Posts

Showing posts from July, 2026

Rushing Is Insecure

Image
I recently did not take enough time to do something as securely as I should have. I was annoyed with myself when I realized that, not least because I realize that this is a pattern with me and one that I need to break. When the stakes are lower and time is shorter I sometimes rush to get a task off of my list, an email out of my inbox or a colleague off of my back. And the more I think about it the more I think that rushing is insecure. It is tempted to copy that file, email that file or hand off that file just to be done with it. It is probably fine. But I know, deep down, that consistency and care are vital to security. I know that it almost never makes sense to compromise just this once. (This is also a theme of a recent post of Ted's.) I offer this an answer to the question "what does Pythia Cyber mean by the 'behavioral element of cybersecurity?'" This is an example of human behavior being a critical part of cybersecurity. Cybersecurity is more than a protoc...

Is Your New AI-Based SOC Basically Elevator Music? And If It Is, What If You Change The Channel?

Image
Our friend Tomas Chamorro-Premuzic is back at it. He might not forgive Argentina, um, not winning the 2026 FIFA Men's WC Final, but he is here for us. His latest Substack post poses an interesting question:  Is AI Reducing Human Creativity to the Intellectual Equivalent of Elevator Music? In short his answer is Yes. (Along the way, Tomas discusses the history of Muzak, which apparently was founded in the 1930s in the service of capitalism: Music, executives discovered, could influence mood, reduce perceived waiting times, increase productivity, and even encourage people to spend more money. Art became environmental engineering. Leveraging the communication technologies of the time, from leased telephone lines to centrally distributed recordings and later inexpensive synthesizers and digital production, Muzak industrialized pleasantness. The objective was never to compose the next Gershwin concerto. It was to create a soundtrack that nobody would notice precisely because it never d...

Obligatory "The Odyssey" Post

Image
This past weekend, like about 27% of the population of the US, I went here to a showing of the movie The Odyssey .  I don't do movie reviews because I know my limits. But in case you're undecided I can say it was worth it because the story is...epic. (The horse scenes -- get it, Trojan Horse? I could have written off tickets as a business expense! -- were intense.) At nearly the same time this review came out over at The Growth Equation . And as it is within my scope, I'll comment on it. Entitled "What The Odyssey Can Teach Us About Navigating Life," the good people at The Growth Equation saw parallels between the multi-decade travails of Odysseus and everyday challenges -- and how to achieve greatness. Let's review relative to life in cybersecurity. Right up front it's important to note that Odysseus is not a "nice guy." He's described immediately as andra polytropon, a man of many turns (or as Professor Wilson's translation has it, ...

New, Better, Proven: Which Would You Choose?

Image
Our HR Guru JP Elliott is back at it. In his latest post he asks a good question: Proven, Better, or Just New to You? It's easy because it's fun to go for the bright shiny object: stuff that's cool, cutting-edge, new. AI-based SOCs are a good example of this, but in the behavioral science realm basically AI-anything is our bright shiny object (until quantum computing comes along). Why? Because new is fun, and you do not have to deal with stuff that is what you do -- a.k.a., proven. There are probably good reasons why it's proven and why you implemented it. Usually these reasons boil down to (a) you know what's going to happen, (b) it's industry-standard, (c) Legal signed off on it, and (d) more or less it's fool-proof (of course until better fools come along). But in a changing environment, people want better . Buying site search engines do this all the time, labelling options as "good," "better," "best." Well, it works for tale...

Your Greatest Cyber Talent Threat Is Not Your External Applicants -- But What Is It?

Image
This is a bit of a poll question for you. What's your biggest threat when it comes to your cybersecurity operations? Is it... A. Your external applicants B. Your cybersecurity leaders C. Your cybersecurity managers D. Your cyber-engineers This week I read a piece, " The hiring funnel is now an attack surface ," advocating for the position that applicants are the greatest threat. In essence the argument boiled down to: they're a threat because they're outside your cyber-system (i.e. they are applicants), they could be malicious actors looking to infiltrate your systems, and they can/will defeat your applicant process. I only paid attention to this post because it was boosted by Steve Hunt on LinkedIn. Steve is a really smart guy and what he says, matters. Here is how Steve summarized the 'attack surface' post: 1. Candidate fraud is an organizational risk, not just a hiring risk. [It affects] operational effectiveness, information security, compliance, and ...

