<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Chris Martorella]]></title><description><![CDATA[Chris Martorella]]></description><link>https://chrismartorella.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!4bXP!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9410a619-2bc9-4701-b40a-0c4e7aa4ca95_300x300.jpeg</url><title>Chris Martorella</title><link>https://chrismartorella.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 03 Jun 2026 01:33:37 GMT</lastBuildDate><atom:link href="https://chrismartorella.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Chris Martorella]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[chrismartorella@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[chrismartorella@substack.com]]></itunes:email><itunes:name><![CDATA[Chris Martorella]]></itunes:name></itunes:owner><itunes:author><![CDATA[Chris Martorella]]></itunes:author><googleplay:owner><![CDATA[chrismartorella@substack.com]]></googleplay:owner><googleplay:email><![CDATA[chrismartorella@substack.com]]></googleplay:email><googleplay:author><![CDATA[Chris Martorella]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Rise of AI Agents: Transforming Cybersecurity Team Structures ]]></title><description><![CDATA[A Practical Framework for the AI-Enabled Security Organization]]></description><link>https://chrismartorella.substack.com/p/the-rise-of-ai-agents-transforming</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/the-rise-of-ai-agents-transforming</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Mon, 23 Dec 2024 09:46:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1H6D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The integration of Agentic AI into cybersecurity represents a fundamental shift in how organizations defend against and respond to threats. This article explores how autonomous AI agents can transform traditional security team structures, examining their impact through the lens of Team Topologies methodology. We'll dive into new interaction patterns between humans and AI agents, practical implementation considerations, and key challenges organizations need to address. </p><p>Whether you're a CISO planning your team's evolution or a security leader evaluating AI adoption, this guide provides a framework for successfully integrating AI agents while maintaining essential human expertise and control.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1H6D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1H6D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!1H6D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!1H6D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!1H6D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1H6D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1513250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1H6D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!1H6D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!1H6D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!1H6D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79080878-a9f8-4d92-84bb-7944ad43f42b_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>First thing first.. What is an Agent?</strong></h3><p>The distinction between simple LLM-based tools and true AI agents has crucial implications for cybersecurity teams. While chatbots (LLM) might help with documentation or basic queries, AI agents can actively participate in security operations - from threat hunting to incident response. This capability to act autonomously while accessing <strong>multiple data sources</strong> and <strong>tools</strong> makes them potential "virtual team members" rather than just automated tools.</p><p>The main difference of AI Agents with just LLM models bots, is that they have access to Data sources (RAG, DB), External tools (API,Code, etc), Language Models and Machine learning in order to perform their tasks, and produce the results needed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xEcC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xEcC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 424w, https://substackcdn.com/image/fetch/$s_!xEcC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 848w, https://substackcdn.com/image/fetch/$s_!xEcC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 1272w, https://substackcdn.com/image/fetch/$s_!xEcC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xEcC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png" width="883" height="631" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6179552e-307c-4432-b572-21eb86ce38b1_883x631.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:631,&quot;width&quot;:883,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39907,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xEcC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 424w, https://substackcdn.com/image/fetch/$s_!xEcC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 848w, https://substackcdn.com/image/fetch/$s_!xEcC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 1272w, https://substackcdn.com/image/fetch/$s_!xEcC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179552e-307c-4432-b572-21eb86ce38b1_883x631.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Understanding how to integrate these AI agents effectively requires a structured approach to team organization. The <a href="https://substack.com/inbox/post/153157601?r=ij5cn&amp;utm_campaign=post&amp;utm_medium=web&amp;triedRedirect=true">Team Topologies methodology</a> provides an excellent framework for mapping where and how AI agents can deliver the most value in your security organization. Let's explore how AI agents can enhance each team type's capabilities while maintaining clear boundaries and responsibilities.</p><p></p><h3><strong>Introducing AI Agents into Cybersecurity teams:</strong></h3><p>In the previous article discussed how we can leverage <a href="https://substack.com/inbox/post/153157601?r=ij5cn&amp;utm_campaign=post&amp;utm_medium=web&amp;triedRedirect=true">Team Topologies methodology for organizing Cybersecurity teams in Startups and Scale ups</a>. The emergence of Agentic AI  is going to transform how we structure and operate cybersecurity teams. Here's my view on how Agentic AI could fit into different team types described in the article based on Team topologies methodology:</p><h4><strong>Stream-Aligned Teams:</strong></h4><p>Focused on a single, valuable stream of work, such as a product or service. They are cross-functional and empowered to build and deliver end-to-end functionality. In these teams the Agents could be part of the team as a virtual team member or we can have fully automated teams:</p><ul><li><p>AI agents acting as "<strong>virtual team members</strong>"</p><ul><li><p> For continuous security monitoring and initial incident triage, for example having a Tier 1 SOC team made up completely of Agents.</p></li><li><p>Automated threat hunting and anomaly detection with human oversight.</p></li><li><p>AI-powered security testing and vulnerability assessment integrated into CI/CD pipelines.</p></li><li><p>AI agent monitoring an application&#8217;s deployment in real-time, automatically detecting anomalies such as unusual API behaviour, and alerting the team while containing the issues.</p></li></ul></li><li><p><strong>AI powered autonomous Offensive team</strong>,  finding vulnerabilities,  exploiting them and recommending fixes (that can be hand over to Security Engineer agent that will apply the fix)</p></li></ul><h4><strong>Enabling Teams</strong></h4><p>Provide expertise and support to Stream-aligned teams, helping them overcome obstacles and build up their capabilities. Security experts who help bridge knowledge gaps, and provide guidance:</p><ul><li><p>AI assistants that help scale security knowledge sharing and training, contextualized to team domain and way of working.</p></li><li><p>Automated security documentation generation and maintenance</p></li><li><p>AI-driven security architecture recommendations based on historical data and best practices</p></li><li><p>AI secure coding copilots that follows company standards and principles.</p></li><li><p>AI Security Fixing Agents (Code or patching)</p></li></ul><p>AI-driven interactive knowledge bases (Agents) could enable developers to implement secure code without relying heavily on security engineers, finally democratizing security amongst developers. This is where many people is currently investing at the moment. We can have AI Security champions customized for every engineer or team.</p><h4><strong>Platform Teams</strong></h4><p><strong>These teams build and maintain a set of security tools and services that other teams can leverage. This might include identity and access management solutions, logging and monitoring infrastructure, and vulnerability scanning tools.</strong></p><p>AI could dynamically adjust firewall rules, access permissions or cloud configuration in response to detected threats, ensuring a <strong>self-healing infrastructure</strong>. AI-enhanced security platforms that learn and adapt to organization-specific threats and behaviours.</p><h4><strong>Complicated Subsystem Teams</strong></h4><p>Specialized teams that deal with technically complex domains that require deep expertise.</p><ul><li><p>AI agents specializing in complex security domains (cryptography, zero-trust architecture)</p></li><li><p>Automated research and analysis of emerging threats</p><p></p></li></ul><p>I believe the main two types of teams that will see the influence of Agents are the Stream aligned and the Enabling teams first, many of the early AI Agents Cybersecurity solutions are currently focused on:</p><p><strong>-Offensive security like <a href="https://xbow.com/">XBow</a> </strong></p><p><strong>-Security operations like <a href="https://torq.io/ai-agents-for-the-soc/">Torq</a></strong></p><p><strong>-Application Security like <a href="https://zeropath.com/">Zeropath</a> </strong></p><p><strong>-Code Copilots and autofixers like <a href="https://github.com/features/copilot">Github Copilot</a></strong></p><h2><strong>New Interaction patterns with AI Agents</strong></h2><p>How would the Interactions patterns could look like in the future with the adoption of AI Agents? Here we focus in the interaction patterns with AI Agents, instead of between teams, but we should consider that there could be fully autonomous teams that will need an interaction pattern with human teams or other autonomous teams.</p><p></p><h4><strong>AI-Human Collaboration (Human in the loop)</strong></h4><p>AI agents and human professionals will need to function as a cohesive team, balancing autonomy and human expertise. This collaboration can take many forms, each requiring clear processes and protocols.</p><p>&#8226; <strong>Clear Handoff Protocols: </strong>AI agents excel at handling routine tasks but must know when and how to escalate to human experts. For example:</p><p><em>An AI agent monitoring a Security Operations Center (SOC) detects anomalous outbound traffic indicative of data exfiltration. It quarantines the source, logs detailed diagnostics, and alerts human analysts for a deeper forensic investigation.</em></p><p>&#8226; <strong>Defined Escalation Paths for Complex Security Decisions: </strong>Certain tasks&#8212;like deciding on a trade-off between shutting down a system to block an attack versus maintaining availability&#8212;require human judgment. AI can provide analysis and options but must defer to human decision-making.</p><p>&#8226; <strong>Collaborative Workflows: </strong>AI Agents suggest remediation steps for vulnerabilities, and human teams validate and refine the suggestions before implementation. These workflows foster trust while maintaining human oversight.