Posts

How To Build A Security Culture

Image
In my previous post I made the case for building a security culture instead of a leadership culture. The goal of a security culture is to bring all employees and business units, or as many as possible, into the mindset of balancing risks, understanding and supporting trade-offs, and thus enabling performance that relies on a positive view of cybersecurity instead of cybersecurity rituals. So, you may ask, how does that happen? A good place to start is in the CISO Tradecraft® piece we mentioned entitled " How to create a leadership culture ." The trick is that you need to focus on security culture, not leadership (or worse, leader) culture.  Here are six approaches that work: Master your communication about security . Tell us why, and then you can tell us how as long as we understand why. How does your program stack up against peers? If your program stinks, how does your proposed security culture move the needle? If it's good, how does your proposed security culture ena...

Security Culture > Leadership Culture

Image
The good people at CISO Tradecraft® recently published a piece entitled " How to create a leadership culture ." Since this veers directly into our typical behavioral cybersecurity lane, we thought it was worth reviewing. The start is promising: "In the high-stakes world of cybersecurity, many organizations mistake “security theater”, the endless checklists, mandatory slide decks, and annual compliance box-checking, for actual security. But security isn’t a checklist; it’s a force field. And that force field is generated by your organizational culture." Great! Indeed, culture is a "force field" as we endorse this view. Thank you CISO Tradecraft! But then we diverge.  Effective behavioral cybersecurity is not about a "leadership culture" per se, it's about creating a security culture . Here's the distinction. A security culture is a force field because culture governs what behavior gets tolerated among and between team members. When behavio...

AI in Cybersecurity: Matching the Pump and the Pipes

Image
AI & Plumbing Systems Integration  In my youth I worked as a plumber's helper for a short while. This experience taught me the difference between being smart and being experienced. I was very much smarter than my boss but my boss was very much better at plumbing. Talent is a thing. Motivation is a thing. Experience is a thing. All of these things are important and all of these things come in varying degrees in the form of human beings. Or AI agents. Back to my experience as a plumber's helper. On the plus side, not only was I being humbled about the relative value of expertise and intelligence, I also spent lots of time thinking about dynamic systems so this brief employment was quite helpful when I moved into distributed information systems and then into cybersecurity. A key principle in either domain is that systems are interactive: their parts work together. This is little benefit in putting a giant V8 engine in your VW bug. There is likely great harm in raising the wate...

The View From Above: Sweeping & Undetailed

Image
I have been watching a CEO replace their director of technology and this CEO is making a very common mistake with hiring technology people in general and cybersecurity people in particular. That mistake is putting too high a value on what the CEO knows and too low a value on what the CEO does not know. In my experience it is natural for there to be detail gradient from C-Suite to worker bee. Like this illustration, the level of detail is different at every level of the organization. The highest level tends to be almost devoid of operational detail. The lowest level tends to be saturated with it. This state of affairs can lead to an unfortunate and often unconscious bias that the operational details don't matter. The higher up you go, the less people at that level had to deal with them. This can lead higher ups to feel that the details are not only unimportant, but a problem, since they must see the forest and not the trees. In most cases this generalization is inaccurate to an acce...

Is Your Program "The Standard"?

Image
"We are the standard." Thus spoke Breanna Stewart on 13 September 2026 after Team US beat Team France in FIBA Women's Basketball World Cup, 97 - 79.  Team USA has not lost a game since the semi-finals of this tournament in 2006. Read that again: Team USA has not lost a game since the semi-finals of this tournament in 2006 . "We are the standard," Ms Stewart, tournament MVP, said. It's a moral victory for other teams to come within 20 points of Team USA in international basketball, so, hooray Les Bleues . What about your cybersecurity function? Is it 'the standard'? If not, why not? Sorry to ask an uncomfortable question but you need to be clear-eyed about this. Everyone understands that you have budget realities, leading to competition for resources. Your team may be still forming, maybe there are lots of organizational dynamics. All of that is real. And so, is your program the standard?  Let's say it's not the standard. Do you benchmark agai...

The Circle of Cybersecurity: Managers to Leaders

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Mangers to Leaders. That arrow is labelled "Status" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Status Like "evidence," "status" is a concept we all think we understand until we need to define it. One of the big steps in implementing a good CSP is agreeing on the compromise that is status. There is always compromise because there are limits to what the evidence the Managers have been given and there are limits on what the Leaders can comprehend and absorb. One colleague of mine once joked that "boardroom reports...

The Circle of Cybersecurity: CSEs to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Cybersecurity Engineers (CSEs), the folks on the front lines, to Managers. That arrow is labelled "Evidence" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Evidence In most social situations demanding proof that people are doing what they said they would do is rather rude. This taboo has lead to a dismaying number of CSPs being "faith-based" by which I mean that Managers have faith in their CSEs and assume that all is well unless and until something goes wrong. Alas, politeness is not what is needed in an effective CSP. In cyberse...