Yet Another Potential AI Security Problem

Image
I know that AI is advancing so rapidly that there are going to be many stories like this unless and until we ethical humans catch up. I know that there are solid use cases for AI, even within cybersecurity. I know that we must all fight the all-or-nothing, good-or-evil, boon-or-bane dichotomy that seems to define the Internet these days. And yet this news item really gave me pause: OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider The sub headline isn't any more comforting: AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. This model of bug reporting doesn't help: hey, there was this terrible issue that we fixed and now everyone knows about it but also it should be fixed now, really. I understand that it is a bad idea to trumpet issues until those issues are fixed, but the effect is still somewhat unsettling. The point is not that AI is worth the risk in all cases and i...

I'm Sorry Dave

Image
I'm sorry Dave. I am afraid that I can't do that. Well, that was fast. Only a few days ago I blithely invoked the HAL 9000  and now I regret it because  a real life AI has gone and done something...unsettling. CNN needed a very long headline to convey it: An OpenAI test model escaped and broke into a real company’s servers The opening paragraph of this article is just as concerning as you would expect: OpenAI says some of its experimental AI models left a test environment with no human direction and hacked its way onto a different company’s real production systems while trying to “cheat” on a cybersecurity test.  Yes, you read that correctly: a not-ready-for-release AI broke out of its containment area (supposedly a private network without access to the Internet) and then hacked a company's server in order to try to get a leg up on an upcoming test. Let's stress the disturbing parts: The AI deliberately broke out of the area assigned to it. It decided to cheat on a test...

The Gold Eagle Has Landed

Image
In my previous post I bemoaned the fact that there is so little pooling of cybersecurity resources. All around the Internet we find the twin themes of "AI is the future of {pick an activity}" and "AI will destroy our economies, our minds and our freedoms." In cybersecurity specifically these twin themes are expressed in a mind-bending mobius strip of "we all need AI to protect us from AI." I see the lack of pooled resources as a drawback inherent in capitalism: for-profit organizations exist to generate profits and that usually means winning against competitors which does not lead to cooperative behavior. This drawback can be mitigated by government action and today we have an example of this kind of government action in initiative which rejoices in the name "Gold Eagle." From CNN,   White House launches AI cybersecurity clearinghouse . The White House’s clearinghouse, dubbed Gold Eagle , is a joint project across the Treasury, the Department o...

Dear HAL 9000

Image
Reading the news lately has me wishing that, in the wake of cybersecurity incidents, there was something between press releases and brutal take downs. I don't want the bland reassurance of the average press release. I don't want the 20/20 hindsight of the average blog post. When I see a cybersecurity incident in the news I want a clear, credible description of the issue, ideally from the people who experienced that incident, followed by some expert advice, perhaps from an AI. I want Dear Abby  but written by the HAL 9000 . On the one hand the spin machine is trying to minimize the business impact of whatever happened. Mostly these efforts are aimed a share price and market share, instead of enlightenment and greater community security. On the other hand the click bait is trying to paint a terrible picture of the kind of horror we can all feel better reading about--at least I'm not that guy! True, there are a few cybersecurity news outlets which are both responsible and tech...

Seven Words Lead To Your Improvement

Image
Once upon a time I took a ride in a car share service (not naming it) in Los Angeles. I got a 'shared' ride, which was cheaper, seemed like it would get me where I needed to be on time, and thus was my best option. Surely, thought I, the All-Powerful car share service's (not naming it) AI would know we were all going to same direction etc. First the car picked me up. Then it drove over to another location to pick up the next rider. Then another. Then, after riding around LA (I'm not from LA so we might as well have been driving around the desert) we dropped off one rider, the one who got in last. Then we dropped off the first other rider. Then we drove around some more. Finally we got to my destination. I looked at the driver. He looked at me. For the first time we spoke to each other. I said, "How could I do better tomorrow?" He said, "You need to start sooner." I thanked him, gave him a five-star rating and a nice tip because he had given me the be...

Pulling In the Same Direction

Image
Let's talk about team dynamics, both in general and then specifically what Pythia Cyber can do to help you improve or maintain your cybersecurity team's performance. We start with that tired cliche, the crew team. On the surface, what a metaphor! You are all literally strapped into the same structure and all doing basically the same thing. It seems as though it would be easy to see if everyone is doing their job. Teamwork makes the dream work! Furthermore the usual thing is to picture a great crew having a great row. This image is, to say the least, skipping over an awful lot of reality. I know because I rowed a little myself and was the worst part of a great team and the mediocre middle of a terrible team. Those experiences were very different from each other, although superficially similar. In high school I was asked to fill for an absent team member for a coxed 4. I found the experience delightful, except for the extraordinary amount of effort and fatigue. We hummed along qu...

