Posts

Showing posts with the label NIST CSF

Litany Of The Hacked: July 2026 Wrap-Up

Image
  Sing, o goddess, of the litany of the hacked from July 2026. Sure, we're keeping with the Homer theme, and yes we appreciate that the Anthropic product that 'launched a thousand ships' (+/-) was named Mythos.  Let's check the litany for this month. Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes: Department of Education and police national legal database (both UK)...Fairlife Milk (a unit of Coca-Cola)...AssuranceAmerica...Greenfield Communications...Accenture Consulting...Homeland Security Information Network (HSIN)... In mitigation: one week later there is already a 'post-mortem' of the OpenAI/HuggingFace incident c/o Jen Easterly : https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem. We'll come back to that another time. But in aggravation (yep that again) Anthropic announced that one of its products also acted autonomously, though allegedly...

Happy Semiquincentennial!

Image
You may have been around for the bicentennial...maybe you'll be here for the tercentennial...but seize the semiquincentennial while you have it! (image credit: After Jasper Johns, Public domain, via Wikimedia Commons)

The Art of Cybersecurity

Image
I love the phrase "more art than science" because I feel that only pure science is "science" in the popular sense of "following clearly defined rules and therefore providing clear, reliable answers." There is a similar issue with logic and mathematics; if you can somehow cram a topic into either one of these containers then whatever ridiculously wrong conclusions you come to are given instant credibility. For example, this old chestnut: All apes are hairy. All men are hairy. Therefor all men are apes. This seems logical, but it isn't logical and it certainly isn't true. So it is with cybersecurity: Cybersecurity is about access to computer technology. Technology is science. Therefore cybersecurity is a science. Cybersecurity is about human beings interacting with computer technology. Human beings are inconsistent and capable of ignoring reason and of using terrible judgement. Therefore cybersecurity is most definitely not purely a science. If you p...

Litany Of The Hacked: June 2026 Wrap-Up

Image
The litany of the hacked is our listing for each known/reported hack in the previous month. The point of the litany is not shame but awareness-raising that, well, these sorts of things happen. Apparently, hackers went for the lay-up while the NY Knicks wrapped up a WORLD CHAMPIONSHIP to attack MSG. Thanks -- not -- a lot, MSG. And so, the litany of the hacked, which for June 2026 now includes: Madison Square Garden Sports Corp...Station Casinos… Israel Holocaust Support Center…Dashlane…Meta’s AI support bot…Anthropic's Claude platform...MyPillow…Fortinet...California Water Service...NAIC...Sacramento Fire Department...University of Nottingham...Texas Department of Fish and Wildlife...Alamo Heights ISD...Prince George's County (MD)... Other than the MSG hack, the one that catches our attention is the attack on Anthropic. In this attack, Anthropic accused a Chinese commerce company that shall not be named in setting up a flood -- almost 25000 -- of fake accounts to steal informat...

Mapping Leadership Talent To Cybersecurity: Part 6, Recover

Image
And eventually -- it stops. They move on. You are victorious, but frazzled. Now is the time to take stock, rebuild relationships, and prepare for the next engagement. Time for the final NIST CSF pillar, Recover. Let's let Brendan discuss it : Recover is the step you take to undo the damage or restore the service. Recover is a bit more deliberate and thoughtful than Respond. You have time pressure, almost always, but there is rather less of it. The cybersecurity crisis is over, but if you need to keep your systems down for the recovery, then the operations crisis has just begun: how long can the downtime continue, in the name of preventing future problems and gathering evidence? The answer depends on your situation. Your ability to arrive at that answer often depends on how well thought-out your IRP is. Recover should always end with a review that considers how to be better in the future. This is a crucial step to making you safer than you were before. It is very common to just want...

Mapping Leadership Talent To Cybersecurity: Part 5, Respond

Image
It's time to break the glass -- don't just stand there, do something! This is no time to find out whether your cybersecurity governance is adequate, or whether you have identified all the right assets, or whether your protection protocols are in place. Your systems have detected a problem and it's time for action. Let's let Brendan discuss it : Both the Respond pillar the Recover pillar are unlike the other three, they are triggered by an incident and different from the other steps because the other steps are part of normal operations. Respond and Recover also always happen in tandem, which is why we group them together as part of the Incident Response Plan (IRP). The IRP formalizes incident handling, so that everyone knows what their role is in advance. The IRP covers both the Respond step (halting the problem and trying to restore normal operations) and the Recover step (undoing as much of the damage as possible, preventing a recurrence). The IRP gives us a Respond ch...

Mapping Leadership Talent To Cybersecurity: Part 4, Detect

Image
  Detecting cyber-intrusions or threats to information systems falls naturally in the NIST CSF sequence after you've identified what assets you're going to defend and you've developed a process to defend those assets. Let's let Brendan discuss detection : The Detect pillar is where daily Cybersecurity operations come into play. Someone has to do the monitoring, and not simply watch the events go by, but confirm that the activity being monitored is either expected or appropriate. Most importantly, the Detect step is about separating the worrisome from the normal, and then taking appropriate action to either confirm that there is an issue or to discover that there is a good explanation. If there is a problem, then we have “an incident” so we go to the Respond pillar (and Incident Response Plan (IRP)). As part of Detect, you gather evidence. Sometimes the evidence shows you that all is well. Sometimes the evidence shows you that something odd is happening. Sometimes the ev...