</p><p>&#8226; <strong>Dynamic Role Reassignment: </strong>AI Agents could step in to handle surge tasks during incidents, such as analyzing thousands of phishing emails simultaneously or log entries, freeing human teams to focus on critical decision-making.</p><h4><strong>AI Supervision Models</strong></h4><p>Integrating AI into security workflows requires robust supervision to ensure that AI systems operate as intended and align with organizational goals and ethical standards.</p><p>&#8226; <strong>Human Oversight of AI-Driven Security Operations: </strong> <em>When an AI system recommends blocking a user account for suspicious behavior, a human supervisor reviews the AI&#8217;s reasoning to ensure it&#8217;s not based on flawed logic or biased data.</em></p><p>&#8226; <strong>Quality Control Frameworks for AI-Generated Security Controls: </strong>Organizations must validate the efficacy of AI-generated policies.</p><p><em>Before implementing an AI-generated WAF rule, a platform team could simulate the rule in a sandbox environment to confirm its impact on legitimate traffic.</em></p><p>&#8226; <strong>Regular Assessment of AI Performance and Decision-Making: </strong>AI systems need periodic audits to evaluate performance, accuracy, and adherence to regulatory requirements.</p><p><em>A quarterly review of AI incident triage outcomes can highlight areas where the AI needs retraining or where false positives are too frequent.</em></p><h4><strong>AI-to-AI Collaboration (Agent Networks)</strong></h4><p>As AI Agents become more prevalent, they will need to interact not just with humans but also with other AI systems.</p><p>&#8226; <strong>Autonomous Agent Communication: </strong>AI Agents could coordinate responses to incidents, sharing insights and dividing tasks. <em>Example:</em> One AI Agent might focus on isolating affected systems during an attack, while another investigates the source of the breach.</p><p>&#8226; <strong>Agent-Orchestrated Workflows: </strong>Multiple AI Agents working together can streamline complex tasks. <em>Example:</em> During an incident, an AI network could handle threat detection, forensic analysis, and containment actions simultaneously, reporting progress to human supervisors in real-time.</p><h4><strong>AI-Driven Training and Mentorship</strong></h4><p>AI agents can act as a mentor or trainer, helping human teams scale their expertise.</p><p>&#8226; <strong>Interactive Security Training:</strong></p><p>AI provides dynamic, scenario-based training modules tailored to individual skill levels. <em>Example:</em> A junior analyst might engage with an AI-powered simulation that mimics a live cyberattack, honing their skills in a controlled environment.</p><p>&#8226; <strong>On-the-Job Guidance: </strong>AI Agents provide real-time recommendations during active incidents. <em>Example:</em> During a ransomware attack, the AI suggests containment strategies and guides the team step-by-step through remediation processes. Or a Coding Copilot that will advise while coding on recommendations based on the context of the codebase. </p><h4><strong>AI as Mediators</strong></h4><p>AI Agents can serve as intermediaries, bridging communication gaps between human teams or systems.</p><p>&#8226; <strong>Centralized Decision-Making: </strong>AI consolidates data from disparate tools and teams to provide a unified perspective.<em>Example:</em> An A I Agent compiles insights from threat intelligence platforms, endpoint detection systems, and SOC logs to present a prioritized action plan for the incident response team.</p><p>&#8226; <strong>Contextual Insights for Human Decisions: </strong>AI delivers tailored insights based on the role and expertise of the human team member <em>Example:</em> Forensic analysts receive deep-dive technical data, while executives get high-level summaries with recommended actions.</p><h2><strong>Considerations for AI Integration in your team, Are you ready?</strong></h2><p>In this exciting journey we are experiencing, companies will have to consider multiple challenges to ensure that they are prepared and adapt to these changes. Here are a summary of the main considerations when adopting AI Agents:</p><p><strong>Skills Evolution: </strong>The introduction of AI agents needs a shift in skill sets and roles within cybersecurity teams.</p><ul><li><p>Security teams will need to develop AI literacy, team members should receive training on how to interpret AI outputs, customize AI models, and intervene when necessary.</p></li><li><p>Focus on higher-level decision making and AI supervision.</p></li><li><p>New roles emerging for AI-security specialists.</p></li></ul><p>I have noticed recently that many teams are not even experiencing with AI solutions, and are thinking on traditional approaches for next year plans, still many people is sceptics of AI capabilities and dismisses these solutions in favour of traditional approaches.  </p><p>When it comes to AI literacy, I recommend <a href="https://www.deeplearning.ai/courses/">Deeplearning.ai</a> courses, particularly the short courses https://www.deeplearning.ai/courses/ where you can learn many of the concepts, and frameworks in a short period of time.</p><p><strong>Organizational Impact: </strong>AI integration can fundamentally alter how organizations structure and operate their cybersecurity functions.</p><ul><li><p>Potential for improved security engineer to developer ratios through AI augmentation. <em>A SOC with 10 engineers managing 1,000 incidents monthly could handle the same workload with 5 engineers supported by AI triage systems.</em></p></li><li><p>New team interaction patterns with AI mediating communications: <em>An AI-driven SOC might automatically prioritize incidents and allocate them to specialized teams, reducing bottlenecks in triage and response workflows.</em></p></li><li><p>New security governance models incorporating AI oversight</p></li></ul><p></p><p>As cybersecurity teams embrace AI agents, the focus must remain on collaboration, transparency, and ethical implementation. The journey toward an AI-augmented Cybersecurity team future is both exciting and charged with challenges&#8212;are you ready to adapt?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Beyond the Security Team of One: Scaling Cybersecurity from Startup to Scale-up]]></title><description><![CDATA[&#129516; Evolution Through Value Streams - Traditional security team scaling fails when following headcount instead of value streams - Security organisations thrive when evolving based on business impact rather than company size.]]></description><link>https://chrismartorella.substack.com/p/beyond-the-security-team-of-one-scaling</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/beyond-the-security-team-of-one-scaling</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Sun, 15 Dec 2024 17:13:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vERA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>&#129516; Evolution Through Value Streams</strong> - Traditional security team scaling fails when following headcount instead of value streams - Security organisations thrive when evolving based on business impact rather than company size.</p><p>&#127919; <strong>Reality of Security Team Ratios</strong> - With security-to-developer ratios of 1:50 to 1:120, traditional scaling isn't sustainable - Success requires shifting from "doing security" to "enabling security at scale" - Platform teams and enabling patterns can help security teams achieve 3-5x impact</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Team Topologies provides a framework to balance security needs with business growth.</p><h2>Introduction</h2><p>A few years back, as result of a reorganisation in a company I worked for, I came across with a book that proposed different ways to organise teams and collaboration for engineering organisations, based on the needs of the business to enable fast flow of value. The book is called "<a href="https://teamtopologies.com/">Team topologies</a>", introduced by Matthew Skelton and Manuel Pais. I had seen this methodology used in many companies to reshape their whole organisation for better productivity and efficiency.</p><p><em><strong>"Team Topologies is the leading approach to organizing business and technology teams for fast flow of value, providing a practical, step-by&#8209;step, adaptive model for organizational design and team interaction."</strong></em></p><p><strong>Based on Conway's Law, </strong>which<strong> says</strong> that software architectures inevitably reflect the organisational communication patterns of the companies that create them. The way teams communicate and collaborate directly shapes the systems they build. <strong>Team Topologies</strong> builds on this principle by deliberately designing team interactions to produce desired architectural outcomes.</p><p>In the dynamic world of startups and scale-ups, where agility and adaptability are crucial for survival and growth, security organisations must evolve alongside the companies they protect. The Team Topologies model offers a promising solution to address these challenging ratios, providing a team-oriented framework that helps security groups deliver value efficiently despite limited resources.</p><p>The challenge of organising security teams becomes particularly important in large engineering organisations, where hundreds of developers may be supported by only a handful of security engineers. Industry surveys and my experience indicate that the ratio of security developers to engineers typically ranges from 1:50 to 1:120 (depending industry), creating significant odds against security teams' effectiveness.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vERA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vERA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 424w, https://substackcdn.com/image/fetch/$s_!vERA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 848w, https://substackcdn.com/image/fetch/$s_!vERA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 1272w, https://substackcdn.com/image/fetch/$s_!vERA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vERA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png" width="768" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:663659,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vERA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 424w, https://substackcdn.com/image/fetch/$s_!vERA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 848w, https://substackcdn.com/image/fetch/$s_!vERA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 1272w, https://substackcdn.com/image/fetch/$s_!vERA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d43aa9b-0cbc-471d-aa54-e1fdb5ad80a9_768x768.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Four Fundamental Team Types in team topologies:</strong></h2><p>When it comes to teams, Team topologies advocate for the following four types:</p><p><strong>Stream-Aligned Teams: </strong>Focused on a single, valuable stream of work, such as a product or service. They are cross-functional and empowered to build and deliver end-to-end functionality.</p><p>In cybersecurity, these teams focus on specific security domains or products:</p><ul><li><p>Examples include Application security teams, Infrastructure security teams, or Security Operations teams.</p></li></ul><p>They operate with high autonomy and are responsible for end-to-end security in their domain</p><p><strong>Platform Teams: </strong>These teams build and maintain a set of security tools and services that other teams can leverage. This might include identity and access management solutions, logging and monitoring infrastructure, and vulnerability scanning tools.