
Share your knowledge and learn from others! Exchange valuable security best practices to stay informed and improve cybersecurity tactics. 🤝
Learn and Share Cybersecurity Best Practices
124 members
European Cyber Security Month - Measuring Success @channel It’s my final instalment of things to consider ahead of Security Awareness Month, so let’s tackle something meaningful - metrics. This month gives us some rare things: budget, attention, and a captive audience for four weeks, and the hard part isn't producing the content (we've done that for you here - sosafe-awareness.com/ecsm-2026) - it's proving it worked. Many of us finish the month with ticked communication objectives and an ‘engagement’ figure, but still can't answer the key question: did behaviour change 🤷? The challenges
💬 Engagement is not action. Page views, stand visits, and quiz completions tell you people were exposed to content, not that they did anything differently afterwards.
⌛ The measurement window is short. A month of content won't produce a month of measurable behaviour change - culture shifts show up over a longer horizon, well after the campaign team has moved on.
🤔 Self-reported confidence is unreliable. It’s helpful to have a post-campaign survey asking “do you feel more confident reporting a security concern?”, but it’s measuring sentiment, not action.
👉 Attribution is challenging. If reporting rates rise in October, was it the campaign, a recent ‘near miss’, or a manager reminding their team?
Solutions worth trying
💥 Pick the key behaviours before the month starts. As mentioned in my first ECSM post, run a cultural maturity assessment to decide which behaviours need to change and which teams need most attention. Then select some associated metrics - for a ‘Safe Data Handling’ theme, that might be DLP blocks and overrides, or the percentage of documents classified on creation.
📈 Baseline first. Pull three months of the metric before the campaign launches, so later numbers have something real to sit against.
⏰ Extend measurement past the month itself. Behaviour changes that fade within two weeks aren't culture change - they're a reaction resetting to baseline. Re-check the same metric at 30 and 90 days.
👀 Widen your view. In the Communications Plan, we had a column just for measurement - review those ideas, e.g. how many reminder (‘trigger’) stickers are still on phones after 90 days.
📶 Trend analysis. As part of the feedback loops we discussed last week, record every comment, complaint and question from staff to follow up and build trust. Analysis can reveal the problem areas needing attention, and an appetite to revisit issues you though were done.
💬 Engagement still matters. Exposure doesn't strongly correlate with behaviour change, but tracking interactions can indicate which channels are most successful.
🔄 Follow up. Pair behavioural metrics with something qualitative - speak to line managers or run a short survey in later months to confirm that message landed, and stuck. If behaviours changed, ask why.
None of this needs to be complicated. It needs to be decided before the campaign launches, tied to a few specific behaviours, and checked again after the noise has died down. Focus on creating metrics that tell leadership something important about how the organisation actually behaves and where the risks still lie. That’s all on ECSM for now, but we are planning something for November – hopefully where we can all review what happened, what worked and we’ll avoid next time. Best of luck everyone 🫡!
European Cyber Security Month - Feedback loops @channel Last week, we talked about the importance of a full Communications Plan for your Security Awareness Month. After all, security programmes are built to push messages out - training, education, policy updates. What we may not be so good at is listening 🙉. That imbalance sits at the centre of security culture work: we measure click rates and completion percentages and call it engagement, but true engagement isn't one-directional 🔃. If we want people to believe security is done with them, not to them, we have to value listening as much as broadcasting. Consider the difference between two scenarios:
A mandatory module is pushed to all staff telling them about a new process or policy;
A question is issued to all staff - “what gets in your way when you try to report a security concern?”
