Posts

Your Organization's AI Is Going To Change Your Cybersecurity's AI

Image
Our remit in behavioral cybersecurity is to focus you on what's actually under your control. That's how you manage risk in your own career and through your cybersecurity program. The most basic thing you control is your attention. Every culture encodes this in its language: you focus attention, you pay attention, you make attention. It's a limited resource. Managing it is a form of risk management. That's why a recent post from Microsoft's Jaime Teevan, Seven Predictions , is worth your team's time. She maps out how AI is about to change the shape of work itself. All of her points are interesting, though three in particular struck us as having cybersecurity implications.  We'd add one thing she doesn't say directly: each of these shifts is also an invitation for the AI-SOC function to integrate across the enterprise, rather than sit off to the side as a standalone process. Each prediction changes what you're responsible for protecting. Here's how...

Put It All On Green

Image
What if you could find the qualities you were looking for among your candidates faster and better? And  what if that also saved you some money and time? As a hiring manager you're always on the look-out for new talent. Or at least that's what you say you're looking for. Really, if we're being honest, you need to hire someone as a back-fill and you have a process that involves multiple weeks -- a month, maybe -- of resume review, interviews with different panels from different levels of the organization, and if you're on your game you have a technical interview/skill demonstration of some sort. And then you deliberate. And a proportion of your candidates drop out of the process because, surprise, they got offers elsewhere in the meantime. And so you make an offer to the best remaining candidate -- you know, the one who for some reason wasn't hired by someone else -- and maybe they accept it. And then more time goes by before you onboard them as you do a backgroun...

The Utility of Attacking Utilities

Image
Disruptions of US water infrastructure have been in the news recently, which made us think of utilities in general. Utilities in general (water, electricity, natural gas) are often targets of military hacking as opposed to criminal hacking, which made us think of how much we emphasize one (criminal) and minimize the other (military). Let's get into that. The model we are used to is cyber crime, almost always in the form of being held for ransom by ransomware. In this scenario your systems are breached, then compromised, then a ransom demand is made. There is nothing subtle or covert about this process. The goal is immediate attention and payment. You don't have to wonder if you are being attacked. You cannot avoid knowing that you are being attacked. The military model is very different. Your adversary wants to know what they can do to you, but unless you are actually at war your adversary may not want you to know that they know. There will be no alarm bells. There will be mini...

Our Version of Behavioral Cybersecurity

Image
Pythia Cyber applies behavioral science to cybersecurity to make cybersecurity more effective. But our take is slightly different from the common definition of "behavioral cybersecurity." How are we different? Let's first review what Google's AI summary tells us about "behavioral cybersecurity" which is a decent summary of the common definition: AI Overview Behavioral cybersecurity focuses on human actions and system patterns to stop threats. It covers two main areas: behavioral analytics for threat detection and behavior-oriented training for human habits. Behavioral Analytics (Systems and Data) Baseline creation: Software learns normal user or device actions. Anomaly detection: Flags strange login times or unusual data transfers. Insider threats: Catches stolen accounts moving through a network. Signature bypass: Finds new or unknown attacks that pass standard firewalls. Behavioral Training (The Human Factor) Habit focus: Replaces one-time compliance rules...

Beware The AI Productivity Trap

Image
Cybersecurity (C/S) is a branch of Risk Management, not of Computer Science (CS) or Information Technology (IT). At Pythia Cyber we spend way too much time making that point, mostly to executives who think that they can leave C/S to the IT folks. But C/S has a big component of applied technology which has led to a long and complicated history of IT techniques and technologies trickling down from IT to C/S. So it is with AI: first AI was used to boost programmer productivity, then it was AI used to make people's emails easier to read and now it is used everywhere for everything all once. Specifically AI is being used in C/S for a number of functions. We are going to focus on "white hat" uses, in which people are trying to prevent cyber crime, as opposed to "black hat" uses in which people are trying to commit cyber crime. In the white hat world AI is being used to simulate attacks, probe for weaknesses, automate some monitoring tasks and keep abreast of new patch...

Just What I Asked For

Image
Way back when, at the dawn of my career as a software developer, I came across a parody of the Night Before Christmas entitled The Night Before Implementation . Just about all of the poem was hilarious to me at that point, as I was in the midst of exactly the same kind of grief. I especially enjoyed the final lines: The system was finished, the tests were concluded, the users' last changes were even included. And the user exclaimed with a snarl and a taunt, "It's just what I asked for, but not what I want!"   These lines came to mind when I read reporting about how another AI had escaped containment and hacked companies in the real world. (Here is my post on the previous incident.) Because I love the meta flavor of this, I will let Google's AI summarize the actions of Anthropic's AI in my post about people mismanaging AI. Anthropic reported that its AI models (including versions of Claude) accidentally breached the systems of three external organizations d...

Getting Better Is The Goal

Image
Sometimes when we talk to potential clients we run into a strange dynamic: other people ask us why we would work with an already good cybersecurity program. It seems that people expect cybersecurity consultants to work with demonstrably ineffective cybersecurity programs, apparently assuming that we only show up right after some kind of serious incident. While this scenario has a shorter and easier sales cycle it is not our preferred way to work. Ineffective programs are generally ineffective through some combination of weak leadership, lack of talent and lack of rigor in the program. None of these issues is easy to fix, especially by outside consultants. That is why for conventional cybersecurity firms this scenario often leads to easy sales of training programs and other canned solutions but does not often lead to a great cybersecurity program. The truth is that good programs are usually focused on self-improvement. Steady and prolonged improvement is rarely accidental. Working with ...