6 Matching Annotations
  1. Sep 2026
    1. “The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following,” he said, referring to a recent FBI emphasis on 10 fundamental defensive measures like multifactor authentication.

      How much of the risks would really be prevented if we implemented better cyber security practices.

    2. “The wave is coming. I don’t think we’ve hit the crest yet,” Bilnoski said. “We see an exponential increase in the use of AI, whether it’s nation-state or criminal.”

      If we are hearing everyone from Bill Gates to Jason Binoski say that AI is heralding our doom, why aren't we doing anything about it?

    1. That experience fundamentally shifted my mindset: it is much easier to be compliant than secure. Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.

      Has this always been the case? Adversaries have generally been more adept. I agree that it speeds up threat actors capabilities, but threat actors have always been more adept.

    2. ederal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

      What is "operational reality"? I think for businesses, it is staying in the "green," so checking the boxes for programs and policies. Whereas, in the scope of the "defender's dilemma," the defenders users these programs and policies to their advantage.

    1. For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation.

      From Ben Buchanan, "The Legend of Sophistication," "sophistication bears on the applicability and utility of the offense-defense balance in cyber operations, an area of both academic and policy debate." "Sophistication" is often an ill-defined term. I think in this case, "technically clever" would probably provide a better definition.

    2. The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.

      In terms of tooling gap, there is some variability. While state-sponsored adversaries are generally better resourced, I would argue that some groups like "Salt Typhoon" and "Volt Typhoon" are very adept at living-off-the-land. And numerous other APTs are likely using open source and security tooling to great effect, so I would argue that their knowledge of how to utilize those tools has made them much more effective. And that, is where the gap is truly closing. Where an AI model can potentially walk you through an attack chain