</p><ul><li><p>Create self-service capabilities for other teams</p></li><li><p>Example: Security tooling team that maintains SIEM, vulnerability scanners, and security automation platforms</p></li></ul><p><strong>Enabling Teams: </strong>Provide expertise and support to Stream-aligned teams, helping them overcome obstacles and build up their capabilities. Security experts who help bridge knowledge gaps, and provide guidance:</p><ul><li><p>Reduce dependencies on security experts by teaching rather than doing the work. Think of Security Champions concept for example.</p><p>Example: Security architecture team that assists other teams in implementing secure designs</p></li></ul><p><strong>Complicated Subsystem Teams: </strong>Specialised teams that deal with technically complex domains that require deep expertise.</p><ul><li><p>Focus on specific security domains that need deep technical knowledge</p><p>Example: Cryptography team or security research team</p></li></ul><p>In my experience the most common team patterns in cybersecurity are the Stream aligned teams and Enabling teams, at least when talking about Startups and Scale ups.</p><h2><strong>Team Interaction Patterns</strong></h2><p>The book introduces another important concept, which is the way these team interact with other teams in the organisation. We have the following options:</p><p><strong>1. Collaboration: </strong>Deliberate working together between teams with a defined mission and timeline, requiring high bandwidth communication.</p><ul><li><p>Security<strong> platform teams</strong> working closely with <strong>stream-aligned teams</strong></p></li><li><p>Regular knowledge sharing sessions between <strong>enabling teams</strong> and other security teams</p></li><li><p>Cross-team security incident response exercises</p></li></ul><p><strong>2. X-as-a-Service: </strong>One team provides something for other teams to consume asynchronously with minimal collaboration, typically through self-service platforms or APIs.</p><ul><li><p>Security <strong>platform</strong> <strong>team</strong> providing self-service security tools</p></li><li><p>Automated security scanning in the SDLC (Static Analysis, Dependency scanning, Secret scanning, etc.)</p></li><li><p>Security policy as code frameworks</p></li></ul><p><strong>3. Facilitating: </strong>One team helps another team learn or develop a new capability through teaching and mentoring, with the goal of making the receiving team self-sufficient.</p><ul><li><p><strong>Enabling teams</strong> conducting security training</p></li><li><p>Security architecture reviews and consultations</p></li><li><p><a href="https://miro.com/miroverse/threat-modeling-stride/">Threat modeling</a> processes and workshops</p></li></ul><h2><strong>Team Topologies for Security teams in Startups</strong></h2><p>As cybersecurity needs expand across organisations - whether they're innovative startups disrupting markets or scale-ups experiencing rapid growth - security teams face a transformation challenge. The evolution from a single security generalist or small team handling all security concerns to a multi-tiered security organisation requires careful planning. This transition point typically emerges when the traditional "<strong>security does everything</strong>" approach starts showing signs of strain, often manifesting in delayed responses to security incidents, mounting <a href="https://open.substack.com/pub/chrismartorella/p/security-technical-debt-in-software?r=ij5cn&amp;utm_campaign=post&amp;utm_medium=web&amp;showWelcomeOnShare=false">security technical debt</a>, and overwhelmed security professionals trying to juggle too many responsibilities. The introduction of specialised security platforms and dedicated platform teams becomes not just beneficial but essential for sustainable scaling. However, this transformation requires thoughtful decisions and clear organisational principles to ensure that security operations maintain their effectiveness while becoming more scalable.</p><p>So what are the options we have when we look at the different phases of growth of a startup? Let's see some examples:</p><h3><strong>Early-Stage Startup (1-100 employees)</strong></h3><p>At this stage, security is often handled by a small (one person usually, depending the core business), versatile team that combines multiple roles:</p><ul><li><p>One<strong> stream-aligned</strong> team handling both application and infrastructure security</p></li><li><p>Security lead acting as an enabling team to support developers</p></li><li><p>Leverage managed security services to fill gaps</p></li></ul><h3><strong>Growth Stage (100-300 employees)</strong></h3><p>As the organisation grows, the security structure evolves:</p><ul><li><p>Dedicated small <strong>stream-aligned teams</strong> for application security and infrastructure security, usually same small team covering both domains.</p></li><li><p>Small<strong> platform team</strong> creating security tooling and automation</p></li><li><p>Part-time <strong>enabling team</strong> providing security guidance across the organisation</p></li></ul><h3><strong>Scale-up Stage (300-3000 employees)</strong></h3><p>The security organisation becomes more sophisticated:</p><ul><li><p><strong>Multiple stream-aligned teams</strong> focused on different security domains</p></li><li><p>Dedicated <strong>platform team</strong> for security infrastructure</p></li><li><p><strong>Full-time enabling team</strong> for security architecture and consultation</p></li></ul><p>At this stage we have a full security organisation</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nUuR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nUuR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 424w, https://substackcdn.com/image/fetch/$s_!nUuR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 848w, https://substackcdn.com/image/fetch/$s_!nUuR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 1272w, https://substackcdn.com/image/fetch/$s_!nUuR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nUuR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png" width="1456" height="692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:692,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:159996,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nUuR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 424w, https://substackcdn.com/image/fetch/$s_!nUuR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 848w, https://substackcdn.com/image/fetch/$s_!nUuR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 1272w, https://substackcdn.com/image/fetch/$s_!nUuR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510cdba3-6cbe-4eb7-add9-3d348af518ff_1598x760.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Common Pitfalls in Security Team Evolution</strong></h2><p>Based on my experience helping organisations transform their security teams, here are critical pitfalls to avoid and strategic approaches to consider:</p><h3><strong>Early-Stage Pitfalls (1-100 employees)</strong></h3><h4><strong>1. The "Security as Afterthought" Trap</strong></h4><p><strong>What Usually Happens:</strong></p><ul><li><p>Security person hired too late</p></li><li><p>No security considerations in early architecture decisions</p></li><li><p>Accumulation of security debt (Link to my other article)</p></li></ul><p><strong>Strategic Approach:</strong></p><ul><li><p>Engage security expertise even as a part-time consultant early</p></li><li><p>Build security into architectural decisions from day one</p></li><li><p>Create lightweight but scalable security processes</p></li></ul><h4><strong>2. The "One-Person Army" Syndrome</strong></h4><p><strong>What Usually Happens:</strong></p><ul><li><p>Single security person trying to do everything</p></li><li><p>No documentation or knowledge transfer</p></li><li><p>Burnout and potential single point of failure</p></li></ul><p><strong>Strategic Approach:</strong></p><ul><li><p>Focus on high-impact, automated solutions</p></li><li><p>Build security champions program early</p></li><li><p>Create documented processes and playbooks</p></li></ul><h3><strong>Growth Stage Pitfalls (100-300 employees)</strong></h3><h4><strong>1. The "Tool Proliferation" Problem</strong></h4><p><strong>What Usually Happens:</strong></p><ul><li><p>Too many security tools purchased without integration strategy</p></li><li><p>Teams overwhelmed with alerts and notifications</p></li><li><p>Limited return on security investments</p></li></ul><p><strong>Strategic Solution:</strong></p><ul><li><p>Develop a tool integration strategy</p></li><li><p>Focus on platform team development</p></li><li><p>Implement automated correlation and prioritisation</p></li></ul><h4><strong>2. The "Scaling Wall" Challenge</strong></h4><p><strong>What Usually Happens:</strong></p><ul><li><p>Security becomes a bottleneck</p></li><li><p>Increasing friction with development teams</p></li><li><p>Rising number of security incidents</p></li></ul><p><strong>Strategic Solution:</strong></p><ul><li><p>Implement security-as-code practices</p></li><li><p>Develop self-service security capabilities</p></li><li><p>Create clear escalation paths and SLAs</p></li></ul><h3><strong>Scale-up Stage Pitfalls (300-3000 employees)</strong></h3><h4><strong>1. The "Communication Breakdown" </strong></h4><p><strong>What Usually Happens:</strong></p><ul><li><p>Siloed security teams, little communication and alignment across different security teams. </p></li><li><p>Inconsistent security practices across teams</p></li><li><p>Duplicate efforts and inefficiencies</p></li></ul><p><strong>Strategic Solution:</strong></p><ul><li><p>Implement clear interaction patterns</p></li><li><p>Regular cross-team security forums</p><p></p></li></ul><h4><strong>2. The "Legacy Drag" Effect</strong></h4><p><strong>What Usually Happens:</strong></p><ul><li><p>Old security practices don't scale</p></li><li><p><a href="https://open.substack.com/pub/chrismartorella/p/security-technical-debt-in-software?r=ij5cn&amp;utm_campaign=post&amp;utm_medium=web&amp;showWelcomeOnShare=false">Technical debt</a> in security infrastructure</p></li><li><p>Resistance to change from established teams</p></li></ul><p><strong>Strategic Solution:</strong></p><ul><li><p>Regular security architecture reviews</p></li><li><p>Planned <a href="https://open.substack.com/pub/chrismartorella/p/security-technical-debt-in-software?r=ij5cn&amp;utm_campaign=post&amp;utm_medium=web&amp;showWelcomeOnShare=false">technical debt</a> reduction</p></li><li><p>Change management strategy for security evolution</p></li></ul><p>Do these sounds familiar to you? </p><h3>Recommendations when implementing Team Topologies</h3><p>If you are looking to implement team topologies or improve your security organisation, I recommend focusing on:</p><ol><li><p><strong>Quick Wins First</strong></p><ul><li><p>Identify immediate pain points</p></li><li><p>Implement high-impact, low-effort solutions</p></li><li><p>Build credibility for larger changes (Iterative approach)</p></li></ul></li><li><p><strong>Sustainable Growth</strong></p><ul><li><p>Design for scale from the start</p></li><li><p>Build automated and self-service capabilities</p></li><li><p>Focus on knowledge transfer and documentation</p></li></ul></li><li><p><strong>Cultural Transformation</strong></p><ul><li><p>Create feedback mechanisms</p></li><li><p>Celebrate security wins and learnings</p></li></ul></li></ol><p>These are simple but powerful tips when considered in any process to improve the security team organisation.</p><h3>Final thoughts</h3><p>Remember that team structures should remain flexible and adapt to changing security needs and organisational growth. Regular review and adjustment of team topologies ensure continued effectiveness of your security organisation, remember that what brought you here wont take you to the next level your business will need.