Only the second suggests their experience matters enough to shape what happens next. Employees don't conclude “security cares about us” because of a well-produced campaign; they conclude it because, at some point, they said something was broken and we fixed it ✅. Without that loop, even the best-designed awareness content reads as friction from someone who doesn't care 🤷♂️. The trouble is, one channel can't do this job. 👩💼Executives rarely respond to a survey - listening to them means being in the room; 🧑🏭 Operational staff live with legacy technologies that resist changes, so we need to walk the floor, not just email a policy; and 🧑💼Office workers leave a trail in help desk tickets and everyday grumbling about workplace process frictions that quietly drive workarounds. Treating all three as one audience is how we lose the connection, and the trust, we're trying to build. Collecting feedback is the easy part. What changes behaviour and creates culture is visibly acting on it. A control adjusted because the factory floor flagged it as unworkable, or a reporting process simplified because people kept giving up halfway through - these are the moments that convert feedback into evidence of care. A feedback loop that goes nowhere is worse than none at all ⏯️- it teaches people not to bother. If users don't get a valid, personalised response to every suspicious email they report, they'll simply stop. Security culture isn't something a campaign announces into existence. It accumulates as the residue of hundreds of small moments where the organisation either responded to what people told it, or didn't. The key question isn't how to communicate security better - it's how well we listen, and what we're prepared to change because of what we hear 👂. So, during Security Awareness Month, capture the voices, feedback and complaints from each person, and record who said what. Investigate, and circle back with personalised responses and explanations. We may not fix everything, but if people understand how, why and when, that's the basis for trust 🫶.
European Cyber Security Month - Planning The Delivery @channel October is nearly here! It’s the pinnacle moment in many of our programmes, when we get permission to push our message harder than ever across Security Awareness Month. Over the next 3 weeks, I’ll pop in with tips, reminders and tools to help you be as prepared as you can be for the coming month. In this first episode, I want to focus on three things:
📉 Before you start this journey, it’s important that you’ve assessed your cultural maturity and the risks it points to. Decide which behaviours need to change, what ‘better’ looks like, and which teams need the most attention. If you haven’t done this already, loop back and do it NOW to give yourself a foundation for what comes next.
🎯 SoSafe has already built a set of content for you: sosafe-awareness.com/ecsm-2026. It has four weeks of awareness content covering Phishing, Voice Scams, Shadow AI and Deepfakes. If these topics overlap with your key messages, feel free to use this content.
📣 Free content is great, but it’s only half the solution – you need a solid communications plan to drive your messaging and interactions. Following on from last week’s ‘Off The Hook’ PPT, I’ve created a Communications Plan template, pre-populated with some example content.
The plan will drive clarity about what you are trying to achieve. Most of the columns are self-explanatory but a few deserve some explanation:
BJ Fogg Focus - Highlights the specific behaviour-change lever that you are using in that scenario – try to ensure you cover all three for each topic!
Mouthpiece - Separates content from delivery - we know that other voices often carry more credibility than the CISO, so choose deliberately for maximum impact
Associated policy - Gives you a place to record which policy covers this message, aiding in any subsequent Q&A with staff.
Tests - Freeform column to record ideas for metrics that validate scope and impact of your communication. Useful to prove value when we get to November.
Take the template and adapt it to your needs. I’d love to know which columns work for you, which don’t, and what you add. One thing’s certain: don’t head into October without a clear plan for every communication activity.