Mapping Leadership Talent to Cybersecurity: Part 3, Protect

Image
Cybersecurity fundamentally is about managing risks to information system assets through the protection of those assets. Sure, there are many parts and processes related to protection but it's the core ethos of cybersecurity. Let's let Brendan discuss it : As we covered in the first post in this series, the Identify pillar gives us a list of assets (what we are protecting) and for each asset, a risk (what we are trying to avoid). The Protect pillar is mitigating each of the risks for each of the assets. The procedure or method or technology that we use to do the mitigating is called “a control” and we say that the Protect pillar “assigns a control to each risk.” A control should produce evidence that it is working, otherwise monitoring that control is difficult and overseeing the monitoring is impossible. It can be tricky to distinguish assets from controls. In cybersecurity, an asset is a resource that an organization needs to protect, like hardware, software, data, or networ...

Mapping Leadership Talent To Cybersecurity: Part 2, Identify

Image
  This is Part 2 of our series on mapping the Pythia Cyber Cybersecurity Leadership Talent Stack to the NIST CSF 2.0 pillars*. Part 1, on mapping cybersecurity leadership talent to Governance, is here .  Maybe the most obvious part of cybersecurity is identifying what needs protecting. This is where the NIST CSF starts also.  Let's let Brendan discuss it : The Identify pillar identifies cyber assets (just “asset” henceforth) which are on the "Must Protect Now" list. We recommend that, as you go along, you keep a "Must Protect ASAP" list and a "Should Protect Someday" list. Why isn’t there a single Asset List? Because no one has all the time and money and experts that they could possibly need to protect anything and everything of value to their organization. What is an asset in this context? An asset has to meet all of these requirements: An asset is “critical” by which we mean its absence would severely limit operations (It can be tricky to distinguish...

Happy Juneteenth!

Image
Today is a day in the US to celebrate the Emancipation Proclamation . The commemoration started in Texas because it took from 1 January 1863 until 19 June 1865 for the news to reach Texas that slaves were freed. Why that long? Because -- Texas. Also there was a war and Texas was a Rebel state, and there was no Internet. And DC is a long ways away from Galveston, TX where the news was announced. Here are two lessons to take from this holiday. First, all people are created equal. Sure, some are taller, some better at coding, others more empathetic or better-looking or more adept at poetry. But we're all equal.  "Buit wait!," you exclaim, "Isn't that what the Declaration of Independence says and not the Emancipation Proclamation?" We'll get to the DoI in a few weeks but think of it this way. The Declaration of Independence does indeed capture the novel idea that "We hold these truths to be self-evident, that all men are created equal, that they are en...

Mapping Leadership Talent To Cybersecurity: Pt. 1, Governance

Image
Of all the BORING parts of cybersecurity, or maybe of any process such as ruling in Medieval England, start the counter with governance. It's not why you went into comp sci or systems administration work or anything like that. Seems only like people who can't code go there. Surprise! This is one of the most important touchpoints a technical leader has with the organization. Remember, you may know how to code but the general managers in the organization do not -- and they know how to do governance.  In fact NIST didn't have governance originally on its CSF pillars list. But it's there now. Let's let Brendan discuss it : This function is what you would expect and a great step toward what is needed. Adding this function validates Pythia Cyber's top-down approach in which we start at the top of the organization to set the priorities, the budget and the goals. This function makes the link to Risk Management clearer as well. We hope that this official recognition of t...

The Respond or Recover Pillar: Like Practicing Bleeding?

Image
There is an old military pilot's saying that sky diving is like practicing bleeding. The point is that bleeding is unpleasant, often unavoidable and something that you can probably just figure out as you go along, so why worry about it before then? Except that you absolutely should not just figure it out as you go along. You absolutely should know basic first aid and have an idea of how to stop bleeding should it occur. Alas, this same attitude often makes a hard job harder: implementing your  NIST CSF  Respond Plan or Recover Plan in the face of an outage. And yes, this is another example of how behavioral science greatly improves cybersecurity. Human beings avoid negative stimuli and seek out positive stimuli. We all know this, but many of us pretend that this isn't true or worse, that it isn't true of us or our team . But it is true and if you don't actively make this work for you it will absolutely work against you. What does this have to do with cybersecurity, you...