</p><p>Team Topologies provides a flexible and scalable framework for organising cybersecurity teams in startups and scale-ups. By understanding and implementing these patterns appropriately, organisations can build security teams that effectively protect their assets while supporting rapid growth and innovation.</p><p>The key to success lies in starting with a <strong>minimal viable structure</strong> and evolving it gradually based on organisational needs. Regular assessment and adjustment of team structures ensure that security capabilities grow in alignment with business requirements.</p><p>Stay tuned for the follow up on how teams could evolve when adding AI agents into the mix.</p><p>If you want to discuss this topic or have ideas on how to organise better security teams, please contact me via <a href="https://www.linkedin.com/in/christianmartorella/">Linkedin</a> or drop some comments in this article.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[From Startup to Enterprise: How to Escape the Security Tech Debt Trap ]]></title><description><![CDATA[In the fast-paced world of software development, tech debt is a common issue that every engineering team faces sooner or later.]]></description><link>https://chrismartorella.substack.com/p/security-technical-debt-in-software</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/security-technical-debt-in-software</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Tue, 15 Oct 2024 07:28:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yWx2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the fast-paced world of software development, tech debt is a common issue that every engineering team faces sooner or later. Among the various forms of tech debt, <strong>security tech debt</strong> stands out as <em>particularly</em> critical due to the potential risks it poses. This article delves into what security tech debt is, how it is generated, strategies to effectively manage it, and the importance of prioritizing security, especially considering how it affects companies at different stages of their journeys.</p><h3><strong>What is Security Tech Debt?</strong></h3><p>Security tech debt refers to the accumulation of security vulnerabilities, weaknesses, and non-compliance within a software system. This type of debt arises when immediate pressures to deliver functionality lead to shortcuts or compromises in security. Like financial debt, security tech debt incurs "<strong>interest</strong>" in the form <strong>of increased risk</strong>, potential breaches, compliance failures and <strong>higher future remediation costs</strong>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yWx2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yWx2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!yWx2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!yWx2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!yWx2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yWx2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png" width="462" height="462" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:462,&quot;bytes&quot;:1636436,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yWx2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!yWx2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!yWx2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!yWx2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f2773f4-2c30-4488-9961-ae6d3bd7c07a_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>So how is security Tech Debt Generated?</strong></h3><p>There are points in the company journey when engineers ask themselves, how did we get to this point? And this is not single reason problem, but has many components: </p><ol><li><p><strong>Rapid Development Cycles: </strong>Pressure to meet deadlines often leads to security being an afterthought. Quick fixes and bypassing thorough security reviews contribute to vulnerabilities. This affects more Startups and Scale-ups where finding product market fit and fast growth is key.</p></li><li><p><strong>Lack of Security Expertise: </strong>Inadequate training and a lack of dedicated security staff can result in the implementation of insecure coding practices and overlooked security considerations. Also the inconsistency in security practices across different teams or projects can lead to inconsistent application of security controls and processes if any.</p></li><li><p><strong>Lack of security awareness and culture:</strong> Many development teams may not have a strong understanding of security principles. This lack of awareness can lead to poor coding practices, insufficient threat modeling, and neglect of security best practices, ultimately contributing to the accumulation of tech debt.</p></li><li><p><strong>Legacy Systems: </strong>Outdated technologies and legacy code that were developed without modern security standards in mind contribute significantly to security tech debt. Legacy systems tend to be overlooked and maintaince of such systems is not prioritized. Operating system and libraries tend to be End of Life and not support provided by vendors aka "no security patches".</p></li><li><p><strong>Neglecting Regular Updates: </strong>Delaying updates and patches for third-party libraries and dependencies introduces vulnerabilities that could have been avoided. Sometimes the lack of proper testing processes, and the worry of incompatibility of newer versions with your system makes team to push these changes to a future that never arrive.</p></li><li><p><strong>Resource constraints:</strong> Limited budgets and personnel can hinder an organization's ability to invest in security. When resources are stretched thin, security initiatives may be deprioritized, resulting in tech debt as teams are unable to address known vulnerabilities or implement necessary security controls.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2m-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2m-Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 424w, https://substackcdn.com/image/fetch/$s_!2m-Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 848w, https://substackcdn.com/image/fetch/$s_!2m-Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 1272w, https://substackcdn.com/image/fetch/$s_!2m-Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2m-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png" width="768" height="595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:595,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70177,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!2m-Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 424w, https://substackcdn.com/image/fetch/$s_!2m-Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 848w, https://substackcdn.com/image/fetch/$s_!2m-Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 1272w, https://substackcdn.com/image/fetch/$s_!2m-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85d5d4-5ed6-4b3b-a7e1-aafb0ee974bf_768x595.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It mostly boils down to <strong>prioritising releasing product features</strong>, and&nbsp; focusing on other areas like availability and performance over Security, due to the perception of customers on the product experience. Security is not perceived as a problem if customer dont see it, while availability and performance could mean the difference when building a new product, particularly in the early stages of growth of a company.</p><h3><strong>Tech Debt at Different Company Stages</strong></h3><p>Security tech debt impacts companies differently depending on their stage of growth. Understanding these differences is crucial for tailoring effective strategies to deal with security technical debt.</p><p><strong>Startups:</strong></p><ol><li><p><strong>Limited Resources</strong>: Startups often operate with limited resources and tight deadlines. This environment can lead to significant security tech debt as the focus is primarily on rapid development and market entry.</p></li><li><p><strong>Ad Hoc Security</strong>: Security practices may be inconsistent or ad hoc, increasing the risk of vulnerabilities.</p></li></ol><p><strong>Scale-Ups:</strong></p><ol><li><p><strong>Rapid Expansion</strong>: As companies grow, the complexity of their systems increases. The initial tech debt can quickly become unmanageable if not addressed.</p></li><li><p><strong>Increased Exposure</strong>: With growth, the potential impact of security breaches also increases, as the company handles more data and transactions.</p></li></ol><p><strong>Enterprises:</strong></p><ol><li><p><strong>Complex Systems</strong>: Large enterprises often have numerous legacy systems, each contributing to a substantial security tech debt.</p></li><li><p><strong>Regulatory Requirements</strong>: Enterprises are subject to stringent regulatory and compliance requirements, making security tech debt even more critical.</p></li></ol><p>Also it is the case that if a company incurs in Security tech debt, this will grow together with the company through all the phases, reaching to the point that when the company is big and complex fixing the security tech debt will become big and complex as well. (Captain obvious)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oe-5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oe-5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 424w, https://substackcdn.com/image/fetch/$s_!oe-5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 848w, https://substackcdn.com/image/fetch/$s_!oe-5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 1272w, https://substackcdn.com/image/fetch/$s_!oe-5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oe-5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png" width="476" height="386" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a575d130-d892-4f68-8810-7e567f2ea74a_476x386.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:386,&quot;width&quot;:476,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17746,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oe-5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 424w, https://substackcdn.com/image/fetch/$s_!oe-5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 848w, https://substackcdn.com/image/fetch/$s_!oe-5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 1272w, https://substackcdn.com/image/fetch/$s_!oe-5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa575d130-d892-4f68-8810-7e567f2ea74a_476x386.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>So how can we deal with Security tech debt?</strong></h3><p>There are many things that we can do to reduce the Security tech debt, but we can group them in these four categories: </p><ol><li><p><strong>Prioritize Security in Development:</strong></p><ul><li><p><strong>Shift Left/Secure by design</strong>: Integrate security practices early in the development process. Conduct regular security training for developers, introduce tooling in the developers processes, and provide visibility to the security posture of the code, libraries, images used in their projects.</p></li><li><p><strong>Security Requirements</strong>: Clearly define security requirements and ensure they are part of the acceptance criteria for every project.</p></li><li><p><strong>Threat Modeling/Design reviews</strong>: Conduct thorough threat modeling exercises to identify and prioritize security issues based on potential impact and likelihood.</p></li></ul></li><li><p><strong>Adopt a Risk-Based Approach:</strong></p><ul><li><p><strong>Risk Assessment</strong>: Continuously assess and prioritize security tech debt based on the severity and exploitability of vulnerabilities.