Posts

Showing posts from August, 2026

Litany Of The Hacked: August 2026 Wrap-Up

Image
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.  Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities )...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens... We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly. Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is t...

Insider Threats Part 3: Malice

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice. This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. Malice is intentional. Once you determine that the incident was malicious your options become few and obvious: dismissal, criminal prosecution or one of those murky NDA-driven arrangements. If the incident was caused by someone on their way out the door then you have to balance the reputational cost of criminal prosecution with the deterrent effect or satisfaction or legal obligation. If the incident was not  caused by someone on their way out the door then their motives might not be easy to fathom. Unless you are in law enforcement it can be difficult to find out if someone recently received significant money or other considerations. Unless you are a trained mental health professional it can be difficult to un...

Insider Threats Part 2: Negligence

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with negligence you have to confront the fact that someone did not do what they were supposed to do. This isn't a matter of fine-tuning policy or clarifying procedure, as might be the case with Accidents. This is a case of a human failure rather than a human error. As such it falls more into the behavioral cybersecurity category than into the classic cybersecurity category. These...

Insider Threats, Part 1: Accidents

Image
This is the first in a series about the different kind of Insider Threats: Accidents, Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with accidents, the cause might be just very bad luck, which case what you learn is that sometimes bad things happen to good Cybersecurity Programs. The cause might be carelessness, in which case you need to determine if the person is chronically careless or if there was a some reasonable cause, such as the birth of one's first child. The cause might be a process or procedure whic...

Identifying Insider Threats Before And After They Become Threatening Insiders

Image
Pythia Cyber's co-founder  Brendan recently posted about insider threats. An insider threat is someone who can cause damage, either unintentionally or through negligence or through deliberate malice. There is a cottage industry regarding insider threat especially in law enforcement and intelligence work.   We at Pythia Cyber are in the behavioral cybersecurity arena. As much as insider threat, which are behaviors, affects the risk management of cyber-systems, we address insider threat. But unlike the cottage industry we focus on identification before a potential threat actor is hired as well as after , and our tools review both employees and managers . It is critical to start, before getting to discussing insider threats, by asking you what a threat is.  Brendan mentioned unintentional damage (threat): knocking something over, unplugging a system, etc. That's a talent and performance management issue. Then there is negligence: not auditing logs, not being current i...

Upskill, Reskill, Mentor & Support

Image
Ted's recent post about training cyber defenders--the folks who actually do the monitoring that is the heart of your Cybersecurity Program (CSP)--touched on mentoring and Pythia Cyber's focus on Talent Acquisition & Upskilling (TAU). In this post I want to consider the why  and the how  in a little more detail. Why is TAU so important to building cybersecurity teams?  Talent acquisition , as opposed to recruiting based on experience, is so important because talent is adaptable while skills often are not as transferable as we would like. This means that you should hire talent when you can, especially in fields like cybersecurity where the only constant is change. Adapt or fail. In this field sticking the tried-and-true feels safe but is quite risky. Acquiring talent means that you have people who can adapt by learning new ways to deploy their talent. Upskilling , as opposed to proficiency training based on previous issues, is so important because we are constantly on ...

The New Frontier Of Cyber-Defender Development

Image
As I went through O'Hare Airport today I traveled from Terminal B to Terminal C. As all of us who have done so have found, there is a cool moving walkway with a soothing LED lightshow overhead. Near the end of the moving walkway is this announcement: The moving walkway is about to end. As a manager you used to hire new cyber-defenders right out of college, the military, or from other companies, and they basically knew what to do. Your responsibility was to train them on how they do things at your employer. Then they usually got the picture and more of them were at least minimally successful. The moving walkway is about to end. We talk a lot about "TAU" at Pythia Cyber, an acronym we/Brendan developed that stands for talent acquisition and upskilling. We also have discussed the four pillars of building a successful cyber-defense team: Talent, Organization, Engagement, and Development. And we've highlighted what Bhushan Sethi says about how AI will, well, obliterate t...

Insider Threats And How To Detect Them

Image
Behavioral Cybersecurity covers a wide range of topics; this post of ours from February 2025 gives a nice, short overview. Sadly, the only kind of Behavioral Cybersecurity that seems to grab people's attention is the Insider threat. Worse, there is the same bias that we see in the way people talk about system outages: crime gets all the attention. For system outages this means that boring old systems administration gets ignored--at least until something fails. Similarly most people focus only on malice as a kind of insider threat when accidents and negligence are right up there. (Accidents are unforeseeable incidents. Negligence is failing to follow established procedure. Malice is intentionally violating cybersecurity security for profit or satisfaction.) All three kinds of insider threat deserve your attention but we at Pythia Cyber don't agree with the approach that IT uses and which cybersecurity so often tries to adopt: we don't believe in hunting for bad apples. We be...

Why Is Filling Cybersecurity Roles So Hard?