Off the Hook – Phone addiction and Meta’s legal settlement @channel As our summer breaks start to end, many of us have had a front-row seat to something that’s been hard to ignore: our family’s, and our own, relationship with social media/phones 📱. The unstructured days of the school holidays 🏖️ strip away routines that normally keep phone use in check, and for many households the result has been a summer of near-constant scrolling, gaming, and notification-chasing. Whether it was watching a teenager disappear into TikTok for hours, or catching yourself reaching for your phone when there's a lull in conversation, the pattern is familiar: apps engineered to be irresistible, delivering just enough reward to keep us coming back 📲. Interestingly, this isn't simply a matter of willpower. This same topic has been the subject of serious legal scrutiny in the US. You may know that Meta ♾️ recently agreed a landmark settlement worth around $18 billion, resolving claims that it knowingly designed Facebook and Instagram to be addictive, and that they misrepresented the harm this caused to children's mental health. As part of the deal, Meta committed to daily usage limits and "nighttime blocks" for teenage users, stronger age-verification measures, and new tools to help parents manage their children's use of its platforms. Although they deny any wrongdoing, these changes are an acknowledgment that social media products need guardrails & regulation, not just goodwill & best endeavours. This is a useful reminder for us all: if the platforms themselves are being required to build in friction and limits, there's a strong case for doing the same at home*. If this is a topic you think your user base could be interested in, I have good news 🥳! This week, I’ve created a handout that you can use to within your own organisations. The handout, ‘Off the Hook’, sets out six practical steps to help you and your family regain control over phone habits as the new school year begins. The goal isn't to demonise technology, but to try to break the automatic reflexes, and to do it as a household, with everyone's buy-in. Feel free to brand, revise and utilise this handout if you think it could be of value, either in parallel to communication about the Meta court case, or as part of your plans for October’s awareness month. * interestingly, in ‘Careless People’ (a book written about Meta by an internal whistleblower) it was highlighted that senior members of the Meta leadership team were very strict about their own children having no, or very limited, access to social media platforms… make of that what you will…🤨
Trust Me, I'm From IT! @channel In preparation for my session at SoSafe Academy earlier this week, I was creating content about how to establish trust between the CISO and the Board. It made me ponder the benefits of trust on a wider scale. It’s an awkward truth, but the IT team is often the least trusted voice in the building👨💻. They show up uninvited, tell people they're doing it wrong, disrupt working flow, and then vanish leaving staff confused and irritated. That’s an issue in itself, but what’s worse is that Security is often perceived as just another part of IT! Is it any wonder therefore, that our messages struggle to get through? 🙉 Trust is a mental shortcut our brains use to decide who's worth listening to under pressure, and who’s opinions have value. We judge advice by how we feel about the messenger, not simply the merits of the message. This technique is used by attackers all the time - look at the 2023 MGM Resorts breach for example. Attackers didn't crack any encryption - they simply rang the IT help desk, sounded confident, and asked for a password reset. The help desk trusted the caller's tone and basic authentication over any advanced verification process. That's authority bias, social proof & years of training a ‘help desk’ to help, working exactly as evolution intended, just weaponised against us. If attackers can build trust in five minutes on the phone, we can surely build genuine trust with our own colleagues. So how can we build trust with our user base instead? Three behavioural levers:
🔄 Reciprocity - always be looking to help. I used to tell my team that the answer to any user request was always “Yes”, we just needed to figure out how to say yes safely. Look for opportunities to add value and make the users life easier. Once you are perceived to be ‘on their side’, things will get much easier.
📶 Consistency - as German (& British!) rail commuters know, it’s difficult to trust a service that is inconsistent. By always having the same helpful response, by showing up every time, by always being calm, regardless of cause, you will become much more approachable to staff. Which leads onto…
🆘 Psychological safety - remove the risk, blame and finger pointing from any engagement. Reward the person who reports "I think I clicked something," fast, publicly, and warmly. That single cultural signal does more for security than any awareness poster you can print.
Trust isn't earned through authority; it's earned through repeated, low-stakes proof that we're on the user’s side. It will spread slowly, user by user, as each one encounters a reason to trust you, so be the colleague who always helps, not the department that judges — and watch engagement follow. Talking Points 1. Do you have any metric tracking trust levels? If so, what does that look like? 2. What’s the one thing your department has done that made the biggest difference to how much the user base trust the Security function?