&nbsp; Evaluate security vulnerabilities based on their potential impact and exploitability. Focus on high-risk issues first. Context here is king, the more context you have the better.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fCoY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fCoY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 424w, https://substackcdn.com/image/fetch/$s_!fCoY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 848w, https://substackcdn.com/image/fetch/$s_!fCoY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 1272w, https://substackcdn.com/image/fetch/$s_!fCoY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fCoY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png" width="518" height="378.53846153846155" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:456,&quot;width&quot;:624,&quot;resizeWidth&quot;:518,&quot;bytes&quot;:46981,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fCoY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 424w, https://substackcdn.com/image/fetch/$s_!fCoY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 848w, https://substackcdn.com/image/fetch/$s_!fCoY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 1272w, https://substackcdn.com/image/fetch/$s_!fCoY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39859062-7f6c-4fb6-a7cc-2038e1a712fc_624x456.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li></ul></li><li><p><strong>Refactor and Update Legacy Systems:</strong></p><ul><li><p><strong>Modernization Plans</strong>: Develop plans to refactor or replace legacy systems incrementally to adhere to current security standards.</p></li><li><p><strong>Patch Management</strong>: Implement a robust patch management process to keep all systems and dependencies up to date.</p></li><li><p><strong>Slipstreaming</strong>:&nbsp; Usually generic tech debt activity mitigation will involve keeping libraries and OS updated to the latest version, which on its own will reduce the number of vulnerabilities to the bare minimum. If there are initiatives for patching, upgrading system and libraries, ensure Security team <strong>contribute, participate and leverage </strong>those projects as it will contribute positively to reduce the security tech debt. For example if there is a Quality process or initiatives, this is a great opportunity to embed security there and join forces. </p></li><li><p><strong>Golden Images and version drifting:</strong> In cloud native environments where is easier to manage the fleet with IaC and CI/CD pipelines the goal should be to have the latest Golden Image available, and monitor drifting against it. There are Secure containers and image providers like Seal.security and Chainguard.dev to ensure that you have a vulnerability free base golden images.</p></li></ul></li><li><p><strong>Foster a Security Culture:</strong></p><ul><li><p><strong>Awareness Programs</strong>: Conduct regular security awareness programs to keep security top of mind for all team members.</p></li><li><p><strong>Security Champions programs</strong>: Appoint security champions within development teams to advocate for security best practices and act as liaisons with security experts.</p></li><li><p><strong>VIsibility on the security posture: </strong>You cant fix what you dont know. Surfacing the security posture of the systems, assets and components</p></li><li><p><strong>Transparency across the organization</strong>: Communicate the importance of prioritizing security to all stakeholders, including leadership and engineering teams. Provide regular updates on the status of security tech debt and the efforts to address it, highlighting successes and areas needing attention.</p></li><li><p><strong>KPIs and Metrics</strong>: Establish key performance indicators and metrics specifically for security tech debt reduction.</p></li><li><p><strong>Incentives/Gamification</strong>: Create incentives for teams to prioritize and effectively manage security tech debt, recognizing and rewarding their efforts. Work with positive reinforcement instead of focusing on the negatives, in security we have a long track record of focusing on the negative, the bad and the ugly, we know that it doesnt work as we think, and it is time to move to positive reinforcement, celebrating the wins and achievements.</p></li></ul></li></ol><p></p><h3><strong>Allocating Time to Address Tech Debt</strong></h3><p>Managing security tech debt requires a deliberate allocation of time and resources. Without this dedicated effort, <strong>security issues can quickly accumulate, becoming more difficult and costly to address in the future</strong>, so the longer we wait the more difficult it will be for us.  Here&#8217;s a couple of ways I am familiar with,  to incorporate time allocation into your workflow:</p><ol><li><p><strong>Scheduled Tech Debt Sprints:</strong></p><ul><li><p><strong>Dedicated Time</strong>: Allocate regular intervals (e.g., one sprint per quarter) specifically for addressing tech debt, with a significant focus on security issues.</p></li><li><p><strong>Team Involvement</strong>: Ensure all team members understand the importance of these sprints and actively participate in identifying and resolving security tech debt.</p></li></ul></li><li><p><strong>Continuous Improvement Cycles:</strong></p><ul><li><p><strong>Integrate into Agile Practices</strong>: Make tech debt remediation a part of the ongoing development process by including it in your backlog and sprint planning. Many companies allocated around 20-30% for dealing with general tech debt which includes security work. This is in theory, if you ask engineers usually it&#180;s difficult to prioritize and use this time, as product features and other priorities tend to require all the sprint time, this will be highly related with the maturity of the Engineering and product organization.</p></li><li><p><strong>Review and Reflect</strong>: Regularly review progress on tech debt reduction and adjust strategies as needed to ensure continuous improvement.</p></li></ul></li><li><p><strong>Bug Bash Sessions:</strong></p><blockquote><p>&#8226; <strong>Focused Collaboration</strong>: Organize regular &#8220;security bug bash&#8221; sessions where cross-functional teams gather to find and address security-related bugs and vulnerabilities. These sessions can create a sense of urgency and excitement around tackling security tech debt, as well as surface issues that might be overlooked during regular sprints.</p><p>&#8226; <strong>Reward &amp; Recognition</strong>: Recognize and reward the team for contributions during these sessions. Positive reinforcement encourages team members to actively participate and prioritize security.</p></blockquote></li></ol><p></p><p>No matter your company&#8217;s stage, addressing security tech debt early is critical to sustaining long-term growth and resilience. Here are some tips for the different phases of company growth:</p><p>&#8226;<strong> Startups</strong>: Start integrating security into your development process today. Even with limited resources, a proactive approach will help avoid costly, unmanageable security debt in the future.</p><p>&#8226; <strong>Scale-Ups</strong>: As you scale, so does your exposure to security risks. Take immediate steps to assess and prioritize your security tech debt, ensuring you don&#8217;t carry vulnerabilities into your next growth phase.</p><p>&#8226; <strong>Enterprises</strong>: With complex systems and strict regulatory requirements, incremental improvements in your security infrastructure are essential. Focus on refactoring and patch management to modernize legacy systems and maintain compliance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!udVG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!udVG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!udVG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!udVG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!udVG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!udVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png" width="402" height="402" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:402,&quot;bytes&quot;:1770985,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!udVG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!udVG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!udVG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!udVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29f49631-2a65-492c-9d53-6d9c11419ac8_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Remember,&nbsp; like financial debt, security tech debt incurs "<strong>interest</strong>" in the form <strong>of increased risk</strong>, potential security breaches, compliance failures and <strong>higher future remediation costs</strong>.  Security debt grows alongside your company, but by dedicating time and resources now, you can keep it manageable. Whether you&#8217;re a startup, scale-up, or enterprise, make security a key part of your strategy&#8212;schedule tech debt sprints, dedicated % time for tech debt, foster a security culture, and celebrate every win. Your future self and company will thank you!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[80/20 rule and Cybersecurity]]></title><description><![CDATA[Maximize security with minimal effort]]></description><link>https://chrismartorella.substack.com/p/8020-rule-and-cybersecurity</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/8020-rule-and-cybersecurity</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Tue, 24 Sep 2024 08:18:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Let&#8217;s continue with the principles and simplification of Cybersecurity, as I believe this is an area that will benefit lot&#8217;s of people and will make Cybersecurity better for everyone &#128578;</p><p>Long time ago I discovered the 80/20 rule when I got my hands on this book by Richard Koch:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cw4f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cw4f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 424w, https://substackcdn.com/image/fetch/$s_!cw4f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 848w, https://substackcdn.com/image/fetch/$s_!cw4f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!cw4f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cw4f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png" width="518" height="690.6666666666666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:518,&quot;bytes&quot;:1717405,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cw4f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 424w, https://substackcdn.com/image/fetch/$s_!cw4f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 848w, https://substackcdn.com/image/fetch/$s_!cw4f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!cw4f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd46a05a2-9f80-407d-bf35-f067490340d5_1200x1600.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I remember being&nbsp; pretty shocked at the concept, but the more I delved into it, the more it became a key tool in my decision-making and analysis.</p><p>What I am surprised is that not everyone is familiar with it, and I was assuming that everyone knows and apply it, but it is normal to assume that something you know is easy and everybody knows it.</p><p>So what is it about?&nbsp; the <strong>80/20 rule says that roughly 80% of the results are obtained with 20% percent of the effort</strong>.&nbsp; Think about that for a moment, most of what you accomplish comes from just a small fraction of what you do.</p><p>This rule is also called the <strong>Pareto Principle</strong>, named after Vilfredo Pareto (1848&#8211;1923) an Italian engineer, sociologist, economist, and philosopher. Originally, Pareto observed this phenomenon in <strong>wealth distribution, noting that 20% of Italy&#8217;s population owned 80% of its wealth</strong>.