<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Michael Corn]]></title><description><![CDATA[Society, Cybersecurity, Higher Education, Privacy]]></description><link>https://michaelcorn.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!cNHq!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9cba4a5-8317-4964-8978-3b00fb38b498_420x420.png</url><title>Michael Corn</title><link>https://michaelcorn.substack.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 13 Aug 2026 21:45:25 GMT</lastBuildDate><atom:link href="https://michaelcorn.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Michael Corn]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[michaelcorn@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[michaelcorn@substack.com]]></itunes:email><itunes:name><![CDATA[Michael Corn]]></itunes:name></itunes:owner><itunes:author><![CDATA[Michael Corn]]></itunes:author><googleplay:owner><![CDATA[michaelcorn@substack.com]]></googleplay:owner><googleplay:email><![CDATA[michaelcorn@substack.com]]></googleplay:email><googleplay:author><![CDATA[Michael Corn]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The enablement of decision making]]></title><description><![CDATA[What does the modern CISO or CIO need from AI?]]></description><link>https://michaelcorn.substack.com/p/the-enablement-of-decision-making</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/the-enablement-of-decision-making</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Thu, 13 Aug 2026 17:41:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hSc4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hSc4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hSc4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hSc4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hSc4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hSc4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hSc4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg" width="332" height="221.40934065934067" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:332,&quot;bytes&quot;:588510,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/210984376?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hSc4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hSc4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hSc4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hSc4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8868dc1-4abb-4f2e-b832-21e61d8a0b4c_4896x3264.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><div class="pullquote"><p>Since this is a post on AI, I feel compelled to comment on the <a href="https://about.fb.com/news/2026/08/the-future-is-for-everyone/">latest screed</a> on AI from Mark Zuckerberg, which is getting a lot of press: a sales representative for a company with one product says lots of things, largely speculative, that try to hold off regulators and influence public opinion. The weakest of declarative signals. Meanwhile, his company&#8217;s practices remain unchanged. The real question is why this is reported as important or news. While there is a long history of treating successful businessmen as thought leaders, this conflation of a press release with &#8216;thoughtful envisioning&#8217; only contributes to our national lack of direction for large language models. On the other hand, with the dismantling of the Federal Government and academia, perhaps press releases are all we have left.</p></div><p>I had an interesting conversation a couple of days ago, one that left me feeling unsettled. The question that was asked had to do with what I, or any CISO, might need from AI. It was at once both simple and nuanced, but I felt I lacked a good answer. Some of this is obvious - contemporary AI is proving to be a highly sophisticated engine of automation, one that can be configured through natural language prompts. Further, as a pattern-matching heuristic par excellence, AI has the potential to discover and extract extremely subtle events in traditionally noisy data. This is to say, the possibilities for AI to assist with many dimensions of security operations is clear.</p><p>AI can assist with automating data aggregation for incident response, or teasing out attack chains from disparate data sources, and as a colleague suggested, asset discovery. By routing outbound traffic to commercial AI sources through a gateway, and correlating that with endpoint data, the potential to corral AI use in your environment (or even implement DLP on AI traffic) is powerful. </p><p>This operational impact can go far beyond technical matters. Modern LLMs can be used to scan existing and new contracts for specific cybersecurity requirements, quickly building an inventory of contracts requiring attention from cybersecurity specialists. One can imagine creating an assessment tool that asks researchers, in a TurboTax fashion, a series of guided questions and spits out both recommendations for improving cybersecurity, and flags projects warranting a closer look from the security team. None of these were impossible before LLMs took off, but they have been made much easier to achieve.</p><p>But if we put this class of operational tooling to the side, what&#8217;s left? What is it that we, as CISOs - or CIOs for that matter - truly need from modern AI?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>What CISOs need from AI is not better tools for detecting failure, but systems that make failure - specifically, deviation from reality - structurally difficult to sustain. In short, they need governance validation as a living system. So rather than asking AI to handle SOC automation, the CISO needs to ask: can AI continuously detect when what we say, what we do, and what we fund diverge? For example, if policy says &#8220;all research systems must use MFA&#8221; (a declarative signal), while our logs show only partial adoption (a behavioral signal derived from telemetry) and our budget shows no investment in enforcement (the allocative signal), then AI is surfacing a misalignment at scale. And this happens continuously, without waiting for audits. Now we&#8217;re going beyond ordinary security telemetry by adding policy and resource allocation (budget and staff time) into the algorithm, that is, governance validation. Surely this is the space a CISO should operate within.</p><p>In my <a href="https://michaelcorn.substack.com/p/obsolence-under-discontinuity">last post</a>, I imagined a future where security becomes an emergent property of an architecture, rather than a set of layered-on controls<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. This leads to a very specific framing: can AI embed security constraints directly into workflows so they are no longer negotiable? This is tricky, and probably not a short or even medium term goal. Nevertheless, if we&#8217;re to move from the chain of &#8220;CISO reviews to exception process to after the fact enforcement,&#8221; we need to start positioning AI within workflows. This would mean architecting them to handle inline decision-making (such as at procurement or research design time), and to perform real-time validation. This would turn insecure systems into &#8220;impossible states&#8221; instead of &#8220;discouraged behaviors.&#8221; As attractive as this is, it makes me uncomfortable writing it down - it begins to feel a bit hand wavey. The model is close to &#8220;get AI, a miracle occurs, security emerges.&#8221; But essentially, I&#8217;m arguing the importance of recognizing this role for AI and to begin searching for the opportunities to create and use that role in your workflows.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/the-enablement-of-decision-making?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/the-enablement-of-decision-making?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>Throughout my posts, I&#8217;ve argued for the primacy of <a href="https://michaelcorn.substack.com/t/thought-work">thought work</a>, and against its degradation by so many modern management practices. Yet there&#8217;s an important analogy to be made between the practice of cybersecurity and the analysis I provided in my discussion of Baudrillard and modern political life. In politics, hyperreality is supported by the velocity with which lies are propagated and how that far exceeds our capacity for rationally evaluating them. &#8220;Flooding the zone&#8221; is effective and as a result, people abandon truth-testing for affiliation-testing. The contemporary CISO is also saturated with signals. While they may be largely telemetry - and more akin to a map than an opinion - their complexity and interdependencies challenge not just our ability to respond to them, but to aggregate and analyze them into a higher-level description of an environment. &#8220;So you have detected 100k probes and attacks in the last hour, what does that really tell me about our security posture?&#8221;</p><p>Perhaps AI can help restore truth-testing by compressing complexity into evaluable signals. Can we leverage both the analytical skills of the modern LLM and its linguistic fluency to create synthesized, decision-ready representations of reality, to prioritize contradictions (not just risks) using some of the non-telemetric data such as resources? Can it provide explanations of why something matters in context? I admit, this does feel a little bit like cognitive offloading (which skirts a dangerous line), but perhaps if I frame this as a signals compression activity that enables CISOs&#8217; thought work, it&#8217;s more palatable. In an absurdly complex environment, with deeply nuanced signals, AI can help restore the human capacity to evaluate reality.</p><div><hr></div><p>I think our discussions about AI and security are focused largely on AI as a tool that helps us <em>see more</em>. And that&#8217;s fine, and hopefully productive. But a CISO is more than a traffic cop for security operations. The CISO needs to view not just the telemetry of operations, but all the various dimensions of cyber risk throughout their organization - that is, the organization as system. AI&#8217;s role is not to expand visibility, but to enforce alignment - binding what we say, what we do, and what we fund back to reality.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>From security as a managerial function to security as an ambient property of the system.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Obsolence under discontinuity]]></title><description><![CDATA[Is it time to rethink the CISO role from the ground up?]]></description><link>https://michaelcorn.substack.com/p/obsolence-under-discontinuity</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/obsolence-under-discontinuity</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Thu, 06 Aug 2026 19:29:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zgi4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zgi4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zgi4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zgi4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zgi4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zgi4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zgi4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg" width="338" height="224.01785714285714" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1456,&quot;resizeWidth&quot;:338,&quot;bytes&quot;:994406,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/209395075?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zgi4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zgi4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zgi4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zgi4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4ae6b9e-33a7-4eef-b58f-43a5303eb9a0_3089x2048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>I&#8217;ve had this persistent image in my mind about the implications of that favorite <a href="https://classicsofsciencefiction.com/2019/12/02/would-generation-ship-crews-ever-forget-their-mission/">science fiction trope</a> of a multi-generational starship. This is, I believe, one of the silliest solutions to the problem of space being absurdly large  (and a lazy form of narrative world building). I won&#8217;t bother detailing this, <a href="https://www.youtube.com/watch?v=0nOGPyK9EF8">many others</a> have done so with more specificity than I have patience to do here. But the image I keep returning to is this: what happens when 3000 years into a journey, someone invents faster than light travel<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> and in a short time, catches up to that ship and says &#8220;time to stop - you don&#8217;t need to do this anymore&#8221;?</p><p>The issue I want to discuss in this post isn&#8217;t science fiction, it&#8217;s about when one technology or principle leapfrogs its predecessor, rendering that predecessor utterly obsolete. In particular, I&#8217;ll explore the question: is the CISO role as we think of it today, about to become historical baggage? And if so, what should replace it and why? </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>It seems obvious the CISO role has been <a href="https://michaelcorn.substack.com/p/so-you-want-to-hire-a-ciso">undergoing an evolution</a>. But the CISO role may be structurally misaligned with emerging architectures. The CISO has evolved from operations manager to organizational executive as the role&#8217;s scope has been remapped from technical controls to risk. What we call &#8220;technical controls&#8221; has itself been broadened from elements of technology to elements of process or workflow. Yet the CISO chafes at being constrained: limited in both span of control and recognition as an institutional operator, the CISO is burdened by an increasing scope with limited authority and span of control.</p><p>But constraint is the operative word.  Especially within higher ed, the CIO has traditionally been seen as a service delivery system - focused on availability, performance, cost, or user satisfaction. In contrast the CISO is seen as a constraint system, controlling risk or enforcing control validation. These aren&#8217;t just different domains; they produce competing signals. For the CIO the success signals (and the rewards tied to them) are visible: systems work, users are happy, and delivery is fast. These are low-friction signals. The success signals for the CISO are both quieter (invisible actually) or when visible, rarely warmly embraced. The CISO signals that risk is reduced, controls are enforced, and friction is introduced (when necessary). These are cost-inducing signals. This is why organizations put the CISO under the CIO because the constraint signal is subordinate to the delivery signal.</p><p>This delta also operates in the financial space. This is why CIOs always focus on &#8216;optimization&#8217; or cost reduction. Their goal is to minimize friction and accelerate delivery. Whereas the CISO generally <em>imposes</em> costs on the organization by introducing friction where risk demands it. Allocative friction<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> would be the right label. In the context of my earlier post on deviation from the narrative becoming more expensive than the narrative deviating from reality, left to its own devices, the organization will reliably optimize for lower friction over higher assurance. After all uptime is visible while security failures are probabilistic and often delayed. In effect, the reporting line of CISO to CIO becomes a biasing mechanism w/in the institution: it structurally suppresses costly security signals.</p><p>I think this is why, every conversation about why the CISO needs to be elevated quickly devolves into some version of security needing an independent path to impose cost. We couch it in all the prose of shining a light on risk or ensuring leadership is properly informed during the decision making process, but it boils down to the same thing: pay attention, you need to resource these mitigations.</p><p>We, correctly, point out that the existing reporting structure normalizes quiet risk acceptance. We see this over and over again: project pressure leads to a &#8220;temporary exception.&#8221; A CIO incentivized to deliver will result in the exception being accepted. This disincentivizes the CISO to escalate and with that, the exception becomes the new baseline. As I mentioned in a recent <a href="https://michaelcorn.substack.com/p/institutional-signals#:~:text=for%20the%20latter.-,Behavioral%20signals,-reveal%20what%20our">post</a>, &#8220;Behavioral signals reveal what our preferences are when under constraint - essentially signaling how we behave when tradeoffs are real.&#8221; And exceptions, especially when they become normalized, articulate our preferences more clearly than the finest policy statements.</p><p>The question is, why does this argument show up more often in discussions about the role of the CISO than in other areas? I think it&#8217;s because, sticking with the security as constraint model, this aligns it more closely with other functions that are independent from the operators they constrain. I&#8217;m thinking of roles like legal counsel or internal audit. CISOs - security - constrain the system itself. Counsel and Audit have independence from operational incentives. If we look at some of the other typically executive functions, in contrast, they optimize within the system, for example, the CFO for finance, the CHRO for the workforce, or the CIO for operational efficiency.</p><p>Essentially, the CISO can function anywhere in the organization (particularly if it benefits from multiple reporting lines), but the interrogative question we should ask is: can the organization sustain costly security signals when they conflict with delivery signals? <em>If the entity responsible for imposing cost reports to the entity incentivized to remove it, the cost will eventually disappear.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/obsolence-under-discontinuity?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/obsolence-under-discontinuity?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>But I want to pivot a bit at this point, and introduce a new thread to the discussion. As I was talking to a friend and colleague the other day about the role of the CISO, we were marveling at the problem set being laid at the CISOs feet. Four quick examples that came up in the conversation are now plumping up the portfolio of every CISO: post-quantum cryptography (PQC), a redefinition of critical infrastructure, becoming the vanguard of cultural change, and of course artificial intelligence<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. I speak to CISOs all the time both personally and professionally and almost no one has time, capacity or expertise to tackle these. These are not incremental problems, but rather they are discontinuous shifts. Most of us are flailing to stay on solid ground, while the chaos of modern information assurance spins us like cows sucked into a tornado<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>.</p><p>Let me briefly unpack those four examples. While it may feel like post-quantum cryptography is perpetually over the horizon, in practice we can now start to see what that looks like and anticipate its arrival. <em>Every</em> cryptographic algorithm currently in use, securing everything from web traffic, to personal communications, to banking, to data archiving will need replacing. Worse, we&#8217;ve just seen one of the top candidates for a PQC algorithm fall to <a href="https://arstechnica.com/security/2026/07/mythos-uncovers-crypto-weaknesses-that-went-unknown-for-years/">Claude&#8217;s Mythos&#8217; analysis</a>. Perhaps this is a one-off, but it illustrates that the perfect storm is brewing - the basis of all secure data technologies is collapsing and the power of nearly unlimited spending is attacking its replacement.</p><p>This leads directly to the next question: the redefinition of critical infrastructure. Traditionally &#8220;critical infrastructure&#8221; was meant to cover life-safety services or health services: power, water, emergency response, healthcare. In our digitally mediated world, however, digital infrastructure now supports almost all of our daily activities. Computers steer tractors, authentication is required to access medical care, most financial transactions are digital. For higher education, as we saw with the recent <a href="https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think">Canvas incident</a>, when digital systems disappear, so does instruction and much of research. Eliding with PQC, if the algorithms underpinning digital activity collapse, should every cryptographic element now become part of your inventory of critical infrastructure?</p><p>Finally, what do I mean by cultural change? For the CISO (or really, any security professional), cultural change results from our introduction of friction into existing practices. Wanna get on the network? Now you&#8217;ve got to register your laptop. Wanna access a specific website? You&#8217;re going to need MFA installed on your phone or a token. But today, the real action is in the research space. Addressing security mitigations is far more than just requiring faculty to use MFA or back up their data: it&#8217;s introducing constraints into a system that has long operated without or with minimal administrative influence. It&#8217;s a separate system entirely, one that prides itself on autonomy, discovery, and entrepreneurialism. CISOs need to approach research less as established functionaries in an organization, but more as anthropologists studying a foreign civilization<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/obsolence-under-discontinuity?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/obsolence-under-discontinuity?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>If the portfolio has expanded to include quantum-proofing civilization, redefining critical infrastructure, and rewriting faculty culture - all while trapped inside a reporting structure designed to subordinate constraint to delivery - the current CISO role hasn't just become difficult, but pyrrhic. Add to this the sizable personal liability CISOs now face by having, for example, to attest to security practices for any number of data sharing agreements or to the accuracy of SPRS scores<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>. Modern CISOs are increasingly treating employment negotiations like corporate officers and demanding specific D&amp;O (Directors &amp; Officers) insurance coverage, explicit corporate indemnification, and dedicated budget for independent legal counsel before taking a job. Given how far higher education has to go in this dimension, one begins to question the viability of the role in its entirety. Or at least the wisdom of anyone incautious enough to accept it.</p><p>Which returns me to the example of the poor, obsolete generational starship. Despite FTL travel, the starship doesn&#8217;t have to abandon its mission. It&#8217;s free to continue on its course, struggling with the inertia of endless existential maintenance and social stress. But it is no longer relevant in the larger saga of human expansion into space. </p><p>The modern CISO role is our starship: a self-contained artifact of historical practice driven by inertia, while discontinuous shifts in technology and liability warp space around it. Are we so mired in existential and social maintenance, that we are blind to being made obsolescent by the advancement of the world around us? The present crisis is not a temporary gap to bridge, but a reckoning - the role is being left behind by the very world it was built to secure.</p><p>Obviously, I&#8217;m suggesting the CISO is a transitional role - necessary for a prior architecture of control, but misaligned with the one we are entering. The question is not whether the role continues, it clearly will, but whether it remains aligned with the architecture of the world it is meant to secure.</p><div><hr></div><p>To practice cybersecurity today feels like we are trying to enforce a traditional &#8220;architecture of control&#8221; over an increasingly chaotic and expansive domain: it&#8217;s like trying to manage air traffic with a stop sign. The CISO is left maintaining the <em>rituals</em> of control (e.g., policy documents, annual awareness training, and manual audits) while the actual velocity of technology and data moves around them unimpeded.</p><p>I see the necessity of moving past the current formulation of the CISO as a consequence, not of role failure, but of the CISO having to bridge two incompatible paradigms. In the first, we have security as a managerial function. Here security is treated as a separate function that &#8220;adds protection&#8221; to existing systems, after the fact, through policy and monitoring. That is, security as an overlay. In the second, we have security as an ambient attribute. Security is built into the underlying &#8220;physics&#8221; of the architecture itself. A place where data provenance, cryptographic boundaries, automated compliance validation, and resilient systems are native to how code, networks, and data operate. This is security as a system property. These are not incremental problems&#8212;they are discontinuous shifts. Thus the modern CISO must simultaneously engineer systems while effecting cultural change, all while swallowing institutional liability.</p><p>In an <a href="https://michaelcorn.substack.com/p/open-question-no-7-cybersecurity">earlier post</a> I argued for the evolution of the CISO into something called a Chief Digital Risk Officer (CDRO)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a>, largely decoupled from operational responsibilities. I still believe this is the right next step for institutions. It represents a kind of codification in different people and roles, both of the two paradigms I just described. But does it truly position us for the kind of disruptive changes we can already anticipate for our environment?</p><p>It&#8217;s a valuable exercise to speculate on the future of the CISO. If we stick with evolutionary models, the CDRO is not a disruptive step, it&#8217;s a kind of adaptive mutation, not a speciation event; fundamentally it is a specialized form of CISO. However, increasingly the field is leaning into risk enforcement as embedded and federated: where security decision rights are codified into platforms, pipelines, and procurement gates. In many ways we&#8217;re trying to change security from a centralized constraint function to become a property of the system&#8217;s governance fabric. I don&#8217;t need to review every software purchase, the purchasing process natively enforces this for me<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>.</p><p>If we want to continue evolving the CISO, we want to ask what it would take to achieve an environment where we&#8217;re not managing exceptions but designing systems where exceptions are impossible or irrelevant. This suggests not a CISO but something like a Chief Trust Architect, who is not managing risk, but rather they&#8217;re eliminating entire classes of risk through design constraints.</p><p>Of course, once this sort of role is possible, the next logical step would be to imagine it within the context of automation, AI driven or not. Here we&#8217;re moving from human decision making to machine-enforced reality. Essentially a policy compiler coupled to control plane ownership. In this world a non-compliant system doesn&#8217;t trigger a meeting, but is entirely unable to deploy. Similarly, unauthorized data use isn&#8217;t &#8216;detected&#8217;, but cannot be executed. This is truly the disruptive moment (and frightening in some ways given how technology can be abused by authority), but with this realized, the CISO as we know it, disappears. Security is no longer a function, but an emergent property of the architecture. Risk management has been transformed into risk elimination<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a>.</p><p>Even today, we see elements of this vision manifesting in our environments. But these remain narrowly scoped and are exclusive to technology. We don&#8217;t see it in the human and governance dimension. Of course, this is precisely the dimension most CISOs struggle with. While technology can be compiled, human trust and faculty governance cannot. If we automate the technical controls, the <em>actual</em> work left for security leadership isn&#8217;t managing firewalls, it&#8217;s navigating human politics, institutional ethics, and research trust. This is particularly challenging in higher education, because university culture is explicitly built against centralized control planes and &#8220;policy compilers.