The Summer Security Paradox: Why Fewer Attacks Still Means More Vulnerability @channel As I was drafting this article, I found something I didn’t expect - ransomware attacks decline by 18% during summer ! Now although that may sound like great news, it comes with some significant caveats. 🏖️ Summer's Hidden Attack Vectors While ransomware declines, travel-related phishing can spike. Kaspersky blocked 26% more phishing attempts in 2024, noting a surge in summer, targeting travellers with holiday themed phishing scams – e.g. last-minute holiday bargains; fake airline/hotel updates; travel insurance alerts. Then there's your out-of-office auto-reply. It’s a low-risk way for attackers to assess your organisation - they can scope out an understanding of who’s away, for how long and who covers their work. This information can map out decision-making chains and enable more competent & informed social engineering. ⤵️ The Resilience Collapse Of key concern is that summer staffing levels can break controls. One individual covering multiple roles means segregation of duty fails; the office ‘expert’ may be absent so escalations are avoided; or the sheer volume of work means tasks are put to one side, or corners are cut to hit deadlines. This may mean that your understaffed SOC doesn’t detect the attack; a junior Finance clerk pays that urgent high value invoice; or your internet facing systems don’t get the latest patch – either way, you’ll be increasing your vulnerability exactly when attackers know you’ll be running depleted teams. 👍 Addressing The Risk Although it seems that the attackers may take a summer vacation too, it’s not a time to become complacent 🍹. The controls you’ve created across the rest of the year are stretched thin, & defences are less effective, so when an attack does happen you are less able to detect and respond. Consider these pre-holiday steps:
Travel related phishing - Run a pre-holiday phishing simulation that is holiday themed, supported by a communication plan to remind people about contextually-correct lure emails!
Out-of-office auto-reply - Educate staff on information leakage and the importance of external out-of-office responses that don't broadcast key information.
Summer staffing - Ask line managers to remind their staff about the need to adhere to process regardless of the summer break, even if that impacts deadlines. Ensure playbooks (who's on-call, decision thresholds, out-of-band communication for critical incidents) are up to date before people leave, and specifically call out which systems can have updates deferred.
Talking Points 1. What risks do you see over summer? Untrained contract staff filling roles, skill depletion etc? 2. How do you educate people on summer risks without triggering them?
🧊 Monthly Icebreaker - July @channel
"If attackers can make the unsafe action feel ordinary, organisations need to make the safe action feel expected."
Social engineering isn't always about clever phishing emails or sophisticated attacks. More often, it's about exploiting the everyday moments we all experience: a rushed request, a familiar name, the discomfort of pushing back on a colleague or manager. The most dangerous requests don't feel dangerous at all. How do you build a culture where your team feels empowered to stop and question - even under pressure? And on a personal note: when did you last pause before acting on an urgent request and what made you stop? Drop your thoughts in the comments. 💡 📖 Worth a read: The new social engineering risk hiding inside ordinary work decisions
Your Phone Number Is Your Key. Someone Else Wants It. @channel Your mobile phone isn't just a device — it's the master key to nearly everything you own digitally. Email, banking, crypto, HR systems, family messaging: any account secured by a text message code ultimately depends on that one physical SIM 📶. That makes it a prime target, and criminals are exploiting it at industrial scale through SIM-swapping.📲 The attack is simple. Criminals gather personal details on a target — from data breaches, social media, or phishing — then call the victim's mobile carrier, impersonate them, and request the number be moved to a SIM the attacker controls 👥. If the carrier believes the story, the switch happens in seconds and every subsequent call, text, and one-time passcode goes to the attacker. The victim just sees "No Service," 📵 and by the time they realise why, their accounts are already gone. This isn't theoretical, security firm Kroll, ironically a cybersecurity consultancy, had an employee's number SIM-swapped after T-Mobile transferred it to an attacker with no contact to Kroll itself. Sensitive customer data was exposed, and victims were immediately hit with follow-up phishing. 🐟 More recently, the group Scattered Spider sent tens of thousands of fake IT support texts to harvest employee logins, used them to identify high-value cryptocurrency holders, then SIM-swapped those individuals to intercept authentication codes and drain their wallets. The US Department of Justice confirmed at least $8 million stolen. 🕷️💰 What Your Staff Need To Know This attack lives and dies at the human layer — yet most staff don't even know SIM-swapping is possible. Three things matter:
Sudden loss of signal is a red flag, not a glitch 🚩. If a phone goes to "No Service" unexpectedly, treat it as a security emergency: contact IT and the carrier immediately.
SMS isn't a secure channel 📱. One-time codes sent by text can be intercepted once a number is compromised. Push staff toward authenticator apps or hardware keys instead.
Be suspicious of urgency ⌛. Any unexpected request — by text, call, or email — to verify credentials or click a login link deserves scrutiny. Scattered Spider's whole playbook relied on someone complying quickly without questioning.