</p><p>I have seen it and applied in many aspect of my life, more heavily at work, and particularly in Cybersecurity.</p><p>The first example I have noticed, was when doing <strong>vulnerability assessments</strong> usually 80% of vulnerabilities where found in 20% of the assets. In Internal security assessment I remember that is was consistent, usually due to legacy system concentrating the majority of the vulnerabilities, or the assets belonging to particular teams that for different reasons they were struggling with patching or decommissioning services. I remember that at one point we started to add this observations in the audit/vulnerability assessment reports, to show how focusing in a few assets would reduce the amount of vulnerabilities. Usually the discussion on the customer side went&nbsp; &#8220;Do we need these systems? can we decommission them?&#8221; (I understand that this approach could be focusing just in volumen and not presicely on risk, today we have much more context to make better prioritization desicions with Vulnerability indicators like KEV, asset exposure, attack path and the likes).</p><p>If we look into <strong>security controls</strong>, we can find that 80% of the incidents could be prevented by implementing 20% of available security controls, you should&nbsp; implement the most effective controls first, for example multi-factor authentication, regular patching, and employee security awareness training could prevent the majority of potential security incidents.</p><p>Another example could be that 80% of <strong>policy violations</strong> may involve 20% of security policies, focus on enforcing and improving the most frequently violated policies.</p><p>When it comes to <strong>Threat intelligence</strong> 80% of relevant threat intelligence may come from 20% of sources. Focus on the most reliable and applicable threat intelligence feeds. You should understand which sources where most useful over the time, and which sources provided the most actionable intelligence.</p><p>The 80/20 principle is especially relevant in <strong>project management</strong>. When starting new projects, it&#8217;s important to recognize that 80% of the results will come from just 20% of the effort. However, completing the remaining 20% of the work will still require significant effort. By adopting agile practices and an iterative approach, you can deliver value early on with that initial 20% of effort, ensuring progress and impact from the start.</p><p>When looking at <strong>compliance</strong> we may see that 80% of compliance requirements might be satisfied by 20% of your security controls, thus Implementing multi-purpose controls that address multiple compliance needs will provide time and resources savings.</p><p>When it comes to <strong>Data protection</strong>, 80% of sensitive data may reside in 20% of your databases or systems, focus encryption and access control efforts on these critical data stores first.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8Gh4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8Gh4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!8Gh4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!8Gh4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!8Gh4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8Gh4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png" width="628" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:628,&quot;bytes&quot;:1133533,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8Gh4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!8Gh4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!8Gh4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!8Gh4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F106c73c7-7e2c-42b3-a86c-75d1188fd718_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So how can you start applying this principle in your way of working?</p><p><strong>Step 1: Identify Your 20%</strong></p><p>Begin by assessing your daily activities. Reflect on the following:</p><p>&#8226; Which tasks or actions yield the most significant results?</p><p>&#8226; Which clients, projects, or relationships offer the highest return on your time and energy?</p><p>In a cybersecurity context, this could involve identifying the systems, controls, or protocols that contribute most to your security posture.</p><p><strong>Step 2: Focus on the most impactful Tasks</strong></p><p>After pinpointing your 20%, shift your attention. Dedicate more time to these high-impact activities and less to those that don&#8217;t significantly advance your goals. This might involve delegating tasks, saying &#8220;no&#8221; more often, or reorganizing your priorities to concentrate on work that adds the most value&#8212;whether it&#8217;s in managing key clients, projects or securing critical assets.</p><p><strong>Step 3: Cut the Low-Value 80%</strong></p><p>This step can be challenging: reduce or eliminate time spent on low-value tasks. These are the activities that consume time but contribute little to your objectives. It could be excessive meetings, unnecessary emails, or even habits that drain your energy. By minimizing these, you&#8217;ll free up valuable time to invest in your 20%, such as focusing on essential security measures or client relationships.</p><p><strong>Step 4: Continously reevaluate</strong></p><p>The 80/20 Rule isn&#8217;t a one-time task. It requires regular reevaluation. Every few months, take a moment to reassess your 20%. As your goals and priorities evolve, so will the activities that deliver the highest returns. This consistent evaluation ensures that you stay focused on what matters most, whether in life or in maintaining a strong cybersecurity stance.</p><p>I hope this principle will help you improve your decision making and prioritization skills making your cybersecurity teams more efficient.</p><p>Take a moment to assess your cybersecurity strategy today. Identify the key areas where the 80/20 principle can make the most impact, and start focusing your efforts where they count the most.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Build vs. Buy: The Hidden Costs of In-House Solutions]]></title><description><![CDATA[I&#8217;ve seen teams repeatedly opt to build their own solutions because it seemed cheaper, or because &#8220;there&#8217;s no product on the market that offers this one critical feature we need.&#8221; Often, they also assume it will be &#8220;easy to automate.&#8221;]]></description><link>https://chrismartorella.substack.com/p/build-vs-buy-the-hidden-costs-of</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/build-vs-buy-the-hidden-costs-of</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Thu, 12 Sep 2024 19:44:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!23nH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve seen teams repeatedly opt to build their own solutions because it seemed cheaper, or because &#8220;there&#8217;s no product on the market that offers this one critical feature we need.&#8221;&nbsp; Often, they also assume it will be &#8220;easy to automate.&#8221;</p><p>Particularly in cybersecurity teams, the process usually starts with a simple Python script running on a server via crontab. For the first few days, everything works smoothly&#8212;until it doesn&#8217;t. The script stops delivering results, and the team discovers the server crashed after a certain number of runs. To mitigate this, they add a second script to monitor the first one and set up email or Slack alerts for failures. Vulnerabilities in the OS and libraries start to pop, now upgrading, patching and maintaincnace in general gets added on top.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Then, one weekend, it fails again, but this time it impacts a larger process, requiring on-call support. Now, that simple script has grown into a full-fledged operation&#8212;complete with monitoring, runbooks, on-call shifts, and ongoing maintenance. And we are not considering if the engineer that built it and maintained it leaves the company, and someone else that doesn&#8217;t have the right experience needs to pick it up. In hindsight, the cost of building and maintaining this custom solution often ends up being comparable to (or even exceeding) the price of a vendor solution.</p><h3><strong>The Strategic Dilemma: Build vs. Buy</strong></h3><p>The decision to build in-house or buy from a vendor is one of the most fundamental in operations strategy. (Actually I learnt about this in Operations Strategy course in the while doing the MBA). Yet, too often, it&#8217;s made based on short-term cost savings&#8212;especially when companies are trying to stay competitive or cut their cost base (very relevant now in 2024).</p><p>Efficiency should be the guiding principle behind any <strong>build vs. buy</strong> decision, but this strategic choice affects operational performance in complex ways. It can also stifle or enable innovation, which is increasingly critical for companies aiming to stay relevant in fast-changing industries.</p><p>When you build in-house, you have full control, allowing you to experiment, iterate, and potentially innovate faster. However, the question becomes whether this innovation is core to your business or a distraction from your primary goals. And you dont want wasting resources where you don&#180;t need them. In some cases, relying on external vendors can foster innovation by freeing up your team to focus on what truly matters&#8212;allowing them to explore new ideas rather than getting bogged down in maintaining internal systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!23nH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!23nH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!23nH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!23nH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!23nH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!23nH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png" width="570" height="570" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:570,&quot;bytes&quot;:1570594,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!23nH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!23nH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!23nH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!23nH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30879bb-5053-4f96-8d77-ba89efd578b0_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>When Does buying Make Sense?</strong></h3><p>The first thing to consider is whether the task or component has long-term <strong>strategic</strong> importance to the company or your team in particular. If it does, buying likely isn&#8217;t the best option. Similarly, if your team possesses specialized skills or knowledge in this area, it usually makes more sense to keep the work in-house.</p><p>However, <strong>innovation</strong> must also be factored into this equation. If the task or solution you&#8217;re considering building plays a central role in fostering innovation within your team&#8212;driving new business models, improving customer experiences, or developing a competitive advantage&#8212;then it&#8217;s worth keeping in-house.</p><p>On the flip side, if the task is routine or the solution became a <strong>commodity</strong> and doesn&#8217;t contribute directly to innovation or your competitive edge, buying can be a smart move. A good vendor may even introduce innovative features or processes that would be too resource-intensive for you to develop on your own. (Vendors partnerships is another topic)</p><p>Once these strategic factors have been evaluated, you can turn your attention to operational performance and cost. If your in-house performance is far superior to any supplier, buying may not be worth it. However, if your performance lags behind and you can&#8217;t realistically improve it in-house, buying becomes a more attractive option&#8212;especially if achieving the desired improvement internally would be too costly or complex.