Posts

You & The CFO: A Risk Management Partnership

Image
Brendan has written a lot lately on cybersecurity as risk management. Another person in your organization who manages risk is the Chief Financial Officer (CFO). Is there any ovelap? Your CFO is supposed to keep the company's books straight and tell the board when something doesn't add up. Now imagine telling that same CFO: also, go adopt the new accounting software company-wide, use it yourself for the close, and be the one who catches it when it's wrong. That's roughly the position CFOs are in with AI according to Deloitte's Q2 2026 CFO Signals survey . More than half of CFOs are using AI for financial planning and budgeting. Forty-one percent use it to analyze financial data. Yet only 43% say they're very confident in their organization's AI governance framework. Most land at "somewhat confident," which is a polite way of saying "we haven't stress-tested this," which is even more polite than "I have no idea." As a CISO you...

How to Describe Cybersecurity: Bottom Up vs Top Down

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. After we explain how C/S isn't an IT function , they often ask "then why it is always presented to us as an IT function?" The answer is pretty simple: because most explanations use the bottom up approach. Those explanations work backwards from foiling an on-going cyberattack by showing an evil hacker in his lair and contrasting that with our heroes at their desks, heroically typing away to thwart evil in real-time. This image is ridiculous but in an understandable way: this image is visual, which suits film and TV. This image compresses the time-scale, which suits film and TV. This image gives us a nice symmetry of evil versus good. Of course this image is grossly simplified, as so many images are. We show teaching as the act of standing up in front of a class and talking or writing on the whiteboard. Anyone who has ever known a teacher kn...

Cybersecurity As Management Fuction Example: Ransomware

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. At least they pretend to be surprised. We suspect that they really want  C/S to be an IT function because then they  wouldn't have to take any responsibility for it. As we have written about before, part of this reluctance to embrace C/S comes from fear of the unknown: most managers and leaders are quite familiar with accounting, marketing, sales, legal and HR. They are not familiar with C/S. Part of this reluctance comes from fear of the scary way in which C/S is presented, as an arcane dark technological enterprise marrying crime and science. Hooded figures in the dark type away on black keyboards, surrounded by so many monitors, all of which have green text on a black background. As we will see in a subsequent post, this image is the result of laziness and fatigue. In this post we will give a counter example that any business person can understa...

Keeping You In The Race Every Day

Image
As a professional you are always in the race. The bad guys are running hard. Your competitors are innovating. You're getting bogged down in administrivia, your costs are soaring, and your fellow employees see you as the captain of the no-fun team. How do you keep your focus? We saw this piece, " The mile world record holder can teach you about more than just running ," recently on The Athletic (behind paywall). The story is about how Josh Kerr, who recently broke the men's world record time in the mile run at 3 minutes 42.66 seconds (which is nuts), keeps his head in the game. It seemed like something you could benefit from. One reason you could learn from Kerr is that his approach is simple, and simple is best, because you need to keep your head in the game too. 1. Write out your perfect day. That one caught my attention also. What about you? Are you able to write out what your perfect day is? (Presume we keep it in the realm of work- or profession-related.) Are you ...

Who Do You Trust More -- Your Dentist Or Your CISO?

Image
You probably have an appointment schedule with your dental office that gets you there every 6 months. The best case scenario is that these are routine cleaning appointments with 90 seconds of DDS time to tell you that yep everything still looks good. What happens when, well, things don't look so good but you don't have any tooth pain? Do you just do what the doctor says and get the treatment (for maybe thousands of dollars) because after all the doctor is a medical professional with very significant educational experience and credentials that need constant updating? Do you go dental practice shopping because you suspect that your current dentist wants to drill and bill? Do you trust your dentist? What about the CISO of the company you just invested in? Do you just do what the cyber-practice leader says and get the AI-based SOC (for maybe millions of dollars with constant upgrades) because after all the leader is a battle-tested professional with very significant educational exp...

Litany Of The Hacked: August 2026 Wrap-Up

Image
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.  Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities )...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens... We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly. Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is t...

Insider Threats Part 3: Malice

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice. This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. Malice is intentional. Once you determine that the incident was malicious your options become few and obvious: dismissal, criminal prosecution or one of those murky NDA-driven arrangements. If the incident was caused by someone on their way out the door then you have to balance the reputational cost of criminal prosecution with the deterrent effect or satisfaction or legal obligation. If the incident was not  caused by someone on their way out the door then their motives might not be easy to fathom. Unless you are in law enforcement it can be difficult to find out if someone recently received significant money or other considerations. Unless you are a trained mental health professional it can be difficult to un...