The master-key analogy holds one final lesson: most people wouldn't hand a stranger their front door key — but every day, carriers do exactly that 🔑. Until the industry fixes its verification processes, it's on each of us to make that key worth as little as possible, by removing SMS as the single point every account depends on. Actions
Assess whether staff are adequately trained on the signs of SIM-swapping and how to respond.
Identify any services or apps within your own organisation that still use SMS as an authentication or verification challenge, and explore switching to an authenticator app.
Review your own accounts — many still default to SMS. Where possible, switch to stronger verification.
Over To You
How have you educated your staff, and your IT Service Desk, about SIM-swapping?
What new processes did the Service Desk need to deploy to counter this threat?
How ShinyHunters Exploits the Human Layer @channel So I already had a draft of this weeks’ post, but my reading of the recent cyber news has made me reconsider, and I think this is the more important topic right now. In the last month alone, ShinyHunters has: · breached Kodak (2.2 million records published after a three-day ransom deadline expired), · threatened One Medical patients across 250 clinics with the release of 8.8TB of healthcare data, · targeted Madison Square Garden Sports, releasing 26 million customer records, and · exploited a critical Oracle PeopleSoft zero-day to compromise over 100 organisations worldwide. June 2026 is not an anomaly — it is the new rhythm. ShinyHunters has now stolen data on over 400 million individuals this year alone, across more than 40 confirmed breaches, and their pace is accelerating. It’s vital we understand how they operate as it’s within our capability to do a better job of resisting them! Although the recent Oracle PeopleSoft campaign is a stark illustration of ShinyHunters’ expanding technical capability, it is an exception in one important respect: it relied on a software vulnerability (CVE-2026-35273). The majority of ShinyHunters’ 2026 portfolio is NOT technical: the Kodak extortion; the Council of Europe payroll dump (429,000 documents including 15 years of payslips), and the Coinbase breach earlier in the year all share a common thread — the attackers got in through people, not technical vulnerabilities. The Playbook: Weaponizing the Helpdesk Experience ⚡ ShinyHunters has industrialised social engineering at a scale that most organisations are not prepared for. The group now deploys AI-generated vishing calls at scale 🤖 — meaning a human attacker need not even be on the line for the initial contact ☎️ Technique 1 - Attacking the Helpdesk 🎯 Every organisation has either internal IT helpdesks or outsourced third-party versions — staffed by agents trained to be helpful. That helpfulness is the vulnerability. When a caller knows an employee's name, manager, and the systems they commonly log into (all trivially assembled from LinkedIn and prior breaches), their instinct is to assist – it’s what their metrics drive them to do! Without robust caller authentication protocols, that instinct is an open door to password resets, MFA bypass, and policy exceptions. ShinyHunters knows this. Their operational cadence suggests they actively profile organisations before calling, selecting targets where helpdesk controls are weakest. Technique 2 - Attacking the User 🎯 Additionally, these AI agents impersonate IT support staff, manufacture urgency around fake outages, and guide service desk agents into resetting credentials or reading back one-time authentication codes. MFA fatigue attacks compound this further: flood an employee with push notifications, then call them pretending to be IT and asking them to "approve the one that just came through to stop the error." What Good Authentication Looks Like 👍 The controls required to defend both these attacks are well understood. What is missing is consistent enforcement across both internal and third-party desks. Security leaders should act on four priorities immediately:
Caller verification: Helpdesk agents must strongly verify identity, ideally though independent channels before acting on any account request. Similarly, users must validate that it’s their Helpdesk colleagues calling before engaging.
MFA reset lockdown: Password resets that could disable or bypass MFA must require elevated approval workflows — never single-agent discretion.
Phishing-resistant MFA: Where possible, migrate away from push-based authenticators as they are vulnerable to both fatigue attacks and real-time phishing interception (NB. This is what my planned post was about – so look forward to something on this in the next week or two!)
Third-party contractual controls: Service desk providers must meet the same authentication standards as internal teams. So, include contractual obligations, audit rights, and regular red team exercises that address social engineering scenarios.
