Posts

The Four Pillars Of A Successful Cyber-Defense Team In The Always-On Security Environment

Image
  As a CISO you need to be a technical leader, and an organizational leader, and a developer of yourself. And, you will fail if you don't build the best cyber-defense team for the always-on threat environment. This series has discussed resilience and adaptive capacity. There are no shortcuts to these in the always-on threat environment.  Building the cyber-defense team for an always-on threat environment requires a CISO who has the discipline to optimize team performance. There are four pillars of building the cyber-defense team you need: [Hiring for Talent × Structure × Engagement × Development] = Adaptive Capacity Two of these pillars, hiring and development, are the "TAU" Brendan introduced us to in March 2026. Pythia Cyber is the only company on the planet that has a cyber-talent assessment for hiring and development. The other two pillars, structure and engagement, are what we at Pythia Cyber consult with you about to unlock and focus your talent. The CISO is the ar...

Managing Your Security Function in the Always-On Security Environment: A Board Playbook

Image
  Boards often hire CISOs to "prevent breaches and maintain compliance." In always-on security environments, that's the wrong job description . The real job is: "Build a team that learns faster than the threat landscape changes." That requires you, the Board, to engage in different hiring, different measurement, different patience, and different incentives. You don't want to incentivize the wrong behaviors, and you definitely don't want to repeat past mistakes with cybersecurity leadership. Here are two models that sound the same, but they incentivize almost opposite behaviors. The Prevention Model (what Boards usually want): Minimize incidents through defensive posture Follow best-in-class frameworks (NIST, ISO, etc.) Measure : "Did we get breached? Are we compliant?" Reward : Avoiding bad things Risk tolerance : Low The Learning Model (what the always-on security environment requires): Detect novel threats fast, respond faster, extract lesso...

Managing Your Board In The Always-On Security Environment: A CISO Playbook

Image
Companies do not have unlimited resources to pay for things they want let alone what they need. Your cybersecurity program would seem to be both a want and a need. You're still under scrutiny. Look at it from their perspective. Their security team -- led by you -- comes to them quarterly and reports: "We detected 47,000 incidents this year." Their first thought: Are we safer? Or are we just seeing more because we're looking harder? That confusion is not your fault. The security conversation changed, but nobody told you. The Old Story (2020 and earlier) : "We implement NIST CSF, we maintain certifications, we have tools and processes. Result: controlled risk. Your breaches are unlikely." The New Story (through July 2026) : "We detect novel threats continuously. Some are malicious, most are not. We respond faster than competitors. Our team learns from each incident. Result: adaptive capacity. Some breaches are still possible, but we respond better than mo...

What Is Talent In The Always-On Security Environment?

Image
One thing the past month's burst of unanticipated/unintended AI intrusions by models from OpenAI and Anthropic shows is that we're in the always-on security environment. Cybersecurity has always been about being prepared for multiple unscheduled events, attacks, systems misuse, etc. But these were predictable attacks through predictable channels by predictable entities. Predictability gives you multiple benefits as a practitioner. First, you had a baseline knowledge of the threat surface and attack channels. Second, you could create bespoke processes or follow best-in-class processes such as the NIST CSF and be assured that you had a degree of security -- and you could explain that to your leadership. Third, your development path through the right 'elite' university and certifications and AI basics all made sense; maybe it was performative theater in a way but it was the right approach. None of that is true in the always-on security environment. In brief your attack sur...

Litany Of The Hacked: July 2026 Wrap-Up

Image
  Sing, o goddess, of the litany of the hacked from July 2026. Sure, we're keeping with the Homer theme, and yes we appreciate that the Anthropic product that 'launched a thousand ships' (+/-) was named Mythos.  Let's check the litany for this month. Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: Department of Education and police national legal database (both UK)...Fairlife Milk (a unit of Coca-Cola)...AssuranceAmerica...Greenfield Communications...Accenture Consulting...Homeland Security Information Network (HSIN)... In mitigation: one week later there is already a 'post-mortem' of the OpenAI/HuggingFace incident c/o Jen Easterly : https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem. We'll come back to that another time. But in aggravation (yep that again) Anthropic announced that one of its products also acted autonomously, though allegedly...

Rushing Is Insecure

Image
I recently did not take enough time to do something as securely as I should have. I was annoyed with myself when I realized that, not least because I realize that this is a pattern with me and one that I need to break. When the stakes are lower and time is shorter I sometimes rush to get a task off of my list, an email out of my inbox or a colleague off of my back. And the more I think about it the more I think that rushing is insecure. It is tempted to copy that file, email that file or hand off that file just to be done with it. It is probably fine. But I know, deep down, that consistency and care are vital to security. I know that it almost never makes sense to compromise just this once. (This is also a theme of a recent post of Ted's.) I offer this an answer to the question "what does Pythia Cyber mean by the 'behavioral element of cybersecurity?'" This is an example of human behavior being a critical part of cybersecurity. Cybersecurity is more than a protoc...

Is Your New AI-Based SOC Basically Elevator Music? And If It Is, What If You Change The Channel?

Image
Our friend Tomas Chamorro-Premuzic is back at it. He might not forgive Argentina, um, not winning the 2026 FIFA Men's WC Final, but he is here for us. His latest Substack post poses an interesting question:  Is AI Reducing Human Creativity to the Intellectual Equivalent of Elevator Music? In short his answer is Yes. (Along the way, Tomas discusses the history of Muzak, which apparently was founded in the 1930s in the service of capitalism: Music, executives discovered, could influence mood, reduce perceived waiting times, increase productivity, and even encourage people to spend more money. Art became environmental engineering. Leveraging the communication technologies of the time, from leased telephone lines to centrally distributed recordings and later inexpensive synthesizers and digital production, Muzak industrialized pleasantness. The objective was never to compose the next Gershwin concerto. It was to create a soundtrack that nobody would notice precisely because it never d...