Posts

The Circle of Cybersecurity: Managers to Leaders

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Mangers to Leaders. That arrow is labelled "Status" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Status Like "evidence," "status" is a concept we all think we understand until we need to define it. One of the big steps in implementing a good CSP is agreeing on the compromise that is status. There is always compromise because there are limits to what the evidence the Managers have been given and there are limits on what the Leaders can comprehend and absorb. One colleague of mine once joked that "boardroom reports...

The Circle of Cybersecurity: CSEs to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Cybersecurity Engineers (CSEs), the folks on the front lines, to Managers. That arrow is labelled "Evidence" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Evidence In most social situations demanding proof that people are doing what they said they would do is rather rude. This taboo has lead to a dismaying number of CSPs being "faith-based" by which I mean that Managers have faith in their CSEs and assume that all is well unless and until something goes wrong. Alas, politeness is not what is needed in an effective CSP. In cyberse...

The Circle of Cybersecurity: Managers to CSEs

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the second downward arrow, what flows from Managers Cybersecurity Engineers (CSEs), the folks on the front lines. That arrow is labelled "Procedures" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Procedures In theory all you need for your CSP is for procedures to be transmitted from Managers to CSEs. In practice, this is where the rubber meets the road. To stretch the analogy, this is where the tires of your Policies meet the road debris of previous decisions, the potholes of cyberattacks, the ice of accidents and the oil slicks of negligence. And, of course, the imp...

The Circle of Cybersecurity: Leaders to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the first downward arrow, what flows from Leaders to Managers. That arrow is labelled "Policies" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Priorities In such a framework the first thing that leaders have to do is bless a list of digital assets to be protected. The managers may well provide a super set of all possible candidates, but the leaders need to impose priority on that super set. Almost no organization can protect every possible digital asset all the time. Resources Once the digital asset list is set for the time period--usually a year--then the organizati...

The Circle of Cybersecurity

Image
Ted recently wrote about the pain of rewarding performance with promotion and the purported death of the entry-level CS job . This got me thinking about the actual CS jobs that I have seen in the wild.When looking at actual CS jobs, size matters so we will start with that dimension. Small Organizations In very small organizations there isn't a Cybersecurity Program (CSP) so much as there is a guy or gal in IT who moonlights as The Person Who Keeps Us From Doing Dumb Stuff. This is a part-time Cybersecurity Engineer (CSE) even if they don't call it that. There is no formal communication channel between leadership and the valiant part-time CSE. The disaster-recovery aspect of the job is folded into the system administration duties. Medium-Sized Organizations In medium-sized organizations you have a CSP with a few people in it, mostly refugees from IT who Secure The Network. This is often a supervisor and two helpers who sort of communicate with senior management on an ad hoc basi...

R.I.P. Entry-Level Cybersecurity Jobs?

Image
This is not the first or last time we will address the (alleged, purported, actual, imagined) demise of the entry-level job. That newbie fresh-out-of-college or right-out-of-the-military cyber-defender that had all the certs and none of the savvy? You might kiss it goodbye.  But in reality you're kissing that position description goodbye, not the role.  In brief we at Pythia Cyber think the nature of entry-level cybersecurity work will change but not disappear. Like any change process, its trajectory of change is unknowable; 5 years from now we will have a new labor force that arose from pressures we have now. Over at The Signal , Alex Banks is having all of the angst. These three nonconsecutive paragraphs tell his story: Nobody learns their trade in their first year. If you’re honest about your own, what you actually learn is a collection of many small micro-experiences that compound into a long list of intangibles that can rarely be named yet can only be sharpened through ...

Promotability & Performance -- If Only It Were That Simple

Image
Every security team has one: the analyst who triages faster than anyone else, the engineer who reads a packet capture like a second language, the threat hunter whose instincts catch what the tooling misses. When a leadership slot opens up, that person is the obvious pick. They're the strongest performer on the team. They are also, disproportionately, a bad bet for the management role, a specific kind of risk most security organizations aren't measuring. The reason is more precise than "not everyone is management material." Performance and potential are different psychological constructs, predicting different outcomes, and most security talent pipelines quietly collapse them into one. Here are five key points for you to remember in your review of performance v. potential. First point: climbing is not the same skill set as performing . Advancing in an organization and performing at higher/management levels draw on overlapping but distinct profiles. The people who get no...