Posts

Litany Of The Hacked: November 2025 Wrap-Up

Image
Did your November cybersecurity process pile up like a mulch stack? We started a series named the litany of the hacked . It's a monthly list of entities that have been successfully hacked. The point of these litany posts is to note that this sort of thing happens and it has consequences. Pretending that you can whistle past the graveyard in cyberspace is foolish and delusional. And so, the litany of the hacked, November 2025 edition. The litany now includes: US Congressional Budget Office...Manassas City, Virginia Public Schools...Logitech...Mobile Commons and OnSolve CodeRED (two text alert system providers)...Asus...Protie...SitusAMC (banking mortgage loan servicer)...Harvard University's Alumni Affairs and Development Office systems...Princeton University's alumni affairs and development systems...University of Pennsylvania's alumni affairs and development systems...Google's Antigravity platform...KFNC (Houston's ESPN radio station)... That's quite a vari...

Enjoy A Hack-Free Thanksgiving

Image
We at Pythia Cyber are taking a break this Thanksgiving. Never fear, we'll return on 1 December 2025 with...The Litany Of The Hacked!   Ask us how you can avoid mistaking the giant fruit bat for a Thanksgiving turkey...

Transforming Yourself: Finding The Career Signals In Your Labyrinth

Image
Recently we came across this small labyrinth in Charlottesville, VA. It is an Eagle Scout project by Carys Smith of Boy Scout Troop 1029 that was completed in May 2023 -- congratulations, by the way! Most of the time we don't think of the difference between a labyrinth and a maze. This sign helps us get our bearings on the distinction, quoting in full: A labyrinth is not a maze. A maze is designed for you to lose your way, a labyrinth is designed for you to find your way. I couldn't find this quote on the Internet, so -- double congratulations, Carys! Our brief series on transformation and change management comes to this point: In your cybersecurity career, you may feel that you are in a maze. But it's not a maze because no one is trying to make you lose your way. It is a labyrinth where you need to reflect, reorient, and choose your next step, one step after another. Your cybersecurity career is a process of continually finding your way. Our former colleague Adam Dickson ...

Business Leaders Speak This Language -- Do You?

Image
  Speaking of managing a transformation: Our HR Guru JP Elliott is back again with language skill tips! Sometimes as a technologist you must wonder what your nontechnologist peers are talking about. After a while it becomes familiar enough, you can make out patterns and themes, but their business language skills are usually superior. JP has some suggestions, or directions, for you: Master these metrics and you'll be on the road to speaking their language:  • Revenue Growth • Gross Margin • EBITDA • Free Cash Flow Sure , you say, right after I reconfigure this system! OK maybe but you need a guide. Here are JP's recommendations for learning to speak the language that your executives speak: 𝗛𝗲𝗿𝗲'𝘀 𝘆𝗼𝘂𝗿 𝗿𝗼𝗮𝗱𝗺𝗮𝗽 𝘁𝗼 𝗯𝘂𝗶𝗹𝗱 𝗳𝗶𝗻𝗮𝗻𝗰𝗶𝗮𝗹 𝗮𝗰𝘂𝗺𝗲𝗻: 𝟭. Find Your Finance Mentor 𝟮. Read Your Company's 10-K (yes, actually read it)  𝟯. Calculate True Operating Costs  𝟰. Learn One Metric Monthly  𝟱. Connect Everything to Business Impact He...

Feast or Famine in Change Management

Image
This is the second of two related posts; the other one is here . In theory I am all for change management; in IT change is inevitable. In fact, to keep things the same you often have to change them constantly. In a field with so much flux built in, managing the change is essential. In practice I see two problems with how change management is implemented. In accordance with common practice I will keep my rants to one issue per post. This post is about the difficulty of avoiding ruts in Change Management. One rut is to say "every change goes through maximum change management" and the other rut is to say "change management is so painful that we will create an 'emergency change' or 'trivial change' pathway and use that pathway ALL THE TIME." (In this context, "overhead" means testing, validating, documenting and deploying.) In the previous post I examined how difficult it is to be sure that a given change is as small (in scope and therefor pres...

The Butterfly Effect & Change Management

Image
This is the first of two posts on this topic. The second one is here . In theory I am all for change management; in IT change is inevitable. In fact, to keep things the same you often have to change them constantly. In a field with so much flux built in, managing the change is essential. In practice I see two problems with how change management is implemented. In accordance with common practice I will keep my rants to one issue per post. This post is about the difficulty of assessing the potential impact of any given change, and how that leads to poor change management decisions. In an idea world rolling out changes is an exercise in risk analysis: for a small change there need only be a small amount of overhead while a large change merits a large amount of overhead. (In this context, "overhead" means testing, validating, documenting and deploying.) Note that we are often a bit sloppy with our terminology here: is a small change small in scope (amount of stuff being changed, ...

Be The Transformation You Wish To See

Image
When was the last time you were not only 100% satisfied with how things were and you not only wished they would stay that way because they were so perfect, you worked to make those circumstances or things stay just as they were? Can't think of anything like that, can you. Nope. We've written about the speed with which cybersecurity skillsets change. We've written about coaching and the necessity of change. We've even written about how the cybersecurity threat environment changes so rapidly that it is never the same over time. Point is, your cybersecurity career is an active process of transformation . You need to manage the transformation actively. That means you are gaining insights, knowledge, and experience; you are growing your influence (let's hope); the threats you face are changing, which means the organization's perceptions of its risks are changing.  Cybersecurity is about authorized access, and that access is an ongoing transformation of how users, ...