&#8221;</p><p>Earlier I described the breakdown of signals, when the organization cannot sustain <strong>c</strong>ostly behavioral or allocative signals, it defaults to weak ones such as policy or exceptions to those policies. The system&#8217;s true preference is for delivery over assurance. In the vision I&#8217;ve described, you can see a new signal architecture defined: that of &#8220;ambient security,&#8221; where in place of declarative signals (e.g., &#8220;policy requires MFA&#8221;) we are moving towards compiled behavioral signals, (e.g., &#8220;non-MFA systems cannot deploy&#8221;). This doesn&#8217;t just evolve the CISO but it eliminates the gap between signal and enforcement. That&#8217;s a transition from social signaling systems to computational signaling systems.</p><p>In the final analysis, all of this suggests that while the <em>technology</em> will become ambient and self-enforcing, the <em>CISO role</em> will either dissolve into platform code or survive strictly as a political/diplomatic function that mediates between human culture and machine enforcement. The CISO exists today as the human mechanism for enforcing costly signals, but as institutions fail to sustain those costs, the role may be displaced by architectures that make deviation impossible rather than punishable.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>As much as I wish it were otherwise, FTL travel simply isn&#8217;t going to happen outside of science fiction.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>As a reminder, an allocative cost is one imposed through budget, time, or operational delay.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>I think everyone is familiar enough with the impact of AI that I don&#8217;t need to expand on it here.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Not an image I&#8217;ve ever applied to cybersecurity before, but it&#8217;s growing on me.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>Hopefully not as evangelicals trying to convert a remote tribe. History has shown us how that never ends well.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Higher Ed may still be somewhat insulated, but it doesn&#8217;t take a mind reader to look at something like the U.S. Securities and Exchange Commission (SEC) Cybersecurity Disclosure Rules to see what our future holds. Its voluntary dismissal notwithstanding, the prosecution of the SolarWinds case demonstrated a willingness to target CISOs individually under securities fraud and reporting statutes when regulators believe public assurances mask unaddressed internal vulnerabilities.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>With a hat tip to my old friend and colleague in just this role at the University of Illinois System Office.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>Yes, I realize this is an ideal state - practice is far more complicated.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>This deserves some pushback - it&#8217;s unclear to me if we&#8217;re truly eliminating risk in this vision or just displacing it. Reality is a harsh mistress.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Simulacra and Simulation]]></title><description><![CDATA[Institutional signals and the corruption of democracy]]></description><link>https://michaelcorn.substack.com/p/simulacra-and-simulation</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/simulacra-and-simulation</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Wed, 29 Jul 2026 03:51:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ptKl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ptKl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ptKl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ptKl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ptKl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ptKl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ptKl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg" width="249" height="373.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2184,&quot;width&quot;:1456,&quot;resizeWidth&quot;:249,&quot;bytes&quot;:283293,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/208639872?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ptKl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ptKl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ptKl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ptKl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F507ba87b-43fb-4952-badd-259b09902175_3264x4896.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="callout-block" data-callout="true"><p>I&#8217;ve avoided writing about politics for some time - though as I have illustrated in many pieces, it&#8217;s essentially impossible to ignore them if you worry at all about cybersecurity and national security (even at the purely local level). Part of the challenge is that there&#8217;s simply so much good political writing that to do so feels either derivative or weak in comparison.</p><p>However, as I reflected on the frameworks on norms and signals I laid out in the last few posts, something jelled for me. I was reminded of <em>Simulacra and Simulation</em> by Baudrillard (which I hadn&#8217;t read in ages) which seems almost prescient on rereading. I think, borrowing from my frameworks, that Baudrillard&#8217;s hyperreality is a system operating on asserted signals without validation or enforcement. So in this essay I don&#8217;t want to simply apply Baudrillard to politics, but rather offer a general theory of institutional signal failure across domains.</p><p>How did we end up where we find ourselves today? We need to understand what it means to live in a country where a quarter of the voters entered into a quid pro quo for their vote: we&#8217;ll grant you the grift, if you give us the racism. But more frustratingly, we can all see this - we know the rhetoric is not merely propaganda, but voiced with a shamelessness that&#8217;s hard to fathom.</p><p>I should additionally note, since it&#8217;s received a lot of press, that I&#8217;ve disabled Substack&#8217;s AI detection feature. It seemed pretty harmless and I ran it several times while writing this (I don&#8217;t use AI while writing, I write to explore ideas, not generate content), and it dutifully reported my text as 100% human. Until I wrote the last paragraph and suddenly it reported the text as 30% AI and 20% AI assisted. Twenty words of 3000 somehow broke the scanning engine. I&#8217;ve noticed this type of thing before testing the generally available LLMs. The more I polish and smooth over the language, the more likely it&#8217;ll throw a false positive and flag some text as AI generated.</p></div><p>Let&#8217;s begin by describing what Baudrillard meant by &#8220;hyperreality&#8221;: hyperreality is a condition in which media, signs, and symbols become so pervasive that they replace objective physical reality, leaving behind a world composed entirely of self-referential simulations. In this state, the boundary between the real and the representation collapses, and the copy - or <em>simulacrum,</em> in his terms - becomes more authentic, engaging, and real to people than the actual world it originally represented. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>This should be all too familiar to any of us, raised in a world where vitamin-enhanced sugar cubes are marketed as &#8220;part of a balanced breakfast&#8221; and water is mysteriously labeled as &#8220;smart&#8221;. Ultimately, hyperreality is a system where symbols and ideas no longer refer to underlying truths, but only to other images, substituting genuine experience with a manufactured consensus. In our own hyperreality, patriotism is reduced to a performance of symbols - allowing us to ignore the material mistreatment of Gold Star families and veterans.</p><p>Baudrillard warned that late-stage media environments produce <em>&#8220;</em>more and more information, and less and less meaning<em>.&#8221;</em> In the vocabulary of institutional signaling, this is far more than information overload: it is signal collapse. What do I mean by &#8220;signal collapse?&#8221; The key is to remember that &#8220;signal strength is defined by the cost of deviation from that signal. That is, a signal is strong to the extent that it is costly for the institution to violate it. The strength of a signal isn&#8217;t about how loudly it&#8217;s stated - it&#8217;s about how painful it would be to act against it.&#8221; This is, to my earlier question, the key to understanding how we arrived here.</p><p><span>Earlier I noted that declarative signals (writing a policy, issuing a statement, making a public claim) are cheap signals because they carry almost zero cost of deviation. In contrast, allocative signals (reallocating budgets, shifting capital) and behavioral signals (actions taken under constraint) are expensive signals because they require tangible sacrifice. If there is a cost to diverging from a signal, the signal becomes more valuable.</span></p><p><span>But when our media ecosystems overproduce declarative signals at a velocity that exceeds our ability to evaluate those signals, the traditional mechanism of </span><em><span>truth-testing</span></em><span> breaks down. We (the public) adapt by substituting truth-testing with affiliation-testing. Thus, truth-testing is expensive; it requires evaluating claims against empirical evidence, institutional baselines, and allocative reality. Further it may be practically impossible in the political realm. How is anyone to tell if &#8220;those votes were rigged&#8221;?</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> While a<span>ffiliation-testing is cheap: evaluating a claim based solely on whether adopting it signals alignment with an identity group. &#8220;I&#8217;m with the guy who looks, prays, or hates like me&#8221;. Being cheaper and faster make affiliation-testing very difficult to challenge.</span></p><p><span>Once hyperreality is birthed, especially in our modern media ecosystem, it becomes a self-supporting feedback loop. </span>It persists because modern media platforms are structurally engineered to maximize engagement, and engagement favors friction-free claims. A declarative signal - a tweet, a viral soundbite, an outrage-inducing headline - costs nothing to produce, spreads instantaneously, and demands zero cognitive effort from the consumer. It offers immediate identity reinforcement. <span>Hyperreality persists because platform incentives and identity reinforcement reward the consumption of cheap declarative signals over the friction of real-world allocative facts. When algorithms optimize for attention, cheap declarative signals win every time, driving out the heavy, inconvenient weight of empirical reality.</span></p><div><hr></div><p>It&#8217;s worth examining Baudrillard&#8217;s four stages from reality to hyperreality. We begin with stage one, where the symbol is a faithful reflection of reality. The classical example of stage one is a map that accurately depicts the terrain - or perhaps a true empirical accounting of a research budget. Stage two (usually labeled something like &#8216;masking and perverting reality&#8217;) takes us to the familiar space of traditional political spin. In stage two, the facts are manipulated while still acknowledging that an underlying factual reality exists. </p><p>Stage three (dedicated to masking the absence of reality) is where we really see the dominant mode of modern hyper-politics. The &#8220;Stop the Steal&#8221; movement constructed a dense ecosystem of affidavits, hearings, and legal filings designed to mask the complete absence of a stolen election. Similarly, the Border Wall functioned primarily as a Stage 3 symbol - a massive declarative signifier of &#8220;absolute security&#8221; masking the complex, un-wallable reality of visa overstays and global supply chains.</p><p>But even stage three is an incomplete description of what we see unfolding around us. In stage four, what Baudrillard would call pure simulacrum, we emerge into a new meta-level of media. Here, interpretive signals - how leadership frames reality - become entirely decoupled from allocative reality (what is actually funded or operationalized). &#8220;We&#8217;re winning bigtime&#8221; while losing. &#8220;We have far more munitions &#8230; and far more than we need,&#8221; while pausing attacks due to <a href="https://www.bbc.com/news/articles/c0qvnk2ezp7o">munitions shortfalls</a>. In this stage we see executive leadership reacting to cable news chyrons about tweets regarding previous cable news chyrons<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><p>This brings us back to the notion of signal strength. Historically, democratic institutions enforced norm stability because the cost of deviating from objective reality was relatively high. <span>If a political leader made an empirically false claim, a kind of institutional friction developed: friction created by the press, the judiciary, and oversight bodies, which imposed a non-negotiable penalty. With this in mind, it should be of no surprise that these three agents are precisely those targeted by the current administration. I suppose I should add academia to that list - science strives to concern itself with expounding ground truths, and academia distills those, becoming both a voice for them and a conduit for inculcating them into the civic body. Essentially, academia represents another source of friction - it introduces a cost and a challenge to the meta-level creation of false narratives that make up Baudrillard&#8217;s stage four</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a><span>.</span></p><p><span>In a nutshell, I see our modern world as the result of an inversion of the traditional cost structure where deviation from reality is expensive. Hyperreality describes a system in which institutional decay renders those costs weak, non-binding, or selectively applied. The penalty for deviating from empirical reality no longer propagates reliably through the ecosystem. In a healthy institutional system, an empirically false claim acts like a fault in a circuit: it triggers corrective friction across independent nodes such as courtrooms or newsrooms. In a hyperreal system, that circuit is broken. The false signal is absorbed, amplified, or insulated by partisan echo chambers, allowing the speaker to suffer zero penalty from their base while actively gaining power from the outrage it generates. We see this daily - the louder we yell, the more we amplify and reinforce the false signal.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/simulacra-and-simulation?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/simulacra-and-simulation?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p><span>When the cost of deviating from reality drops, the incentive structure inverts: the primary cost becomes deviation from the narrative. To acknowledge empirical reality when it contradicts the identity-binding simulation (e.g., a local official certifying a clean election or a public health officer acknowledging epidemiological data) is to risk immediate, total exile from the ecosystem that confers legitimacy and power. The cost of standing with reality becomes infinitely higher than the cost of embracing the simulation. I suspect Anthony Fauci could testify to this inversion of cost.</span></p><p><span>We see this played out in at least two dimensions. Speaking truth that conflicts with hyperreality brings the immediate flood of condemnation and smears from the administration and right-wing echo chamber (top down); simultaneously, we see the explosion of trolls (the bottom up) whose vehemence seems mysterious unless understood in terms of the identity affiliation test. Trolls are not (merely) attacking the contrary voice, they are identity signalling to their own compatriots. Like termites, the material they chew becomes the scaffolding of the hyperreality they have embraced</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a><span>.</span></p><div><hr></div><p><span>At this point, I&#8217;d like to revisit my earlier observation that institutions don&#8217;t reveal their strategy through aspirational documents; they reveal them through what they tolerate and what they fund. I think this is significant for I don&#8217;t view Baudrillard as an epistemological lament about the lack of meaning. Rather, I&#8217;m interpreting it here as a theory of power. Our public institutions, the courts, scientific bodies, research universities, election boards, they exist precisely to act as reality anchors. They exist to enforce the cost of deviation on false signals.</span></p><p><span>What we have seen exposed through the current era, is the profound fragility of these institutions. Decades of press consolidation, partisan gerrymandering, and the erosion of shared authorities had already weakened these anchors</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a><span>. This shines a light on why, during the Reagan era, the Federal government was so targeted as &#8220;</span><a href="https://www.youtube.com/watch?v=iF8h9j-b7ho"><span>the problem</span></a><span>.&#8221; This marks, perhaps not the start, but the point of acceleration for the attack on those elements of friction that hobbled the establishment of modern hyperreality</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a><span>. When institutions fail to enforce the cost of deviating from reality, the simulation expands to fill the void.</span></p><p><span>In this environment, narrative control is not merely public relations; it is operational authority: when institutional signals decay, power is reallocated to whoever controls the simulacrum. This is, I think, the core of why so many of us are so frustrated. We hear the propaganda, we find the lies transparent, yet our sense of that friction affects no change. What appears to us as a detachment from reality is, more precisely, the fragmentation of institutional authority over what counts as real. We are living in two worlds - the real and the hyperreal simultaneously.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/simulacra-and-simulation?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/simulacra-and-simulation?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>Naturally, the big question is how we re-establish a cost for deviation from reality. The sheer speed with which the mechanisms of hyperreality operate make this extremely difficult. Imagine the challenge of responding to <a href="https://www.kcra.com/article/donald-trump-truth-social-2025/69838178">168 posts in a single day</a> on truth social. Of course, simply the act of <em>reporting</em> on them is an <em>amplification</em> of them. How are we to introduce a cost to this flood of dreck? </p><p>The obvious option is to move from asserted capability to measured outcomes. Which neatly mirrors my claims for cybersecurity. Just as we move from vendor tool claims to raw telemetry and control validation, in politics we must move from narrative assertions to empirical reality and institutional verification. This is to say that we shouldn&#8217;t ask politicians to &#8220;be more honest&#8221; (a cheap declarative appeal); the solution is to re-architect institutional governance so that political claims are automatically subjected to &#8220;control validation&#8221; (such as statutory review triggers, real-time spend tracking, and binding metrics).</p><p>Hyperreality is what happens when asserted signals replace measured signals as the basis for decision-making. <span>Thus we must restore costly institutional signals. In the context of cybersecurity and governance norms, I identified three primary steps: first, we need publicly binding metrics. It is necessary to move from vague claims of integrity to transparent, un-gameable metrics that create real operational consequences when violated. Next, we require shared behavioral commitments. For cybersecurity, this means cross-institutional mutual aid, pre-negotiated baselines, and joint accountability mechanisms that make narrative deviation painful. Finally, and perhaps most difficult, we should require allocative alignment. This means refusing to accept strategy documents or political rhetoric that are not backed by hard budget reallocations and structural enforcement.</span></p><p><span>Can analogies to these be found for politics? Fortunately, we can use the current administration as a guidebook to identify what&#8217;s missing from our current governance structure. It is a literal roadmap for where institutional signals fail to impose cost. For publicly binding metrics, they will matter only insofar as they create enforceable consequences - automatic review triggers, statutory penalties, or loss of authority when thresholds are violated</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a><span>.</span> We want independent, real time budget transparency, not just appropriations, but actual spend tracking tied to stated policy goals. And of course, election system metrics, such as audit rates or certification timelines.</p><p>For shared behavioral commitments we want cross-institutional constraints that bind behavior even under pressure. These might include pre-committed election integrity pacts, where all parties agree in advance to honor certified outcomes and legal processes. Surely we can legislate cross-branch enforcement norms, e.g., automatic compliance with subpoenas and bipartisan oversight triggers where predefined conditions force joint investigation regardless of party control.</p><p>If in cybersecurity, budgets and not policies reveal truth, then in politics allocation is the only credible signal of priority. But remember, it&#8217;s not just spending that matters, it&#8217;s spending on actual threats. Allocative alignment is not &#8220;money is spent.&#8221; It is &#8220;money is constrained by measurable reality and produces falsifiable outcomes.&#8221; </p><p>In my cybersecurity framing, allocative signals are strong because they are costly to reverse, they are observable, and critically, they are anchored to operational reality (i.e., risk, incidents, systems). But in politics, many allocations fail that last condition.</p><p>For example, immigration enforcement spending clearly signals a commitment to a narrative, but is not actually in alignment with empirical threat models - it lacks clear success criteria that could invalidate the policy. Thus it is a costly signal, but one that is not constrained by any truth<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>. Essentially we have a budget tied to symbolic priorities, where success is defined internally to the narrative and we lack any mechanism for disconfirmation. Ironically, the problem is not that we fail to spend; it&#8217;s that we increasingly spend in ways that reinforce narratives rather than constrain them.</p><p>Thus, what we are observing is not merely narrative distortion, but a systemic control failure: institutions no longer enforce the constraints that bind signals to reality. If we&#8217;re to restore reality, then claims, behavior, and resources must be forced back into alignment.</p><p><span>As in cybersecurity, the true test of a system is not its steady-state signaling, but its behavior under stress. Elections, pandemics, and international or economic crises exposed that institutional signals no longer held under pressure.</span></p><p>Norms are not sustained by agreement; they are sustained by coordinated, costly signals that produce real-world consequences. Trump was not the architect of a post-truth world; his administration was the first political entity to fully optimize for an environment where American institutional signaling had already collapsed. Until institutions are willing to make deviating from real-world reality costly again, the simulation will continue to govern.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Obviously I&#8217;m painting a fairly black and white picture here. We, the average citizen, can reasonably distinguish between the absurd (the election was rigged) and the likely (it wasn&#8217;t). It&#8217;s not always as simple as Occam&#8217;s razor, but this takes a kind of thoughtfulness that&#8217;s impossible when our attention spans have been reduced to 30 seconds between commercials. The rise of digital platforms that are by design built around ultra-short form content both exacerbates the problem and is a rational response to consumer demand.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>While throughout this posting I&#8217;m borrowing from cybersecurity to analyze politics, I have seen stage four even within IT. At a previous position, a disastrous ERP deployment was described by the CIO as &#8220;so successful they haven&#8217;t invented words to describe it.&#8221; At once erasing the vocabulary of dissent, as well as creating a fictional reality around which all other narratives must be formed.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Actually I suspect a good argument can be made that academia creates friction for politicians in stages two through four. As is often quoted, &#8220;reality has a liberal bias.&#8221;</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Of course, a variation of this has been in effect for as long as public comments on media have been supported. I noticed many years ago how comments in popular press journals repeat unsupported claims and build on them, cementing their &#8220;establishment&#8221; as fact. Before long, these claims become the centerpieces of actual articles and the circle is complete.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>I should probably add Citizens United to this as perhaps the ultimate accelerant. Once corporations were granted effective citizenship, and wealth concentration became so extreme, everything I&#8217;m discussing experienced the rapid expansion. America has become a corporation, with us as mere shareholders of a single share.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Recall that during the Reagan years, when it became clear that &#8216;trickle down economics&#8217; was a disaster, his administration didn&#8217;t modify their approach, they modified the economic model making predictions.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>For example, mandatory disclosures of executive actions, use-of-force data, or emergency powers with automatic review triggers.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>There&#8217;s another dimension here I&#8217;m not addressing in the main body: there&#8217;s an unspoken narrative that supports the entire anti-immigrant rhetoric, and that&#8217;s, simply put, racism. The real goal here is removing brown people from the country.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Institutional signals]]></title><description><![CDATA[It&#8217;s important to realize that all signals are not equal]]></description><link>https://michaelcorn.substack.com/p/institutional-signals</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/institutional-signals</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Wed, 22 Jul 2026 21:54:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!u9i4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u9i4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u9i4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u9i4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u9i4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u9i4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u9i4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg" width="270" height="158.9217032967033" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:857,&quot;width&quot;:1456,&quot;resizeWidth&quot;:270,&quot;bytes&quot;:569705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/207680899?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u9i4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u9i4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u9i4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u9i4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5dfdda-0b62-4661-8fa2-3c46fc4f6fc3_6000x3533.