Posts

The View From Above: Sweeping & Undetailed

Image
I have been watching a CEO replace their director of technology and this CEO is making a very common mistake with hiring technology people in general and cybersecurity people in particular. That mistake is putting too high a value on what the CEO knows and too low a value on what the CEO does not know. In my experience it is natural for there to be detail gradient from C-Suite to worker bee. Like this illustration, the level of detail is different at every level of the organization. The highest level tends to be almost devoid of operational detail. The lowest level tends to be saturated with it. This state of affairs can lead to an unfortunate and often unconscious bias that the operational details don't matter. The higher up you go, the less people at that level had to deal with them. This can lead higher ups to feel that the details are not only unimportant, but a problem, since they must see the forest and not the trees. In most cases this generalization is inaccurate to an acce...

Is Your Program "The Standard"?

Image
"We are the standard." Thus spoke Breanna Stewart on 13 September 2026 after Team US beat Team France in FIBA Women's Basketball World Cup, 97 - 79.  Team USA has not lost a game since the semi-finals of this tournament in 2006. Read that again: Team USA has not lost a game since the semi-finals of this tournament in 2006 . "We are the standard," Ms Stewart, tournament MVP, said. It's a moral victory for other teams to come within 20 points of Team USA in international basketball, so, hooray Les Bleues . What about your cybersecurity function? Is it 'the standard'? If not, why not? Sorry to ask an uncomfortable question but you need to be clear-eyed about this. Everyone understands that you have budget realities, leading to competition for resources. Your team may be still forming, maybe there are lots of organizational dynamics. All of that is real. And so, is your program the standard?  Let's say it's not the standard. Do you benchmark agai...

The Circle of Cybersecurity: Managers to Leaders

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Mangers to Leaders. That arrow is labelled "Status" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Status Like "evidence," "status" is a concept we all think we understand until we need to define it. One of the big steps in implementing a good CSP is agreeing on the compromise that is status. There is always compromise because there are limits to what the evidence the Managers have been given and there are limits on what the Leaders can comprehend and absorb. One colleague of mine once joked that "boardroom reports...

The Circle of Cybersecurity: CSEs to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Cybersecurity Engineers (CSEs), the folks on the front lines, to Managers. That arrow is labelled "Evidence" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Evidence In most social situations demanding proof that people are doing what they said they would do is rather rude. This taboo has lead to a dismaying number of CSPs being "faith-based" by which I mean that Managers have faith in their CSEs and assume that all is well unless and until something goes wrong. Alas, politeness is not what is needed in an effective CSP. In cyberse...

The Circle of Cybersecurity: Managers to CSEs

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the second downward arrow, what flows from Managers Cybersecurity Engineers (CSEs), the folks on the front lines. That arrow is labelled "Procedures" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Procedures In theory all you need for your CSP is for procedures to be transmitted from Managers to CSEs. In practice, this is where the rubber meets the road. To stretch the analogy, this is where the tires of your Policies meet the road debris of previous decisions, the potholes of cyberattacks, the ice of accidents and the oil slicks of negligence. And, of course, the imp...

The Circle of Cybersecurity: Leaders to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the first downward arrow, what flows from Leaders to Managers. That arrow is labelled "Policies" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Priorities In such a framework the first thing that leaders have to do is bless a list of digital assets to be protected. The managers may well provide a super set of all possible candidates, but the leaders need to impose priority on that super set. Almost no organization can protect every possible digital asset all the time. Resources Once the digital asset list is set for the time period--usually a year--then the organizati...

The Circle of Cybersecurity

Image
Ted recently wrote about the pain of rewarding performance with promotion and the purported death of the entry-level CS job . This got me thinking about the actual CS jobs that I have seen in the wild.When looking at actual CS jobs, size matters so we will start with that dimension. Small Organizations In very small organizations there isn't a Cybersecurity Program (CSP) so much as there is a guy or gal in IT who moonlights as The Person Who Keeps Us From Doing Dumb Stuff. This is a part-time Cybersecurity Engineer (CSE) even if they don't call it that. There is no formal communication channel between leadership and the valiant part-time CSE. The disaster-recovery aspect of the job is folded into the system administration duties. Medium-Sized Organizations In medium-sized organizations you have a CSP with a few people in it, mostly refugees from IT who Secure The Network. This is often a supervisor and two helpers who sort of communicate with senior management on an ad hoc basi...