Posts

Litany Of The Hacked: August 2026 Wrap-Up

Image
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.  Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities )...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens... We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly. Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is t...

Insider Threats Part 3: Malice

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice. This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. Malice is intentional. Once you determine that the incident was malicious your options become few and obvious: dismissal, criminal prosecution or one of those murky NDA-driven arrangements. If the incident was caused by someone on their way out the door then you have to balance the reputational cost of criminal prosecution with the deterrent effect or satisfaction or legal obligation. If the incident was not  caused by someone on their way out the door then their motives might not be easy to fathom. Unless you are in law enforcement it can be difficult to find out if someone recently received significant money or other considerations. Unless you are a trained mental health professional it can be difficult to un...

Insider Threats Part 2: Negligence

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with negligence you have to confront the fact that someone did not do what they were supposed to do. This isn't a matter of fine-tuning policy or clarifying procedure, as might be the case with Accidents. This is a case of a human failure rather than a human error. As such it falls more into the behavioral cybersecurity category than into the classic cybersecurity category. These...

Insider Threats, Part 1: Accidents

Image
This is the first in a series about the different kind of Insider Threats: Accidents, Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with accidents, the cause might be just very bad luck, which case what you learn is that sometimes bad things happen to good Cybersecurity Programs. The cause might be carelessness, in which case you need to determine if the person is chronically careless or if there was a some reasonable cause, such as the birth of one's first child. The cause might be a process or procedure whic...

Identifying Insider Threats Before And After They Become Threatening Insiders

Image
Pythia Cyber's co-founder  Brendan recently posted about insider threats. An insider threat is someone who can cause damage, either unintentionally or through negligence or through deliberate malice. There is a cottage industry regarding insider threat especially in law enforcement and intelligence work.   We at Pythia Cyber are in the behavioral cybersecurity arena. As much as insider threat, which are behaviors, affects the risk management of cyber-systems, we address insider threat. But unlike the cottage industry we focus on identification before a potential threat actor is hired as well as after , and our tools review both employees and managers . It is critical to start, before getting to discussing insider threats, by asking you what a threat is.  Brendan mentioned unintentional damage (threat): knocking something over, unplugging a system, etc. That's a talent and performance management issue. Then there is negligence: not auditing logs, not being current i...

Upskill, Reskill, Mentor & Support

Image
Ted's recent post about training cyber defenders--the folks who actually do the monitoring that is the heart of your Cybersecurity Program (CSP)--touched on mentoring and Pythia Cyber's focus on Talent Acquisition & Upskilling (TAU). In this post I want to consider the why  and the how  in a little more detail. Why is TAU so important to building cybersecurity teams?  Talent acquisition , as opposed to recruiting based on experience, is so important because talent is adaptable while skills often are not as transferable as we would like. This means that you should hire talent when you can, especially in fields like cybersecurity where the only constant is change. Adapt or fail. In this field sticking the tried-and-true feels safe but is quite risky. Acquiring talent means that you have people who can adapt by learning new ways to deploy their talent. Upskilling , as opposed to proficiency training based on previous issues, is so important because we are constantly on ...

The New Frontier Of Cyber-Defender Development

Image
As I went through O'Hare Airport today I traveled from Terminal B to Terminal C. As all of us who have done so have found, there is a cool moving walkway with a soothing LED lightshow overhead. Near the end of the moving walkway is this announcement: The moving walkway is about to end. As a manager you used to hire new cyber-defenders right out of college, the military, or from other companies, and they basically knew what to do. Your responsibility was to train them on how they do things at your employer. Then they usually got the picture and more of them were at least minimally successful. The moving walkway is about to end. We talk a lot about "TAU" at Pythia Cyber, an acronym we/Brendan developed that stands for talent acquisition and upskilling. We also have discussed the four pillars of building a successful cyber-defense team: Talent, Organization, Engagement, and Development. And we've highlighted what Bhushan Sethi says about how AI will, well, obliterate t...