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Listening for signals</figcaption></figure></div><p>Throughout a handful of posts, I&#8217;ve been exploring the <a href="https://michaelcorn.substack.com/t/norms">idea of cybersecurity norms</a> - wrestling with just what norms are, and what it means to have norms in the first place. In the most recent piece, where I posit a modest list of norms, I argue that despite the daunting challenge of establishing norms across an entire sector or nation, we have more agency than it may appear. Essentially, the starting point in establishing norms is to simply start talking about them; talking leads to changes in practice, messaging, and ultimately informal agreements and beliefs. Ideally these form a precondition for the codification of norms in law, treaties, and similar durable frameworks.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>I came to this belief not through a linear path from an analysis of norms to a pattern of practice, but organically. As I&#8217;ve described elsewhere, it gets exhausting listening to people complain about organizational culture, all while normalizing the very culture they&#8217;re complaining about. Similarly, I&#8217;ve written critically about strategy documents, having said that, if you want to truly understand an organization&#8217;s &#8220;strategy,&#8221; examine its budget. Institutions don&#8217;t reveal their priorities through strategy documents - they reveal them through signals: what they codify, what they fund, what they tolerate, and what they ask.</p><p>Most recently I started thinking about how an organization &#8220;signals&#8221; anything, and specifically, norms. That is, what I want to call institutional signals are the externally and internally visible manifestations of how an organization operationalizes norms - revealed through decisions, structures, language, and behavior under constraint.</p><p>It&#8217;s important to realize that all signals are not equal. Some are cheap, some are costly. The costly ones are more trustworthy. For example, writing a policy strikes me as a cheap signal. Publishing a report is a tad costly, a medium signal. Reallocating budget, on the other hand, is an expensive signal. Meanwhile, revoking a policy exception or changing behavior is a very expensive signal.</p><p>Which leads me to propose that signal strength is defined by the cost of deviation from that signal. That is, a signal is strong to the extent that it is costly for the institution to violate it. The strength of a signal isn&#8217;t about how loudly it&#8217;s stated - it&#8217;s about how painful it would be to act against it. </p><p>I want to use this post to explore institutional signals&#8212;because if we, as a community, are going to find our voice and establish durable norms, we need a consistent and recognizable set of signals for how we engage with each other and with society.</p><div><hr></div><p>We should start by looking at what it is we actually say. I&#8217;m thinking of explicit statements of intent and identity. Statements that signal &#8220;here is what we claim to value.&#8221; Three distinct examples come to mind. Obviously, a signal could be the codification of norms and policies. Fairly weak, but still a signal. Another example might be a transparency report. I&#8217;ll expand on these in a later post, but I think they represent yet another relatively simple, but impactful, opportunity for collective action and norm establishment. Finally, you&#8217;ll see statements about regulatory alignment that sound great, but are truly more performative than not. Statements about HIPAA compliance within the health sector, or privacy compliance in the commercial sector. Especially within the U.S., most cybersecurity and privacy regulations are floors - bare minimums that are able to be enacted despite our pay to play legislative system. Treating the floor as a statement of high institutional value is the very definition of a cheap signal.</p><p>We should next consider what we actually value. Perhaps &#8220;allocative&#8221; is the proper adjective here. What we fund and prioritize - allocative signals - would include budgetary proportionality. As we&#8217;ve all noticed, our organizations invest the vast majority of cybersecurity funding into enterprise systems; while largely neglecting the truly existential research mission. While we are beginning to see cybersecurity inserted into research proposals (at least sufficiently to cover mandated security controls), this is still rarely done institutionally and at most schools it is rather ad hoc. Nevertheless, it feels like an issue of proportionality, an allocation of effort, so I&#8217;ll leave it as an example here.</p><p>I can think of two additional classes of signals: what we do under pressure and signals that reveal how we think and frame reality. I&#8217;ll label these behavioral for the former, and interpretive for the latter.</p><p>Behavioral signals reveal what our preferences are when under constraint - essentially signaling how we behave when tradeoffs are real. For example, when we make an exception to a policy or a norm we are exercising exception discipline. While exceptions are deeply ingrained in cybersecurity (through the notions of a compensating control and risk acceptance) they do surface how an organization balances competing demands, perhaps more clearly than any other signal. </p><p>Similarly, how an organization chooses to participate in sector activities is another form of behavioral signal. Any reader of this blog knows that I feel this is an area we - the higher education sector - are not giving enough attention to. Though that in itself is a deafening signal. I&#8217;ll say more about this in a moment.</p><p>The final class of signals, interpretive signals, demonstrate how we (usually management and leadership) understand a problem space<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. As I&#8217;ve discussed in earlier posts, the <a href="https://michaelcorn.substack.com/p/advice-to-a-new-cio">intellectual style of executive inquiry</a> and the use of <a href="https://michaelcorn.substack.com/p/the-weight-of-simple-words">reductionist language</a> are massively important - and loud - signals to our organizations.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/institutional-signals?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/institutional-signals?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>I want to pivot somewhat from a theoretical discussion of signals, towards concrete steps we, as individuals and organizations, can take. Can we inventory a set of organizational signals that could be used to advance the establishment of cybersecurity norms, and thus, the practice of cybersecurity writ large? The purpose of my classification of signals is to provide a framework for just such an analysis - to bring a little discipline to the subject. </p><p>We have already examined three examples of declarative signals:</p><ul><li><p>Establishing a policy</p></li><li><p>Releasing a report (the result of an analysis)</p></li><li><p>Performative regulatory compliance.</p></li></ul><p>And we&#8217;ve all seen how these signals get amplified - for example, when one institution models a policy on another&#8217;s. Unfortunately, that amplification is rarely one of directed or community action. It happens by passive diffusion, i.e., informal adoption of a policy in broad strokes, rarely even with public acknowledgement<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. But without that signal of acknowledgement - of declared shared belief - what does it really accomplish? Recall that my goal is to encourage the establishment of norms, which raises the bar considerably. It&#8217;s no longer enough to say &#8220;everyone has a policy on AI,&#8221; but rather, &#8220;can&#8217;t we develop a sector-wide AI policy for general adoption?&#8221; Or perhaps, given pressure to fold research activities into a research security program, could we develop a framework for such a program under the auspices of an organization such as AAU or APLU that is broadly used to shape local programs?</p><p>The value of this approach is not just in the establishment of a norm, but to demonstrate to external regulators, federal sponsors, and society at large that we have the maturity to act cohesively. Essentially I&#8217;m hoping we can move beyond observation (&#8220;here&#8217;s what we see among our members&#8221;) to sector agency (&#8220;we came together and agreed on a norm.&#8221;)</p><p>While declaring and speaking is powerful, acting has much more impact. Here we move to consider examples of allocative signals. Obviously, expecting institutions to reallocate massive capital overnight toward research cybersecurity - where the vulnerability is most acute - is unrealistic. But we can create the conditions that apply pressure for re-allocation of resources and signal those. I can imagine goals being set and metrics collected on one or two dimensions of cybersecurity related to resources. Perhaps something along the lines of &#8220;percentage of operating budget devoted to research cybersecurity.&#8221; Or, &#8220;percentage of grant proposals that include funding requests for cybersecurity elements.&#8221; </p><p>I&#8217;m not going to hazard a guess as to what those percentages should be - but a <em>public</em> commitment to achieve some community agreed upon percentages would be a tremendous forcing function. To anyone who&#8217;s rolling their eyes: remember, it&#8217;s the absence of metrics and commitments like these that gave birth to programs like CMMC and NSPM-33&#8217;s cybersecurity requirements. We are quietly reaping what we&#8217;ve sown<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. </p><p>It&#8217;s reasonable to be skeptical that establishing these goals and publishing progress metrics will result in any actual reallocation of resources. Yet, organizations are competitive; donors, agencies, and legislators will see those metrics and ask about them. What&#8217;s important in this scenario is not just the selection of a goal for each metric, (though the work to develop these is valuable); that is merely a declarative signal. What pushes this into the allocative class is the publishing of performance metrics and the pressure that results from that visible signal<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. After all, if we want norms, we need shared signals. If we want shared signals, we need shared metrics. And metrics only matter when they create consequences.</p><p>It&#8217;s hard to imagine a point in time when behavior under constraint is more relevant. We&#8217;re seeing school after school wrestle with the contraction of Federal funding, the open assault on academic freedom, and aggressive censorship - the complete politicization of the academic sphere. Any discussion of institutional signaling would be incomplete without pointing out that there is a deep fear of signaling due to the current administration&#8217;s actions. Signaling can put a target on your back. This is to say, that while there is a cost to signaling, there&#8217;s also the cost of signaling under political pressure. In fact, it is the highest-cost signal: signaling when the penalty is external, not internal.</p><p>Be that as it may, I can think of a few behavioral signals worth adding to our inventory. I mentioned exception handling; basically the curation of exceptions to policies and standards. While the nature of research activities will necessitate exceptions (either through compensating controls or risk acceptance), institutions will need to adopt via policy a stance that 1. exceptions must be treated as first-class objects with lifecycle management, not informal accommodations, and 2. regulatory and policy interpretation must be owned by a single authoritative function, not negotiated ad hoc.</p><p>But those are local matters - for the purposes of this post, I&#8217;m more interested in how behavioral signals are created. Are we prepared to take action <em>as a sector</em> on questions of cybersecurity? Some of these should be fairly straightforward to build consensus around, for example, the deployment of staff or expertise to assist peer institutions during active incidents, or a willingness to loan tooling, licenses, or infrastructure capacity during crises<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>.  This could include a commitment to participate in cross-institution incident response exercises. But all of these rest on the presumption of pre-established mutual aid agreements for cybersecurity response. </p><p>Imagine the impact of a consortium agreement, especially in light of our current budget crisis, that pledged the protection of baseline cybersecurity funding during institutional budget cuts.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/institutional-signals?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/institutional-signals?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>Some behavioral signals seem obvious to pursue. Such as participation in joint development of frameworks (not just their adoption), or a willingness to publicly endorse and align with sector-wide baselines. Are schools prepared to contribute to open security models, playbooks, or reference architectures? Though I&#8217;m not sure how we capture whether institutions deviate silently or openly challenge and refine shared norms.</p><p>Others start to truly bring the pain: those that bring transparency under reputational risk. For example, publishing post-incident reports with meaningful technical detail. I used to have more sympathy for holding this information close to the vest, but I now believe that in our modern threat landscape, this habit works against us. The bad actors already have these details - that&#8217;s why they were successful. Hiding this information only damages our community. We must develop the willingness to expose internal gaps or failures publicly.</p><p>Behavioral signals are where norms stop being aspirational and become visible. This is because they reveal what institutions are willing to do when cooperation is costly and reputation is at risk, particularly under time constraints. This is why they&#8217;re worth more attention - they are quite literally the establishment of norms in action.</p><p>I&#8217;m going to skip over interpretive signals for the most part, I&#8217;ve written at length about them before. But before moving on, let me bullet point the various signals I&#8217;ve described into a list with some expanded suggestions.</p><p>Declarative Signals <em>(explicit statements of intent and value)</em></p><ul><li><p>Codifying broad policies: publishing institutional policies on emerging domains, such as AI usage or research cybersecurity governance.</p></li><li><p>Releasing analytical reports: publishing transparent institutional reports on the adoption and efficacy of security controls within research programs.</p></li><li><p>Establishing performative regulatory baselines: agreeing upon a sector-wide baseline interpretation for implementing federal standards, such as NSPM-33 controls.</p></li></ul><p>Allocative Signals <em>(resource commitments and visible metrics)</em></p><ul><li><p>Tracking budget and proposal metrics: formally committing to target benchmarks - such as the <em>percentage of operating budget dedicated to research cybersecurity</em> and the <em>percentage of grant proposals requesting explicit security funding</em> - and publicly publishing progress metrics for both.</p></li></ul><p>Behavioral Signals - Local Discipline <em>(internal governance under constraint)</em></p><ul><li><p>Standardizing exception management: creating a sector-wide, shared repository of compensating controls and formal risk acceptances tailored specifically to research environments.</p></li><li><p>Centralizing regulatory authority: codifying in policy that all regulatory and compliance interpretations regarding research security are owned by a single internal authoritative function, rather than negotiated ad-hoc across departments.</p></li></ul><p>Behavioral Signals - Sector Collaboration <em>(costly, active cooperation under fire)</em></p><ul><li><p>Codifying mutual aid agreements: establishing formal, pre-negotiated cybersecurity mutual aid agreements across systems and regional consortiums.</p></li><li><p>Operationalizing emergency staffing: creating clear policy and execution mechanisms to rapidly deploy staff and technical expertise to assist peer institutions during active incidents.</p></li><li><p>Pre-clearing emergency resource loans: standardizing contract language that enables - and explicitly signals a willingness to execute - the loaning of tooling, software licenses, or infrastructure capacity during crises<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>.</p></li><li><p>Executing joint exercises: establishing annual, cross-institutional incident response exercises with mandatory participation commitments.</p></li><li><p>Committing to transparent post-incident reporting: publishing detailed post-incident technical reports as early as technically feasible - potentially allowing a trusted peer partner to draft the report during the incident to expedite its public release.</p></li></ul><p>Not surprisingly, in practice many of the signals from one category are coupled synergistically with others. Behaving one way is something; telling people you&#8217;re doing it is another. Coupling the two not only carries operational weight but is almost the definition of creating accountability. </p><p>Norms are not created by agreement, rather they are created by coordinated, costly signals that produce consequences. The list above makes no claim to being comprehensive. It&#8217;s not difficult to expand upon it. But I offer it up as a model to build upon, a model of institutional behavior change.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>It&#8217;s worth reminding the reader who isn&#8217;t in a senior management role, that this same approach is effective regardless of your stature or role in the organization. If you&#8217;re predictable enough to end up on a &#8216;<a href="https://en.wikipedia.org/wiki/Buzzword_bingo">buzzword bingo</a>&#8217; card, some self reflection is warranted.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I do wonder, now that everyone is relying on LLMs to shape their writing, and LLMs are trained by scraping the public internet, if we&#8217;ll find new institutional policies normalizing in content and style due to their common dependency on LLMs.  Someone needs to develop an LLM tagging plugin that shows you which LLM wrote most of anyone&#8217;s policies.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>It&#8217;s tempting to see these programs as the result of failing with voluntary compliance. Regulators step in with blunt force when a vacuum of voluntary, measurable accountability is discovered. Having a mature set of established norms would have both reduced the strength of that vacuum and perhaps given regulators a starting point more apposite with institutional practice.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Having worked for a number of years in a system institutional reporting office has given me a sensitivity to how fearful institutions are about releasing activity data. It&#8217;s often highly nuanced, yet read without any nuance at all. Publishing metrics like those I&#8217;m proposing is a bell that can&#8217;t be unheard. But more than fear of misinterpretation, I believe institutions fear metrics because metrics create accountability.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>It would make a terrific topic for our procurement experts and attorneys to consider how to add to our procurement contracts the ability to share licenses during another institution&#8217;s crisis.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>I should acknowledge that mutual aid can feel like a asymmetric drain on high-maturity institutions. It&#8217;s worth remembering that true sector-wide norms require framing mutual aid as collective immunity rather than transactional trading.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Norms 2.0]]></title><description><![CDATA[Ontology, taxonomy, norm]]></description><link>https://michaelcorn.substack.com/p/norms-20</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/norms-20</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sat, 18 Jul 2026 03:52:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LrAy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LrAy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LrAy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LrAy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LrAy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LrAy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LrAy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg" width="322" height="214.7403846153846" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:322,&quot;bytes&quot;:423057,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/195494696?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LrAy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LrAy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LrAy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LrAy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F607d8092-48c4-490d-b040-3e1becbc9ff6_4896x3264.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">The ontology of lunch</figcaption></figure></div><p>Perhaps the obvious starting place is to ask if the use of cyber weapons is even in our writ. Earlier I drew parallels between the <a href="https://michaelcorn.substack.com/p/what-can-cybersecurity-learn-from">use of bioweapons</a> - a category of munition that has both norms and binding regulations governing their use - to cybersecurity. Are malware packages and hacking tools a form of munition and if so, are the norms covering their use part of the field of cybersecurity<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>? </p><p>If you start researching cybersecurity norms first thing in the morning, you&#8217;ll find yourself with plenty of time for a lengthy lunch. A review of the current international consensus reveals fewer than a handful of foundational agreements, though one, the Budapest Convention, is essentially superseded by the UN Convention against Cybercrime (UNCAC), so perhaps three. Of the remaining two, none have any binding obligations. It&#8217;s noteworthy, though not entirely surprising, that the US is not a signatory to the UNCAC.</p><p>I want to talk about norms in the cybersecurity context, but let me begin by defining the ecosystem we&#8217;re talking about. To use a now less common term, cyberspace, which is a layered, interdependent system in which digital actions propagate across technical, physical, and institutional domains, and where certain classes of systems - those sustaining human life, shared infrastructure, and societal legitimacy - possess a higher moral and functional status requiring both restraint and active stewardship by state actors. It is a system with keystone species (DNS, hospitals), shared habitats (supply chains), and cascading failures; failures that propagate across human, technical, and institutional planes.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>But I feel it&#8217;s necessary to work our way to norms from more general primitives. So let&#8217;s talk about the four ontological classes that come to mind:</p><ul><li><p>Human life systems (a biophysical layer)</p></li><li><p>Shared systemic infrastructure (a digital commons layer)</p></li><li><p>Institutional systems (the socio-political layer)</p></li><li><p>Actors (a layer of agency)</p></li></ul><p>In the biophysical layer, digital disruption leads to immediate physical harm. In this class we have the obvious, such as hospitals and other medical facilities, industrial control systems (such as water, power, and nuclear), and the not so obvious, such as emergency response systems. </p><p>The commons layer is where any &#8220;corruption&#8221; leads to systemic loss of trust or function across many actors. I would place items like DNS or supply chains in this class - perhaps even software ecosystems. Systems where the fragility is manifest through interdependence.</p><p>For the socio-political layer, we see any sort of manipulation can lead to a loss of legitimacy or social order. The most timely example of this is the attempted election interference from Russia in support of Trump. But equally as valid is the onslaught facing academic research and science - both from the administration and from malign foreign actors and insiders.</p><p>Finally, with the agency layer, we have both state and non-state actors; but in either case I personally view the state as the primary unit of accountability - even in a transnational digital system.</p><p>Layered over these we can create a simple tiered ontology of harm. From 1. immediate physical harm (death and injury), 2. systemic functional collapse (internet instability), to 3. institutional/epistemic harm (corruption of knowledge or loss of trust).</p><p>At this point I think we&#8217;re ready to start talking about norms, but I want to offer up one more ontology on the way, an ontology of norms. I think this is the easiest to define: we have obligational and prohibitive norms. Prohibitive norms are those where an actor must show restraint, e.g., don&#8217;t attack hospitals or don&#8217;t poison supply chains. This is analogous to the prohibition on attacking ambulances in war zones. An obligational norm is one where you must act. Inaction itself is a form of harm. Examples of this would be safe-haven accountability or mutual assistance. Critically, responsibility extends beyond direct action. </p><p>Essentially I&#8217;m arguing that it&#8217;s sufficient for our purposes to say the world consists of: <em>life-critical systems</em> (which must never fail), <em>shared infrastructure</em> (which must remain trustworthy), <em>institutions</em> (which must remain legitimate) and <em>actors</em> (must exercise restraint and responsibility). For our purposes, harm flows upward from technical disruption to human and societal consequences.</p><p>Ontologies tell us things about reality - that is, what exists and what fundamentally matters. If we&#8217;re going to move toward defining norms of behavior, then we need to place everything into a taxonomy. The taxonomy is how I&#8217;m going to arrange the elements of the ontology. The taxonomy is what we say out loud: a structured list of norms. The ontology is the quieter claim underneath it: a theory of what kinds of systems exist, which ones matter more than others, and how harm actually propagates between them. If the ontology is wrong or incoherent, the taxonomy will feel arbitrary. If the ontology is sound, the taxonomy becomes almost inevitable. I think of it as the index of rules built on the ontological models. This is necessary if we&#8217;re to move beyond abstractions and to discrete action statements<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/norms-20?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/norms-20?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>So anchoring my taxonomy of cybersecurity norms are human safety and life-critical systems. These are non-negotiable prohibition norms. They represent an absolute floor, for which violations create a direct risk to human life. Expanding slightly on the examples I gave above, we have three fundamental norms:</p><ul><li><p>Medical sanctuary<br>No targeting of healthcare systems, public health infrastructure, or medical supply chains.</p></li><li><p>Life-critical infrastructure protection<br>No operations against ICS (power, water, nuclear, etc.) where failure cascades into physical harm.</p></li><li><p>Emergency response immunity<br>No disruption of CERTs/CSIRTs or disaster-response networks.</p></li></ul><p>(You&#8217;re probably already scoffing since we know hospitals and ICS systems are regularly targeted today. Remember, we&#8217;re building norms at this point, not looking at what&#8217;s actually happening. It&#8217;s what&#8217;s happening that&#8217;s a forcing function for the creation of these norms.)</p><p>Next in our taxonomy we have the integrity of shared systems. What might be called the digital commons. These preserve the baseline trust required for a functioning global digital ecosystem.</p><ul><li><p>Core internet infrastructure protection<br>No tampering with DNS, NTP, BGP, routing, or physical backbone systems.</p></li><li><p>Supply chain integrity<br>No deliberate insertion of vulnerabilities into widely used software, hardware, or open-source ecosystems.</p></li><li><p>Responsible vulnerability handling<br>Maintain disciplined vulnerability disclosure practices (VEP-style), with narrow and time-bound exceptions.</p></li></ul><p>Third in the taxonomy is something we might call institutional integrity and civil order. These are norms that if realized would protect societal and governance functions from destabilization.