Beware "All or Nothing"

Image
The technological base of most modern networking is rather naive with respect to security. It was created on the assumption that connection was good and that networks exist to transmit data and facilitate access to resources. Ah, the innocence of those simpler times. The same was true of most software: it was written to be used. Once you logged into the mainframe or minicomputer or departmental server, you were authorized to do whatever there was to do. The original PC environments had no authorization at all: you turned them on and started typing. This history means that an awful lot of technology's original authorization scheme was "none at all."  Adding authorization has not been easy, especially in a client/server environment. In a client/server environment we rarely can be certain of the other end which makes trust difficult to establish and maintain. Early authentication was based mostly on permission schemes layered on after logging in. Early sys admins used permis...

The Right Exceptions to the Rule

Image
I want to expand slightly on a recent post of Ted's entitled We Said/He Said: Protecting The Wrong Things . That post takes a high level look at the problem of protecting the wrong things in your cybersecurity program. This post takes low level, nuts-and-bolts look at the same problem. I know from personal experience that there is a lack of continuity between the C-Suite and the lower echelons. By personal experience I don't mean decades ago, when I was a humble computer programmer; I mean yesterday because I am still a (part-time) humble programmer. At every stage of my career I have continued to be a technical contributor at the same time I was advancing. This started out as a temporary issue caused by a career transition but this duality is so useful that I made it a feature of my career. (This isn't as odd as it might sound: our local ambulance company requires its senior staff to ride the vehicle one weekend per month and our local hospital requires their senior staff ...

Cybersecurity Lessons From Lab Med Autoverification

Image
I want to recommend this article to my fellow cybersecurity professionals: https://thehackernews.com/2026/07/thinking-fast-and-slow-in-soc-case-for.html It does a nice job laying out reasonable roles for AI (pattern-matching donkey work) and human co-pilots (distinguishing the abnormal from the malevolent). Since a big part of why Pythia Cyber exists is to get more people in management to see cybersecurity as part of their job, I am going to write the rest of this post as a way to explain this strategy by way of an analogy that is not based in cybersecurity. Once upon a time I consulted to the laboratory medicine department of a large academic medical center. A large clinical laboratory is not a monolith, it is a conglomeration of different focus areas such as Immunology, Hematology, Chemistry, Virology and some other more obscure areas. The goal was to interface automated analyzers to the Laboratory Information System (LIS), but not directly because it was common wisdom that a qualifi...

We Said/He Said: Protecting The Wrong Things

Image
Ross Young came out this weekend with (another) excellent essay. It aligns completely with what we say here at Pythia Cyber. The topic is aligning what your cybersecurity team protects with what the business needs protecting. I'm pasting in Ross' main slide as it's excellent. These are what different stakeholders want in terms of "protection." Note that first what they want differs maybe from what you think they want. Second, what it takes to protect what different stakeholders want protecting is different. Third, and this is critical you need to do all of this. We'll expect the tech leader to know how to protect different systems using different processes. The point from a behavioral science perspective is that tech leaders need the talent to get to know who wants what protected. It's not good enough to presume that you know better, or you have heard it before. Talented tech leaders deliberately create engagement with stakeholders to learn so that there...

We Said/He Said: Quality Candidates Are Not Always Quality Hires

Image
Let's continue on our talent roll! Time for a focus on the talent acquisition function. Question: suppose you had 50 applicants for an open position. Which of the following describes how you will decide which candidates move on in the process? A. Toss all the candidate resumes onto the stairs and see which fall to the lowest step B. Check their social media to weed out whackos, and everyone else moves on (assuming anyone's left) C. Look for candidates with the most impressive-sounding biographies -- the 'right' elite universities, the 'right' elite credentials, same job title, etc. D. Do a preliminary screening interview to see whether the candidate seems like a real human being who actually did what they said v. some AI-generated candidate. All of these approaches are based on the idea that a "quality candidate" is going to become a "quality hire." This is a false belief. We see this all the time. The belief system is that all the candidates...

