Posts

Robot Performance Management Risks = f(Cybersecurity AI Agents, Human Risks)

Image
You have a performance review cycle for your SOC analysts. Goals, check-ins, regular conversations about what's working and what isn't. When someone stops performing, you notice, you document it, and eventually you do something about it. When did you last have that conversation about your AI agents? You're not alone if your honest answer is "never." If performance conversations with your human cyber-defenders already make you feel like it's time for a major medical procedure without enough anesthesia, adding one more with an agent sounds like the last thing you need. In a recent McKinsey Talks Talent episode, Kate Smaje put it plainly: most organizations can't recall the last time they prioritized a conversation about the performance of their nonhuman labor. We've built decades of infrastructure for managing human performance. For agents, most companies have nothing. That gap should worry a CISO more than almost anyone else in the building. Smaje make...

You & The CFO: A Risk Management Partnership

Image
Brendan has written a lot lately on cybersecurity as risk management. Another person in your organization who manages risk is the Chief Financial Officer (CFO). Is there any ovelap? Your CFO is supposed to keep the company's books straight and tell the board when something doesn't add up. Now imagine telling that same CFO: also, go adopt the new accounting software company-wide, use it yourself for the close, and be the one who catches it when it's wrong. That's roughly the position CFOs are in with AI according to Deloitte's Q2 2026 CFO Signals survey . More than half of CFOs are using AI for financial planning and budgeting. Forty-one percent use it to analyze financial data. Yet only 43% say they're very confident in their organization's AI governance framework. Most land at "somewhat confident," which is a polite way of saying "we haven't stress-tested this," which is even more polite than "I have no idea." As a CISO you...

How to Describe Cybersecurity: Bottom Up vs Top Down

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. After we explain how C/S isn't an IT function , they often ask "then why it is always presented to us as an IT function?" The answer is pretty simple: because most explanations use the bottom up approach. Those explanations work backwards from foiling an on-going cyberattack by showing an evil hacker in his lair and contrasting that with our heroes at their desks, heroically typing away to thwart evil in real-time. This image is ridiculous but in an understandable way: this image is visual, which suits film and TV. This image compresses the time-scale, which suits film and TV. This image gives us a nice symmetry of evil versus good. Of course this image is grossly simplified, as so many images are. We show teaching as the act of standing up in front of a class and talking or writing on the whiteboard. Anyone who has ever known a teacher kn...

Cybersecurity As Management Fuction Example: Ransomware

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. At least they pretend to be surprised. We suspect that they really want  C/S to be an IT function because then they  wouldn't have to take any responsibility for it. As we have written about before, part of this reluctance to embrace C/S comes from fear of the unknown: most managers and leaders are quite familiar with accounting, marketing, sales, legal and HR. They are not familiar with C/S. Part of this reluctance comes from fear of the scary way in which C/S is presented, as an arcane dark technological enterprise marrying crime and science. Hooded figures in the dark type away on black keyboards, surrounded by so many monitors, all of which have green text on a black background. As we will see in a subsequent post, this image is the result of laziness and fatigue. In this post we will give a counter example that any business person can understa...

Keeping You In The Race Every Day

Image
As a professional you are always in the race. The bad guys are running hard. Your competitors are innovating. You're getting bogged down in administrivia, your costs are soaring, and your fellow employees see you as the captain of the no-fun team. How do you keep your focus? We saw this piece, " The mile world record holder can teach you about more than just running ," recently on The Athletic (behind paywall). The story is about how Josh Kerr, who recently broke the men's world record time in the mile run at 3 minutes 42.66 seconds (which is nuts), keeps his head in the game. It seemed like something you could benefit from. One reason you could learn from Kerr is that his approach is simple, and simple is best, because you need to keep your head in the game too. 1. Write out your perfect day. That one caught my attention also. What about you? Are you able to write out what your perfect day is? (Presume we keep it in the realm of work- or profession-related.) Are you ...

Who Do You Trust More -- Your Dentist Or Your CISO?

Image
You probably have an appointment schedule with your dental office that gets you there every 6 months. The best case scenario is that these are routine cleaning appointments with 90 seconds of DDS time to tell you that yep everything still looks good. What happens when, well, things don't look so good but you don't have any tooth pain? Do you just do what the doctor says and get the treatment (for maybe thousands of dollars) because after all the doctor is a medical professional with very significant educational experience and credentials that need constant updating? Do you go dental practice shopping because you suspect that your current dentist wants to drill and bill? Do you trust your dentist? What about the CISO of the company you just invested in? Do you just do what the cyber-practice leader says and get the AI-based SOC (for maybe millions of dollars with constant upgrades) because after all the leader is a battle-tested professional with very significant educational exp...

Litany Of The Hacked: August 2026 Wrap-Up

Image
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.  Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities )...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens... We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly. Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is t...