</p><ul><li><p>Electoral non-interference<br>No manipulation of election infrastructure or outcomes.</p></li><li><p>Civic and knowledge system protection<br>No disruption or destruction of academic research, scientific collaboration, or public knowledge systems.</p></li></ul><p>Finally, drawing from my comment on state obligations in the agency layer above, we have state responsibility and active obligations that apply across all domains - they&#8217;re not a separate category but a behavioral overlay. </p><ul><li><p>Safe-haven accountability aka due diligence<br>States must not allow their territory to be used for persistent cyber harm.</p></li><li><p>Mutual assistance norm<br>States should assist in the defense and recovery of critical civilian systems under attack.</p></li></ul><p>It&#8217;s natural to look at these and ask how they&#8217;re articulated by your organization, which is probably not a &#8220;state&#8221; (nation state or otherwise). I suspect that while it may appear the most aspirational, this last category may prove to be the most relevant for commercial and academic organizations.</p><div><hr></div><p>This taxonomy adapts the traditional principles of kinetic non-combatant immunity to the realities of a digital ecosystem, though I&#8217;ve tried to expand on that a bit to address our <em>modern</em> digital ecosystem. At least, I believe it provides a reasonable framework for further expansion. I suspect a fuller analysis would look at each proposed norm (and others, it&#8217;s by no means comprehensive) and weigh it against impact and resilience for the purposes of finely tailoring each norm. I&#8217;ve drawn them with a fairly broad brush here.</p><p>But we should consider the issue I dismissed as an aside above, that is, what do we see in practice today and how does the ground reality of modern cyber attacks influence our thinking about norms?</p><p>I&#8217;m not going to detail just how bad it is right now - I&#8217;m really struggling to identify any cybersecurity norms in effect. Half the email I get from Federal authorities is concerned with attacks on infrastructure - that of water and power. The other half are the steady drumbeat of health systems having data stolen or patient systems disrupted.  In a world where a superpower states, &#8220;A whole civilization will die tonight, never to be brought back again; I don't want that to happen but it probably will,&#8221; how are we to argue for restraint from criminal organizations? Norms matter, even when they&#8217;re being ignored.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/norms-20?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/norms-20?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>Naturally the frustration you&#8217;re probably experiencing stems from what seems like an insurmountable problem: it feels like there&#8217;s little or nothing any of us, or even our organizations, can do to establish international norms, norms that appear to be ignored, violated, or deliberately undermined daily. While it&#8217;s true that a norm remains voluntary until it&#8217;s codified in law, I think it&#8217;s important to remember that by definition a norm is &#8220;<span>a </span>shared expectation about appropriate behavior within a community<span>, sustained not primarily through formal enforcement, but through </span>mutual recognition, reputation, and the prospect of inclusion or exclusion<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>&#8221;. </p><p>Thinking about how we choose to express that shared expectation allows me one last ontology, one not of agency, but of expression. This differs from the agency layer I described above, for I&#8217;m not talking about the &#8220;agency to behave according to norms&#8221; but rather, &#8220;how norms are instantiated at different levels of social organization&#8221;. One deals with the capacity to act, while the other is how norms are operationalized. </p><p>This is the moment, in a piece that might be seen as somewhat discouraging, of surprising optimism. For despite our apparent individual insignificance in the grander scope of society, norms begin with the aggregation of behavior and belief, which we express through actions and words. Our agency may feel miniscule, but generally speaking, this is how things actually work. One voice at a time.</p><p>Norms are expressed differently depending on the level of the actor - not just who acts, but how those norms are instantiated. The same norm does not look the same at each level. For example, &#8220;don&#8217;t attack hospitals&#8221; becomes for the state, a matter of international law or doctrine. For an organization it becomes reflected in architectural controls, segmentation, and incident response priorities. For an individual, it is represented by ethical restraint and professional norms.</p><p>It is at this point we should pause and ask how we can contribute to the establishment of these norms. I strongly believe that the most powerful tool we have is voice. If a nation state attacks a hospital in a war zone, or targets an ambulance (or uses an ambulance to move troops) we express outrage. Headlines scream, international committees form and sometimes even warrants are issued. Does behavior change? Are the culpable held to account? Rarely, but that&#8217;s almost beside the point. Norms are expressed and codified and this is for the betterment of society<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>.</p><p>Yet, we don&#8217;t see this same outrage when a cyberattack unfolds. Worse, we reflexively blame the victims. But we must stop conflating a defensive vulnerability with a moral transgression. Soul searching is warranted if your EMR system falls victim to a ransomware attack, but surely the true sin is that of the attacker who is placing financial gain over human health and life safety. </p><p>How we give voice to an event - with apologies or with anger; wearing shame or giving it - is how we have normalized cyberattacks. And it is with that voice we have the agency of expression. </p><p>I want to return to one other element I think we can succeed at - that is, to establish as a norm the notion of mutual defense. Right now, when we talk about helping each other during an incident, or sharing out incident details, we get wrapped around the axle debating incident reporting timelines, liability risks, and PR messaging control. All of these are valid institutional concerns, but we allow this administrative minutiae to obscure a fundamental engineering truth: our multi-institutional technical ecosystem operates as a singular, dynamic system that must be informed and enhanced by collective telemetry. </p><p>Rather than provide a single solution to this question, let me frame it as a series of questions for reflection. What specific policy, legal, or contractual constraint most frequently delays or prevents us from sharing incident information in real time? Which of those constraints is truly non-negotiable, and which persists out of habit or risk aversion? If we had to share meaningful incident data within 24 hours, what would break first - legal review, communications, or technical readiness?</p><p>Translating these questions into immediate operational realities is where the fault lines appear. What mechanism exists today for rapidly engaging external expertise during an incident - and how often has it been used? If that mechanism didn&#8217;t exist, how would we assemble trusted external support within hours? What would a &#8216;mutual aid&#8217; model actually look like between peer institutions: who calls whom, through what channel, with what data?</p><p>To close the loop from expression back to actual norm formation, we have to ask the structural questions: what would it take for rapid, reciprocal incident sharing to become expected behavior rather than exceptional? How would we signal - through our own actions - that we are committed to mutual defense as a norm? What would we publicly praise or criticize to reinforce that expectation across the community?</p><p>I offer up this list of questions as little thought grenades, you can pull the pin on them at your leisure if you&#8217;re so inclined. But while sharing between colleagues does take place, as I&#8217;ve mentioned before, far more than our counsels would probably approve, it remains much more idiosyncratic, often relationship based, and is too unsystematic to even begin to consider norm establishing.</p><p>This brings us back to the ontology of expression. It&#8217;s easy to look at global cyber norms and assume responsibility lies elsewhere - with nation-states, tribunals, or federal frameworks. But a norm is not a document; it is a pattern of behavior. It exists only to the extent that it is enacted.</p><p>For you that means your agency is not abstract. The norm of mutual defense takes shape every time you call a peer to share an active indicator of compromise. It takes shape when you push past reflexive legal caution to share critical telemetry, or when you use your voice to shame those attacking you.</p><p>When you choose transparency over posture, you are not just managing an incident. You are engineering the digital commons. You are turning an aspirational norm into something real - something practiced, expected, and ultimately, durable.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>We did see an attempt, perhaps purely performative, to impose a norm on ransomware actors during COVID, https://www.bleepingcomputer.com/news/security/ransomware-gangs-to-stop-attacking-health-orgs-during-pandemic/. I&#8217;m not sure anyone believes this had any real impact, but as I&#8217;ll discuss later, it&#8217;s still a valuable attempt.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I, like most people, get a bit sloppy when discussing ontologies and taxonomies. Too often, I move between terms as if they were interchangeable. I really need to spend more time reading <a href="https://substack.com/@jessicatalisman">Jessica Talisman&#8217;s substack</a>. You can tell by my reformulation and repetition that I&#8217;m working out and testing my own understanding throughout this last passage.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>See: <a href="https://michaelcorn.substack.com/p/radical-reciprocity">https://michaelcorn.substack.com/p/radical-reciprocity</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>I realize this is a weak salve for those who suffered from the breach of those norms.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Advice to a new CIO]]></title><description><![CDATA[Observe, Understand, Govern, Adapt]]></description><link>https://michaelcorn.substack.com/p/advice-to-a-new-cio</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/advice-to-a-new-cio</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Wed, 08 Jul 2026 00:48:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vjev!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vjev!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vjev!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vjev!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vjev!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vjev!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vjev!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg" width="332" height="350.9258241758242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1539,&quot;width&quot;:1456,&quot;resizeWidth&quot;:332,&quot;bytes&quot;:294308,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/205674943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vjev!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vjev!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vjev!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vjev!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae41c6b-e0c4-4e15-8290-64deac0ba1b4_2756x2914.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">My plaque will say something about pizza</figcaption></figure></div><p>So many of the pieces I post here speak to security and privacy professionals, offering advice on how to manage &#8216;up&#8217;. But often when working with CIOs I find the questions they have equally challenging. Whether you&#8217;re new to the CIO role, or at a new institution, starting a position is a terrific opportunity. I&#8217;ve tried to use every position change as both an opportunity to reinvent myself (to reflect on my own missteps and shortcomings and try to avoid them going forward) as well as to reframe for my staff and colleagues my approach to infosec and being an institutional actor in general.</p><p>For a new CIO to whom infosec probably reports - at least in higher ed - there is also a window of opportunity to have a strategic impact on your infosec program. Now, I can just hear everyone saying &#8220;you dope, shouldn&#8217;t you just listen to your CISO et al and figure out the lay of the land before requesting changes in the zoning laws?&#8221; Of course, but the questions you ask about the infosec program, those very first questions on day one, truly have a long-tail of impact. They&#8217;re a tell, your new staff will read and probably repeat to one another for years.</p><p>What I want to do is separate what you need to know as a manager with operational obligations from what&#8217;s valuable as an executive with strategic responsibilities. The former is going to be concerned with issues of execution: what are we doing, where are the compliance gaps, and what deployment constraints do we have? If your team has summarized these in their Information Assurance Management Plan or <a href="https://michaelcorn.substack.com/p/cybersecurity-requirements-for-research#:~:text=Assurance%20Management%20Plan%20(-,IAMP,-)%2C%20a%20modest%20set">IAMP</a>, great! You can read that over lunch and follow up with your CISO during regular meetings. If they haven&#8217;t created an IAMP or its equivalent, asking for one is a great step - though I&#8217;d do so <em>after</em> working through the more strategic questions. </p><p>It is these strategic questions that, as a campus executive, I would open with. As you might imagine, some deal with governance and decision making, but others try to get at many of the concerns I&#8217;ve raised throughout this blog. I&#8217;ve grouped the questions into four phases:</p><ul><li><p>What is known? (Phase 1)</p></li><li><p>What is testable? (Phase 2)</p></li><li><p>What is enforceable? (Phase 3)</p></li><li><p>What is scalable? (Phase 4)</p></li></ul><p>The bottom line is that while it&#8217;s easy to ask questions that the CISO can discuss but I&#8217;d like to turn them into something they must answer, with evidence.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Phase 1: The Visibility Diagnostic</p><p>In phase 1 we want to test whether the program is grounded in telemetry and outcomes, or in asserted capability derived from tool ownership. Essentially we&#8217;re going to ask a deceptively simple question: how do you know what you know? More specifically, is the security program grounded in observed system behavior, or in asserted capability derived from tool ownership? It&#8217;s far too easy (lord knows I&#8217;ve consistently played this card myself) when asked about, for example, email hygiene, to say &#8220;well, we have paid some absurd amount for Microsoft&#8217;s anti-phishing enhancements.&#8221; This is responding to a question on performance metrics with a tool inventory. So my suggested question would be, &#8220;<em>what aspects of our security posture are directly measured through system behavior - and what are we inferring based solely on the controls we believe are in place?</em>&#8221; This is a difficult question to answer unless performance <a href="https://michaelcorn.substack.com/p/from-genes-to-security-architecture#:~:text=Outcome%20Objective%20or%20%E2%80%9C-,SOO,-%E2%80%9D.%20A%20few%20examples">outcomes are predefined</a>, and answering it forces your CISO to split their answer into one of two buckets: measured vs. assumed. Hopefully it will create some immediate discomfort if everything falls into the second category. Most organizations discover, often uncomfortably, that a much larger portion of their confidence rests on assumption than they expected.</p><p>Along similar lines, you&#8217;ll want to push your team to define success in operational terms and surface performance gaps, not just activity metrics. With this next question you&#8217;ll see that I&#8217;ve added in the notion of &#8220;under stress.&#8221; This hearkens back to my concept of a <a href="https://michaelcorn.substack.com/p/from-genes-to-security-architecture#:~:text=want%20to%20define%20%E2%80%98-,architecture,-%E2%80%99%20as%20declared%20behavior">behavioral architecture</a> by forcing an admission of failure and not just a definition of success. &#8220;<em>For our most critical controls, what explicit outcomes are they expected to achieve under stress - and where do we have evidence they are not meeting those expectations?</em>&#8221; Notice the subtle shift. We're no longer asking whether we own a firewall or an EDR platform. We're asking what claims we are willing to make about their behavior when they are actually needed. Every engineering discipline eventually reaches this point. Bridges are specified by the loads they can carry, not simply by the fact that they contain steel. Aircraft are certified by their behavior under failure, not by an inventory of their components. Cybersecurity, I think, needs to become more comfortable speaking in that same language</p><div><hr></div><p>Phase 2: The Architectural Diagnostic</p><p>I would note that one dimension to being a CISO is dealing with the multitude of pressures you face with regard to specific controls. Compliance regulations and organizational policy often impose controls and activities of low value for which the security organization has no choice but to implement. In some cases these might even damage your security posture - I&#8217;m thinking about obsolete password formation and change policies that auditors love to persist in embracing. Be that as it may, this reality makes it important to distinguish between a security program built on engineering and one built on belief. Every security team develops convictions about what &#8220;works.&#8221; The question is whether those convictions are actually testable.</p><p>The question I would ask to start examining this is, &#8220;<em>which core assumptions about our security posture could be wrong today - and what signal would tell us they&#8217;ve already failed?</em>&#8221; Now there&#8217;s a risk to this question. By asking &#8220;could be wrong today&#8221; and &#8220;already failed&#8221; there&#8217;s an immediacy to the question. Being told by your CISO that some security service, control, or function has already failed is a bell being rung you can&#8217;t unhear. It gets at the difficult reality that those expensive security solutions you fought to fund may in fact be obsolete. The treadmill keeps turning.</p><p>I have two more questions for this second phase, one on dependency mapping and structural blind spots, and another on feedback loops.</p><p>For the first, &#8220;<em>can we trace a critical institutional service end-to-end to the infrastructure and controls it depends on - and identify the specific points where failure would interrupt it?</em>&#8221;; the second asks, &#8220;<em>what is a recent incident or near-miss that caused a permanent change to our architecture or control behavior - and what exactly changed?</em>&#8221;</p><p>The dependency question tests whether the organization actually understands the systems it operates or merely the technologies it owns. Every mature environment contains hidden dependencies that only reveal themselves under stress. Naturally this works for interrogating your organization outside of security as well. It&#8217;ll help surface assumptions (such as once when a power outage took out our data center. The network folks were very proud that all the major nodes had backup power. Unfortunately DNS sat entirely in the primary DC which was down for eight hours. A fuller dependency map would have surfaced this.)</p><p>The second question is, I think, a bit more interesting. It determines whether incidents produce structural adaptation or only procedural updates. By asking, &#8220;what exactly changed,&#8221; you require a kind of precision that eliminates hand waving. It&#8217;s very common to look at incidents (be they malware, attacks, or simple IT failures) as point problems. What you&#8217;re hoping to engender with this question is for failures to result in a holistic understanding of your ecosystem. By insisting on &#8220;what exactly changed&#8221; the conversation shifts from documenting failure to engineering resilience.</p><p>Obviously I&#8217;m dancing around the behavioral architecture idea I introduced in my last post. Behavioral architectures are valuable precisely because they define expected behavior under failure. They don't simply enumerate controls; they specify how the system is expected to respond when assumptions break. Without explicit failure conditions, there is no meaningful architecture - only aspiration.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/advice-to-a-new-cio?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/advice-to-a-new-cio?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>Phase 3: The Governance Diagnostic</p><p>Here I&#8217;m going to talk about risk decisions, but as I edit this I&#8217;m thinking the better way to frame this is around organizational behavior. Can this organization reliably convert decisions into operational change? I&#8217;ve long been struck by our obsession with risk decisions. Canonical thinking about information security rightfully pushes many critical risk decisions high up the organization&#8217;s orgchart, and for good reason: risk decisions always involve two elements: resources for mitigation and risk acceptance. Two elements that usually require very senior executives. I recall irritating a CIO I worked for when I insisted on taking an issue to the Provost since the resultant risk impacted the entire academic mission. I felt it was of such broad impact it went beyond the CIO&#8217;s scope.</p><p>Yet, as every CISO knows, we make dozens of risk and risk acceptance decisions daily. Hopefully we do so with enough savvy to recognize when we&#8217;re exceeding our own scope, but this is the reality of being in a security leadership role. Nevertheless, it&#8217;s valuable to link decisions and outcomes. So for phase 3 my opening question would be, &#8220;<em>where are risk decisions actually made&#8212;and what is a recent example where that decision produced a measurable change in the environment?</em>&#8221; Asking for an example moves this from theory to practice. Notice the emphasis on &#8220;actually&#8221;. Every organization has governance diagrams. Those diagrams tell you where authority is supposed to reside. Asking for a concrete example shifts the discussion from organizational charts to organizational behavior. It reveals whether governance is producing operational consequences or merely documenting conversations. Importantly if answered honestly it separates formal governance structure from actual decision authority and enforcement. It opens the door to that honest conversation about risk decisions and risk acceptance that separates the theatrical from the operational.</p><p>There&#8217;s a lot to plumb around the issue of risk acceptance - but I want to turn to what might be called &#8220;exception discipline&#8221; for the next question. &#8220;<em>How do we track and review policy exceptions - and when was the last time we revoked or reversed one</em>?&#8221; Fortunately, I&#8217;ve noticed more and more schools codifying a rather rigorous policy exception process; if you don&#8217;t have one, you&#8217;re behind the curve. For this question, the term &#8220;revoked&#8221; is the real test, most organizations can&#8217;t answer that. But the goal here is obviously one of maturation - you want to move from passive tracking to active discipline. This question tests whether exception management is active governance or passive accumulation.</p><p>I want to close out phase 3 by looking at the question of decentralization. &#8220;<em>In our most decentralized environments, who is accountable for security outcomes - and how do we verify that accountability is being met?</em>&#8221; Notice that I&#8217;m still pushing on outcomes over roles, and by using &#8220;verify&#8221; explicitly, we surface gaps between nominal ownership and enforceable accountability in a distributed environment. This seems like a fairly straightforward question, but in higher education it truly is a can of worms. While it focuses on accountability, it requires deep engagement on issues from outcome and role definitions, system telemetry and visibility, to resource allocation. I suspect anyone wrestling with the management of risk in distributed environments (or defining the distributed IT role in research security) could do much worse than starting here.</p><p>Remember, exceptions are organizational entropy. Every exception is locally rational. Yet it&#8217;s tempting to say that collectively they redefine the architecture.</p><div><hr></div><p>Phase 4: The Strategic Diagnostic</p><p>The previous phases examined whether the security program understands itself today. The final phase asks a different question: <em>will it still work tomorrow?</em> Strategy is fundamentally about preparing for conditions that have not yet arrived. That means understanding not only where the program succeeds today, but where it will fail as demand, regulation, and adversary capability continue to accelerate.</p><p>As regular readers of this blog know, I&#8217;m always going to advocate for collective action. When I ask CISOs (or security practitioners in general) about what prevents them from collaborating, the most common answer is that they don&#8217;t feel encouraged to do so. What they hear from their management is, &#8220;why should we invest your time in helping others when our own challenges are so vast?&#8221; is commonly reported. I do think some of this is self-imposed. For the most part, collaboration beyond commiseration isn&#8217;t well supported in our community. We seem to <a href="https://michaelcorn.substack.com/p/when-and-how-do-we-work-together">lack much of the infrastructure</a> for true collaboration. That makes it difficult to give &#8220;just a bit of time.&#8221; It&#8217;s the self-fulfilling prophecy of not having the time to collectively solve problems so we spend even more time solving them independently. Which is why I think this next question is so essential if we&#8217;re forward-looking: &#8220;<em>which of our major security challenges are structurally shared with our peers - and what are we doing today to solve them collectively rather than locally?</em>&#8221; This tests whether the organization is leveraging a shared problem space or defaulting to isolated solutions. And no, being told &#8220;I attended a talk on how some other school tackled this&#8221; is not a great response. I recognize that it&#8217;s very difficult for a smaller, less resourced school to participate in collaborative projects. The temptation of simply identifying a successful peer and emulating them is overwhelming, and frankly, probably the right move. But even in those circumstances, it is essential that those smaller schools to participate, however modestly, if for no other reason than to make sure their needs are included as requirements. Collaboration by only the wealthy is a country club, not a model for higher education.</p><p>Finally, I want to return to the issue of system failures. &#8220;<em>Under a step-function increase in demand or threat activity, where does our current model fail first - and how do we know?</em>&#8221; I like this question because it forces several admissions. First, the team must identify actual breaking points rather than vague concerns. Every system has a limiting reagent - whether it&#8217;s staffing, identity infrastructure, governance throughput, incident response capacity, or simply budget. Second, it requires the organization to articulate what it believes its operating model actually is. Surprisingly few security programs possess an explicit model. Most possess diagrams. </p><p>With that, the real opportunity arises. Does that model just show what tools you have, i.e., components and capabilities? Does it simply show where those tools and controls operate, i.e., the topology of your security model? What you&#8217;ll want to see is some system-oriented, behavioral thinking. Identifying indicators leading to outcomes: from what exists to what must happen.