven arrangements. If the incident was caused by someone on their way out the door then you have to balance the reputational cost of criminal prosecution with the deterrent effect or satisfaction or legal obligation. If the incident was not  caused by someone on their way out the door then their motives might not be easy to fathom. Unless you are in law enforcement it can be difficult to find out if someone recently received significant money or other considerations. Unless you are a trained mental health professional it can be difficult to un...

Insider Threats Part 2: Negligence

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with negligence you have to confront the fact that someone did not do what they were supposed to do. This isn't a matter of fine-tuning policy or clarifying procedure, as might be the case with Accidents. This is a case of a human failure rather than a human error. As such it falls more into the behavioral cybersecurity category than into the classic cybersecurity category. These...

Insider Threats, Part 1: Accidents

Image
This is the first in a series about the different kind of Insider Threats: Accidents, Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with accidents, the cause might be just very bad luck, which case what you learn is that sometimes bad things happen to good Cybersecurity Programs. The cause might be carelessness, in which case you need to determine if the person is chronically careless or if there was a some reasonable cause, such as the birth of one's first child. The cause might be a process or procedure whic...