Cybersecurity Is A Team Sport

Image
As part of our continuing series about how and why we bring behavioral science to cybersecurity let us consider that cybersecurity is a team sport. How so?  To start, your organization has a team engaged in direct competition with other teams. The other teams are criminals, vandals, spies and disasters such as hardware failure, software bugs and bad weather. Underestimate your competition at your peril. Like a sports team you cybersecurity team has members with different talents. This is fine because the game you are playing has different positions (roles) as laid out by the  NIST CSF : Identify--requires analytic skills to identify what is really important Protect--requires management to set priorities and IT understanding to make policy & procedure Detect--requires a dogged determination to remain vigilant at all times Respond--requires a good plan and the ability to execute under pressure in an ad hoc team Recover--requires a good plan and the ability to balance the co...

Behavioral Science and the NIST CSF Identify Pillar

Image
Building on our current elevator pitch this post will talk about how and why we apply behavioral science to the Identify pillar of the  NIST CSF . On the face of it, the Identity pillar is the pillar that everyone "gets" because it is so delightfully straightforward and lacking in veils of technological mystery: list all the digital assets your cybersecurity is supposed to protect. There are at least three complicating factors here when I watch this process in action in the wild: the problem of obviousness, the problem of obscurity and the problem of command. Each of these problems has their solution in behavioral science, not technology or methodology. What Is A Digital Asset? In this context, a digital asset is a data set or computer system that you need to do your job. Sounds pretty simple, doesn't it? The Obvious Is Not Always Obvious The commonplace gets overlooked, we all know this. This facet of human nature bites you twice in this process. First, you will tend to...

Pythia Cyber Elevator Pitch 2026-06-11

Image
Like everyone else, we get asked "what's your elevator pitch?" We always have one, but we find it a useful exercise to revisit and revise ours to better fit this ever-changing world of cybersecurity. Here is our latest elevator pitch.

Cybersecurity Training Should Not Stink

Image
A colleague recently tried to be polite about Pythia Cyber's willingness to help organizations overhaul their annual mandatory company-wide cybersecurity training. She was polite but persistent in her questioning the wisdom of this move. Her comments became ever sharper though. Such training is usually a fig leaf for insurance reasons, Nobody takes it seriously. It doesn't accomplish anything. All such training I have ever had has been boring and useless and even a little condescending. I agreed that all of the observations were usually true. So then she tried a different tack: why is Pythia Cyber's training any different? This was a very useful question. Our training is different because our goal is to improve cybersecurity rather than checking bureaucratic boxes. Instead of the scolding tone and the list of dumb things to avoid doing, we use the NIST CSF to frame enlisting your people in the cybersecurity cause. We recommend that you start by surveying your people to find...

AI and Cybersecurity in 2026

Image
Here at Pythia Cyber we engage in real-world consulting. We don't provide you with theoretical solutions to real-world problems. This means that we really try to avoid cool-seeming (but actually useless) topics like "AI and Cybersecurity in 2026." Eye-catching as these headlines are, they either presage a bland and shallow take on a complex issue or they make deep and simplifying assumptions. An example of the bland take is "AI is going to super-charge the cybersecurity threat environment in 2026!" An example of the deep and simplifying assumption is "AI is going to make all phishing into spear phishing in 2026!" You might as well ask "what about electricity and cybersecurity in 2026?" Well, lots of things in cybersecurity will be affected by electricity in 2026, to a high degree; what will thinking about this do to help you protect your digital assets? Not much. Here in the real-world we know that we cannot take perhaps the most general-purp...

Become Expert At Taking Expert Advice

Image
A classic is something that everybody wants to have read and nobody wants to read--Mark Twain With apologies to Mark Twain, cybersecurity is something everybody wants to have and nobody wants to have to do. Over and above the sad truth that security is inconvenient  is the sadder truth that cybersecurity touches the entire organization so many of us are required to interact with cybersecurity without really knowing what it is or why it demands what it demands. Thus most of us either have to trust our cybersecurity team to have made the right trade-offs between convenience (productivity) and security, or we have to find a way to join the conversation without wasting anyone's time. (The second option is the one we at Pythia Cyber recommend, but it is difficult which is why our cybersecurity consulting practice is half behavioral science and half classic cybersecurity.) As with so many other aspects of life in the rapidly-changing, technology-driven 21st century, finding the balance ...

Appreciation: Dr. Eric Cole

Image
We take a moment to note the death of Eric Cole, PhD. We found his writing about cybersecurity to be enlightening, inciteful, and thoughtful. RIP. (image credit: LinkedIn post)

It Is Always Time for Zero Day Vulnerabilities

Image
Oh, sigh. It has only been 5 months since my last post on Zero Day Vulnerabilities  and now I am provoked by news of multiple such vulnerabilities in various Microsoft products . My post was about what that term used to mean, came to mean and means now. It was also about why reacting to these issues has become a potential vulnerability in itself. The short version of the definition is that "Zero Day Vulnerability" now means "you should do what you can about this vulnerability as quickly as you can." The short version of the dangers of panic is that panic is dangerous: just because you need to react to a vulnerability ASAP does not mean that you can cut corner or rush. Remember that not only are human beings prone to error when they rush but that evil human beings may try to exploit that tendency by offering corrupted patches which are, themselves, malware. The best way to be able to react ASAP without rushing is to plan ahead. Of course you cannot predict when any g...