</p><div><hr></div><p>I can think of a number of alternative ways to structure the questions, and with it, the arc of your organizational diagnostic. But I like the four listed above, perhaps slightly reworded as, </p><ul><li><p>Observe (telemetry) - can you observe it?</p></li><li><p>Understand (architecture) - can you explain it?</p></li><li><p>Govern (decision-making) - can you act on it?</p></li><li><p>Adapt (strategy) - will it continue to work when the environment changes?</p></li></ul><p>Which feels to me like more than merely a diagnostic, but a repeatable model.</p><p>Ultimately, these questions aren't intended to evaluate a CISO's technical knowledge or even their management of the security function. They're intended to reveal whether the security program has crossed the line from managing technologies to engineering organizational behavior. Every phase pushes in the same direction: away from inventories and toward outcomes; away from asserted capability and toward observable behavior; away from static architecture and toward systems that continue to function under stress. That's the distinction between owning security products and operating a security program.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[From genes to security architecture]]></title><description><![CDATA[Competition and falsifiability]]></description><link>https://michaelcorn.substack.com/p/from-genes-to-security-architecture</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/from-genes-to-security-architecture</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Thu, 02 Jul 2026 18:55:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!o8A5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o8A5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o8A5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o8A5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o8A5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o8A5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o8A5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg" width="360" height="240.08241758241758" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:360,&quot;bytes&quot;:142709,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/202230254?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o8A5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o8A5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o8A5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o8A5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1101efc4-e171-4fc3-81d8-678b14a79ca3_4896x3264.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Architecture matters</figcaption></figure></div><div class="pullquote"><p>I was out of town much of last week, so between that and some vacation time, I&#8217;m a week or more behind in posting. I actually wasn&#8217;t gone that long, but the cruel mistress of air travel knocked the stuffing out of me for a bit. I&#8217;ve flown home from Shanghai in less time that it took from St. Louis. I&#8217;ll be trying to catch up this week.</p></div><p>It&#8217;s useful to reflect for a second on our changing understanding of the human genome. Classically, the genome was thought of as a series of instructions - instructions for creating proteins. As the human genome project was spinning up, there was a palpable excitement that once fully &#8220;decoded&#8221;, the genome would open the door to understanding the genetic underpinnings of, well, pretty much everything. Got disease X? We&#8217;ll track down and modify the specific gene or genes that controlled that. This also fed some of the most recent eugenics trends. All we need to do is figure out which genes made people taller, stronger, and smarter.</p><p>Now, of course, while our ability to do genetic analysis is now off-the-shelf, we&#8217;ve come to learn that the truth is vastly more complicated. While it&#8217;s true that genes do behave largely as understood, it&#8217;s not a simple matter of modifying a single gene or set of genes, but it is the <a href="https://www.quantamagazine.org/why-the-human-genomes-tangled-physicality-may-confound-ai-20260618/">regulation of genes</a> that may matter equally. Our body enables and disables genes pretty much continuously, and the nuanced interplay of genes and their regulation is the new frontier. This is to say, our genes are components, but it is the system within which they operate that is where the action is. As the linked article points out, the genome is not the architecture nor a framework, but rather components within the broader, and more complicated, system.</p><p>It is this view of architecture as a system, and not a conglomeration of components, that allows this analogy to dovetail with cybersecurity. Or at least, that&#8217;s what I&#8217;m going to propose. In my last post I noted that unlike math, where a problem is decomposed into simpler elements then is recomposed into stable truths, we in cybersecurity seem to lack an analogous process for our challenges. Particularly those where we want to create a stable architecture for a solution - one that is reusable, and in which failures serve to improve future iterations of the architecture.</p><p>I think the shift we should probably make is from thinking of an architecture as a bunch of nouns, to a bunch of verbs. Most reference architectures are essentially inventory lists or compliance checklists. They say, <em>&#8220;</em>a mature organization has an MDR service, a PAM tool, an asset correlator, and an incident response playbook.<em>&#8221;</em> They define the boundaries of the swimlanes and the existence of the equipment. Rather, I&#8217;m going to argue that an inventory list is not an architecture. A real architecture must define system behavior under stress. It isn&#8217;t enough to say you have a firewall; you must explicitly claim what the specific, measurable outcome is when a specific failure mode occurs. For our purposes I want to define &#8216;architecture&#8217; as declared behavior under defined failure conditions.</p><p>My suspicion is that my friends and colleagues who are more facile in all matters architectural are going to email me saying, &#8220;you dope, of course <em>real</em> architecture does just that. Read a book once in a while.&#8221; Perhaps. But I&#8217;m appealing here to how the term is actually used in practice. If you go to your networking team and say, &#8220;can I see our network architecture&#8221; you&#8217;ll get a lovely diagram showing network connections and equipment. If you go to your identity team and ask &#8220;what&#8217;s our identity architecture&#8221; you&#8217;ll get told about databases holding identity attributes, permissions, and a list of supporting services like SSO or MFA. Inventory lists - valuable no doubt, but nouns one and all<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>Part of what I&#8217;m responding to here isn&#8217;t the lack of sophistication in IT architecture. A glance at the work of <a href="https://spaces.at.internet2.edu/spaces/itana/pages/49315986/About">ITANA</a> or even the Educause Enterprise, Business, and Technical Architects community group shows plenty of it. But rather, where it seems to be lacking is within the cybersecurity space. I don&#8217;t know if this is because we&#8217;ve outsourced creating security solutions to vendors, or we&#8217;re all just too busy - my appeal to the defense of The Beleaguered CISO - but what it truly means to have a security architecture must, it seems to me, be more than lists of policies and controls.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>What I&#8217;m describing is called a behavioral reference architecture. A behavioral reference architecture does not describe where controls sit, but how decisions are made and enforced across a distributed system<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. It defines the signals that matter, the logic that interprets them, and the enforcement points that act on them - creating a coherent, testable model of defense rather than a static diagram of components. I&#8217;m going to keep pointing to a fully baked zero-trust architecture as the most commonly understood model. Ironically, the majority of ZT deployments I&#8217;ve seen in higher education leave out the most important component - the policy engine - falling back on modest micro-segmentation and gentle NAC in its place.</p><p>Most reference architectures describe what should be present, not what should happen. Without explicit claims about outcomes, constraints, and failure modes, they cannot be tested, compared, or improved, and thus never converge into shared engineering practice. As you may have noted in my previous post, it is the lack of codified and shared engineering practice among higher ed organizations that I find disappointing. But perhaps this lacuna is a symptom of this more general failure to develop truly &#8220;architectural&#8221; security architectures. Ones that meet the definition of what I&#8217;ve labeled a behavioral reference model.</p><p>Creating these explicit claims (and subsequent tests) of an architecture is, of course, challenging for us in cybersecurity; it&#8217;s relatively straightforward to test for the known, but brutally difficult to do the reverse - which is where most of our challenges arise. I&#8217;m not even sure what the conceptual language of such claims should be. My intuition is telling me that we might want to borrow from the SRE (<a href="https://en.wikipedia.org/wiki/Site_reliability_engineering">Site Reliability Engineering</a>) work done by Google that defines SLOs (Service Level Objectives) and SLIs (Service Level Indicators) for a service. SRE is entirely about how systems behave under stress. Thus SRE defines systems by measurable outcomes and behavior under failure is a first-class concern. But this in a nutshell is our core problem: security lacks agreed-upon SLIs (&#8220;blocked attack rate&#8221; is not as clean as is latency for a networked service) and of course, security vendors sell capabilities, not guaranteed outcomes<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. </p><p>I feel obligated to propose some SLOs and SLIs as examples. To push this analogy let&#8217;s reframe SLIs as a &#8220;SBI&#8221; or a Security Behavior Indicator (SBI). If we want SBIs that are observable, time-bound and tied to behavior, not merely the presence of tooling, then examples might be: </p><ul><li><p>% of privileged logins using phishing-resistant MFA</p></li><li><p>mean time to revoke access after termination</p></li><li><p>% of endpoints reporting EDR telemetry within last 24h</p></li><li><p>time from exploit publication to detection rule deployment</p></li><li><p>% of lateral movement attempts detected in simulation</p></li></ul><p>Similarly we can reframe SLOs as a Security Outcome Objective  or &#8220;SOO&#8221;. A few examples of SOOs include:</p><ul><li><p>&#8805; 99% of administrative authentications use phishing-resistant MFA</p></li><li><p>compromised credentials are disabled within 15 minutes</p></li><li><p>&#8805; 95% of endpoints maintain active EDR telemetry at any time</p></li><li><p>known exploited vulnerabilities are mitigated within 72 hours</p></li></ul><p>Notice the shift that we have made from &#8220;we have MFA&#8221; to &#8220;MFA behaves this way under pressure.&#8221; This is the core of the move from checklists to a behavioral reference model. <em>We are moving from what exists to what must happen</em>. Before the shift, architecture is treated as components (for example, firewall, MFA, PAM), topology (where things sit) and capabilities (what tools can do). After the shift to producing SOOs, architecture becomes explicit commitments about outcomes under defined conditions. </p><p>Remember, we are not merely translating metrics but creating operational narratives. For example, if a compromised credential remains active for 47 minutes against a 15-minute SOO, the architecture has failed - not the user. The question becomes: which dependency (IAM, HR feed, ticketing latency) broke the guarantee?</p><p>We&#8217;ve spent forty years defining what controls we have, and almost no time defining what they must actually do. </p><div><hr></div><p>I suspect part of our challenge (as security professionals) in viewing our environment as a system is that we&#8217;ve fallen back on &#8220;defense in depth&#8221; for so long. Your nextgen firewall doesn&#8217;t recognize an attack and permits it through. No worries, hopefully your endpoint solution recognizes it or its activity on the host. Does that fail as well? Hopefully network segmentation or credential hardening can constrain the infection. And so on, one failure triggering yet another control plane after the other. Essentially, while defense in depth will always remain a wise course, I wonder if we&#8217;ve allowed it to become a proxy for robust systems engineering.</p><p>As I&#8217;ve argued elsewhere, and as a recent article perfectly summarizes, <em>&#8220;</em>the root cause of most successful cyberattacks is not a failure of security controls, but a failure of system design.<em>&#8221;</em> This shouldn't be news to anyone. If you look at the footnotes of that very modern commentary on AI-driven threats, the source material is a remarkably prescient blog post dating back to 2016.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> </p><p>Of course that blog and the comment about a '&#8220;failure of system design&#8221; are referring largely to applications (which are themselves systems). Whereas I&#8217;m speaking about the system of security architecture writ large. I would be remiss not to mention, as was pointed out to me by a colleague while discussing this, that computer science has long wrestled with the issues I&#8217;m raising, but with much deeper thought and academic rigor<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>. For the moment though, I think it&#8217;s enough to try to formulate SOOs and SBIs if for no other reason than to challenge our usual thinking.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/from-genes-to-security-architecture?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/from-genes-to-security-architecture?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>I&#8217;d like to pivot the discussion at this point back to the issue of a lack of convergence of architectures within our community, as well as re-introduce the notion of <a href="https://michaelcorn.substack.com/p/epistemic-humility">epistemic humility</a> as influenced by what we&#8217;ve learned from the drama surrounding Anthropic&#8217;s Mythos. Recall that by epistemic humility I&#8217;m referring to the fact that our environments are rife with things we don&#8217;t and maybe can&#8217;t know about them. Everything from zero-day vulnerabilities to unimagined user-behavior. While it&#8217;s unidimensional, the takeaway lesson from Mythos seems to be that the quantity of unrecognized vulnerabilities in software is far greater than even the most cynical of us imagined.</p><p>For me, some of the significance to this is that because malicious adversaries have the same or similar capabilities as Mythos provides, the attack surface of any security architecture is much larger than we&#8217;re prepared for. If an adversary can auto-generate zero-days at scale, your component inventories (nouns) are completely useless, leaving your system's dynamic degradation behavior (verbs) as your only line of defense. </p><p>Returning to the challenge of testing an architecture: how are we to test its ability to detect and mitigate an attack when the diversity and breadth of those attacks just expanded by an order of magnitude? There is no simple answer to this, except I see this as an even more compelling reason for our community to converge on the most robust solutions for security architecture and to stop assuming that &#8220;which ever vendor we can afford and is popular&#8221; is a strategy for success.</p><p>As I&#8217;ve noted, we have shared references for guidance, e.g., NIST publications and control sets, but we lack a mechanism for shared synthesis of architectural models. That is, architectures that produce consistent and predictable outcomes: SOOs are not defined. I suspect that one reason for this is that our models, our architectures aren&#8217;t falsifiable - they don&#8217;t converge because they don&#8217;t compete.</p><p>A falsifiable reference architecture enables comparison across institutions, iteration, and then convergence. That is, &#8220;did it work?&#8221;, &#8220;what failed and why?&#8221;, and &#8220;this pattern consistently produces the desired outcomes.&#8221; Without falsifiability, you get what I described as the diffusion of practice instead of engineered convergence. I&#8217;m going to argue that SBIs and SOOs are the foundational metrics that make a security architecture falsifiable. If you don't define an SOO, you haven't declared a baseline that can be proven wrong.</p><p>I should probably define falsifiability for those not raised on Karl Popper. Popper proposed that a claim is falsifiable if there exists a conceivable observation that would prove it wrong. Falsifiability has become a cornerstone of the scientific method. Operationally, falsifiability requires someone to define the disconfirming condition, someone to test for it, and importantly, someone to care if it fails. </p><p>The reason I think competition is so essential for us when thinking about falsifiability is that without competition, three things happen. First, there is no incentive to test disconfirmation. It&#8217;s natural to simply test what confirms our beliefs or, alternatively, to quietly reinterpret failures. Second, ambiguity goes unchallenged - without competition, who is going to challenge you on statements like &#8220;the firewall improves our security posture&#8221;? This is not crisp nor will it support exploration of questions like &#8220;under what conditions does it fail?&#8221; Finally, and I&#8217;ve seen this far too often both inside and outside of security, failure is socially suppressed. Failures are often reframed as exceptions. Competition, on the other hand, needs not just independent judgment or reputational stakes, but an incentive to find flaws.</p><p>Fundamentally, falsifiability is not merely a property of a model, but a property of the environment in which it is evaluated. Without independent actors incentivized to challenge it, even a formally falsifiable claim becomes operationally unfalsifiable.</p><p>More simply, without the discipline that competition between security architectures would engender - the discipline to define security behavior indicators and security outcome objectives so that competition is possible - it&#8217;s difficult to see how we will ever move beyond the informal diffusion of practice to engineered rigor.</p><div><hr></div><p>So what should be our next steps? By writing this I&#8217;m hoping to seed some thinking about SBIs and SOOs within the security community. I&#8217;m also hoping that the technical architecture community turns its eye toward cybersecurity. (And remember, a mature cybersecurity architecture will need to account for non-technical, human behavior as well as the usual adversary/defender binary). What would be a good next step is for us to put some thought into establishing the test harness for falsifiability. No one can write a deterministic, purely technical script to test for the vast, unknown attack surface exposed by AI engines like Mythos but we need to bridge the gap between human systems engineering and narrative simulation.</p><p>The closest proxy for a system stress test is the human and administrative execution layer. One option would be to use collaborative, improvisational role-playing exercises as the dynamic test harness<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>. By forcing mixed-role groups (CISOs, researchers, IT engineers, and administrators) to actively improvise how stress, professional ambition, and trust break down a system, you create a generative model that surfaces unexpected behavioral indicators and system failure points that no checklist could predict.</p><p>We also need an open-source repository of behavioral blueprints that declare explicit SOOs. If such an animal already exists it needs to become part of the lingua franca of security professionals. This must include the outcomes from when a model is tested under stress (i.e., when it fails). When an institution experiences a breach, the post-mortem should not simply state &#8220;the user clicked a link,&#8221; but rather: &#8220;Our architecture claimed a 15-minute credential revocation window (SOO), but failed under the stress of an asymmetric identity attack because of a cross-functional dependency gap.&#8221;</p><p>Cybersecurity seems to be entering a new phase, one in which its function more visibly underpins our entire civic and economic life. In this new phase, the nature of collaboration is also under pressure to evolve. Our collaborations must move from asking &#8220;what do we have?&#8221; and start asking &#8220;what must happen, how fast, and how often?&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>To be fair, the wisely designed network architecture does include behavior under failure. Internet Protocol (IP) networking is designed to be highly decentralized and route around damaged links though it still relies on a physical layer of infrastructure to function (which is why it failed so quickly during the 2003 invasion of Iraq. The US heavily targeted those physical links with kinetic weapons.)</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>You can see how this elides with my preoccupation with governance throughout this blog. See: <a href="https://michaelcorn.substack.com/t/policy">https://michaelcorn.substack.com/t/policy</a>. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>A SRE style formulation would look something like this: &#8220;When X &#8594; system does Y &#8594; within T &#8594; observable via Z&#8221;. So translating this from SRE to security we would take something like &#8220;99.9% of requests succeed under load&#8221; and turn it into &#8220;100% of malicious traffic is dropped within X ms,&#8221; sticking with a firewall example.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p><a href="https://www.linkedin.com/pulse/defending-against-mythos-class-attacks-ron-ross-pgqxe/">https://www.linkedin.com/pulse/defending-against-mythos-class-attacks-ron-ross-pgqxe/</a> .</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>See for example: <a href="https://en.wikipedia.org/wiki/Formal_verification">https://en.wikipedia.org/wiki/Formal_verification</a> or <a href="https://en.wikipedia.org/wiki/Model-driven_architecture">https://en.wikipedia.org/wiki/Model-driven_architecture</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>No, this wasn&#8217;t my idea, but that of the <a href="https://www.highergov.com/grant/2545020/">PI of a grant</a> I&#8217;m participating on. We&#8217;re currently using <a href="https://en.wikipedia.org/wiki/Fiasco_(role-playing_game)">Fiasco</a> as the RPG. Working with people smarter than you is always a wise move.</p></div></div>]]></content:encoded></item><item><title><![CDATA[When, and how, do we work together?]]></title><description><![CDATA[Cultural osmosis feels inadequate.]]></description><link>https://michaelcorn.substack.com/p/when-and-how-do-we-work-together</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/when-and-how-do-we-work-together</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Fri, 12 Jun 2026 05:18:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jwoi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jwoi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jwoi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jwoi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jwoi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jwoi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jwoi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg" width="204" height="193.07142857142858" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1378,&quot;width&quot;:1456,&quot;resizeWidth&quot;:204,&quot;bytes&quot;:146369,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/201202912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jwoi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jwoi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jwoi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jwoi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c6dcc3-fa35-4e34-ac96-a1bf63e24065_1912x1809.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>In my continuing quest to find constructive uses of AI, I&#8217;ve been reading a lot about how there&#8217;s a stratum of mathematicians who feel AI is not only helpful, but a harbinger of how math will operate in the future<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. One comment in particular struck me, that &#8220;some math problems were more amenable than others to being solved through large-scale collaboration.&#8221; This naturally gave me pause and forced me to ask whether this is true for us in cybersecurity and privacy.</p><p>Of course, we don&#8217;t often talk about our challenges as &#8220;problems to be solved.&#8221; Instead we have threats to be mitigated, or organizational hurdles that interfere with our ability to implement those mitigations. In earlier posts, I&#8217;ve talked about developing a <a href="https://michaelcorn.substack.com/p/do-we-need-a-cybersecurity-research">research program for higher education cybersecurity</a>, and I&#8217;ve provided my own list of <a href="https://michaelcorn.substack.com/t/open-questions">open questions</a> that I believe if resolved, would help steer the field&#8217;s progress. But in this post, I want to explore the question of whether some of our challenges truly are more amenable to being collectively solved, or if they are so locally constrained that collective action is unnecessary.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>At first glance, I think the heuristic here is pretty straightforward. Collaboration pays off when the problem is shared across organizations, that is, it has a kind of shared exposure. Perhaps from the same technology and same dependencies. Of course there are problems wherein no one sees the full picture; the image only truly develops when information from disparate perspectives can be sewn together. It should be obvious that anything with network effects benefits from aggregation - the value of the analysis or detection likelihood only increases with participation. And lastly, wherever the attackers scale across victims, i.e., adversarial reuse. All of these are familiar to anyone working at any organization with disparate units.</p><p>On the flip side, some problems appear to be solvable without any broad collaboration. I would call out local architecture decisions, or organization-specific risk tolerance and governance matters. And with highly sensitive vulnerability details, collaboration can introduce noise, delay, or risk exposure. But I did say &#8220;at first glance.&#8221;</p><p>As I&#8217;m writing this, I&#8217;m comparing it to my personal lived experience. Like most professionals, I&#8217;ve found sharing and listening to others - be it through a message board, mailing list, or hallway chatter at a conference - to be incredibly helpful. Ironically, it may be more helpful in those items I initially called non-collaborative.  Who hasn&#8217;t spent time describing a difficulty they&#8217;re having with a governance committee, or a local architectural challenge with colleagues? These conversations do normalize practice across the field, albeit slowly. This is more through a kind of diffusion of practice - a passive leak of ideas - rather than a structural adoption of an engineered solution.</p><p>But I want to differentiate this kind of collaboration (perhaps snarkily labeled commiseration) from working collaboratively to <em>solve</em> a problem. Perhaps the distinction is therapy versus engineering. Both are helpful in moving you forward, but only one resolves an issue in a repeatable and codifiable way. There&#8217;s probably some wisdom here in watching out for the category error of &#8220;feeling supported&#8221; with &#8220;building a defense.