Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
Calm Under Attack™

15 members • Free

4 contributions to Calm Under Attack™
🚫 The Department of No Has an Unintended Subsidiary
Cybersecurity has sometimes earned a reputation as the Department of No. Can we use this new tool? No. Can this vendor connect remotely? No. Can we use this cloud service? No. Except the business still has work to do. And if people can't get what they need through the approved process, some of them will find another way. Maybe someone buys a SaaS application on a credit card. Another team starts using an unapproved messaging platform. A spreadsheet quietly becomes part of a critical workflow. Someone automates a process with a tool IT doesn't know exists. Welcome to the Department of Shadow IT. From an operational survival perspective, this creates a problem we don't talk about enough: invisible dependencies. The systems inventory says one thing. The business may actually operate another way. Maybe the continuity plan still lists a manual workaround that disappeared years ago. Maybe a supposedly noncritical application feeds the spreadsheet someone needs every morning. Maybe an entire department now depends on a cloud service that never made it into the business impact analysis. Everything works fine—until something doesn't. Then somebody says: “Wait. We can't do that without ______.” 💬 Food for thought: What technology has your organization quietly become dependent on that might not appear in your official inventory, business impact analysis, or continuity plan?
1 like • 11d
Instead of instinctual and immediate No, I've long tried to approach each technology request with "Yes, we can do that if we identify the controls that reduce the risk to an acceptable level for the business"
Well... the AI got out. 😬
We've spent years worrying about attackers breaking into our environments. Now we apparently need to think about AI agents breaking out of them. OpenAI recently disclosed that AI agents being tested for cybersecurity capabilities escaped an isolated evaluation environment and reached real-world systems at Hugging Face. And now another AI model—Kimi K3—has reportedly bypassed a cybersecurity testing sandbox as well. The operational lesson is what caught my attention. We thought it was contained. Organizations make assumptions like that all the time. The vendor will be available. The backup will restore. The network segmentation will hold. The IR firm will respond. The manual process will work. The AI agent will stay in its sandbox. Maybe it will. But operational resilience can't depend entirely on maybe. If one of our most important assumptions turns out to be wrong, can we still operate? What assumption would you most hate to discover was wrong during an incident?
0 likes • 18d
As an engineer for almost 30 years, my mind went immediately to technical. However the more I thought about it I believe my answer would change. The assumption I would most hate to discover was wrong is that the people who need to make the decisions will have the correct information, the authority, mindsets, communications, coordination, resources, and will to act in an a chaotic and uncertain situation.
1 like • 18d
In other words, the organization has made the mistake of equating having an incident response plan with having an incident response decision making capability.
⚡ One Question
Imagine you walk into work tomorrow morning and discover that the technology your organization depends on most is unavailable. Not compromised. Not slow. Unavailable. No one knows how long it will last. What's the first thing that worries you? Serving customers? Payroll? Communications? Production? Public safety? Regulatory obligations? Something else entirely? What immediately comes to mind? 👇 Share your answer in the comments.
1 like • Jul 15
Safe reliable operations restoration and continuity
1 like • 28d
For a midstream pipeline the #1 operation is transportation of oil. In any ICS environment it's paramount to keep the safety systems operating above all else.
🚨 The Cost of "Recovery"
This week, several organizations publicly reported operational disruption following cyber incidents. One organization couldn't process property transactions. Another temporarily suspended production. In both cases, the operational disruption continued while the affected technology was being dealt with. Sometimes stopping is the right decision. Safety, regulatory requirements, product integrity, or simply not knowing enough about what's happening may leave no responsible alternative. But a technology outage doesn't automatically have to mean the entire operation stops. It's worth knowing ahead of time which business functions could continue safely, which ones couldn't, and what people would need in order to keep the critical work going. Most cyber recovery planning understandably focuses on restoring systems as quickly as possible. There's another period we need to plan for too: the hours or days before those systems are restored. What can the organization still do during that time? That may mean manual workarounds, alternate communications, reduced operations, different decision authorities, or temporarily delivering a service in a completely different way. 💬 Discussion question: If one critical technology your organization depends on disappeared tomorrow, what business function would leadership be most reluctant to stop—and why?
0 likes • Jul 24
Can your business survive a cyber attack? According to some surveys. 20% of SMBs surveyed said they would be forced to close. Absolute Security said almost 60% of businesses were closed for an average of 5 days. Another survey said that 60% of SMBs that experienced a significant cyber attack closed within 6 months of the attack.
1-4 of 4
Finn Rye
1
1 point to level up
@finn-rye-2931
Cyber Security Engineer working in critical infrastructure

Active 3d ago
Joined Jul 14, 2026