Posts

The Circle of Cybersecurity: Managers to Leaders

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Mangers to Leaders. That arrow is labelled "Status" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Status Like "evidence," "status" is a concept we all think we understand until we need to define it. One of the big steps in implementing a good CSP is agreeing on the compromise that is status. There is always compromise because there are limits to what the evidence the Managers have been given and there are limits on what the Leaders can comprehend and absorb. One colleague of mine once joked that "boardroom reports...

The Circle of Cybersecurity: CSEs to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Cybersecurity Engineers (CSEs), the folks on the front lines, to Managers. That arrow is labelled "Evidence" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Evidence In most social situations demanding proof that people are doing what they said they would do is rather rude. This taboo has lead to a dismaying number of CSPs being "faith-based" by which I mean that Managers have faith in their CSEs and assume that all is well unless and until something goes wrong. Alas, politeness is not what is needed in an effective CSP. In cyberse...

The Circle of Cybersecurity: Managers to CSEs

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the second downward arrow, what flows from Managers Cybersecurity Engineers (CSEs), the folks on the front lines. That arrow is labelled "Procedures" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Procedures In theory all you need for your CSP is for procedures to be transmitted from Managers to CSEs. In practice, this is where the rubber meets the road. To stretch the analogy, this is where the tires of your Policies meet the road debris of previous decisions, the potholes of cyberattacks, the ice of accidents and the oil slicks of negligence. And, of course, the imp...

The Circle of Cybersecurity: Leaders to Managers

Image
A recent post of mine, The Circle of Cybersecurity ,  was a bit dense so I am expanding pieces of it in separate posts. This post examines the first downward arrow, what flows from Leaders to Managers. That arrow is labelled "Policies" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Priorities In such a framework the first thing that leaders have to do is bless a list of digital assets to be protected. The managers may well provide a super set of all possible candidates, but the leaders need to impose priority on that super set. Almost no organization can protect every possible digital asset all the time. Resources Once the digital asset list is set for the time period--usually a year--then the organizati...

The Circle of Cybersecurity

Image
Ted recently wrote about the pain of rewarding performance with promotion and the purported death of the entry-level CS job . This got me thinking about the actual CS jobs that I have seen in the wild.When looking at actual CS jobs, size matters so we will start with that dimension. Small Organizations In very small organizations there isn't a Cybersecurity Program (CSP) so much as there is a guy or gal in IT who moonlights as The Person Who Keeps Us From Doing Dumb Stuff. This is a part-time Cybersecurity Engineer (CSE) even if they don't call it that. There is no formal communication channel between leadership and the valiant part-time CSE. The disaster-recovery aspect of the job is folded into the system administration duties. Medium-Sized Organizations In medium-sized organizations you have a CSP with a few people in it, mostly refugees from IT who Secure The Network. This is often a supervisor and two helpers who sort of communicate with senior management on an ad hoc basi...

R.I.P. Entry-Level Cybersecurity Jobs?

Image
This is not the first or last time we will address the (alleged, purported, actual, imagined) demise of the entry-level job. That newbie fresh-out-of-college or right-out-of-the-military cyber-defender that had all the certs and none of the savvy? You might kiss it goodbye.  But in reality you're kissing that position description goodbye, not the role.  In brief we at Pythia Cyber think the nature of entry-level cybersecurity work will change but not disappear. Like any change process, its trajectory of change is unknowable; 5 years from now we will have a new labor force that arose from pressures we have now. Over at The Signal , Alex Banks is having all of the angst. These three nonconsecutive paragraphs tell his story: Nobody learns their trade in their first year. If you’re honest about your own, what you actually learn is a collection of many small micro-experiences that compound into a long list of intangibles that can rarely be named yet can only be sharpened through ...

Promotability & Performance -- If Only It Were That Simple

Image
Every security team has one: the analyst who triages faster than anyone else, the engineer who reads a packet capture like a second language, the threat hunter whose instincts catch what the tooling misses. When a leadership slot opens up, that person is the obvious pick. They're the strongest performer on the team. They are also, disproportionately, a bad bet for the management role, a specific kind of risk most security organizations aren't measuring. The reason is more precise than "not everyone is management material." Performance and potential are different psychological constructs, predicting different outcomes, and most security talent pipelines quietly collapse them into one. Here are five key points for you to remember in your review of performance v. potential. First point: climbing is not the same skill set as performing . Advancing in an organization and performing at higher/management levels draw on overlapping but distinct profiles. The people who get no...

