Posts

Is Your New AI-Based SOC Basically Elevator Music? And If It Is, What If You Change The Channel?

Image
Our friend Tomas Chamorro-Premuzic is back at it. He might not forgive Argentina, um, not winning the 2026 FIFA Men's WC Final, but he is here for us. His latest Substack post poses an interesting question:  Is AI Reducing Human Creativity to the Intellectual Equivalent of Elevator Music? In short his answer is Yes. (Along the way, Tomas discusses the history of Muzak, which apparently was founded in the 1930s in the service of capitalism: Music, executives discovered, could influence mood, reduce perceived waiting times, increase productivity, and even encourage people to spend more money. Art became environmental engineering. Leveraging the communication technologies of the time, from leased telephone lines to centrally distributed recordings and later inexpensive synthesizers and digital production, Muzak industrialized pleasantness. The objective was never to compose the next Gershwin concerto. It was to create a soundtrack that nobody would notice precisely because it never d...

Obligatory "The Odyssey" Post

Image
This past weekend, like about 27% of the population of the US, I went here to a showing of the movie The Odyssey .  I don't do movie reviews because I know my limits. But in case you're undecided I can say it was worth it because the story is...epic. (The horse scenes -- get it, Trojan Horse? I could have written off tickets as a business expense! -- were intense.) At nearly the same time this review came out over at The Growth Equation . And as it is within my scope, I'll comment on it. Entitled "What The Odyssey Can Teach Us About Navigating Life," the good people at The Growth Equation saw parallels between the multi-decade travails of Odysseus and everyday challenges -- and how to achieve greatness. Let's review relative to life in cybersecurity. Right up front it's important to note that Odysseus is not a "nice guy." He's described immediately as andra polytropon, a man of many turns (or as Professor Wilson's translation has it, ...

New, Better, Proven: Which Would You Choose?

Image
Our HR Guru JP Elliott is back at it. In his latest post he asks a good question: Proven, Better, or Just New to You? It's easy because it's fun to go for the bright shiny object: stuff that's cool, cutting-edge, new. AI-based SOCs are a good example of this, but in the behavioral science realm basically AI-anything is our bright shiny object (until quantum computing comes along). Why? Because new is fun, and you do not have to deal with stuff that is what you do -- a.k.a., proven. There are probably good reasons why it's proven and why you implemented it. Usually these reasons boil down to (a) you know what's going to happen, (b) it's industry-standard, (c) Legal signed off on it, and (d) more or less it's fool-proof (of course until better fools come along). But in a changing environment, people want better . Buying site search engines do this all the time, labelling options as "good," "better," "best." Well, it works for tale...

Your Greatest Cyber Talent Threat Is Not Your External Applicants -- But What Is It?

Image
This is a bit of a poll question for you. What's your biggest threat when it comes to your cybersecurity operations? Is it... A. Your external applicants B. Your cybersecurity leaders C. Your cybersecurity managers D. Your cyber-engineers This week I read a piece, " The hiring tunnel is now an attack surface ," advocating for the position that applicants are the greatest threat. In essence the argument boiled down to: they're a threat because they're outside your cyber-system (i.e. they are applicants), they could be malicious actors looking to infiltrate your systems, and they can/will defeat your applicant process. I only paid attention to this post because it was boosted by Steve Hunt on LinkedIn. Steve is a really smart guy and what he says, matters. Here is how Steve summarized the 'attack surface' post: 1. Candidate fraud is an organizational risk, not just a hiring risk. [It affects] operational effectiveness, information security, compliance, and ...

Yet Another Potential AI Security Problem

Image
I know that AI is advancing so rapidly that there are going to be many stories like this unless and until we ethical humans catch up. I know that there are solid use cases for AI, even within cybersecurity. I know that we must all fight the all-or-nothing, good-or-evil, boon-or-bane dichotomy that seems to define the Internet these days. And yet this news item really gave me pause: OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider The sub headline isn't any more comforting: AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. This model of bug reporting doesn't help: hey, there was this terrible issue that we fixed and now everyone knows about it but also it should be fixed now, really. I understand that it is a bad idea to trumpet issues until those issues are fixed, but the effect is still somewhat unsettling. The point is not that AI is worth the risk in all cases and i...

I'm Sorry Dave

Image
I'm sorry Dave. I am afraid that I can't do that. Well, that was fast. Only a few days ago I blithely invoked the HAL 9000  and now I regret it because  a real life AI has gone and done something...unsettling. CNN needed a very long headline to convey it: An OpenAI test model escaped and broke into a real company’s servers The opening paragraph of this article is just as concerning as you would expect: OpenAI says some of its experimental AI models left a test environment with no human direction and hacked its way onto a different company’s real production systems while trying to “cheat” on a cybersecurity test.  Yes, you read that correctly: a not-ready-for-release AI broke out of its containment area (supposedly a private network without access to the Internet) and then hacked a company's server in order to try to get a leg up on an upcoming test. Let's stress the disturbing parts: The AI deliberately broke out of the area assigned to it. It decided to cheat on a test...

The Gold Eagle Has Landed

Image
In my previous post I bemoaned the fact that there is so little pooling of cybersecurity resources. All around the Internet we find the twin themes of "AI is the future of {pick an activity}" and "AI will destroy our economies, our minds and our freedoms." In cybersecurity specifically these twin themes are expressed in a mind-bending mobius strip of "we all need AI to protect us from AI." I see the lack of pooled resources as a drawback inherent in capitalism: for-profit organizations exist to generate profits and that usually means winning against competitors which does not lead to cooperative behavior. This drawback can be mitigated by government action and today we have an example of this kind of government action in initiative which rejoices in the name "Gold Eagle." From CNN,   White House launches AI cybersecurity clearinghouse . The White House’s clearinghouse, dubbed Gold Eagle , is a joint project across the Treasury, the Department o...