Posts

Litany Of The Hacked: September 2026 Wrap-Up

Image
Ah yes friends, it's that time. Welcome to the litany of the hacked, September 2026 edition. There is so much noise, so much static, so little information about how AI is going to rip the guts of your SOC apart. Oh wait, maybe you have an AI SOC and then it will rip apart the guts of an attacking AI. Um, er, hold on, maybe the AIs will conspire to attack you. Or them. Who knows. Our point is not shame, but to create shared awareness to pool resources where possible and build a sense of community. Thus, the litany now includes: the FBI...Springfield (MA) Public Schools...city government of Winona, MN...Anne Arundel (MD) Medical Centers...City of Berlin...Novocure... Manchester, London Stansted and East Midlands airports ...Pixel 6 phone systems...Chrome...Microsoft Exchange...State of Florida Department of Motor Vehicles...Liquid Network...Thomson Reuters...Eagle Mountain, UT...International Meteor Union...government of the United Arab Emirates (by Iran)...AT&T in north Texas (...

If You're "Indispensable" Does That Make You "Unpromotable?

Image
High performers are difficult to find and, well, can be difficult to manage. They challenge managers to improve their own performance management skills. They out-perform, by definition, their peers. And they know it, and they expect whatever "recognition" means to them. One of the hardest skills to learn as a manager of a high-performer is how to end that person's career doing what they were doing so well so that the individual can move to a new position and contribute there. It's about taking people who were indispensable at one level and successfully promoting them. Why is this hard? Multiple reasons: 1. Being good at one set of challenges is not the same as being good at a higher-level set of challenges. The talents that made you excellent at the current level (execution, individual output, mastery of a defined problem) aren't the same traits the new level tests (ambiguity, influence, developing people instead of doing the work yourself). At the very least, tha...

'Moneyball' Your Career

Image
Who knew that eventually Brad Pitt would end up in our blog series? Other than, of course he did. In the CISO Tradecraft® piece we've been touting recently there's a section we haven't touched yet: their case that aspiring leaders should apply ' Moneyball '-style statistics to their own careers. The point is that you're rarely promoted purely on your own merits, you're selected against whoever else happens to be in the room . Sometimes the deciding factor isn't your strength, it's the field's weakness. That's a useful, slightly uncomfortable idea, and it connects to something we've argued in this space before : climbing and performing are not the same test. Moneyball makes that concrete. If promotion decisions are relative then "I'm ready" was never the whole question. "Ready relative to who else is being considered, using what criteria, at what level" is the actual question. If that feels off-putting, CISO Tradec...

How To Build A Security Culture

Image
In my previous post I made the case for building a security culture instead of a leadership culture. The goal of a security culture is to bring all employees and business units, or as many as possible, into the mindset of balancing risks, understanding and supporting trade-offs, and thus enabling performance that relies on a positive view of cybersecurity instead of cybersecurity rituals. So, you may ask, how does that happen? A good place to start is in the CISO Tradecraft® piece we mentioned entitled " How to create a leadership culture ." The trick is that you need to focus on security culture, not leadership (or worse, leader) culture.  Here are six approaches that work: Master your communication about security . Tell us why, and then you can tell us how as long as we understand why. How does your program stack up against peers? If your program stinks, how does your proposed security culture move the needle? If it's good, how does your proposed security culture ena...

Security Culture > Leadership Culture

Image
The good people at CISO Tradecraft® recently published a piece entitled " How to create a leadership culture ." Since this veers directly into our typical behavioral cybersecurity lane, we thought it was worth reviewing. The start is promising: "In the high-stakes world of cybersecurity, many organizations mistake “security theater”, the endless checklists, mandatory slide decks, and annual compliance box-checking, for actual security. But security isn’t a checklist; it’s a force field. And that force field is generated by your organizational culture." Great! Indeed, culture is a "force field" as we endorse this view. Thank you CISO Tradecraft! But then we diverge.  Effective behavioral cybersecurity is not about a "leadership culture" per se, it's about creating a security culture . Here's the distinction. A security culture is a force field because culture governs what behavior gets tolerated among and between team members. When behavio...

AI in Cybersecurity: Matching the Pump and the Pipes

Image
AI & Plumbing Systems Integration  In my youth I worked as a plumber's helper for a short while. This experience taught me the difference between being smart and being experienced. I was very much smarter than my boss but my boss was very much better at plumbing. Talent is a thing. Motivation is a thing. Experience is a thing. All of these things are important and all of these things come in varying degrees in the form of human beings. Or AI agents. Back to my experience as a plumber's helper. On the plus side, not only was I being humbled about the relative value of expertise and intelligence, I also spent lots of time thinking about dynamic systems so this brief employment was quite helpful when I moved into distributed information systems and then into cybersecurity. A key principle in either domain is that systems are interactive: their parts work together. This is little benefit in putting a giant V8 engine in your VW bug. There is likely great harm in raising the wate...

The View From Above: Sweeping & Undetailed

Image
I have been watching a CEO replace their director of technology and this CEO is making a very common mistake with hiring technology people in general and cybersecurity people in particular. That mistake is putting too high a value on what the CEO knows and too low a value on what the CEO does not know. In my experience it is natural for there to be detail gradient from C-Suite to worker bee. Like this illustration, the level of detail is different at every level of the organization. The highest level tends to be almost devoid of operational detail. The lowest level tends to be saturated with it. This state of affairs can lead to an unfortunate and often unconscious bias that the operational details don't matter. The higher up you go, the less people at that level had to deal with them. This can lead higher ups to feel that the details are not only unimportant, but a problem, since they must see the forest and not the trees. In most cases this generalization is inaccurate to an acce...