Take Action Now 🫵 The volume and velocity of ShinyHunters' June 2026 activity should be a clear signal - this is not a threat to monitor, it is a threat to act on. We, as security leaders should be reaching out this week to internal Helpdesk management and every third-party provider with access to production systems, auditing caller authentication procedures against the techniques documented here, and scheduling live social engineering tests. The group has made clear, breach after breach, that they will keep calling until someone picks up and helps them in. The question is whether your ‘Help” desks are ready to refuse. Over To You 💬
What caller authentication processes have you found that work well for your Helpdesk interactions?
Are your Helpdesk willing to say ‘no’, and refuse help?
How do you audit your third-party Helpdesk providers to ensure they meet your standards and robustly defend against social engineering attacks?
I don't know if everybody has a similar challenge, but lately I had a longer discussion about ransomware groups, preparing for a ransomware attack, etc. The following source helped me a lot to get insights into ransomware negotiations and how to prepare. Maybe you are as curious as I am, or need to prepare your BCM for ransomware attacks: ransomware.live
Andrew R. Tbh, I'd go with this kind of approach. Using emotions is in my opinion the most effective way to change or push certain behaviours.
I try to trigger "fun" by adding some gamification to our security campaigns like team rankings and challenges, for example on our Display in our bistro.
I also try to trigger "curiosity" by having 1on1 dialogues with colleagues and showing them what is actually going on behind the scenes of our security measures like "how we secure our organization".
And I trigger "appreciation/trust" by handing out mini lego fishermen with a handwritten card to colleagues who report really dangerous phishing emails or do really good in our e-learnings.
I'd always try to avoid negative emotions more than necessary and focus on positive ones instead. But I think it heavily depends on the company culture. Highly regulated organisations might see things a bit differently. 😅
@channel - Interested to know how you leverage emotional content to engage people and change behaviour? I recall one firm that used yellow 'parking tickets' that would be placed on a desk that had left a laptop on it, physically unsecured, overnight - and you'd have to take your ticket to IT to get your laptop back. That emotion is 'shame' as everyone would see the ticket as they walked passed your desk! Not sure that's a great way of doing it though... 😬
The Deficit Thinking Trap: Why Knowing Better Doesn't Mean Doing Better There's a question that should make every security professional uncomfortable: if our users already know they shouldn't click suspicious links, why do they keep clicking them? 🤔 We've been running security awareness programmes for decades, and yet breach after breach still starts with a human. So what's going wrong? One answer lies in a flawed assumption — one that psychologists and public health researchers abandoned years ago. It's called deficit thinking. That’s the belief that poor decisions stem from a lack of information, and that simply giving people the right facts will change their behaviour. To our logical, IT-professional brains, that sounds entirely reasonable. It's also wrong - and neuroscience has been telling us so for thirty years. 😳 In his 1994 landmark work “Descartes' Error”, neurologist Antonio Damasio dismantled the idea that decisions are purely rational. He studied patients with damage to the emotional centres of the brain. These were people with perfectly intact IQs, who could solve complex puzzles and pass knowledge tests, yet they couldn't make simple everyday decisions - choosing what to eat, managing money, picking between two options — all became paralysing exercises in endless deliberation. Why? Because without emotion, decision-making breaks down entirely. 🔄 Damasio showed that healthy brains use somatic markers — gut feeling, or emotional shortcuts — as rapid filtering mechanisms. These aren't noise cluttering up our rational thinking - they are the thinking. Logic and emotion work together, and when emotion is absent, even the smartest people can struggle and make poor choices. So what does this mean for security awareness? It means that handing someone a training module and expecting behavioural change is just wishful thinking. It’s like being on a weight loss journey. You know precisely what you should eat, and can recite the basics of a healthy diet without hesitation, yet knowing it and doing it when you're tired, stressed, and someone's put birthday cake in the office kitchen are entirely different things. 🎂 The emotional and contextual wiring to act on your knowledge in that moment is where the gap exists. Consider what attackers actually exploit — urgency, fear, authority, the anxiety of a deadline 😬. These are precisely the emotional triggers that Damasio's somatic markers engage with & respond to. A phishing email that creates panic is bypassing rational thought deliberately, and a training video watched six months ago has almost no emotional weight in that moment. It simply isn't in the fight. Deficit thinking also ignores:
Context — under pressure, the brain defaults to fast, emotional shortcuts, not careful risk calculation;
Environment — if the secure choice is harder than the insecure one, you've already lost before awareness enters the picture.