&#8221; </p><div><hr></div><p>The first example that comes to mind, of a problem that meets all four dimensions of the collaborative heuristic is building a network border<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. Practitioners from outside of higher ed are going to read this and think we&#8217;re nuts for ever having to debate it. The traditional functional model many of us have settled on is roughly this for network ingress:</p><p>                Internet &#8594; IP black hole service &#8594; firewall &#8594; IPS </p><p>Ah, I&#8217;m feeling nostalgic for simpler days. As anyone who&#8217;s older than my dog knows, the scars we earned arguing for that border firewall run deep. At many schools that battle continues because of either cost or arguments about academic freedom<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><p>But the idea of a network location being a control plane has been eroded to the point of near irrelevance. Increasingly we now think of the network border as porous and dynamic in that it&#8217;s highly distributed across cloud, SaaS, your legacy Internet border and endpoints. The border has become secondary to identity and policy enforcement. Of course, what&#8217;s interesting here isn&#8217;t just what the border is, but how visibility and enforcement move as the notion of a border dissolves<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. Even as the border dissolves, the<strong> </strong>need for a shared model increases, not decreases. Examining this through the lens of the heuristic I provided above we see a distinct contributing factor, that is, shared technology and exposure. Most of us are wrestling with this same challenge and with the same vendors. By the heuristic I outlined earlier, this is exactly the kind of problem that should converge under collaboration. And yet, it hasn&#8217;t.</p><p>It&#8217;s clear to me that we lack some agreed upon approach to this problem. We <em>could</em> look at some of the canonical docs on network protection (e.g., NIST SP 800-41, NIST SP 800-53 SC-7 or AC-4 and of course NIST SP 800-207 which explicitly critiques and evolves beyond perimeter-based models), and I know many of us individually do. But I just don&#8217;t see anything passing as a community adopted model. We have references, but not a model. Guidance, but not convergence. Perhaps that&#8217;s because we are so loosely federated, there truly is no hub; it&#8217;s all spokes. </p><p>Equally as possible it&#8217;s because we&#8217;ve embraced a tad too eagerly the general belief that we&#8217;re all special snowflakes. &#8220;That model may work for <em>them</em> but they&#8217;re richer, bigger, smaller, poorer, less experienced or important than we are.&#8221; As idiosyncratic accretions of personalities and preferences, we <em>are</em> all special snowflakes. But I&#8217;d like to believe a perimeter is a perimeter (even if we&#8217;re abandoning the notion of one).</p><p>So we have these canonical architectures, we have decades of experience and shared practice, we&#8217;ve had time and commonality to figure this out, yet we haven&#8217;t converged on a solution. While it&#8217;s true the problem changed shape, it still remains shared. Yet despite everything, we behave as if the problem is local. Perhaps the fundamental issue is that we are treating a collective engineering problem as if it were a local architectural preference. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/when-and-how-do-we-work-together?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/when-and-how-do-we-work-together?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>I suppose we should also ask: are the problems we need to solve in cybersecurity &#8220;solvable&#8221; in the same fashion as the math problems that kicked off this exploration? We know that a mathematical proof can be solved in more than one way (although often one method turns out to be the same approach in merely a different guise). But unless an error is found, a successful and complete proof is a statement of a kind of truth. The Pythagorean Theorem is a statement of fact: the square of the longest side (the hypotenuse) <em>is</em> equal to the sum of the squares of the other two sides. Is this kind of permanence true for us? Are our challenges truly solvable or merely &#8220;solvable given what we currently know of the threats and attack methodologies&#8221;? </p><p>Mathematicians solve for eternal truth, while CISOs only ever solve for time<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>. I suspect, sticking with the mathematical flavor, we could posit something like a theorem of cybersecurity depreciation. In cybersecurity our solutions are all born with a half-life. Naturally, this half-life cuts both ways. The ephemeral nature of solutions would seem to work against the value of creating a codified repository - why spend the time to polish and codify something that will immediately begin eroding? Whereas it also suggests that collective intelligence - collaborative analysis and maintenance - would help identify when a solution&#8217;s time is up, so to speak.</p><p>Another element that stands out in the writing on AI and math is how so much of the work is focused on either discovery or fragmentation. In some cases, an AI is used merely to offer up novel approaches to problems; in others, such as the Quanta piece I cited, the work begins by breaking a problem into a large number of smaller pieces, lemmas, the atomic components of the larger molecule of the theorem. It&#8217;s tempting to think that the market is taking care of the latter for us. Every vendor tackles each functional component as an element to be optimized. However, even in integrated solutions, such as nextgen firewalls that combine traditional firewalls and IPS functionality, that integration is more of a papering over of the edges. The UI tries to smooth over the reality that you have two products in the same chassis. These don&#8217;t solve a single problem, but present several solutions that are conveniently bundled into one SKU<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>. It&#8217;s tempting to argue that attackers optimize for reuse while defenders optimize for procurement.</p><p>At its core, math&#8217;s use of AI involves breaking a problem into its atomic components, which are individually proved, then recombined to form stable truths. Whereas in cyber, vendors control the decomposition, but no meaningful recomposition takes place, and what results we have rust over time. Addressing this may be much more impactful than any specific engineering-centric challenge we face. What would decomposition and recomposition look like for cybersecurity problems, and how do we recapture this space from the commercial marketplace - or at least influence it?<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a></p><p>I&#8217;ve been overextending the network border challenge but I can think of a few other narrower examples. For instance, if one university sees a handful of suspicious emails and another sees similar domains registered while a third observes credential harvesting endpoints, each sees mere noise. But collectively we see an early-stage phishing campaign developing. Thus, this meets heuristic number two, distributed visibility. Only by working collaboratively does the full image resolve as the telemetry is correlated.</p><p>Similarly, ransomware attacks seem to fit heuristic number four, adversarial reuse, whereby the attacker scales across victims. With most ransomware we have the same tooling reused. I&#8217;m thinking of highly commoditized frameworks like Cobalt Strike, credential harvesters like Mimikatz, and living-off-the-land binaries. It&#8217;s common to see the same attack chain, from phishing to foothold to privilege escalation to backup targeting. And of course, they show the same monetization patterns at each victim. After all, attackers want reuse because it lowers their cost. That means, however, that defenders can amortize detection and response across victims. Thus, we develop a shared understanding of the entire detection chain, not merely IOCs. This <em>should</em> lead to shared incident response playbooks, and preemptive control placement. But again, only with aggressive collaboration.</p><p>All of this is to say, that while vendors sell individual, fragmented lemmas (SKUs) that offer cosmetic integration, the actual threat landscape <em>is</em> highly integrated, repetitive, and optimized for scale. If attackers are amortizing their costs across victims through reuse, defenders are practically committing malpractice if they don't amortize their defenses through collaboration.</p><div><hr></div><p>So why is it that despite our shared ecosystem, our shared experience, our shared references (NIST et al), we lack shared synthesis mechanisms? Why is it that within the institution of higher education cybersecurity practice, there is no institutional mechanism for turning shared experience into shared architecture? Lord knows it&#8217;s not for a lack of venues. We have consortia and conferences, national, regional, and local; we have all the modern tools of communication and collaboration available to us, yet with few exceptions we lean into commiseration and cultural osmosis over engineering<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>.</p><p>The wisest manager I ever worked for once, no doubt when I was justifying some procrastination on my part, dope slapped me with &#8220;people do what they want to do.&#8221; Advice that helped me be a better manager myself, but forced me to do some serious internal reflection on my own decisions. Which returns me to my opening question: Which problems should be collaboratively solved - and what should we do about it?<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a> </p><p>To be sure, the broader barriers to collaboration often appear structural. We look at the landscape and notice a missing hub - the lack of a dedicated project owner or central catalyst to drive a community-wide initiative. But this absence is largely self-inflicted. In higher education, we wear our decentralization and institutional federation as a badge of honor, and we project that fierce independence onto the very organizations we establish to help us. Consequently, our collective bodies are designed more to facilitate polite communication than to execute rigorous collaboration.</p><p>Similarly, our lack of common metrics is a calculated omission. Defining hard security metrics is notoriously difficult, but it also threatens to decrease our local degrees of freedom and challenge our subjective preferences. Even our shocking lack of an agreed-upon, curated repository of solutions is less a resource constraint and more a defense mechanism. I view all of these structural gaps not as the root cause of our failure to collaborate, but rather as the visible artifacts of our unwillingness to converge. In the end, we do what we want to do.</p><p>I&#8217;ve provided a simple heuristic for evaluating challenges, but I suspect the failure to build a collectively engineered defense is fundamentally a failure of will and culture. In our relative isolation, it&#8217;s simply too easy to forget that the larger culture of our profession isn&#8217;t something that exists independent of us. Culture is an emergent artifact of the millions of small choices we make in our daily lives. We choose our own wardrobe. Perhaps we are also choosing fragmentation over convergence.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>For a popular and digestible read on these issues, see <a href="https://www.quantamagazine.org/how-terry-tao-became-an-evangelist-for-ai-in-math-20260608/">https://www.quantamagazine.org/how-terry-tao-became-an-evangelist-for-ai-in-math-20260608/</a>. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>First, <em>shared exposure</em> implies we&#8217;re using the same vendors (Palo Alto, AWS, Cloudflare, etc.). Second, <em>distributed visibility</em> because no one sees full traffic patterns across institutions. Third, <em>network effects</em> since we can build better models with shared telemetry. And fourth, <em>adversarial reuse</em> appears as attackers probe borders across institutions in repeatable ways.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Opposing a firewall under the flag of academic freedom is indeed to use a false flag. The more fundamental issue is an endemic mistrust of institutional administration (&#8220;surely you&#8217;re using these tools to spy on us&#8221;). The irony that these same individuals fully embrace commercial tools with business models based on spying on their customers is lost on no one.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>I searched for discussions of this issue - there are many - for example <a href="https://edtechmagazine.com/higher/article/2026/03/cloud-security-monitoring-higher-education-minding-visibility-gap-perfcon">https://edtechmagazine.com/higher/article/2026/03/cloud-security-monitoring-higher-education-minding-visibility-gap-perfcon</a>. But notice who&#8217;s quoted, major vendors selling point solutions, not higher education practitioners.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p><a href="https://michaelcorn.substack.com/p/the-persistence-of-investment">https://michaelcorn.substack.com/p/the-persistence-of-investment</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Yes, I realize that this bundling, when done well, can make managing these services less burdensome.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>As I&#8217;m copy editing this, it struck me that this might be the most interesting question raised in the entire post. I&#8217;ll have to return to it in the future.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>I think of the fine work done by the Trust and Identity folks and NetPlus team at Internet2 as solid examples of community driven collaboration. The work done on Science DMZs also jumps to mind, as does some large scale collaborative infrastructure projects like the Open Science Grid.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>I am increasingly convinced that many of the issues we believe are truly local (e.g., governance, policy) are in fact as amenable to large scale collaboration as are purely technical challenges. It would make a terrific study to see if even something as idiosyncratic as risk tolerance <em>really</em> occupies a broad spectrum, or if our love of marveling at a problem merely makes it seem that way.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[The security practice registry]]></title><description><![CDATA[Are we merely historians of our own infrastructure?]]></description><link>https://michaelcorn.substack.com/p/the-security-practice-registry</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/the-security-practice-registry</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sat, 06 Jun 2026 23:48:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V2Vj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V2Vj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V2Vj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V2Vj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V2Vj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V2Vj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V2Vj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg" width="178" height="267" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2184,&quot;width&quot;:1456,&quot;resizeWidth&quot;:178,&quot;bytes&quot;:1146196,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/200832039?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V2Vj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V2Vj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V2Vj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V2Vj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b672ac5-26f2-4fdb-a814-a114c4b336be_3264x4896.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Leaves of Grass</figcaption></figure></div><p><em>The past and present wilt&#8212;I have fill&#8217;d them, emptied them.<br>And proceed to fill my next fold of the future.</em></p><p>I don&#8217;t think Whitman would have made much of a CISO. We struggle precisely because we live at that juncture between the past and the future - existing practices and planned ones. Our present is almost impossible to empty; for us, the present is little more than the accumulation of past practices we firmly grasp, fearful of letting go of what was won with such difficulty. We hoard the past, and in doing so we constrain the future. What was hard-won becomes untouchable, and the result is not stability but inertia - an environment where new approaches struggle to take hold because the old ones are never truly released. Our resources are finite, yet our desire - our need to respond to new threats - is unlimited.</p><p>In this post, I want to reflect on the issue of balancing historical practice with new demands, through the lens of the term <em>security practice registry</em>, and three possible definitions for it. Each offers a similar but distinct framing for historical practice that can help inform and guide future actions. Each definition expands the scope of the registry - from institutional memory, to sector coordination, to ecosystem trust.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Let&#8217;s start with the control plane. In this framing, a security practice registry acts as a centralized authoritative database where the organization logs and tracks exactly <em>which</em> security controls, policies, or practices are active across various units. It asks &#8220;what are we carrying?&#8221; In one sense, it is an institutional risk and governance ledger. For most of us, especially in higher education, this is the space where GRC tools live. At a larger scale, globally matrixed corporations use continuous controls monitoring platforms - I&#8217;m thinking of a tool like <a href="https://panaseer.com/">Panaseer</a> (which I have no personal experience with). In this market, the tool logs both vulnerabilities and whether specific controls have been implemented in discrete business units across the enterprise.</p><p>What&#8217;s lovely in this approach is that instead of a generic compliance checklist, this registry maps reality. I find this attractive because it articulates what we&#8217;re actually doing (and where) even if it rarely touches on why. One need not &#8220;speak truth to power&#8221; but simply describe the situation on the ground. Observation over analysis.</p><p>Alternatively, we can view a security practice registry as a form of collective telemetry, a sector-wide defense repository. It asks &#8220;how we compare and calibrate?&#8221; When applied to a community or industry sector (like a sector-specific Information Sharing and Analysis Center, or ISAC), a security practice registry functions as a collaborative blueprint. Rather than sharing volatile threat intelligence data like changing IP addresses or file hashes, organizations use a registry to share their structural defensive postures. It catalogs the specific configurations, architectural designs (such as protected, anonymous networks for research), and mitigation steps that peer institutions are successfully deploying against targeted threats. It allows a sector to baseline what &#8220;best practice&#8221; looks like in a complex environment. But caution is warranted; do not confuse comparative and normative risk<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>Finally, we can continue our outward expansion to define a security practice registry as a supply chain and software registry architecture. Here we ask &#8220;what we unknowingly import into the future?&#8221; In software engineering and DevOps (such as managing open-source package managers like npm, PyPI, or DockerHub), the phrase refers to the security protocols enforced by a platform registry. This includes logging cryptographic signing practices, verifying software provenance (like Software Bills of Materials, or SBOMs), and ensuring a transparent, auditable trail of code custody to prevent software supply chain attacks.</p><p>For each framing we have plenty of examples, the ones provided here are merely illustrative. GRC and CCM tools serve as the institutional risk and governance ledger. Sector-wide telemetry emerges through platforms like CIS CSAT, MITRE ATT&amp;CK Mitigation Matrix, and D3FEND, which encode shared defensive patterns against common threats. At the supply chain layer, Sigstore, OpenSSF Scorecard, and secure container registries (e.g., Docker Scout, AWS ECR) extend this logic outward, enforcing provenance by requiring artifacts to map to SBOMs.</p><p>One object class, &#8220;security practice registry&#8221;, three different instantiations of the object, each with differing properties, but all three offer value to us as security practitioners. More plainly, all three of these at first glance look like mere technical artifacts, when in truth they serve as governance primitives. That is, they shape decision-making by structuring visibility, not by prescribing action<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. Collectively they ask &#8220;how does this help us decide what to keep versus discard?&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/the-security-practice-registry?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/the-security-practice-registry?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>It&#8217;s worth pointing out that by calling these governance primitives, I&#8217;m using &#8220;governance&#8221; in two ways. The immediate conclusion is that it refers to formal institutional governance processes - and that&#8217;s correct. But it also refers to the kind of managerial governance we exercise over our office activities, the agency our organizations have invested in us as practitioners. I won&#8217;t fully untangle this knot here, but it is worth reflecting on how to balance those two domains of governance. I suspect that for expediency, we all try to expand the latter and minimize the former. In reality, the decision tree for this is cultural and organizational, and not a function of expertise or practice logic.</p><p>Be that as it may, by using these artifacts - these three forms of registry - to inform governance decisions, we begin to wrestle historical and current practices to the ground. They show us where and at what scale actual risk exists within our ecosystems. Importantly, each reveals a different type of risk.</p><p>The supply chain and software registry is largely a <em>risk of the unknown</em>. It shows us gaps in our knowledge (or at least visibility) about the products we introduce into our ecosystem. An incomplete SBOM or a poor Scorecard measure suggests the need to more deeply interrogate a product. Being an outlier in the space of collective telemetry could mean you&#8217;re the only one doing something right. But more likely is that you&#8217;ve recreated the wheel or fallen down a rabbit hole. Innovation and creativity are valuable but sometimes you just need to use a hammer, and not engineer a nail insertion protocol. Here the risk is that delta between you and the rest of the world - a signal that needs explaining. This is the<em> risk of isolated deviation. </em>While our scientific workflows are uniquely open, the underlying technical primitives - identity management, network routing, credential storage - are not. Conflating unique research with unique infrastructure is how we fall down these customized rabbit holes.</p><p>Of course, the institutional risk and governance ledger gives you a literal map, the topology of practice risk in your organization. It allows you to ask &#8220;why isn&#8217;t MFA being used in a specific unit?&#8221; or &#8220;why does one research lab have 80% of our policy exemptions?&#8221; True, this is not the same as the classic risk register, i.e., an inventory of threats, but it reveals where we are weak thus showing where resilience is lacking. I would label this the <em>risk of permeability</em>, where your internal enterprise fabric is structurally thin.</p><div><hr></div><p>Exploring the notion of a security practice registry reveals a reusable model where risk visibility and governance influence are emergent properties. What I find attractive in this formulation is how we can use one mental model to surface multiple forms of risk. This allows us to shift the past from a burden to be carried to a tool to inform planning and governance. In evaluating this or any model we should always pose the question, &#8220;what does this let me <em>ask</em> that I couldn&#8217;t ask before?&#8221; Critically, this model creates visibility and thus a pressure to act. But governance determines whether that action is thoughtful or reactive. Visibility is not the same as wisdom; registries create the former, while governance must supply the latter.</p><p>Whitman believed that to grow, a person must possess the radical capacity to shed their former selves, their past mistakes, and even their hard-won achievements. If you keep your vessel full of the past, you have no room to receive the future. History should no longer be a weight holding us back, but through the use of practice registries it becomes a ladder helping us better survey our landscape and make future decisions based on that wisdom. History becomes the embodiment of traceable wisdom<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I think this happens more than we realize. Historically, institutions looked at their peers' low self-assessment scores and felt a false sense of security based on comparative risk (&#8220;everyone else is failing too&#8221;). In doing so, they completely ignored the absolute normative risk of non-compliance, resulting in the broad winking and nodding we saw with SPRS scores that ultimately forced the federal government to mandate CMMC.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>You&#8217;ll note that I&#8217;m trying to inject a deliberative step here. It&#8217;s tempting to view the intelligence coming from any of the three framings as initiating action (e.g., &#8220;see, they&#8217;re not using MFA, let&#8217;s force it on them.&#8221;) And that may ultimately be the result. But what I&#8217;m encouraging here is for you to pause and ask, in partnership with governance, the question of <em>why</em> something is what you&#8217;ve discovered. These registries increase visibility and visibility increases pressure to act, yet I am advocating deliberation through governance before action. This deliberation is what allows you to inject thoughtfulness into your operational workflow - essentially, to step for a second off the treadmill.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>See: <a href="https://michaelcorn.substack.com/p/traceable-wisdom">https://michaelcorn.substack.com/p/traceable-wisdom</a>.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Open question no. 8: the Federal Government as a partner]]></title><description><![CDATA[Our most pressing need will be the most uncomfortable to address.]]></description><link>https://michaelcorn.substack.com/p/open-question-no-8-the-federal-government</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/open-question-no-8-the-federal-government</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sun, 31 May 2026 02:56:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IqBM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IqBM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IqBM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!IqBM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!IqBM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!IqBM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IqBM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg" width="210" height="315" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2184,&quot;width&quot;:1456,&quot;resizeWidth&quot;:210,&quot;bytes&quot;:1101026,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/199086277?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IqBM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!IqBM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!IqBM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!IqBM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46a2b75b-0912-4256-b235-5d3c8570fc89_3264x4896.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>&#8230; how do we address the need for this important and non-public threat intelligence? Second, how to prevent the penetration into systems and the theft of data by the US Government. Given the legal instruments available to the government what technologies can assist in protecting PII and private communications? Or more broadly, entire targeted groups?