</p><p><strong>Here is simple visualization of the considerations when making this decision:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r0yI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r0yI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 424w, https://substackcdn.com/image/fetch/$s_!r0yI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 848w, https://substackcdn.com/image/fetch/$s_!r0yI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 1272w, https://substackcdn.com/image/fetch/$s_!r0yI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r0yI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png" width="1456" height="553" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/def59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:553,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:398230,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!r0yI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 424w, https://substackcdn.com/image/fetch/$s_!r0yI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 848w, https://substackcdn.com/image/fetch/$s_!r0yI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 1272w, https://substackcdn.com/image/fetch/$s_!r0yI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdef59d5a-e128-4ee6-8447-5baa981bc7d3_3246x1232.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ultimately, the build vs. buy decision requires careful consideration on your company&#8217;s core capabilities and how they contribute to your competitive advantage. Innovation plays a crucial role in this evaluation. If developing a solution in-house would lead to breakthrough innovations or strengthen your position in the market, the additional costs and complexity may be worth it.</p><p>But once you&#8217;ve determined that the activity is neither strategically important nor critical to your competitive edge or innovation efforts, the focus should shift to finding the most effective solution. Remember, buying a solution isn&#8217;t just about saving money&#8212;it involves significant effort and resources. You&#8217;ll need to research vendors, run proofs of concept, negotiate contracts, and plan for a migration process that often includes running parallel systems until the new solution is fully functional, onboarding the new service, learning, etc. This is a major project in its own right, which is why many companies only go down this path when every other option has been ruled out&#8212;or when internal costs have become unsustainable. </p><p> &nbsp;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Simplifying Security - Razors in Cybersecurity II ]]></title><description><![CDATA[In the previous article I introduced the concept of Philosophical Razors and how can they be applied to Cybersecurity.]]></description><link>https://chrismartorella.substack.com/p/simplifying-security-razors-in-cybersecurity</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/simplifying-security-razors-in-cybersecurity</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Mon, 09 Sep 2024 17:59:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XNtF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the <a href="https://substack.com/home/post/p-148362555">previous article</a> I introduced the concept of Philosophical Razors and how can they be applied to Cybersecurity. These are principles or rule of thumb that allows us to quickly analyze and eliminate unlikely explanations, or avoid unnecessary actions. We introduced two Razors &#8220;Occam's Razor&#8221; and &#8220;Hanlon's principle&#8221;.&nbsp; Let's continue with a few more Razors that I believe that will be helpful to aid your decision making:</p><h3><strong>Newton's Flaming Laser Sword (Alder's Razor)&nbsp;</strong></h3><p>Is a philosophical principle introduced by cognitive scientist Mike Alder. It states: <strong>&#8220;What cannot be settled by experiment is not worth debating.&#8221;</strong> </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>This razor emphasizes the importance of focusing on practical, testable questions rather than wasting time on abstract or theoretical arguments that lack empirical evidence. You might be wondering why Alder's chose this name? He chose the term &#8220;<strong>Flaming Laser Sword</strong>&#8221; to make it sound more dramatic and memorable than other philosophical &#8220;razors&#8221; like Occam&#8217;s Razor. The &#8220;sword&#8221; represents its power to cut through pointless or unresolvable discussions.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XNtF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XNtF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XNtF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XNtF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XNtF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XNtF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png" width="472" height="472" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:472,&quot;bytes&quot;:1275187,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XNtF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XNtF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XNtF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XNtF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3cf874e-3e03-469e-886a-5f4b8073daac_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here are some scenarios where we can apply it in Cybersecurity:</p><ul><li><p><strong>Evidence-Based Security</strong>: Focus on strategies and tools with proven effectiveness, usually this will take you back to the basics. Avoid getting bogged down in theoretical debates without practical data.</p></li><li><p><strong>Vendor Claims of &#8220;100% Security</strong>&#8221; Some vendors may claim that their product offers &#8220;100% protection&#8221; from all threats. Instead of debating the impossibility of perfect security, apply <strong>Alder&#8217;s Razor</strong>: demand real-world testing. Conduct penetration testing, threat simulations, or review independent security audits to assess the actual performance of the solution under attack scenarios, rather than engaging in theoretical arguments about absolute security.&nbsp; If you can obtain third party assessments and other customers testimonials that can help you support and speed up this process much better.&nbsp;</p></li><li><p><strong>Risk prioritization:&nbsp; </strong>Imagine a security team is debating whether to focus on a hypothetical risk from quantum computing breaking encryption algorithms versus addressing known vulnerabilities in their existing systems like weak passwords and the lack of MFA. According to Alder&#8217;s Razor (&#8220;<strong>What cannot be settled by experiment is not worth debating&#8221;</strong>), the focus should be on the proven risks that can be empirically tested and mitigated, such as patching vulnerabilities or implementing stronger password policies. Theoretical discussions about future risks like quantum computing encryption-breaking should be set aside until there is concrete, testable evidence that those risks are imminent.&nbsp;</p></li></ul><h4><strong>Why is this important?</strong></h4><p><strong>Resources and Time</strong>: In cybersecurity, resources and time are finite and scarce. Focusing on risks that can be directly mitigated today, rather than on theoretical risks that cannot be tested or quantified, leads to more effective risk management.</p><p><strong>Evidence-Based Action</strong>: By applying Alder&#8217;s Razor, the team avoids getting caught up in speculative debates and instead addresses real, measurable risks that are more likely to impact the organization now.</p><h3><strong>Sagan Standard&nbsp; - &#8220;Extraordinary Claims Require Extraordinary Evidence&#8221;</strong></h3><p>The Sagan Standard, coined by astronomer Carl Sagan, is a principle that emphasizes the need for strong, compelling evidence when extraordinary claims are made. Essentially, the more unlikely or exceptional a claim is, the higher the burden of proof should be. This standard is a tool for critical thinking, helping to avoid accepting extraordinary assertions without the necessary validation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q1iN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q1iN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!q1iN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!q1iN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!q1iN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q1iN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png" width="534" height="534" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:534,&quot;bytes&quot;:1617336,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q1iN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!q1iN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!q1iN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!q1iN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb53e2bd0-65c9-4621-83d6-7fbc92051406_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One of the most famous and common application of the Sagan Standard is in UFO sightings or claims of alien life. While there are many claims about UFO encounters, extraordinary evidence (such as physical proof or high-quality documentation) is required to seriously entertain the idea that aliens have visited Earth. Simply seeing a light in the sky is not enough; such an extraordinary claim demands extraordinary, undeniable evidence. (the Alien presented in the Mexican Congress don&#8217;t think it counts)</p><p><strong>Threat Intelligence</strong>: Threat claims of new, sophisticated attacks with skepticism until strong evidence is provided. Before going after the latest shiny actor, make sure that there is enough information from reputable sources about this threat/actor.&nbsp;</p><p><strong>Attributing an Attack to an actor</strong></p><p>Attributing a cyberattack to a sophisticated actor, like a government-backed group, is an extraordinary claim. The Sagan Standard would require extraordinary evidence such as detailed forensic analysis, indicators of compromise (IoCs), and corroboration from multiple intelligence sources before such an attribution can be made.</p><p><strong>Zero-Day Exploit Detection</strong></p><p>A vendor claiming that their product can detect and block all zero-day exploits would need to provide extraordinary evidence, like independent testing data or successful real-world use cases against previously unknown threats. The more exceptional the claim, the more data is needed to validate it.</p><p><strong>Vendor Claims of Unhackable Systems</strong></p><p>When a vendor claims their system is &#8220;unhackable&#8221; or &#8220;100% secure,&#8221; the Sagan Standard suggests that this extraordinary claim requires extraordinary evidence. Instead of accepting the claim at face value, you should demand rigorous third-party testing, audits, and penetration testing reports that support this claim.</p><h4><strong>Why is this important?</strong></h4><p>&#8226; <strong>Impact of Attribution</strong>: Incorrectly attributing an attack to a nation-state can lead to misaligned resources and effrots, or even get you into legal and financial troubles. (depending on your organization)</p><p>&#8226; <strong>Skepticism</strong>: The Sagan Standard prevents security teams from jumping to conclusions based on extraordinary claims without adequate proof. It encourages evidence-based approach before accepting such attributions.