Robot Performance Management Risks = f(Cybersecurity AI Agents, Human Risks)

Image
You have a performance review cycle for your SOC analysts. Goals, check-ins, regular conversations about what's working and what isn't. When someone stops performing, you notice, you document it, and eventually you do something about it. When did you last have that conversation about your AI agents? You're not alone if your honest answer is "never." If performance conversations with your human cyber-defenders already make you feel like it's time for a major medical procedure without enough anesthesia, adding one more with an agent sounds like the last thing you need. In a recent McKinsey Talks Talent episode, Kate Smaje put it plainly: most organizations can't recall the last time they prioritized a conversation about the performance of their nonhuman labor. We've built decades of infrastructure for managing human performance. For agents, most companies have nothing. That gap should worry a CISO more than almost anyone else in the building. Smaje make...

You & The CFO: A Risk Management Partnership

Image
Brendan has written a lot lately on cybersecurity as risk management. Another person in your organization who manages risk is the Chief Financial Officer (CFO). Is there any ovelap? Your CFO is supposed to keep the company's books straight and tell the board when something doesn't add up. Now imagine telling that same CFO: also, go adopt the new accounting software company-wide, use it yourself for the close, and be the one who catches it when it's wrong. That's roughly the position CFOs are in with AI according to Deloitte's Q2 2026 CFO Signals survey . More than half of CFOs are using AI for financial planning and budgeting. Forty-one percent use it to analyze financial data. Yet only 43% say they're very confident in their organization's AI governance framework. Most land at "somewhat confident," which is a polite way of saying "we haven't stress-tested this," which is even more polite than "I have no idea." As a CISO you...

How to Describe Cybersecurity: Bottom Up vs Top Down

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. After we explain how C/S isn't an IT function , they often ask "then why it is always presented to us as an IT function?" The answer is pretty simple: because most explanations use the bottom up approach. Those explanations work backwards from foiling an on-going cyberattack by showing an evil hacker in his lair and contrasting that with our heroes at their desks, heroically typing away to thwart evil in real-time. This image is ridiculous but in an understandable way: this image is visual, which suits film and TV. This image compresses the time-scale, which suits film and TV. This image gives us a nice symmetry of evil versus good. Of course this image is grossly simplified, as so many images are. We show teaching as the act of standing up in front of a class and talking or writing on the whiteboard. Anyone who has ever known a teacher kn...

Cybersecurity As Management Fuction Example: Ransomware

Image
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. At least they pretend to be surprised. We suspect that they really want  C/S to be an IT function because then they  wouldn't have to take any responsibility for it. As we have written about before, part of this reluctance to embrace C/S comes from fear of the unknown: most managers and leaders are quite familiar with accounting, marketing, sales, legal and HR. They are not familiar with C/S. Part of this reluctance comes from fear of the scary way in which C/S is presented, as an arcane dark technological enterprise marrying crime and science. Hooded figures in the dark type away on black keyboards, surrounded by so many monitors, all of which have green text on a black background. As we will see in a subsequent post, this image is the result of laziness and fatigue. In this post we will give a counter example that any business person can understa...

Keeping You In The Race Every Day

Image
As a professional you are always in the race. The bad guys are running hard. Your competitors are innovating. You're getting bogged down in administrivia, your costs are soaring, and your fellow employees see you as the captain of the no-fun team. How do you keep your focus? We saw this piece, " The mile world record holder can teach you about more than just running ," recently on The Athletic (behind paywall). The story is about how Josh Kerr, who recently broke the men's world record time in the mile run at 3 minutes 42.66 seconds (which is nuts), keeps his head in the game. It seemed like something you could benefit from. One reason you could learn from Kerr is that his approach is simple, and simple is best, because you need to keep your head in the game too. 1. Write out your perfect day. That one caught my attention also. What about you? Are you able to write out what your perfect day is? (Presume we keep it in the realm of work- or profession-related.) Are you ...

Who Do You Trust More -- Your Dentist Or Your CISO?

Image
You probably have an appointment schedule with your dental office that gets you there every 6 months. The best case scenario is that these are routine cleaning appointments with 90 seconds of DDS time to tell you that yep everything still looks good. What happens when, well, things don't look so good but you don't have any tooth pain? Do you just do what the doctor says and get the treatment (for maybe thousands of dollars) because after all the doctor is a medical professional with very significant educational experience and credentials that need constant updating? Do you go dental practice shopping because you suspect that your current dentist wants to drill and bill? Do you trust your dentist? What about the CISO of the company you just invested in? Do you just do what the cyber-practice leader says and get the AI-based SOC (for maybe millions of dollars with constant upgrades) because after all the leader is a battle-tested professional with very significant educational exp...

