What Is Talent In The Always-On Security Environment?




One thing the past month's burst of unanticipated/unintended AI intrusions by models from OpenAI and Anthropic shows is that we're in the always-on security environment.

Cybersecurity has always been about being prepared for multiple unscheduled events, attacks, systems misuse, etc. But these were predictable attacks through predictable channels by predictable entities. Predictability gives you multiple benefits as a practitioner. First, you had a baseline knowledge of the threat surface and attack channels. Second, you could create bespoke processes or follow best-in-class processes such as the NIST CSF and be assured that you had a degree of security -- and you could explain that to your leadership. Third, your development path through the right 'elite' university and certifications and AI basics all made sense; maybe it was performative theater in a way but it was the right approach.

None of that is true in the always-on security environment.

In brief your attack surface is broader (though I cast doubt on the extremes of this argument) and the rate of incidents is beyond your capacity. Attack vectors are increasing and testing the limits of your defenses. Taking a break seems like something you do not have the luxury for until, I don't know, sometime in the future.

But yet you still have cybersecurity, because:

1. not all incidents are malicious attacks. This is a familiar lesson from medical research: if you search harder with more-sensitive tools, why yes you'll find something.

2. you have capacities now you didn't have previously based on "lessons learned." Think of it this way: your threat surface increased, but your threat resilience, which is your capacity to adapt, also increased.

Resilience is your most important behavioral asset in the always-on security environment. Self-confidence is not resilience; an AI-based SOC is not resilience; more certifications are not resilience; quick-fix "burnout" interventions are not resilience. These are all important and we endorse them. However, these are patches that don't mitigate the real issue that you work in an always-on security environment. 

Resilience means thinking about your own self-management as a means to create engagement with your tradecraft, engagement with your team, and appreciation for your own resources. These levers -- craft, team, personal growth -- are keys to resilience and excellence. The outcomes of resilience will follow: the judgment to escalate intelligently vs. just triaging, the psychological flexibility to adapt when incident response fails; trust in your team so you don't burn out alone; self-care (not self-medicating please) to move to a new level of capacity.

Brett Steenbarger, a psychologist who coaches hedge fund traders, talks about resilience as, fundamentally, coming back to homeostasis -- not getting overly depressed about a bad trade or overly excited about a good one. That's a good headline but if you read what Brett says further he talks about homeostasis as an outcome of growth. You don't have an innate level of homeostasis, you develop and refine it. 

That's resilience.

Always-on security is not a drill or a set of over-stuffed binders. It's your presence in each moment of your cybersecurity career.

Ask us how you can prepare to meet the moment of always-on security.

(image credit: Santeri Viinamäki, CC BY-SA 4.0 <https://creativecommons.org/licenses/by-sa/4.0>, via Wikimedia Commons)

Comments