This is where Adaptive Defence reframes the challenge entirely. Rather than asking "did they receive the training?", it asks "what shaped their behaviour in that specific moment?" Effective interventions are contextual, timely, and emotionally resonant — a nudge at the point of risk, not a lecture delivered weeks before the threat arrives. The science is clear: we are not rational actors who occasionally get emotional. We are emotional actors who occasionally get rational. Security programmes that ignore this will keep solving the wrong problem. Over to you:
Do your users know what good security behaviour looks like — but still don't do it? What factors do you see driving that gap?
Have you found that interventions work better at an emotional level, rather than just an informational one? What were the best ones?
Are we too focused on what people know and not enough on the various environmental forces we're asking them to operate within? How can we change these forces?
Need a relevant story to demonstrate to the Board how just one user can have a massive impact? https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/ The 'secure chat' platform for the French government was compromised by a single socially engineered user account, allowing the attack to access 643k messages, download 13Gb of media and access restricted messages..
доверяй, но проверяй? @channel In April this year, a cybersecurity firm called BePrime made headlines for all the wrong reasons. The company — a managed security services provider serving major brands including Starbucks, Whirlpool, and energy companies across Latin America — was breached because its admins neglected to put MFA on their own accounts! 🤦 The attacker walked straight in, stealing 12.6 GB of data including plaintext credentials, security audit reports, API keys, taking control of 1,858 network devices, and accessing live surveillance camera feeds at client offices. This wasn't a sophisticated zero-day or some AI-powered supply chain attack, just a cybersecurity company that hadn't bothered to protect itself with basic controls. It was the equivalent of a professional locksmith leaving their own front door unlocked. It brought back an uncomfortable memory of my own - we’d managed to resist a high-profile pen test until the attackers located an unsecured Excel document holding the credentials to almost every database we had. It was a DB Admin trying to 'smooth his workflow', but for the firm, it was ‘game over’. The awkward truth in both cases: the threat wasn't sophisticated. It was human. Convenience trumped security. And that's a pattern that doesn't get easier to manage — it gets harder. So what do we do?
Remove trust entirely? 🔒 Physical searches on entry and exit, locked-down toolsets, strict access controls. Effective, maybe. But miserable places to work, and talented people leave.
Extend trust generously? 🤝 And periodically discover your intellectual property sitting in a competitor's pitch deck.
Ronald Reagan 🇺🇲 borrowed the old Russian axiom: "Trust, but verify" (the text at the top of this piece in case you were wondering!). It sounds like the sensible middle ground. The problem is that we don't actually verify. We say we will, we build policies that assume we do, and then reality intervenes. Monitoring every action every user takes simply isn't operationally feasible, and even when we try, the research suggests that a verification culture can actively damage the trust it claims to protect, pushing behaviours underground rather than eliminating them. ‘Guardrails’ appear to be a reasonable compromise — constrained environments where creativity is permitted within defined boundaries and toolsets. But a motivated employee with a company credit card can bypass most of them before lunch. There's no clean answer here. Which is why I'd love to hear from you 🫵:
What balance have you found between giving staff the flexibility they want, and keeping them from making expensive mistakes?
How do you divide your controls — what's enforced through culture and what through technology? And which works better?
Here's a controversial one: do you think "trust, but verify" is fundamentally broken as a model — and if so, what should replace it? Zero Trust architecture? Outcome-based accountability? Something else entirely?
I'll start: I think the phrase does more harm than good. It gives organisations the comfort of sounding rigorous without the discipline of actually being rigorous….
