Posts

Moral Harm Is Your New Insider Threat Vector

Image
Recently I attended a presentation by Dr. Chloe Wilson, an expert in the organizational dynamics of moral harm that arise from witnessing or participating in activities that run against a person's own moral or ethical code. This may sound abstract, but relying on trite college-sophomore retorts -- whose morals, whose ethics? -- misses the point entirely. Wilson's research doesn't measure harm against some external moral standard, it measures whether the person themself  perceives a violation of their own values. That sidesteps the sophomoric relativism question rather than getting stuck in it. The grind of high-op-tempo work in a SOC can wear on someone's sense of right and wrong, or their professional pride, whether or not anyone outside them would agree there's anything to object to. Brendan's posts on threats arising from unintentional damage, negligence, and malice are strong statements about conceptualization of traditional insider threat. They describe ...

Your Job As A Manager In A Cyber-Defender Group Is Going To Get Weirder, Soon

Image
Your job as a manager in any organization is to keep your direct reports focused, deal with their personal issues, and appease your superiors. It can be thankless. In fact about 50% of managers fail, so it can also lead to joblessness.  All that for what is probably a few pennies more an hour in your paycheck compared to what you made as a front-line cyber-defender. Oh hey it's also going to get weirder soon. As we just published in yesterday's Litany of the Hacked, you can now expect not only gangs of humans to hack you but also gangs of AI models (that are "behaving in unexpected and concerning ways" -- see yesterday's post) and gangs backed by nation-states. But surely, you know, there are laws about this that will help. Well, no. In an uncomfortable piece in the NY Times this week, there is no governmental regulation coming from anywhere to rein in the aggressiveness of AI models. China? Nope. EU? Nope. US? Nope. There are laws regarding people who are hacker...

Litany Of The Hacked: September 2026 Wrap-Up

Image
Ah yes friends, it's that time. Welcome to the litany of the hacked, September 2026 edition. There is so much noise, so much static, so little information about how AI is going to rip the guts of your SOC apart. Oh wait, maybe you have an AI SOC and then it will rip apart the guts of an attacking AI. Um, er, hold on, maybe the AIs will conspire to attack you. Or them. Who knows. Our point is not shame, but to create shared awareness to pool resources where possible and build a sense of community. Thus, the litany now includes: the FBI...Springfield (MA) Public Schools...city government of Winona, MN...Anne Arundel (MD) Medical Centers...City of Berlin...Novocure... Manchester, London Stansted and East Midlands airports ...Pixel 6 phone systems...Chrome...Microsoft Exchange...State of Florida Department of Motor Vehicles...Liquid Network...Thomson Reuters...Eagle Mountain, UT...International Meteor Union...government of the United Arab Emirates (by Iran)...AT&T in north Texas (...

If You're "Indispensable" Does That Make You "Unpromotable?

Image
High performers are difficult to find and, well, can be difficult to manage. They challenge managers to improve their own performance management skills. They out-perform, by definition, their peers. And they know it, and they expect whatever "recognition" means to them. One of the hardest skills to learn as a manager of a high-performer is how to end that person's career doing what they were doing so well so that the individual can move to a new position and contribute there. It's about taking people who were indispensable at one level and successfully promoting them. Why is this hard? Multiple reasons: 1. Being good at one set of challenges is not the same as being good at a higher-level set of challenges. The talents that made you excellent at the current level (execution, individual output, mastery of a defined problem) aren't the same traits the new level tests (ambiguity, influence, developing people instead of doing the work yourself). At the very least, tha...

'Moneyball' Your Career

Image
Who knew that eventually Brad Pitt would end up in our blog series? Other than, of course he did. In the CISO Tradecraft® piece we've been touting recently there's a section we haven't touched yet: their case that aspiring leaders should apply ' Moneyball '-style statistics to their own careers. The point is that you're rarely promoted purely on your own merits, you're selected against whoever else happens to be in the room . Sometimes the deciding factor isn't your strength, it's the field's weakness. That's a useful, slightly uncomfortable idea, and it connects to something we've argued in this space before : climbing and performing are not the same test. Moneyball makes that concrete. If promotion decisions are relative then "I'm ready" was never the whole question. "Ready relative to who else is being considered, using what criteria, at what level" is the actual question. If that feels off-putting, CISO Tradec...

How To Build A Security Culture

Image
In my previous post I made the case for building a security culture instead of a leadership culture. The goal of a security culture is to bring all employees and business units, or as many as possible, into the mindset of balancing risks, understanding and supporting trade-offs, and thus enabling performance that relies on a positive view of cybersecurity instead of cybersecurity rituals. So, you may ask, how does that happen? A good place to start is in the CISO Tradecraft® piece we mentioned entitled " How to create a leadership culture ." The trick is that you need to focus on security culture, not leadership (or worse, leader) culture.  Here are six approaches that work: Master your communication about security . Tell us why, and then you can tell us how as long as we understand why. How does your program stack up against peers? If your program stinks, how does your proposed security culture move the needle? If it's good, how does your proposed security culture ena...

Security Culture > Leadership Culture

Image
The good people at CISO Tradecraft® recently published a piece entitled " How to create a leadership culture ." Since this veers directly into our typical behavioral cybersecurity lane, we thought it was worth reviewing. The start is promising: "In the high-stakes world of cybersecurity, many organizations mistake “security theater”, the endless checklists, mandatory slide decks, and annual compliance box-checking, for actual security. But security isn’t a checklist; it’s a force field. And that force field is generated by your organizational culture." Great! Indeed, culture is a "force field" as we endorse this view. Thank you CISO Tradecraft! But then we diverge.  Effective behavioral cybersecurity is not about a "leadership culture" per se, it's about creating a security culture . Here's the distinction. A security culture is a force field because culture governs what behavior gets tolerated among and between team members. When behavio...