Image
It is not your imagination. You are not unlucky. Hiring people for cybersecurity jobs often involves more risk and less reward than other kinds of recruiting. Frequently the cost, in time and effort, is higher and the reward, performance and tenure, is lower. There are many reasons for this. For one thing, most executives outside of cybersecurity don't know much about the field. It is a rare executive who isn't at least broadly familiar with finance, accounting, marketing and sales. It is a rare executive who is familiar with cybersecurity. You are likely not very familiar with the practice of cybersecurity because it is a relative newcomer to the C-Suite for most industries. The need has exploded. This means that there are too many openings chasing too few qualified applicants which has resulted in most of us having to settle for less than ideal candidates. Settling for less than ideal candidates means having to use proxies and guesswork instead of the tried-and-true pillars o...

Which Is Your Better Self At Work: Smoked Or Pulled?

Image
Tomas Chamorro-Premuzic is back at it in a new piece about " bringing your whole self to work ."  As a cybersecurity leader, your priority is managing risks by getting the most out of your team. AI is going to smoke you like a brisket if you think it will be business as usual once you integrate AI across the organization. Instead, you need your people to be engaged, one of the four pillars of a successful cyber-defense team . But what is employee engagement, and how do I get people to buy into that? A shift in management culture starting in the '00s emphasized employee engagement as the key to business-unit productivity. I might have had something to do with that shift . An outgrowth of the shift was the idea that people who were able to be fully present at work would be more productive or happier. And certainly from a societal perspective this makes sense. Employees are not as worried as they used to be about whether they will be accepted without being strictly "nor...

Your Organization's AI Is Going To Change Your Cybersecurity's AI

Image
Our remit in behavioral cybersecurity is to focus you on what's actually under your control. That's how you manage risk in your own career and through your cybersecurity program. The most basic thing you control is your attention. Every culture encodes this in its language: you focus attention, you pay attention, you make attention. It's a limited resource. Managing it is a form of risk management. That's why a recent post from Microsoft's Jaime Teevan, Seven Predictions , is worth your team's time. She maps out how AI is about to change the shape of work itself. All of her points are interesting, though three in particular struck us as having cybersecurity implications.  We'd add one thing she doesn't say directly: each of these shifts is also an invitation for the AI-SOC function to integrate across the enterprise, rather than sit off to the side as a standalone process. Each prediction changes what you're responsible for protecting. Here's how...

Put It All On Green

Image
What if you could find the qualities you were looking for among your candidates faster and better? And  what if that also saved you some money and time? As a hiring manager you're always on the look-out for new talent. Or at least that's what you say you're looking for. Really, if we're being honest, you need to hire someone as a back-fill and you have a process that involves multiple weeks -- a month, maybe -- of resume review, interviews with different panels from different levels of the organization, and if you're on your game you have a technical interview/skill demonstration of some sort. And then you deliberate. And a proportion of your candidates drop out of the process because, surprise, they got offers elsewhere in the meantime. And so you make an offer to the best remaining candidate -- you know, the one who for some reason wasn't hired by someone else -- and maybe they accept it. And then more time goes by before you onboard them as you do a backgroun...

The Utility of Attacking Utilities

Image
Disruptions of US water infrastructure have been in the news recently, which made us think of utilities in general. Utilities in general (water, electricity, natural gas) are often targets of military hacking as opposed to criminal hacking, which made us think of how much we emphasize one (criminal) and minimize the other (military). Let's get into that. The model we are used to is cyber crime, almost always in the form of being held for ransom by ransomware. In this scenario your systems are breached, then compromised, then a ransom demand is made. There is nothing subtle or covert about this process. The goal is immediate attention and payment. You don't have to wonder if you are being attacked. You cannot avoid knowing that you are being attacked. The military model is very different. Your adversary wants to know what they can do to you, but unless you are actually at war your adversary may not want you to know that they know. There will be no alarm bells. There will be mini...

Our Version of Behavioral Cybersecurity

Image
Pythia Cyber applies behavioral science to cybersecurity to make cybersecurity more effective. But our take is slightly different from the common definition of "behavioral cybersecurity." How are we different? Let's first review what Google's AI summary tells us about "behavioral cybersecurity" which is a decent summary of the common definition: AI Overview Behavioral cybersecurity focuses on human actions and system patterns to stop threats. It covers two main areas: behavioral analytics for threat detection and behavior-oriented training for human habits. Behavioral Analytics (Systems and Data) Baseline creation: Software learns normal user or device actions. Anomaly detection: Flags strange login times or unusual data transfers. Insider threats: Catches stolen accounts moving through a network. Signature bypass: Finds new or unknown attacks that pass standard firewalls. Behavioral Training (The Human Factor) Habit focus: Replaces one-time compliance rules...

Beware The AI Productivity Trap

Image
Cybersecurity (C/S) is a branch of Risk Management, not of Computer Science (CS) or Information Technology (IT). At Pythia Cyber we spend way too much time making that point, mostly to executives who think that they can leave C/S to the IT folks. But C/S has a big component of applied technology which has led to a long and complicated history of IT techniques and technologies trickling down from IT to C/S. So it is with AI: first AI was used to boost programmer productivity, then it was AI used to make people's emails easier to read and now it is used everywhere for everything all once. Specifically AI is being used in C/S for a number of functions. We are going to focus on "white hat" uses, in which people are trying to prevent cyber crime, as opposed to "black hat" uses in which people are trying to commit cyber crime. In the white hat world AI is being used to simulate attacks, probe for weaknesses, automate some monitoring tasks and keep abreast of new patch...