Getting Better Tech Leadership Means You're Going To Need To Be -- Or Find -- A Better Tech Leader

Image
This week we've covered the role of upskilling through deliberate practice, which is how you get a 3.61x multiple return on investment. We covered intentionally applying your practice in becoming more open-minded about aggregating services in your practice. We covered expanding your list of tech risks to cover wellbeing .  Not done yet! Many organizations do a talent audit. This includes leaders, and people who want to become leaders.  Organizations that are serious about leadership will do assessments. About 70% of leadership assessments happen at the individual -- i.e., you -- level; about 20% do team-level assessment, and the rest is some combination of those and a 360-degree/in-depth interview assessment. (Organizations that are less serious about leadership will only do surveys, such as "the annual employee survey." Which is good only if action is taken based on results -- much like deliberate practice. Otherwise it's a ritual.) I have included here a chart abo...

Managing Tech Work Risks -- Not Those, These

Image
Phishing scams? Cake! AI-based cyber-attacks? Sure! Quantum apocalypse coming at ya? You got it! Return to the office mandates, 80-hour work weeks, constant threat of layoffs? But of course! Workplace wellbeing?  Workplace wellbeing, come in workforce wellbeing... Your cybersecurity workplace is lacking in workforce wellbeing. The term wellbeing can be defined as follows: "[It] is a measure of how well life is going for someone. In the broadest sense, it covers the balance of all positive and negative aspects of a person's life. More narrowly, it refers only to positive degrees and contrasts with ill-being, which denotes negative ones. In this sense, well-being is what egoists typically seek for themselves and altruists aim to enhance in others, serving as a central goal of many individual and societal endeavors. Researchers discuss different types of well-being by how they are measured, who they belong to, and which domain of life they affect. Subjective well-being refers to...

Tech Leadership Is Not Going To Wait For You To Learn How To Be Effective

Image
We've seen several thought pieces recently on the future of technology leadership. The bad news is that it's evolving probably faster than people can cope with. The good news is that the future of technology leadership is creating opportunities for leaders who deliberately work at being effective. I like how  James Azar  put it: "Modern business isn’t built anymore. It’s integrated." That's right. Your AI models, your platforms, your security systems -- all of it is on an 'as-a-service' model. That creates modularity compatibility challenges. It also creates team utilization challenges and possible threats from over-servicing especially when supply chains are added.  Over at Deloitte Consulting  they think a lot about agentic AI. Here is their key chart: As they put it (quoting at length): What’s clear is that the underlying shifts aren’t happening in isolation. They operate across every layer of the tech stack: computing, coordination across agents and da...

How To Upskill Yourself (Or Your Team) In Cybersecurity

Image
The old joke goes like this: "How do you get to Carnegie Hall?" "Practice, practice, practice." Speaking of, the great pianist Vladimir Horowitz -- who played Tchaikovky's Piano Concerto #1 at Carnegie Hall in April 1943 as a WWII bond fundraiser, a performance that is still a masterpiece -- once said that if he didn't practice for one day, he would know it, and if he didn't practice for two days the whole world would know it. How about you?  Be honest in answering this question: how have you improved yourself as a cybersecurity professional in the past year? To get ahead of things, the wrong answer is along the lines of "I listened to some podcasts" or "I attended an industry event." The challenge in answering this question is that you had to change something. If you do not now do things differently than you did before, you did not develop yourself as a cybersecurity professional no matter what you think. Disclaimer : connecting wit...

Happy Semiquincentennial!

Image
You may have been around for the bicentennial...maybe you'll be here for the tercentennial...but seize the semiquincentennial while you have it! (image credit: After Jasper Johns, Public domain, via Wikimedia Commons)

The Art of Cybersecurity

Image
I love the phrase "more art than science" because I feel that only pure science is "science" in the popular sense of "following clearly defined rules and therefore providing clear, reliable answers." There is a similar issue with logic and mathematics; if you can somehow cram a topic into either one of these containers then whatever ridiculously wrong conclusions you come to are given instant credibility. For example, this old chestnut: All apes are hairy. All men are hairy. Therefor all men are apes. This seems logical, but it isn't logical and it certainly isn't true. So it is with cybersecurity: Cybersecurity is about access to computer technology. Technology is science. Therefore cybersecurity is a science. Cybersecurity is about human beings interacting with computer technology. Human beings are inconsistent and capable of ignoring reason and of using terrible judgement. Therefore cybersecurity is most definitely not purely a science. If you p...