Litany Of The Hacked: August 2026 Wrap-Up

Image
The Litany of the Hacked is a monthly feature to, um, highlight the fact that hacks are nearly everywhere.  Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: GitLab...Oracle WebLogic...Norway's public digital services...an unidentified powerplant in the UK (continuing the theme of attacking utilities )...Boston Scientific...Alation...multiple US federal agencies...OpenAI (aggravation: attacked by its own AI agents)...Sheel...Phillips...Siemens... We're moving into an era where, with the encouragement of the White House, private-sector companies are going to start hacking adversarial (state-affiliated) entities. This is going to get ugly. Brendan has been focused this month on insider threats as arising from error (oopsie), negligence (I don't wanna), or malice (because they owe me and because I can!). What we see on this month's litany when married to Brendan's review is t...

Insider Threats Part 3: Malice

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice. This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. Malice is intentional. Once you determine that the incident was malicious your options become few and obvious: dismissal, criminal prosecution or one of those murky NDA-driven arrangements. If the incident was caused by someone on their way out the door then you have to balance the reputational cost of criminal prosecution with the deterrent effect or satisfaction or legal obligation. If the incident was not  caused by someone on their way out the door then their motives might not be easy to fathom. Unless you are in law enforcement it can be difficult to find out if someone recently received significant money or other considerations. Unless you are a trained mental health professional it can be difficult to un...

Insider Threats Part 2: Negligence

Image
This is the second in a series about the different kind of Insider Threats: Accidents , Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with negligence you have to confront the fact that someone did not do what they were supposed to do. This isn't a matter of fine-tuning policy or clarifying procedure, as might be the case with Accidents. This is a case of a human failure rather than a human error. As such it falls more into the behavioral cybersecurity category than into the classic cybersecurity category. These...

Insider Threats, Part 1: Accidents

Image
This is the first in a series about the different kind of Insider Threats: Accidents, Negligence and Malice . This series is itself part of our recent focus on Insider Threats. In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure. When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment). When dealing with accidents, the cause might be just very bad luck, which case what you learn is that sometimes bad things happen to good Cybersecurity Programs. The cause might be carelessness, in which case you need to determine if the person is chronically careless or if there was a some reasonable cause, such as the birth of one's first child. The cause might be a process or procedure whic...

Identifying Insider Threats Before And After They Become Threatening Insiders

Image
Pythia Cyber's co-founder  Brendan recently posted about insider threats. An insider threat is someone who can cause damage, either unintentionally or through negligence or through deliberate malice. There is a cottage industry regarding insider threat especially in law enforcement and intelligence work.   We at Pythia Cyber are in the behavioral cybersecurity arena. As much as insider threat, which are behaviors, affects the risk management of cyber-systems, we address insider threat. But unlike the cottage industry we focus on identification before a potential threat actor is hired as well as after , and our tools review both employees and managers . It is critical to start, before getting to discussing insider threats, by asking you what a threat is.  Brendan mentioned unintentional damage (threat): knocking something over, unplugging a system, etc. That's a talent and performance management issue. Then there is negligence: not auditing logs, not being current i...

Upskill, Reskill, Mentor & Support

Image
Ted's recent post about training cyber defenders--the folks who actually do the monitoring that is the heart of your Cybersecurity Program (CSP)--touched on mentoring and Pythia Cyber's focus on Talent Acquisition & Upskilling (TAU). In this post I want to consider the why  and the how  in a little more detail. Why is TAU so important to building cybersecurity teams?  Talent acquisition , as opposed to recruiting based on experience, is so important because talent is adaptable while skills often are not as transferable as we would like. This means that you should hire talent when you can, especially in fields like cybersecurity where the only constant is change. Adapt or fail. In this field sticking the tried-and-true feels safe but is quite risky. Acquiring talent means that you have people who can adapt by learning new ways to deploy their talent. Upskilling , as opposed to proficiency training based on previous issues, is so important because we are constantly on ...

The New Frontier Of Cyber-Defender Development

Image
As I went through O'Hare Airport today I traveled from Terminal B to Terminal C. As all of us who have done so have found, there is a cool moving walkway with a soothing LED lightshow overhead. Near the end of the moving walkway is this announcement: The moving walkway is about to end. As a manager you used to hire new cyber-defenders right out of college, the military, or from other companies, and they basically knew what to do. Your responsibility was to train them on how they do things at your employer. Then they usually got the picture and more of them were at least minimally successful. The moving walkway is about to end. We talk a lot about "TAU" at Pythia Cyber, an acronym we/Brendan developed that stands for talent acquisition and upskilling. We also have discussed the four pillars of building a successful cyber-defense team: Talent, Organization, Engagement, and Development. And we've highlighted what Bhushan Sethi says about how AI will, well, obliterate t...