</p><p><a href="https://michaelcorn.substack.com/p/where-to-begin#:~:text=how%20do%20we%20address,broadly%2C%20entire%20targeted%20groups%3F">Where to begin?</a></p></blockquote><p>In this post, I will address both of the questions raised by open question no. 8, more fully &#8220;the untrustworthiness of the federal government.&#8221; Both are inflections of the more general question of how we, as the higher education community, should respond to the behavior of the Feds. While I&#8217;m framing this as a federal issue, the collapse of the SCOTUS has allowed a number of states to &#8216;get in the game&#8217; of suppressing academic freedom - <a href="https://pen.org/academic-freedom-political-ideology-texas-campuses/">Texas in particular stands out</a> - so what I&#8217;m proposing here needs to work regardless of where the suppression arises from<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>As IT practitioners there are two dimensions to academic freedom we need to discuss. Naturally it&#8217;s tempting to delve into the nature of - and frankly limits on - academic freedom. Importantly, academic freedom is not bounded primarily by <em>content</em>, but by context, role, and impact. Is the speech within the scope of professional expertise? Does it interfere with institutional function or violate law/policy? Does it meet the norms of the discipline<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>? While academic freedom is largely a framework of self-policing norms, its weakness under the current onslaught is that it simply never was codified in a fashion to resist a governmentally driven politicization. Academic freedom is often protected by institutional policy, but that and 50 cents won&#8217;t buy you a cup of coffee these days<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. </p><p>I should note upfront that my proposals below don&#8217;t really address &#8220;protecting the right to academic freedom&#8221; but rather they &#8220;protect the activity of academic freedom as practiced by academics.&#8221; Essentially we want to preserve the advancement of science and the privacy of thought, despite the legal barriers being erected around them.</p><p>But I want to start with the question of how institutions should respond to the weakening of Federal threat intelligence - which has been achieved both by eliminating traditional resources and, more perniciously,  by changing the identification of &#8220;adversary&#8221;. Then I will return to the question of protecting academic freedom.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Let&#8217;s begin with how our community can respond to the absence or weakening of Federal resources for threat intelligence. As you&#8217;ve undoubtedly noticed I often argue for community-centered action in response to community-wide threats.  Which is precisely what I want to do here. We simply do not leverage the telemetry our scale affords us. Even if we were to focus on only the RUCC<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> or AAU schools, collecting and correlating attack and probe information would be formidable indeed. Think of this as a strategy for <em>sector sovereignty</em>.</p><p>I have to confess, I have at times been skeptical of such an approach. Our commercial providers already collect this data at a much larger scale and many of us already buy this aggregation either independently or as part of a technology bundle. Further, I saw how difficult it was to build interest in such an effort when I worked within large systems. It was also hard to see the lack of interest and uptake of the REN-ISAC&#8217;s MISP service (and its predecessors) without reaching the conclusion that commercial options were largely meeting community needs<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>.</p><p>Nevertheless, there are several reasons to pursue a sector-based threat intelligence initiative. While I&#8217;ve long been struck by how poorly we articulate precisely how we are distinctive from other sectors in terms of the attack mechanisms, the question I have is this: if we can&#8217;t articulate our uniqueness as a sector, either we&#8217;re not a sector at all or this reflects on our own self-awareness. We either are something, or we&#8217;re not. And if we are, then what are the attributes that define us?</p><p>It&#8217;s easy to assume that the usual metaphor of universities being more like cities than businesses is correct. But that sort of works against us in the cyber realm. There are over 19,000 cities in the US, around 350 with a population over 100k. Yet no one I know of leans on cities as models to emulate for cybersecurity governance or operations. We use that metaphor with our management to differentiate ourselves from commercial businesses who, ironically enough, make up the bulk of every city.</p><p>If our heterogeneity of function doesn&#8217;t differentiate us, what does? One obvious distinction is the role and scale of the student population. While online-forward schools such as ASU or the University of Phoenix may treat students as businesses treat &#8216;customers&#8217;, for more traditional four-year and community colleges, students represent both constant change (with a class entering and exiting every year) and a flexibility of roles. Many, if not most, traditional students are also employees at some point in their education. But does this represent a distinction with regards to our cyber posture? I think so - it requires us to allow unmanaged, non-enterprise systems to have access to enterprise administrative accounts. It brings tens of thousands of systems onto our &#8220;corporate&#8221; networks and with it, risks that need to be addressed.</p><p>But threat intelligence is primarily about the threat, not our risk surface. Is the profile of the threat surface attacking us truly different from what it is for any other business? Surely a great many attacks are what we can call opportunistic: launched broadly across broad swaths of network addresses, hoping to find a soft underbelly. I doubt those represent any sort of targeted attack unique to higher education. It is true that our research activities may be subject to targeted attacks, but outside of a handful of fields (e.g., quantum, biomedical, materials science), it is unclear whether these are driven by the intrinsic value of the IP itself or are better understood as part of sustained campaigns of capability-building aimed at advancing nation-state competitiveness.</p><p>My suspicion is that actionable threat intelligence, that is, actionable and valuable to our community, emerges not from examining either the threat profile of the attackers, or our internal risk surface, but rather <em>from the intersection of these two</em>. Our unique posture of vulnerability wrought by our federated administration, churning student population, the entrepreneurial nature of research, and our hands-off approach to securing it, creates a profile of successful attacks. My instinct and experience tell me it&#8217;s unlikely any one of us, even at the larger institutions, see enough data to fully form that profile. Commercial threat feeds remain valuable, but they fundamentally lack our context. Each of us is like a piece of a hologram that has been shattered. We see the full image but only at lowered resolution. Only by assembling the whole does the image sharpen up. </p><p>Ultimately, this is why I&#8217;ll continue to argue for higher education to act as a sector with regard to threat intelligence. Politically it positions us by demonstrating agency and maturity. Practically it may be the most effective response we can muster to the erosion of Federal sources of threat intelligence.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/open-question-no-8-the-federal-government?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/open-question-no-8-the-federal-government?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>But some problems require more than signal aggregation, others require a less observable surface. Thus, I want to return to the other dimension of protecting academic freedom that I promised to discuss above. Instead of the sovereignty of our sector, think of this as <em>individual sovereignty</em> - protecting the person. As I&#8217;ve written in other pieces about the primacy of privacy as a necessary condition for academic freedom<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>, I believe that it is increasingly unlikely that any digital manifestation of thought work is free from surveillance. This has taken on a new urgency to address with the openly hostile attacks on academics and academic institutions by the current administration and its allies. </p><p>Like a knot that tightens when you pull on it, schools cannot openly admit to trying to solve the problem of protecting academic freedom. To do so only makes the situation worse. There is no magic solution given the hostility of the government to open discourse and research that runs counter to a racist agenda, or that challenges skepticism around climate change or vaccine efficacy. Yet, as technologists there are steps that can be taken. </p><p>I&#8217;ve discussed two previously. First, the creation of fully protected and unmonitored networks for ideation and research - <a href="https://michaelcorn.substack.com/p/the-seclusion-of-our-own-minds#:~:text=Naturally%20the%20question">a network architecturally designed for anonymity</a>. Second, that we systemically revisit how library materials are searched and accessed to <a href="https://michaelcorn.substack.com/p/a-cartography-of-cybersecurity">ensure untraceability</a>. Neither of these are terribly difficult engineering problems, but they do require an institutional response. Neither is truly achievable without institutional adoption.</p><p>The third possibility - born of watching how targeted communities function under totalitarian and repressive regimes - is the availability of user-managed encryption tools. The most famous of these was PGP<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a> though no doubt better options exist these days. As someone who&#8217;s worked for a central organization my entire career, I always avoided recommending these user managed encryption tools. They have a sharp edge - without central access to the decryption keys, it&#8217;s just too easy for a well-intended faculty member to permanently lock themselves out of data or a system. That risk still exists, but I think the risk / reward balance has shifted. Imagine the world we&#8217;ve awoken in: simply stating &#8220;perhaps we should study the effect of racism on minorities&#8221; is sufficient to get you banned from Federal funding or fired from your job. Despite the expanding use of AI within scientific research, I wonder how many of our faculty question the risk they&#8217;re exposing themselves to by interacting on research topics with LLMs<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>.  This may be the modern manifestation of the &#8216;gaze of the observer&#8217; on modern research.</p><div><hr></div><p>When I started this series I had intended to focus this piece on how we, as an industry, could respond to the current political crisis. But it&#8217;s increasingly clear that we&#8217;re not organized for that fight. We write pleading whitepapers, we make elegant statements on the centrality of higher education and its research mission to the national health and competitiveness. But we operate on the assumptions that the norms of behavior and reason are still in effect, when they&#8217;re not. Slowly, it&#8217;s becoming clear that in one sense, all that we have assumed about the progression of society, science, and modern democracy, has been at the largess of a functioning government - something we utterly lack. Nothing prepared us, as one example, for a government capable of issuing <a href="https://www.whitehouse.gov/presidential-actions/2026/05/realigning-united-states-core-childhood-vaccine-recommendations-with-best-practices-from-peer-developed-countries/">mandates</a> to <em>reduce</em> the number of vaccinations children receive.</p><p>Thus, it seems we must look inwards, to actions we can take ourselves as individuals, institutions, and a community to protect the core of our mission. A final note. You may notice that on one hand I&#8217;m arguing for collective, sector-wide coordination in cyber threat intelligence, while on the other for individualized, decentralized safeguards in academic freedom. It&#8217;s worth asking why one problem is solved through aggregation and the other through fragmentation. I don&#8217;t think the answer is any surprise: one requires visibility, the other deniability - a shared signal versus personal protection. But that dichotomy struck me as I was finishing this post, and it&#8217;s probably one worth reflecting on as we continue to react to the changing world around us.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>By which I mean that with the SCOTUS embracing ideology over the rule of law, we&#8217;ve seen an emboldening of outrageous state laws that historically never would have been allowed to stand if evaluated by constitutional principles.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>As I was doing background reading for this post, I found the principles governing it much more mature and explicit than is usually considered. 1. Relevance to professional role (the &#8220;germaneness&#8221; standard): academic freedom protects teaching, research, and extramural speech, but it is generally bounded by expectations of disciplinary competence and relevance. 2. Institutional mission and operational constraints: universities retain the authority to define curricula, degree requirements, and program structures. Academic freedom does not typically override institutional decisions about <em>what</em> is taught or <em>how programs are organized</em>, even if it protects how faculty engage within those frameworks. 3. Legal limits (speech not fully protected): academic freedom operates within broader First Amendment (or equivalent) frameworks, meaning it does not protect, for example, unlawful conduct (e.g., harassment, discrimination, threats). 4. Professional ethics and peer accountability: academic freedom is traditionally paired with the expectation of scholarly integrity and methodological rigor. Fabrication, plagiarism, or persistent deviation from accepted standards of evidence can fall outside its protection. This last point strikes me as particularly salient (deviation from accepted standards of evidence) if scientific inquiry is to purge itself of the contamination of nonsense imposed on it, for example by the current administration. 5. Extramural speech and reputational considerations: the classic formulation (e.g., AAUP) is that faculty should be free from institutional censorship but also bear responsibility to be accurate, exercise restraint, and clarify they are not speaking for the institution. I did my best to summarize my reading on the topic here, please drop me a note or comment if you see a mistake. Much of this derives from AAUP sources.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Of course the most recent attack is being codified in this <a href="https://www.federalregister.gov/public-inspection/2026-10817/regulation-for-federal-financial-assistance">horrific piece of nonsense</a>. For an excellent summary see <a href="https://substack.com/inbox/post/199685587">Elizabeth Ginexi&#8217;s summary</a>. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Research University CIO Conclave.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>As I&#8217;ve suggested before, the RI seems structurally and systemically incapable of becoming a modern ISAC, weighed down by inertia and history.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>I&#8217;ve raised this in several pieces, but the argument is most fully developed in <a href="https://michaelcorn.substack.com/p/the-seclusion-of-our-own-minds">The seclusion of our own minds</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p><a href="https://en.wikipedia.org/wiki/Pretty_Good_Privacy">https://en.wikipedia.org/wiki/Pretty_Good_Privacy</a>. See also <a href="https://www.occrp.org/en/feature/encryption-a-godsend-to-all-who-seek-privacy-even-criminals">https://www.occrp.org/en/feature/encryption-a-godsend-to-all-who-seek-privacy-even-criminals</a>. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>Most academics view ChatGPT or Claude as private digital assistants. They completely forget that every prompt is a log stored on corporate servers, vulnerable to federal subpoenas, national security letters, or data breaches.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Shared control and cross-functional discomfort]]></title><description><![CDATA[Services not functions]]></description><link>https://michaelcorn.substack.com/p/shared-control-and-cross-functional</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/shared-control-and-cross-functional</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Tue, 19 May 2026 03:13:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BZJo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BZJo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BZJo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BZJo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BZJo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BZJo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BZJo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg" width="262" height="393" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2184,&quot;width&quot;:1456,&quot;resizeWidth&quot;:262,&quot;bytes&quot;:566699,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/198156985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BZJo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BZJo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BZJo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BZJo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76d6bdc6-d7ab-431a-8f4c-73212f73c4f9_3264x4896.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The path forward is beautiful and dark.</figcaption></figure></div><p>I&#8217;ve created a lot of strategic plans over the years and they&#8217;ve evolved quite a bit as my own experience and sophistication about &#8216;strategy&#8217; have grown<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. I&#8217;ve <a href="https://michaelcorn.substack.com/t/strategy">written a fair amount</a> on this blog about strategic planning as well. I&#8217;ve also talked quite a bit about the notion of <a href="https://michaelcorn.substack.com/t/trust">trust and collaboration</a>, developing trust with your community and collaborating with partners who have shared concerns. We have librarians and educational technology specialists, for example, who both create risk (by standing up new technologies and services) and try to mitigate it through policy and practice. In a healthy institution, these and other constituencies work together. But we still often stay focused on our swimlane - our service or our infrastructure - and we lose sight of the pool.  </p><p>Reflecting a bit more about the recent Canvas incident that <a href="https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think">I posted on last week</a>, however, got me thinking about the nature of strategic planning and its impact on resilience. In this post I want to ask the question of whether we need to think more broadly about strategic planning: to change the scope from &#8220;cybersecurity&#8221; to &#8220;institutional resilience&#8221; and if so, what that might mean for how we do strategic planning for information assurance. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>You see how I brought that broader term, information assurance, back into the discussion. Recall that I define information assurance as an umbrella term that encompasses several distinct yet highly interdependent areas of expertise. These <a href="https://michaelcorn.substack.com/p/open-question-no-7-cybersecurity#:~:text=2-,Information%20assurance,-is%20an%20umbrella">core domains</a> include cybersecurity, privacy, data protection and curation, risk management, and resilience. I do this because I think it&#8217;s an excellent gateway to thinking about an <em>organizational</em> strategic plan, and not merely a <em>cybersecurity</em> strategic plan. </p><p>Now some of my cybersecurity brethren may be saying &#8220;you dope, of course I worry about items like privacy and data protection, I see the scope of what I do as touching almost every aspect of the institution - as you <a href="https://michaelcorn.substack.com/p/open-question-no-7-cybersecurity#:~:text=discovered%20that%20the-,scope%20of%20cybersecurity,-(or%20more%20properly">yourself have argued</a>.&#8221; That&#8217;s wonderful if you&#8217;re doing that and I&#8217;ve seen many of my peers include these in their planning efforts. But let me ask the question a different way: if someone were to ask your privacy officer, your enterprise risk manager, your registrar or your librarians what role they play in institutional resilience, would they point to your strategic plan or to their own? And if the latter, what exactly is coordinating those plans when the system is under stress? If you framed the question using the term cybersecurity, they might at least acknowledge you. But in many organizations, regardless of goodwill and collegiality, everyone stays head down in their lane, just trying to remember to not bump into the edge of the pool with their head.</p><p>More to the point - while your senior executives no doubt expect the CISO to be on point for cybersecurity matters, and the CPO for privacy matters, given the entwined nature of digital systems and business functions (including research and instruction) who will they turn to for addressing mission continuity under degraded conditions? While I would want my facilities staff to be prepared to respond to a tornado destroying a building, and my cyber staff to respond to a ransomware attack, the reality is that everyone would be involved when classes are disrupted or health is put at risk<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. As many schools learned from the <a href="https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think">Canvas incident</a>, regardless of where a problem arises, a rapid and effective response requires marshaling a small army, not a unit. Similarly, proactively building the resilience to weather a storm requires that same army preparing in advance, far more than simply working out an incident response plan. You&#8217;re not looking for &#8220;incident response&#8221; but adaptive capacity across functions.</p><div><hr></div><p>Let me put this more bluntly: I&#8217;m proposing that a mature institution will take a digital equivalent of an &#8220;all hazards&#8221; approach to cyber risk and ensure that a singular organizational strategic plan is created that addresses the totality of information assurance. Creating such a plan involves more than simply including various stakeholders in each other&#8217;s plans - that&#8217;s what we euphemistically call &#8216;coordinating&#8217;. In practice coordinating means &#8220;develop your own plans but meet once in a while for input.&#8221; What most institutions call &#8220;coordination&#8221; is not integration, it&#8217;s parallel planning with occasional conversation. Each domain develops its own strategy, and we reassure ourselves that alignment exists because we meet periodically. It doesn&#8217;t.</p><p>An &#8220;all hazards&#8221; approach, taken seriously, requires something much more demanding: a single, integrated strategic plan that treats information assurance as a system, not a set of adjacent functions. This is not about inviting more stakeholders into the room; it is about abandoning the idea that cybersecurity, privacy, data governance, and resilience can be planned independently at all.</p><p>Such a plan must cut across the boundaries imposed by the org chart and instead organize around collective risk and continuity. Otherwise, we are not building resilience, but rather, we are coordinating silos.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/shared-control-and-cross-functional?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/shared-control-and-cross-functional?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>I can just see the eye rolls taking place as you read this. &#8220;You dope, strategic planning is already complex enough, now I need to throw it out and scope it even broader?!&#8221; Well, sort of. Naturally, there&#8217;s still a need to do functional planning, both tactical roadmaps and strategic plans. If you manage some function - library data curation services, online instruction and pedagogy, privacy, or security - then you need to establish goals and roadmaps that will guide your programs. But the institution will be weaker if it lacks a plan that acknowledges and addresses the <em>system</em> of information assurance. So what barriers and what opportunities are there for moving forward?</p><p>Some of the barriers are pretty obvious: leadership and budgets reflect org charts and different functions are intrinsically more expensive than others. Technology costs and market forces dictate that your 20-person security team is going to be more expensive than a 20-person library data curation team, or a 20-person educational technology team<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. Greater costs imply greater resources which lead to greater capabilities, and that changes the flavor of strategic planning pretty directly. We must acknowledge a harsh operational truth: money dictates and reflects political gravity on a campus.</p><p>I suspect this cost asymmetry can be somewhat mitigated by staying focused on the goals - the <em>what</em> you&#8217;re planning on doing - rather than the <em>how</em>. Perhaps your goal is to ensure instruction can continue despite a 24 hour disruption to internet or LMS access. The plan can then detail who has to prepare for that and point to activities in their work plans. Use the strategic plan to inform and guide your operational roadmap, but avoid turning it into one. This is the hardest part of every strategic plan.</p><p>But even more so than leadership and budgets, I think a bigger challenge is a lack of models for this sort of planning. The only place I&#8217;ve seen this tackled is the material produced by risk management offices - the canonical source for &#8220;all hazards&#8221; planning. But these don&#8217;t seem to be adopted, modified or not, into cyber risk management, especially in higher education<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. Cybersecurity plans are driven by IT infrastructure, data curation strategies are bound to the Library, and privacy initiatives are dictated by the cudgel of compliance<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>. Even institutional strategic plans often struggle to do more than offer motherhood and apple pie references that point to a siloed function&#8217;s subsidiary plan. </p><p>When I think of a strategic plan that addresses risk, I think the product is the process.  The lasting value comes from surfacing risk - that sunlight is the best disinfectant. An organizationally scoped strategic plan will illuminate for leadership that, for example, the risk from ransomware isn&#8217;t just a concern for your IT and cybersecurity teams. It&#8217;s an issue for procurement, for researchers and educators, regardless of where the ransomware lands. This is to say that the process of creating the plan brings transparency to the question of where risk is and how it&#8217;s mitigated.  I am arguing that this is at least as important as, if not even more important than the plan for action itself. It&#8217;s the acknowledgement of a problem necessary before recovery is possible.