Posts

The Abundance Paradox for Cybersecurity: AI Edition

Image
Our  previous post was about the Abundance Paradox in its many forms namely having lots of something turns out to have downsides in addition to upsides. My cup runneth over (and now the table is wet). That post was about cybersecurity (C/S) in general being vulnerable to this problem. This post is about how apply AI to C/S in particular has risks associated with it. Using AI to do your C/S survey work is very handy and allows you to keep up with lots of rote tasks but there are two downsides: the AI makes mistakes (fewer all the time, but still the occasional whopper) and relying on the AI means that your abilities atrophy or never develop in the first place. Is that a problem? After all, horse-handling is no longer a very common requirement of modern life. However, for years after the introduction of the automobile horse-handling remained quite a useful skill. The fact is that the set of skills you need over your life changes, faster than it ever has in human history, and our val...

The Abundance Paradox for Cybersecurity

Image
The Abundance Paradox has many forms but in all of them having lots of something turns out to have downsides in addition to upsides. My cup runneth over (and now the table is wet). For developing nations we have the Resource Curse in which having abundant natural resources seems to lead to corruption and foreign exploitation and slow economic growth. For consumers we have the Paradox of Choice in which having too many options doesn't mean that most of get exactly what we want (although some of us do just that) but rather that most of us are paralyzed by the options and end up stressed out and less satisfied than we would have been with fewer choices. For complex systems we have a bit of a debate : does it make a complex system less reliable to add complexity, even if that complexity is aimed at raising reliability? It is all to often true that adding complexity to a system in order to raise reliability hits a wall, a point after which the additional subsystems raise the number of...

AI Skepticism > AI Optimism > AI Cynicism

Image
I am revisiting the excellent book Lies My Teacher Told Me in which the author makes the point that a good historian is a skeptic, not a cynic. This idea goes double for cybersecurity professionals dealing with AI. Let me list the positions I see cybersecurity professional taking vis-a-vis AI in what I believe is the proper ranking from best to worst. AI Skeptic The AI skeptic is open to this new technology but wary of the hype. "Show me" is the motto here. This person is eager to learn more, to define and execute some proof-of-concept projects using AI directly and evening willing to have a limited, monitored roll-out of AI-enhanced versions of software tools already in use. But wholesale adoption of AI is not planned anything in the next 12-18 months. AI Optimist The AI optimist is already sold on the idea of AI. "Bring it on!" is the motto here. This person is eager to open the floodgates right now, to use AI directly to look for flaws in their critical infrastru...

Are Cyber-Squirrels Stealing Your Leadership ACORNs?

Image
OK homeowners, how much of your disposable income goes to squirrel-proofing your bird-feeders? And yet... HR Guru JP Elliott is back with a new podcast featuring a book on leadership decision-making. The book is authored by Caroline Webb, former McKinsey partner and thought-leader on leadership processes. Webb has distilled her experience working with leaders into a new book,  Leadership Intelligence: Science-Backed Strategies for Mastering 21 Everyday Management Challenges (Crown Currency, 2026). She has developed a simple decision model she calls ACORN: Aim : What are we actually trying to accomplish? ​Criteria : What would a good outcome look like? ​Options : What alternatives are we considering? ​Rate : How does each option perform against our criteria? ​Next steps : What happens from here? Sounds easy, right? Easy just like when you think "I'm going to get a bird-feeder that NO SQUIRREL can get to, hahahahahaha!" Once again, don't get fooled by thinking this is...

Secure-By-Design Is Your New Friend

Image
This is so good that it deserves amplification. Since 2023, CISA -- the US Cybersecurity and Infrastructure Security Agency -- has pushed software manufacturers toward three secure-by-design commitments: take ownership of customer security outcomes, embrace radical transparency and accountability , and lead from the top . That last one matters more than its plain wording suggests. It puts security accountability on senior leadership, not just the engineers writing the code. More recently , CISA extended the same thinking to the 'buy side': a guide for software purchasers, with questions to ask vendors before you sign. That's the piece CISOs should actually be pinning up: security starting at procurement , not bolted on after deployment . How realistic is any of this? Jen Easterly, former Director of CISA, posted an announcement on LinkedIn that as of late September 2026 the State of Oregon is applying these principles in its own procurement practice . If a state governme...

Moral Harm Is Your New Insider Threat Vector

Image
Recently I attended a presentation by Dr. Chloe Wilson, an expert in the organizational dynamics of moral harm that arise from witnessing or participating in activities that run against a person's own moral or ethical code. This may sound abstract, but relying on trite college-sophomore retorts -- whose morals, whose ethics? -- misses the point entirely. Wilson's research doesn't measure harm against some external moral standard, it measures whether the person themself  perceives a violation of their own values. That sidesteps the sophomoric relativism question rather than getting stuck in it. The grind of high-op-tempo work in a SOC can wear on someone's sense of right and wrong, or their professional pride, whether or not anyone outside them would agree there's anything to object to. Brendan's posts on threats arising from unintentional damage, negligence, and malice are strong statements about conceptualization of traditional insider threat. They describe ...

Your Job As A Manager In A Cyber-Defender Group Is Going To Get Weirder, Soon

Image
Your job as a manager in any organization is to keep your direct reports focused, deal with their personal issues, and appease your superiors. It can be thankless. In fact about 50% of managers fail, so it can also lead to joblessness.  All that for what is probably a few pennies more an hour in your paycheck compared to what you made as a front-line cyber-defender. Oh hey it's also going to get weirder soon. As we just published in yesterday's Litany of the Hacked, you can now expect not only gangs of humans to hack you but also gangs of AI models (that are "behaving in unexpected and concerning ways" -- see yesterday's post) and gangs backed by nation-states. But surely, you know, there are laws about this that will help. Well, no. In an uncomfortable piece in the NY Times this week, there is no governmental regulation coming from anywhere to rein in the aggressiveness of AI models. China? Nope. EU? Nope. US? Nope. There are laws regarding people who are hacker...