Posts

Just What I Asked For

Image
Way back when, at the dawn of my career as a software developer, I came across a parody of the Night Before Christmas entitled The Night Before Implementation . Just about all of the poem was hilarious to me at that point, as I was in the midst of exactly the same kind of grief. I especially enjoyed the final lines: The system was finished, the tests were concluded, the users' last changes were even included. And the user exclaimed with a snarl and a taunt, "It's just what I asked for, but not what I want!"   These lines came to mind when I read reporting about how another AI had escaped containment and hacked companies in the real world. (Here is my post on the previous incident.) Because I love the meta flavor of this, I will let Google's AI summarize the actions of Anthropic's AI in my post about people mismanaging AI. Anthropic reported that its AI models (including versions of Claude) accidentally breached the systems of three external organizations d...

Getting Better Is The Goal

Image
Sometimes when we talk to potential clients we run into a strange dynamic: other people ask us why we would work with an already good cybersecurity program. It seems that people expect cybersecurity consultants to work with demonstrably ineffective cybersecurity programs, apparently assuming that we only show up right after some kind of serious incident. While this scenario has a shorter and easier sales cycle it is not our preferred way to work. Ineffective programs are generally ineffective through some combination of weak leadership, lack of talent and lack of rigor in the program. None of these issues is easy to fix, especially by outside consultants. That is why for conventional cybersecurity firms this scenario often leads to easy sales of training programs and other canned solutions but does not often lead to a great cybersecurity program. The truth is that good programs are usually focused on self-improvement. Steady and prolonged improvement is rarely accidental. Working with ...

The Four Pillars Of A Successful Cyber-Defense Team In The Always-On Security Environment

Image
  As a CISO you need to be a technical leader, and an organizational leader, and a developer of yourself. And, you will fail if you don't build the best cyber-defense team for the always-on threat environment. This series has discussed resilience and adaptive capacity. There are no shortcuts to these in the always-on threat environment.  Building the cyber-defense team for an always-on threat environment requires a CISO who has the discipline to optimize team performance. There are four pillars of building the cyber-defense team you need: [Hiring for Talent × Structure × Engagement × Development] = Adaptive Capacity Two of these pillars, hiring and development, are the "TAU" Brendan introduced us to in March 2026. Pythia Cyber is the only company on the planet that has a cyber-talent assessment for hiring and development. The other two pillars, structure and engagement, are what we at Pythia Cyber consult with you about to unlock and focus your talent. The CISO is the ar...

Managing Your Security Function in the Always-On Security Environment: A Board Playbook

Image
  Boards often hire CISOs to "prevent breaches and maintain compliance." In always-on security environments, that's the wrong job description . The real job is: "Build a team that learns faster than the threat landscape changes." That requires you, the Board, to engage in different hiring, different measurement, different patience, and different incentives. You don't want to incentivize the wrong behaviors, and you definitely don't want to repeat past mistakes with cybersecurity leadership. Here are two models that sound the same, but they incentivize almost opposite behaviors. The Prevention Model (what Boards usually want): Minimize incidents through defensive posture Follow best-in-class frameworks (NIST, ISO, etc.) Measure : "Did we get breached? Are we compliant?" Reward : Avoiding bad things Risk tolerance : Low The Learning Model (what the always-on security environment requires): Detect novel threats fast, respond faster, extract lesso...

Managing Your Board In The Always-On Security Environment: A CISO Playbook

Image
Companies do not have unlimited resources to pay for things they want let alone what they need. Your cybersecurity program would seem to be both a want and a need. You're still under scrutiny. Look at it from their perspective. Their security team -- led by you -- comes to them quarterly and reports: "We detected 47,000 incidents this year." Their first thought: Are we safer? Or are we just seeing more because we're looking harder? That confusion is not your fault. The security conversation changed, but nobody told you. The Old Story (2020 and earlier) : "We implement NIST CSF, we maintain certifications, we have tools and processes. Result: controlled risk. Your breaches are unlikely." The New Story (through July 2026) : "We detect novel threats continuously. Some are malicious, most are not. We respond faster than competitors. Our team learns from each incident. Result: adaptive capacity. Some breaches are still possible, but we respond better than mo...

What Is Talent In The Always-On Security Environment?

Image
One thing the past month's burst of unanticipated/unintended AI intrusions by models from OpenAI and Anthropic shows is that we're in the always-on security environment. Cybersecurity has always been about being prepared for multiple unscheduled events, attacks, systems misuse, etc. But these were predictable attacks through predictable channels by predictable entities. Predictability gives you multiple benefits as a practitioner. First, you had a baseline knowledge of the threat surface and attack channels. Second, you could create bespoke processes or follow best-in-class processes such as the NIST CSF and be assured that you had a degree of security -- and you could explain that to your leadership. Third, your development path through the right 'elite' university and certifications and AI basics all made sense; maybe it was performative theater in a way but it was the right approach. None of that is true in the always-on security environment. In brief your attack sur...

Litany Of The Hacked: July 2026 Wrap-Up

Image
  Sing, o goddess, of the litany of the hacked from July 2026. Sure, we're keeping with the Homer theme, and yes we appreciate that the Anthropic product that 'launched a thousand ships' (+/-) was named Mythos.  Let's check the litany for this month. Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: Department of Education and police national legal database (both UK)...Fairlife Milk (a unit of Coca-Cola)...AssuranceAmerica...Greenfield Communications...Accenture Consulting...Homeland Security Information Network (HSIN)... In mitigation: one week later there is already a 'post-mortem' of the OpenAI/HuggingFace incident c/o Jen Easterly : https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem. We'll come back to that another time. But in aggravation (yep that again) Anthropic announced that one of its products also acted autonomously, though allegedly...