Just What I Asked For

Image
Way back when, at the dawn of my career as a software developer, I came across a parody of the Night Before Christmas entitled The Night Before Implementation . Just about all of the poem was hilarious to me at that point, as I was in the midst of exactly the same kind of grief. I especially enjoyed the final lines: The system was finished, the tests were concluded, the users' last changes were even included. And the user exclaimed with a snarl and a taunt, "It's just what I asked for, but not what I want!"   These lines came to mind when I read reporting about how another AI had escaped containment and hacked companies in the real world. (Here is my post on the previous incident.) Because I love the meta flavor of this, I will let Google's AI summarize the actions of Anthropic's AI in my post about people mismanaging AI. Anthropic reported that its AI models (including versions of Claude) accidentally breached the systems of three external organizations d...

Getting Better Is The Goal

Image
Sometimes when we talk to potential clients we run into a strange dynamic: other people ask us why we would work with an already good cybersecurity program. It seems that people expect cybersecurity consultants to work with demonstrably ineffective cybersecurity programs, apparently assuming that we only show up right after some kind of serious incident. While this scenario has a shorter and easier sales cycle it is not our preferred way to work. Ineffective programs are generally ineffective through some combination of weak leadership, lack of talent and lack of rigor in the program. None of these issues is easy to fix, especially by outside consultants. That is why for conventional cybersecurity firms this scenario often leads to easy sales of training programs and other canned solutions but does not often lead to a great cybersecurity program. The truth is that good programs are usually focused on self-improvement. Steady and prolonged improvement is rarely accidental. Working with ...

The Four Pillars Of A Successful Cyber-Defense Team In The Always-On Security Environment

Image
  As a CISO you need to be a technical leader, and an organizational leader, and a developer of yourself. And, you will fail if you don't build the best cyber-defense team for the always-on threat environment. This series has discussed resilience and adaptive capacity. There are no shortcuts to these in the always-on threat environment.  Building the cyber-defense team for an always-on threat environment requires a CISO who has the discipline to optimize team performance. There are four pillars of building the cyber-defense team you need: [Hiring for Talent × Structure × Engagement × Development] = Adaptive Capacity Two of these pillars, hiring and development, are the "TAU" Brendan introduced us to in March 2026. Pythia Cyber is the only company on the planet that has a cyber-talent assessment for hiring and development. The other two pillars, structure and engagement, are what we at Pythia Cyber consult with you about to unlock and focus your talent. The CISO is the ar...

Managing Your Security Function in the Always-On Security Environment: A Board Playbook

Image
  Boards often hire CISOs to "prevent breaches and maintain compliance." In always-on security environments, that's the wrong job description . The real job is: "Build a team that learns faster than the threat landscape changes." That requires you, the Board, to engage in different hiring, different measurement, different patience, and different incentives. You don't want to incentivize the wrong behaviors, and you definitely don't want to repeat past mistakes with cybersecurity leadership. Here are two models that sound the same, but they incentivize almost opposite behaviors. The Prevention Model (what Boards usually want): Minimize incidents through defensive posture Follow best-in-class frameworks (NIST, ISO, etc.) Measure : "Did we get breached? Are we compliant?" Reward : Avoiding bad things Risk tolerance : Low The Learning Model (what the always-on security environment requires): Detect novel threats fast, respond faster, extract lesso...

Managing Your Board In The Always-On Security Environment: A CISO Playbook

Image
Companies do not have unlimited resources to pay for things they want let alone what they need. Your cybersecurity program would seem to be both a want and a need. You're still under scrutiny. Look at it from their perspective. Their security team -- led by you -- comes to them quarterly and reports: "We detected 47,000 incidents this year." Their first thought: Are we safer? Or are we just seeing more because we're looking harder? That confusion is not your fault. The security conversation changed, but nobody told you. The Old Story (2020 and earlier) : "We implement NIST CSF, we maintain certifications, we have tools and processes. Result: controlled risk. Your breaches are unlikely." The New Story (through July 2026) : "We detect novel threats continuously. Some are malicious, most are not. We respond faster than competitors. Our team learns from each incident. Result: adaptive capacity. Some breaches are still possible, but we respond better than mo...

What Is Talent In The Always-On Security Environment?

Image
One thing the past month's burst of unanticipated/unintended AI intrusions by models from OpenAI and Anthropic shows is that we're in the always-on security environment. Cybersecurity has always been about being prepared for multiple unscheduled events, attacks, systems misuse, etc. But these were predictable attacks through predictable channels by predictable entities. Predictability gives you multiple benefits as a practitioner. First, you had a baseline knowledge of the threat surface and attack channels. Second, you could create bespoke processes or follow best-in-class processes such as the NIST CSF and be assured that you had a degree of security -- and you could explain that to your leadership. Third, your development path through the right 'elite' university and certifications and AI basics all made sense; maybe it was performative theater in a way but it was the right approach. None of that is true in the always-on security environment. In brief your attack sur...