Posts

Are Cyber-Squirrels Stealing Your Leadership ACORNs?

Image
OK homeowners, how much of your disposable income goes to squirrel-proofing your bird-feeders? And yet... HR Guru JP Elliott is back with a new podcast featuring a book on leadership decision-making. The book is authored by Caroline Webb, former McKinsey partner and thought-leader on leadership processes. Webb has distilled her experience working with leaders into a new book,  Leadership Intelligence: Science-Backed Strategies for Mastering 21 Everyday Management Challenges (Crown Currency, 2026). She has developed a simple decision model she calls ACORN: Aim : What are we actually trying to accomplish? ​Criteria : What would a good outcome look like? ​Options : What alternatives are we considering? ​Rate : How does each option perform against our criteria? ​Next steps : What happens from here? Sounds easy, right? Easy just like when you think "I'm going to get a bird-feeder that NO SQUIRREL can get to, hahahahahaha!" Once again, don't get fooled by thinking this is...

Secure-By-Design Is Your New Friend

Image
This is so good that it deserves amplification. Since 2023, CISA -- the US Cybersecurity and Infrastructure Security Agency -- has pushed software manufacturers toward three secure-by-design commitments: take ownership of customer security outcomes, embrace radical transparency and accountability , and lead from the top . That last one matters more than its plain wording suggests. It puts security accountability on senior leadership, not just the engineers writing the code. More recently , CISA extended the same thinking to the 'buy side': a guide for software purchasers, with questions to ask vendors before you sign. That's the piece CISOs should actually be pinning up: security starting at procurement , not bolted on after deployment . How realistic is any of this? Jen Easterly, former Director of CISA, posted an announcement on LinkedIn that as of late September 2026 the State of Oregon is applying these principles in its own procurement practice . If a state governme...

Moral Harm Is Your New Insider Threat Vector

Image
Recently I attended a presentation by Dr. Chloe Wilson, an expert in the organizational dynamics of moral harm that arise from witnessing or participating in activities that run against a person's own moral or ethical code. This may sound abstract, but relying on trite college-sophomore retorts -- whose morals, whose ethics? -- misses the point entirely. Wilson's research doesn't measure harm against some external moral standard, it measures whether the person themself  perceives a violation of their own values. That sidesteps the sophomoric relativism question rather than getting stuck in it. The grind of high-op-tempo work in a SOC can wear on someone's sense of right and wrong, or their professional pride, whether or not anyone outside them would agree there's anything to object to. Brendan's posts on threats arising from unintentional damage, negligence, and malice are strong statements about conceptualization of traditional insider threat. They describe ...

Your Job As A Manager In A Cyber-Defender Group Is Going To Get Weirder, Soon

Image
Your job as a manager in any organization is to keep your direct reports focused, deal with their personal issues, and appease your superiors. It can be thankless. In fact about 50% of managers fail, so it can also lead to joblessness.  All that for what is probably a few pennies more an hour in your paycheck compared to what you made as a front-line cyber-defender. Oh hey it's also going to get weirder soon. As we just published in yesterday's Litany of the Hacked, you can now expect not only gangs of humans to hack you but also gangs of AI models (that are "behaving in unexpected and concerning ways" -- see yesterday's post) and gangs backed by nation-states. But surely, you know, there are laws about this that will help. Well, no. In an uncomfortable piece in the NY Times this week, there is no governmental regulation coming from anywhere to rein in the aggressiveness of AI models. China? Nope. EU? Nope. US? Nope. There are laws regarding people who are hacker...

Litany Of The Hacked: September 2026 Wrap-Up

Image
Ah yes friends, it's that time. Welcome to the litany of the hacked, September 2026 edition. There is so much noise, so much static, so little information about how AI is going to rip the guts of your SOC apart. Oh wait, maybe you have an AI SOC and then it will rip apart the guts of an attacking AI. Um, er, hold on, maybe the AIs will conspire to attack you. Or them. Who knows. Our point is not shame, but to create shared awareness to pool resources where possible and build a sense of community. Thus, the litany now includes: the FBI...Springfield (MA) Public Schools...city government of Winona, MN...Anne Arundel (MD) Medical Centers...City of Berlin...Novocure... Manchester, London Stansted and East Midlands airports ...Pixel 6 phone systems...Chrome...Microsoft Exchange...State of Florida Department of Motor Vehicles...Liquid Network...Thomson Reuters...Eagle Mountain, UT...International Meteor Union...government of the United Arab Emirates (by Iran)...AT&T in north Texas (...

If You're "Indispensable" Does That Make You "Unpromotable?

Image
High performers are difficult to find and, well, can be difficult to manage. They challenge managers to improve their own performance management skills. They out-perform, by definition, their peers. And they know it, and they expect whatever "recognition" means to them. One of the hardest skills to learn as a manager of a high-performer is how to end that person's career doing what they were doing so well so that the individual can move to a new position and contribute there. It's about taking people who were indispensable at one level and successfully promoting them. Why is this hard? Multiple reasons: 1. Being good at one set of challenges is not the same as being good at a higher-level set of challenges. The talents that made you excellent at the current level (execution, individual output, mastery of a defined problem) aren't the same traits the new level tests (ambiguity, influence, developing people instead of doing the work yourself). At the very least, tha...

'Moneyball' Your Career

Image
Who knew that eventually Brad Pitt would end up in our blog series? Other than, of course he did. In the CISO Tradecraft® piece we've been touting recently there's a section we haven't touched yet: their case that aspiring leaders should apply ' Moneyball '-style statistics to their own careers. The point is that you're rarely promoted purely on your own merits, you're selected against whoever else happens to be in the room . Sometimes the deciding factor isn't your strength, it's the field's weakness. That's a useful, slightly uncomfortable idea, and it connects to something we've argued in this space before : climbing and performing are not the same test. Moneyball makes that concrete. If promotion decisions are relative then "I'm ready" was never the whole question. "Ready relative to who else is being considered, using what criteria, at what level" is the actual question. If that feels off-putting, CISO Tradec...