Posts

The Circle of Cybersecurity

Image
Ted recently wrote about the pain of rewarding performance with promotion and the purported death of the entry-level CS job . This got me thinking about the actual CS jobs that I have seen in the wild.When looking at actual CS jobs, size matters so we will start with that dimension. Small Organizations In very small organizations there isn't a Cybersecurity Program (CSP) so much as there is a guy or gal in IT who moonlights as The Person Who Keeps Us From Doing Dumb Stuff. This is a part-time Cybersecurity Engineer (CSE) even if they don't call it that. There is no formal communication channel between leadership and the valiant part-time CSE. The disaster-recovery aspect of the job is folded into the system administration duties. Medium-Sized Organizations In medium-sized organizations you have a CSP with a few people in it, mostly refugees from IT who Secure The Network. This is often a supervisor and two helpers who sort of communicate with senior management on an ad hoc basi...

R.I.P. Entry-Level Cybersecurity Jobs?

Image
This is not the first or last time we will address the (alleged, purported, actual, imagined) demise of the entry-level job. That newbie fresh-out-of-college or right-out-of-the-military cyber-defender that had all the certs and none of the savvy? You might kiss it goodbye.  But in reality you're kissing that position description goodbye, not the role.  In brief we at Pythia Cyber think the nature of entry-level cybersecurity work will change but not disappear. Like any change process, its trajectory of change is unknowable; 5 years from now we will have a new labor force that arose from pressures we have now. Over at The Signal , Alex Banks is having all of the angst. These three nonconsecutive paragraphs tell his story: Nobody learns their trade in their first year. If you’re honest about your own, what you actually learn is a collection of many small micro-experiences that compound into a long list of intangibles that can rarely be named yet can only be sharpened through ...

Promotability & Performance -- If Only It Were That Simple

Image
Every security team has one: the analyst who triages faster than anyone else, the engineer who reads a packet capture like a second language, the threat hunter whose instincts catch what the tooling misses. When a leadership slot opens up, that person is the obvious pick. They're the strongest performer on the team. They are also, disproportionately, a bad bet for the management role, a specific kind of risk most security organizations aren't measuring. The reason is more precise than "not everyone is management material." Performance and potential are different psychological constructs, predicting different outcomes, and most security talent pipelines quietly collapse them into one. Here are five key points for you to remember in your review of performance v. potential. First point: climbing is not the same skill set as performing . Advancing in an organization and performing at higher/management levels draw on overlapping but distinct profiles. The people who get no...

Robot Performance Management Risks = f(Cybersecurity AI Agents, Human Risks)

Image
You have a performance review cycle for your SOC analysts. Goals, check-ins, regular conversations about what's working and what isn't. When someone stops performing, you notice, you document it, and eventually you do something about it. When did you last have that conversation about your AI agents? You're not alone if your honest answer is "never." If performance conversations with your human cyber-defenders already make you feel like it's time for a major medical procedure without enough anesthesia, adding one more with an agent sounds like the last thing you need. In a recent McKinsey Talks Talent episode, Kate Smaje put it plainly: most organizations can't recall the last time they prioritized a conversation about the performance of their nonhuman labor. We've built decades of infrastructure for managing human performance. For agents, most companies have nothing. That gap should worry a CISO more than almost anyone else in the building. Smaje make...

You & The CFO: A Risk Management Partnership

Image
Brendan has written a lot lately on cybersecurity as risk management. Another person in your organization who manages risk is the Chief Financial Officer (CFO). Is there any ovelap? Your CFO is supposed to keep the company's books straight and tell the board when something doesn't add up. Now imagine telling that same CFO: also, go adopt the new accounting software company-wide, use it yourself for the close, and be the one who catches it when it's wrong. That's roughly the position CFOs are in with AI according to Deloitte's Q2 2026 CFO Signals survey . More than half of CFOs are using AI for financial planning and budgeting. Forty-one percent use it to analyze financial data. Yet only 43% say they're very confident in their organization's AI governance framework. Most land at "somewhat confident," which is a polite way of saying "we haven't stress-tested this," which is even more polite than "I have no idea." As a CISO you...

How to Describe Cybersecurity: Bottom Up vs Top Down

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. After we explain how C/S isn't an IT function , they often ask "then why it is always presented to us as an IT function?" The answer is pretty simple: because most explanations use the bottom up approach. Those explanations work backwards from foiling an on-going cyberattack by showing an evil hacker in his lair and contrasting that with our heroes at their desks, heroically typing away to thwart evil in real-time. This image is ridiculous but in an understandable way: this image is visual, which suits film and TV. This image compresses the time-scale, which suits film and TV. This image gives us a nice symmetry of evil versus good. Of course this image is grossly simplified, as so many images are. We show teaching as the act of standing up in front of a class and talking or writing on the whiteboard. Anyone who has ever known a teacher kn...

Cybersecurity As Management Fuction Example: Ransomware

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. At least they pretend to be surprised. We suspect that they really want  C/S to be an IT function because then they  wouldn't have to take any responsibility for it. As we have written about before, part of this reluctance to embrace C/S comes from fear of the unknown: most managers and leaders are quite familiar with accounting, marketing, sales, legal and HR. They are not familiar with C/S. Part of this reluctance comes from fear of the scary way in which C/S is presented, as an arcane dark technological enterprise marrying crime and science. Hooded figures in the dark type away on black keyboards, surrounded by so many monitors, all of which have green text on a black background. As we will see in a subsequent post, this image is the result of laziness and fatigue. In this post we will give a counter example that any business person can understa...