The Sky Is Falling: Confessions of a Reformed Cyber Cassandra
I've been practicing increased cybersecurity for a few weeks now. Not the NIST 800-171 kind. The kind I picked up watching our newest cyber hires operate — a stance, a vocabulary, a very particular energy. This week I tried it myself: I walked the facility declaring, that the sky was falling. We shall surely be breached. I said it enough times that it stopped sounding like a bit.
It worked exactly the way it worked for all the Cyber practitioners I had observed. The executive level called an emergency meeting with Cyber. What shall we do, what ever shall we do, they asked, visibly alarmed.
So, we told them.
Spend more on analyst and cyber tools. Hold more meetings. Bring in a C3PAO to assess the compliance program — the paperwork, specifically, because God knows the assessors don't actually care about the control set if you do not have a 300-page SSP, and if we're honest, neither does the org chart that funds them. Hire four cyber analysts. Hire an ISSM to keep the paperwork current. Hire two systems administrators to go implement the controls the paperwork claims already exist.
Leadership said yes to all of it. That should bother you more than the screaming did.
Meanwhile, business development kept doing what business development does — winning more work, on schedule, indifferent to whatever's happening two floors down in the SSP. The paperwork got updated, because paperwork has a deadline and someone's job depends on the deadline. The control set did not get updated at the same pace, because security — in some places — is a suggestion box, and the suggestion box answers to a standing committee of complainers who will find a reason every single sprint that this is not the time to break the thing that works in exchange for the thing that's secure.
I've come to believe there are at least two guaranteed breach mitigations left on the table. One is a system with no network cable in it. The other is a pencil, a legal pad, and a safe. Everything else — every analyst, every ISSM, every tool we bought during the emergency meeting — is a probability adjustment, a purchase of risk reduction, not a guarantee. That's not a criticism of the people doing the work. It's a description of what happens when an assessment industry gets built around evidence of compliance rather than evidence of security, and an organization built around revenue rather than risk decides, reasonably, to feed the machine that's actually being graded.
None of this means the hires were wrong or the tools were wasted. The analysts are good. The ISSM is drowning in exactly the paperwork we asked for. The sysadmins are trying, control by control, to close the gap between what the SSP says and what the network does — a gap that reopens slightly every time BD signs something new, we add new systems under a tight timeline. That gap is not a scandal. It's the normal operating condition of many compliance program I've seen, and pretending otherwise is its own kind of security theater.
So, here's the confession, and the point: screaming that the sky is falling gets you a budget. It does not get you a control set. If you want the second one, someone in that emergency meeting has to ask a harder question than "what shall we do" — they have to ask, "what are we actually willing to slow down for." Until an org is willing to answer that honestly, the compliance program will keep maintaining the paperwork, business development will keep winning its contracts, and the only truly air-gapped thing in the building will keep being the notepad in the safe. (I love the notepad in the safe)