</p><p></p><h3><strong>Hitchens&#8217; Razor - &#8220;What Can Be Asserted Without Evidence Can Be Dismissed Without Evidence&#8221;</strong></h3><p>Hitchens&#8217; Razor, attributed to author and journalist Christopher Hitchens, is a principle of skepticism that emphasizes the importance of evidence when making assertions. It states that if someone makes a claim without providing evidence, there is no obligation to accept or even entertain the claim until evidence is presented.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XwcA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XwcA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XwcA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XwcA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XwcA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XwcA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png" width="452" height="452" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:452,&quot;bytes&quot;:2083391,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XwcA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XwcA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XwcA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XwcA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee69dd7c-125a-4818-bdf8-5fc7eca60b99_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Vendor Claims</strong>: Require solid evidence before investing in new security technologies or services.&nbsp; If a security vendor claims that their product is the &#8220;best on the market&#8221; but offers no data, case studies, or independent reviews to back it up, Hitchens&#8217; Razor allows you to dismiss this claim until real evidence (such as performance benchmarks or client testimonials) is provided. You are under no obligation to consider or trust the claim without solid evidence.</p><p><strong>Unverified Incident Attribution</strong></p><p>An IT staff member might claim that a recent security breach was caused by a particular hacker group without providing forensic evidence, logs, or any indicators of compromise. According to Hitchens&#8217; Razor, this claim can be dismissed until actual proof is presented. Without evidence, the claim holds no weight.</p><p><strong>False Positive Security Alerts</strong></p><p>Security tools often generate false positives. If an analyst claims that a particular alert represents a real threat without offering detailed analysis or correlating evidence, Hitchens&#8217; Razor suggests that this assertion can be ignored until they provide concrete proof that the alert represents an actual security incident.</p><h4><strong>Why This is Important:</strong></h4><p><strong>&#8226; Avoiding Unnecessary Investments</strong>: By applying Hitchens&#8217; Razor, cybersecurity teams avoid investing in tools or technologies based on exaggerated claims that lack evidence, preventing wasted resources and potential security gaps.</p><p>&#8226; <strong>Promoting Evidence-Based Decision Making</strong>: It encourages a culture of evidence-based decision-making in cybersecurity, where solutions are evaluated on their merits, not on unverified promises.</p><p></p><p>Each of these principles contributes to cutting through <strong>unnecessary assumptions</strong>, <strong>exaggerated claims</strong>, or <strong>overcomplicated theories</strong>, helping us focus on the most likely and evidence-based explanations. I noticed through the years, that seasoned experienced Cybersecurity professionals tend to apply many of these razors in their thinking and when making decisions, while more juniors and unexperienced professionals tend to get bogged down in the complexity and the hype of claims from vendors and media. Hopefully, this article inspires you to adopt these principles early, empowering your teams to make smarter, faster decisions&#8212;while cutting through complexity and making security simpler.&#8221;</p><p><em>*Images created with <a href="https://designer.microsoft.com/">Microsoft Designer</a></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Simplifying Security]]></title><description><![CDATA[Applying philosophical Razors to Cybersecurity]]></description><link>https://chrismartorella.substack.com/p/simplifying-security</link><guid isPermaLink="false">https://chrismartorella.substack.com/p/simplifying-security</guid><dc:creator><![CDATA[Chris Martorella]]></dc:creator><pubDate>Sun, 01 Sep 2024 17:26:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FKGV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Recently, I&#8217;ve been reading various books that discuss the importance of having a set of operating principles. These principles serve as a strong foundation for life, providing a reliable framework for making decisions and handling different situations, whether in your personal or professional life.&nbsp;When researching more on principles, i came across the concept of &#8220;<strong>Razors</strong>&#8221;<strong> in a <a href="https://x.com/george__mack/status/1779528225225326926?s=12">tweet</a> from George Mack</strong>, these are principles or rule of thumb that allows us to quickly analyze and eliminate unlikely explanations, or avoid unnecessary actions. You can think of <strong>Razors as mental shortcuts</strong> to help you in problem solving, decision making and critical thinking by reducing the complexity of the situation. &nbsp;</p><p>I&#8217;ve decided to adapt these on the context of Cybersecurity, as I found that this could be very beneficial for Security practitioners.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>When it comes to <strong>Razors</strong> you might be familiar with <strong>Occam's Razor</strong>, this is a fundamental concept in science and critical thinking that emphasizes the importance of simplicity and parsimony when evaluating explanations or theories. It was named after the English philosopher William Ockham (1287-1347).</p><p>A great example of Occam Razors, can be found in medicine, with the principle &#8220;<strong>when you hear hoof beats, think horses, not zebras&#8221; </strong>which means that when diagnosing a patient, doctors consider the simplest and most common explanation for the symptoms. (Horses represents the common, simplest most likely conditions, and Zebras the less likely conditions).&nbsp;</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FKGV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FKGV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FKGV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FKGV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FKGV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FKGV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg" width="1120" height="1120" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1120,&quot;width&quot;:1120,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:324839,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FKGV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FKGV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FKGV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FKGV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff931429-4801-4ba7-b396-b25a1a495188_1120x1120.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>&nbsp;So how can we be apply <strong>Occam&#180;s Razor</strong> in Cybersecurity? &nbsp;</p><ol><li><p><strong>The simplest explanation</strong>: When analyzing a security incident, consider whether the most straightforward explanation (e.g., a malicious actor exploited a known vulnerability) is more likely than a complex one (e.g., a sophisticated nation-state attack). Can we simplify this explanation further? Yes, how many times the root cause of an incident turn up to be a misconfiguration? It's pretty common to first assume that you are under attack, when in reality there was a problem in the latest update of the CI/CD system or a new change in a service that is generating more traffic than expected. <strong>When testing a security hypothesis, prefer simpler explanations over more complex ones.&nbsp;</strong></p><p></p></li><li><p><strong>Prioritize simplicity in design</strong>: When designing security systems, protocols and processes, favor simplicity over complexity. This can help reduce the risk of errors, improve maintainability, testing and make it easier to understand and implement the system. The simpler the system the more reduced the attack surface will be, less opportunities for vulnerabilities, abuses and errors. Simpler system will have less components, interfaces and interactions, as demonstrated by threat modeling the interactions of these components are the ones where the threats manifest. <strong>Less components and interactions means less potential threats.</strong> &nbsp;</p></li></ol><p>&#8220;<strong>Simplicity is the ultimate sophistication</strong>.&#8221;&#8203;&#8212; Clare Boothe Luce</p><ol start="3"><li><p><strong>Avoid unnecessary assumptions</strong>: In threat analysis, don't assume that a particular actor or group is responsible for an incident without sufficient evidence. Instead, start with the simplest explanation (e.g., a single individual or a known adversary group) and add complexity as needed and evidence supports it. &nbsp; Occam's Razor suggests starting with this simpler explanation and adding complexity only if there is sufficient evidence to support more complex theories. It's common that people start assuming that the actors that are in the latest news are the ones behind our incidents.</p></li></ol><p>Another useful razor is the <strong>Hanlon's Razor</strong>, which is a relative modern aphorism, attributed to Robert J. Hanlon&#8217;s coined as part of his book &#8220;<strong>Murphys law Book two: More reasons why Things go wrong!</strong>&#8221; (1980). &nbsp;</p><p><strong>Hanlon&#8217;s principle</strong> states: <strong>&#8220;Never attribute to malice that which can be adequately explained by stupidity.&#8221;</strong> In this context, stupidity can be also understood as ignorance, not knowing, lack of awareness. And here are a couple of examples of its application:&nbsp;</p><ul><li><p><strong>Error/cause analysis</strong>: When investigating security incidents, consider human error before assuming malicious intent. Misconfigurations or mistakes often lead to vulnerabilities as discussed in the previous paragraphs. This part is the one that makes Hanlon&#8217;s close to Occam's, Human error will be the simplest explanation over more complex ones like "we are under attack". Many incidents end up being users who are not familiar or aware of certain company policy and perform a task using a program or website that is not allowed, but the security team identifies as an attack. </p></li><li><p><strong>User Behavior</strong>: Human actions should be interpreted as ignorance or error rather than deliberate malice.&nbsp; Here is the importante of educating users on common security practices rather than assuming they are intentionally bypassing protocols. How many times have you heard a security team member complaining that users are bypassing controls, or not following processes, and when you ask if the users were trained on that process, the answer is &#8220;No&#8221;. &nbsp;<strong>Hanlon&#8217;s razor is very useful to avoid unnecessary conflict and escalations, by avoiding attributing things to malice.</strong></p></li></ul><p>That&#8217;s all for now. In the next article, I&#8217;ll explore more razors and principles that are highly valuable for cybersecurity. <strong>Remember&#8230; if you hear hoofbeats, think horses not zebras.&nbsp;</strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://chrismartorella.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>