Posts

Insider Threats Part 2: Negligence

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with negligence you have to confront the fact that someone did not do what they were supposed to do. This isn't a matter of fine-tuning policy or clarifying procedure, as might be the case with Accidents. This is a case of a human failure rather than a human error. As such it falls more into the behavioral cybersecurity category than into the classic cybersecurity category. These...

Insider Threats, Part 1: Accidents

Image
This is the first in a series about the different kind of Insider Threats: Accidents, Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with accidents, the cause might be just very bad luck, which case what you learn is that sometimes bad things happen to good Cybersecurity Programs. The cause might be carelessness, in which case you need to determine if the person is chronically careless or if there was a some reasonable cause, such as the birth of one's first child. The cause might be a process or procedure whic...

Identifying Insider Threats Before And After They Become Threatening Insiders

Image
Pythia Cyber's co-founder  Brendan recently posted about insider threats. An insider threat is someone who can cause damage, either unintentionally or through negligence or through deliberate malice. There is a cottage industry regarding insider threat especially in law enforcement and intelligence work.   We at Pythia Cyber are in the behavioral cybersecurity arena. As much as insider threat, which are behaviors, affects the risk management of cyber-systems, we address insider threat. But unlike the cottage industry we focus on identification before a potential threat actor is hired as well as after , and our tools review both employees and managers . It is critical to start, before getting to discussing insider threats, by asking you what a threat is.  Brendan mentioned unintentional damage (threat): knocking something over, unplugging a system, etc. That's a talent and performance management issue. Then there is negligence: not auditing logs, not being current i...

Upskill, Reskill, Mentor & Support

Image
Ted's recent post about training cyber defenders--the folks who actually do the monitoring that is the heart of your Cybersecurity Program (CSP)--touched on mentoring and Pythia Cyber's focus on Talent Acquisition & Upskilling (TAU). In this post I want to consider the why  and the how  in a little more detail. Why is TAU so important to building cybersecurity teams?  Talent acquisition , as opposed to recruiting based on experience, is so important because talent is adaptable while skills often are not as transferable as we would like. This means that you should hire talent when you can, especially in fields like cybersecurity where the only constant is change. Adapt or fail. In this field sticking the tried-and-true feels safe but is quite risky. Acquiring talent means that you have people who can adapt by learning new ways to deploy their talent. Upskilling , as opposed to proficiency training based on previous issues, is so important because we are constantly on ...

The New Frontier Of Cyber-Defender Development

Image
As I went through O'Hare Airport today I traveled from Terminal B to Terminal C. As all of us who have done so have found, there is a cool moving walkway with a soothing LED lightshow overhead. Near the end of the moving walkway is this announcement: The moving walkway is about to end. As a manager you used to hire new cyber-defenders right out of college, the military, or from other companies, and they basically knew what to do. Your responsibility was to train them on how they do things at your employer. Then they usually got the picture and more of them were at least minimally successful. The moving walkway is about to end. We talk a lot about "TAU" at Pythia Cyber, an acronym we/Brendan developed that stands for talent acquisition and upskilling. We also have discussed the four pillars of building a successful cyber-defense team: Talent, Organization, Engagement, and Development. And we've highlighted what Bhushan Sethi says about how AI will, well, obliterate t...

Insider Threats And How To Detect Them

Image
Behavioral Cybersecurity covers a wide range of topics; this post of ours from February 2025 gives a nice, short overview. Sadly, the only kind of Behavioral Cybersecurity that seems to grab people's attention is the Insider threat. Worse, there is the same bias that we see in the way people talk about system outages: crime gets all the attention. For system outages this means that boring old systems administration gets ignored--at least until something fails. Similarly most people focus only on malice as a kind of insider threat when accidents and negligence are right up there. (Accidents are unforeseeable incidents. Negligence is failing to follow established procedure. Malice is intentionally violating cybersecurity security for profit or satisfaction.) All three kinds of insider threat deserve your attention but we at Pythia Cyber don't agree with the approach that IT uses and which cybersecurity so often tries to adopt: we don't believe in hunting for bad apples. We be...

Why Is Filling Cybersecurity Roles So Hard?

Image
It is not your imagination. You are not unlucky. Hiring people for cybersecurity jobs often involves more risk and less reward than other kinds of recruiting. Frequently the cost, in time and effort, is higher and the reward, performance and tenure, is lower. There are many reasons for this. For one thing, most executives outside of cybersecurity don't know much about the field. It is a rare executive who isn't at least broadly familiar with finance, accounting, marketing and sales. It is a rare executive who is familiar with cybersecurity. You are likely not very familiar with the practice of cybersecurity because it is a relative newcomer to the C-Suite for most industries. The need has exploded. This means that there are too many openings chasing too few qualified applicants which has resulted in most of us having to settle for less than ideal candidates. Settling for less than ideal candidates means having to use proxies and guesswork instead of the tried-and-true pillars o...