</p><p>The plan does matter though. An effective plan should drive the creation or refinement of your continuity of research and instruction planning efforts. It should help cut through the roadblocks of <a href="https://michaelcorn.substack.com/p/the-third-hut-central-vs-distributed#:~:text=human%20dimensions%20of%20control%2C%20ego%2C%20and%20status">control, ego, and status</a>. But let me say something about this head-on. I think part of why many of us struggle to achieve the kind of collaborative planning I&#8217;m suggesting is precisely because it requires not relinquishing control, but sharing it. Of course I can only speak for myself, but I know many of us frankly resent or at least dread sitting across a table with individuals we don&#8217;t truly respect as experts as they suggest changing how or what you should be doing. You&#8217;re the senior cybersecurity administrator, and you&#8217;re the one who will be held accountable when something goes wrong. I&#8217;ve seen this same issue and reluctance from privacy officers when the cybersecurity team treats a major PII exposure as merely another security incident. I&#8217;ve seen both teams actively hide events from the other.</p><p>You work hard to maintain and manage your span of control, and sitting down with others in cyber-adjacent fields can feel awkward. I&#8217;ve no doubt those in these adjacent domains are having the same thoughts. They may cede to your cybersecurity expertise, but would bristle at being told how to manage their instructional services (for example).  Rightfully so. What I recommend is that you use that tension as a barometer.  If the tension is too high, then either someone is wandering too far outside of their expertise or you&#8217;ve identified an area that needs examination. In either case this needs to be the dead fish put on the table - the unsaid conflict that everyone can smell but nobody wants to name. Ask yourself, what decisions and how governance will be impacted or be changed by exploring that issue. </p><p>Remember, you&#8217;re still going to want to have a cybersecurity strategic plan as the head of cybersecurity - but the <em>institution</em> needs that information assurance strategic plan. Institutions mis-model risk because they plan along org boundaries rather than system dependencies. As I&#8217;ll argue shortly, if you want to address asymmetric accountability you really have to go past those organizational boundaries.</p><p>There are a lot of opportunities in this approach. Fundamentally you want to move from planning for control within domains to planning for continuity across dependencies. You are reframing the unit of planning: from functions to services. Right now, plans are owned by functions (security, privacy, libraries, IT). The opportunity is to shift the unit of analysis to institutional services. This is not merely cosmetic in that it forces cross-functional dependency mapping and with it shared ownership of outcomes. A consequence of this is to make dependencies a first-class artifact. As we saw with Canvas, most institutions do not know what they&#8217;re dependent on. This means the real opportunity is to treat dependency mapping as a strategic deliverable, not a technical exercise.  Thus we are elevating continuity from IT recovery to mission continuity and can answer questions such as how degraded can instruction be and still function? What research activities are time-sensitive versus restartable? What administrative functions must remain real-time?</p><p>The institutional opportunity that may appeal to your leadership is that this sort of analysis can lead to rebalancing institutional investment based on exposure, not tradition. As we all know, inertia and momentum are the biggest challenges to institutional evolution. They&#8217;re part of what enables an underinvestment in research resilience, vendor risk, or identity.</p><p>Earlier I suggested using discomfort to inform decision making. This is not easy, but if successful you&#8217;re turning cross-functional friction into signal, not noise. We overlook these opportunities so often, as when we hear user complaints about security measures as resistance rather than feedback. Once you start looking for it, you find this tendency manifest in so many parts of IT - and I suspect the same is true in many units that support staff or students.</p><p>Ultimately, and perhaps most important, we want to create a shared risk narrative for leadership. Rather than receiving fragmented reports and metrics, the opportunity is to produce a coherent institutional risk narrative, where cybersecurity, privacy, vendor risk, and resilience are presented as one system. Where the trade-offs are explicit and the dependencies are visible. This is what enables actual governance, rather than episodic reaction.</p><div><hr></div><p>On a very practical note, I want to mention a final opportunity, that of mutual support. Presenting annual work plans that include activities involving other units - and for them to do the same - demonstrates two things to your leadership. First, every large organization suffers from operational friction wrought by redundancy and over siloization. Family squabbles so to speak. Addressing issues at the larger institutional scale is a sign of maturity and selflessness. It is always appreciated. Second, and more important in the long run, it reinforces to your executives that the risks each of you wrestle with are not limited to a functional unit. That all the elements of information assurance are risk centers that affect every corner of the institution. With this you are coaching the institution to think holistically, and realistically, about risk.</p><p>I&#8217;ve spoken a lot in this post about continuity - business, research, and instruction. The real challenge here is to lift your head from the water and realize the pool is the real focus of your attention; it&#8217;s not a race, nor languid training laps. I suspect of all the challenges I&#8217;ve outlined, it isn't a lack of templates or asymmetric budgets - it&#8217;s the discomfort of sharing control that stifles us. The maturity of a CISO or a CIO shouldn't be measured by the size of their span of control, but by their willingness to share it to protect the institution's mission.</p><p>The real constraint is not frameworks or budgets but the psychology of shared control and asymmetric accountability. Remember, shared control implies shared accountability and this produces better governance decisions under uncertainty.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I still do strategic planning, though now as a consultant. DM me if you&#8217;re interested in collaborating with me and the firm I work with. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Many people don&#8217;t realize that one of the most critical resources on most campuses are the subzero freezers full of biological samples: often irreplaceable and at tremendous risk when power is disrupted. The top three concerns are usually student health, animal health, and subzero freezers during an emergency.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>OK, stop ROTFL, I realize few edTech or data curation teams see this staffing level. Nor do anyone but the largest R1s have 20+ cybersecurity team members. But if you can&#8217;t have a conversation about salaries with your counterparts, just look at job postings. Cybersecurity positions simply pay 30-50% more.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>This strikes me as a ripe area for a community developed template. I&#8217;m imagining a NIST CSF type scorecard for information assurance that reflects an institutional posture, not merely cybersecurity.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>Please don&#8217;t everyone write me telling me how their plan doesn&#8217;t do this. I&#8217;m painting with a broad brush here.</p></div></div>]]></content:encoded></item><item><title><![CDATA[The lesson is not what you think]]></title><description><![CDATA[Instructure, business continuity, and enterprise IT]]></description><link>https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sun, 10 May 2026 04:22:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!i6Ox!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i6Ox!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i6Ox!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i6Ox!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i6Ox!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i6Ox!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i6Ox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg" width="190" height="231.23626373626374" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1772,&quot;width&quot;:1456,&quot;resizeWidth&quot;:190,&quot;bytes&quot;:109355,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/197050147?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i6Ox!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i6Ox!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i6Ox!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i6Ox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ab3c6b-3aa2-4383-98bd-807dc304420e_1925x2343.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>I had hoped to avoid saying anything about the Instructure ransomware event. It&#8217;s getting so much press at the moment, and honestly I haven&#8217;t reached out to any contacts to even try to find out what really happened. I&#8217;m assuming people smarter and more connected than I am are putting pen to paper and I&#8217;m sure some point soon we&#8217;ll learn the nitty gritty of what happened. Was this a serious case of sophisticated hacking? A self-inflicted wound? God help me if it turns out to be &#8220;some contractor&#8217;s laptop&#8221; or &#8220;a rogue developer&#8217;s unprotected account.&#8221; </p><p>I do, however, want to take a moment for a long overdue self-reference. In one of my first national publications, I think it was for the Chronicle, I referred to our campus provided services as &#8220;dinosauric&#8221;. Mysteriously the editor didn&#8217;t try to make me change it. This came to mind as I was reading <a href="https://www.theatlantic.com/ideas/2026/05/canvas-hack-campus-fragility/687115/?gift=3roZ_s1NCZzw7__fEF1ToeN2jlgDehuiRf6FeTg916w">a short Atlantic piece</a> on the Canvas incident from the perspective of a faculty member. While the article itself is a fun read, the real meat and potatoes are the comments. For me, the money shot is this comment (italics are mine).</p><blockquote><p>I taught at a college that used Canvasas's [<em>sic</em>] competitor Blackboard. It was so clunky, especially in grading and rubrics. For most of Blackboard's functions, <em>I set up a parallel system on Google Docs and through gmail.</em> That saved me tons of headaches. It also made it easy to deal with a courseware outage.</p></blockquote><p>On one hand, this can be seen as a testament to human ingenuity; on the other, it&#8217;s a sign of how dinosauric our enterprise systems can be. This workaround - or some flavor of it - will be all too familiar to anyone who&#8217;s worked in higher education, either academically or administratively<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. It&#8217;s also just as likely to reflect the rule of thumb that people would prefer to use the familiar rather than train themselves to use the unfamiliar. I wouldn&#8217;t at all be surprised if the parallel system described is far more labor intensive than the designed system it&#8217;s replacing. Human nature being what it is.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>Browsing the comments one sees a wide spectrum of beliefs on display: the attitudes range from smug &#8220;tech-skepticism&#8221; to pragmatic defense of progress, all tied together by a shared resentment toward clunky enterprise software. Some comments focus on the lack of agency students and faculty felt when the system went down. That &#8220;the system&#8221; is the law - without it only failure remains. Others point to the &#8220;management vs. learning&#8221; divide, convinced that a learning management system (essentially an administrative front end to a course) has been forced on them as a proxy for the good old days of faculty to student connection<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. </p><p>A few comments go down the path of inevitability and incentives. Since institutions are stuck with these terrible systems, providers have little incentive to improve them. My own take is that while this may be broadly true in a monopoly context, I think the real challenge is deeper than this. And of course, a common thread through many of the comments is pragmatism vs. nostalgia.  Many long for the past of small to modest classes, classrooms with little technology, and only the strength of faculty personality animating teaching.  Others recognize that while these modern systems are flawed, they&#8217;ve permitted the delivery of courses to millions who would otherwise be unable to attend college.</p><p>There are a number of takeaways from this incident and the comments to the Atlantic piece. First, I think it&#8217;s a beautiful encapsulation of how enterprise IT is viewed by faculty, who are the very engine of the institution. Granted, this isn&#8217;t comprehensive data captured by rigorous surveys, interviews, or analysis. It&#8217;s a modest number of Atlantic readers who bothered to post a comment. But it does sound and <em>feel</em> awfully familiar to someone who&#8217;s spent their career in academia.</p><p>Nor is it clear that a great solution exists. Every school wrestles with these hopeless and hopelessly expensive systems - ERP and educational - and none of them are really any good. The delta between tech as experienced IRL and at work just keeps burning user goodwill, despite the obvious improvements these systems have made over the years. I can bank, plan a trip, buy tickets, book hotels, order food, and date with my thumb, but filing an expense report or checking the results of an exam tests anyone&#8217;s patience.</p><p>In a previous role, the CIO had promised the senior administration that a new ERP would be better and cheaper than sliced bread. Since they trusted me, I was quietly invited for a conversation about the matter. I told them the truth: the new system would be hated, more difficult for staff than the finely honed existing system, but that this would lead to a workforce refresh as the older staff retired and were replaced. It would cost 2-4x what they were told - but, the market simply didn&#8217;t offer many alternatives. Just different flavors of &#8216;meh&#8217;. I also said it was necessary since the old system was rapidly becoming unsupportable. In the market of higher ed ERPs, we weren't buying a solution; we were buying a decade of slightly more modern debt. I suspect this paragraph is as true now, and in the future, as it was then.</p><p>So you can see that enterprise IT shops are between a rock and a hard place. This is truly the deeper challenge I alluded to earlier. No one is going to hand you the tens or hundreds of millions it costs for these systems with that as the system pr&#233;cis. Be that as it may, it&#8217;s essential that IT providers understand how their offerings are viewed and give a damn about it. Woven throughout the comments are a number of ideas that simply aren&#8217;t true and should be subject to a deliberate and sustained effort to correct. The beliefs and attitudes <em>are</em> the lived experience of the faculty and cannot be dismissed - but the narratives shaping them can be changed. I recognize that many in IT will see only the na&#239;vete in the comments. But I would argue that to do so is to ignore a valuable source of feedback from an essential community.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/the-lesson-is-not-what-you-think?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>The next takeaway brings us back to the incident itself, or more precisely, our dependency on providers who inevitably will suffer incidents. Everyone is treating this as a security event, when the lesson to learn here is one of business continuity. In an <a href="https://michaelcorn.substack.com/p/traceable-wisdom">earlier piece</a>, I talked about how we should interrogate our governance bodies to lead them to express assumptions and risk tolerances - to operate at the wisdom layer of governance. In response to this event, I would hope schools are asking questions like <em>what are we structurally blind to?</em> <em>What does this say about our procurement model?</em>  W<em>hat risk posture are we choosing?</em> </p><p>Obviously, for the first, many institutions were blind to their total dependence on Canvas. Where else does that dependency lie? As to our procurement model, it is the persistence of these tools despite near universal hatred that needs questioning. In terms of our risk posture, are we trading resilience for the convenience of centralized &#8220;management&#8221;?</p><div><hr></div><p>It&#8217;s simply too easy to tsk tsk at Instructure. While it may yet prove that they deserve some scorn, I would hope institutions use this to look at their own reflection in the mirror of this event.  Outages don&#8217;t create failure - they reveal where the real system already exists. Institutions should recognize that risk posture is an emergent property of procurement and dependency choices seemingly unrelated to cybersecurity. We have co-authored the chaos we now are experiencing.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I also wonder if institutional fragility is being masked by user ingenuity - and what precisely is the scope of that issue?</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Over the years I&#8217;ve taught plenty of courses with hundreds of students - I would have loved a management tool to help with the logistics of those.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Traceable wisdom]]></title><description><![CDATA[Governance and metrics]]></description><link>https://michaelcorn.substack.com/p/traceable-wisdom</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/traceable-wisdom</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Mon, 04 May 2026 03:12:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GySk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GySk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GySk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GySk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GySk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GySk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GySk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg" width="196" height="294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2184,&quot;width&quot;:1456,&quot;resizeWidth&quot;:196,&quot;bytes&quot;:206116,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/196231148?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GySk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GySk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GySk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GySk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9c7c101-48b4-4e24-8abb-99266817894e_3264x4896.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">We love to measure.</figcaption></figure></div><p>My relationship with metrics has been persistent but strained - no doubt something I share with most security and privacy officers. Like a marriage, it begins in the brightness of activity, but with time it deepens, until the true weight settles below the surface. I suspect that almost everyone - not merely security professionals - at some point uses &#8216;activities we can count&#8217; as a metric to demonstrate their contribution. Who hasn&#8217;t shown charts of attacks detected and blocked by an intrusion prevention system to their leadership? What help desk manager hasn&#8217;t counted tickets handled to demonstrate their workload and efficiency? Which privacy officer hasn&#8217;t shown a count of individuals put through privacy training as a proxy for impact?</p><p>At times these sorts of metrics serve a purpose. Showing your institutional leadership that your network experiences 100k attacks and probes an hour ratchets up their tension - a tension you&#8217;re there to reduce. Demonstrating that your help desk ticket growth is 2x per year helps make the case for better tooling or additional staff. But fundamentally these are mere measures of activity, none of which demonstrate a lowering of risk or an improvement in the quality of service (or customer satisfaction). We count these things because we can; we present those counts because we have them, and they demonstrate that we are busy. We revel in them because we are acting as managers, managers concerned with maximizing the use of the resources we&#8217;ve been competing for.</p><p>But these are not the sort of metrics that we should present to governance - they&#8217;re neither strategic nor useful for informing strategic decisions. The body of this post is to look at metrics as a Socratic tool for governance. We need to move from viewing governance as a passive approval queue or administrative checkpoint toward an active, inquiry-based method of strategic leadership. Thoughtfully developed metrics can assist in making this shift happen<strong>.</strong> By this I mean using probing questions to transform technical data into contextual intelligence that guides institutional risk decisions. Essentially, in most boardrooms, metrics are used to <em>end</em> a conversation; instead, I am going to argue that metrics should <em>start</em> a conversation: from &#8220;look, we're doing fine&#8221; to &#8220;the numbers look fine, but what is the story they aren't telling us?&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>I want to start by acknowledging that the space of cybersecurity metrics is multi-dimensional. This isn&#8217;t just an issue of bringing nuance to any discussion of metrics but rather it&#8217;s that metrics themselves serve different purposes in different dimensions. For example, one of the first questions a leader typically asks about cybersecurity is whether their investment - the security budget - is appropriate and adequate. However, in practice this is usually appended with &#8220;compared to our peers.&#8221; This is a classic form of reductionist framing whereby all of the distinguishing characteristics of an institution are reduced to &#8220;peer,&#8221; and on this the comparison rests. &#8220;But XXXX is a similar sized school and their security budget is only 80% of ours&#8221; hinting that we can do with less. I&#8217;ve heard this dozens of times, though no one ever points out the reverse. </p><p>Answering this properly requires examining the risk landscape, the risks mitigated and unaddressed, and working backwards to the investment required. But that&#8217;s a complicated exercise. I&#8217;ve long been a fan of going ultra-reductionist when performing quick and dirty institutional comparisons. These are simple measures both technical (e.g., security budget per active network IP address) and non-technical (e.g., security budget as a percentage of research expenditures) that can be counted consistently across institutions<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>A second dimension has to do with the oversight role of governance. Every governance body can appropriately ask &#8220;where are you in establishing the program you&#8217;ve described and that we&#8217;ve funded?&#8221; While this may not be truly strategic, it inevitably suggests that metrics on program completion have to be part of any metrics portfolio. The challenge here is to couple these metrics to outcomes and risk reduction. Of course, this means that as you build your proposed program, each element of it is justified, not as &#8216;best practice&#8217;, but is explicitly qualified as a form of risk reduction. They should be framed as mitigations for institutional risks that executives already prioritize. But even here we have an opportunity to begin training our governance committees. </p><p>If we limit ourselves to stating &#8220;we&#8217;re only 70% of the way done&#8221; - there&#8217;s little conversation to be had. Essentially even in the case of program completion your metrics should not just reflect outcomes, but expose the assumptions linking activity to outcome to risk. For example, instead of &#8220;% of program complete,&#8221; ask &#8220;what risk remains if this program is only 70% complete - and what assumptions are we making about the missing 30%?&#8221; I like this approach because in it is found some flexibility. Too often a program statement becomes a scorecard your auditors or management uses to box you in. By questioning and surfacing the assumptions underlying the unmet risk you may find the freedom to pivot your remaining resources to more effective efforts.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/traceable-wisdom?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/traceable-wisdom?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>This leads us to the third dimension I&#8217;d like to discuss: that &#8220;smart leadership expresses their &#8216;focus&#8217; through asking questions.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> In the context of working with a governing body, this could be as simple as<strong> </strong>interrogating incentives. For example, probing why certain risks are accepted, such as why an institution might sign a contract that caps a vendor&#8217;s liability far below potential breach costs. What you are hoping for is to start a conversation about risk - a conversation that creates traceable wisdom. Once metrics expose assumptions, someone must interrogate them, and that &#8220;someone&#8221; is governance, hence my focus on inquiry-based leadership. By traceable wisdom, I am referring to the ability of an organization to reconstruct the logic, context, and ethical reasoning behind a past decision, long after the original decision-makers have moved on. It&#8217;s the difference between seeing a firewall rule (the <em>what</em>) and understanding the specific threat or business trade-off that created it (the <em>why</em>).</p><p>In my earlier post on Radical Reciprocity, I introduced the notion of a <a href="https://michaelcorn.substack.com/p/radical-reciprocity#:~:text=It%20introduces%20the%20%E2%80%9C-,Socratic,-%E2%80%9D%20pause%20into%20engineering">&#8220;Socratic&#8221; pause</a>, as a moment where in both engineering and policy development the organization can step back and ask questions about prioritizing proportionality, privacy, and long-term autonomy over expediency. This strikes me as necessary if we are to truly stop treating security and privacy as supplemental, but rather embed them into the organizational culture. </p><p>Increasingly, I am seeing organizational governance as nothing more than a kind of living policy process. One in which big-P policy decisions are made as a kind of &#8220;Just in Time&#8221; policy.  This suggests that for this third dimension of metrics, we don&#8217;t need metrics that are answers (e.g., budget benchmarks or completion rates), but want metrics that are prompts (e.g., risk justification, residual exposure, and assumption testing). Essentially, each dimension of cybersecurity decision-making requires not just different metrics, but different kinds of questions those metrics are meant to provoke.</p><p>You may notice that I&#8217;ve used a little sleight-of-hand by redefining the term &#8216;metric&#8217;. What I&#8217;m doing is overloading the term, moving it from a measurement artifact to a decision instrument. In dimension one - let&#8217;s call it the survival layer - metrics are precisely what we&#8217;re used to thinking of them. They are counts of things, measurement artifacts, used as tools to satisfy the board&#8217;s hunger for benchmarks without losing your soul. For dimension two - the execution layer - we begin the redefinition. Here we pivot from a simple metric, in this example, percentage of program completion, to using it as a springboard for conversation on the implications, assumptions, and meaning of what&#8217;s unfinished. Thus a decision instrument.</p><p>In the third layer, what might be called the wisdom layer of inquiry based leadership, we transition the governing board from being a &#8220;passive approval queue&#8221; to a &#8220;living policy process.&#8221; With each layer, traceability becomes more important. Traceable wisdom strives for logic over legacy. It replaces &#8220;this is how we&#8217;ve always done it&#8221; with &#8220;this is the specific risk we identified in 2024 and why we chose this specific mitigation.&#8221; It creates contextual accountability by acknowledging that decisions are made with <a href="https://michaelcorn.substack.com/p/epistemic-humility">imperfect information</a>. By documenting the <em>context</em> of a choice, you allow future leaders to improve upon it rather than just resenting a seemingly &#8220;bad&#8221; old rule. And critically, traceable wisdom forces the organization to take a longitudinal view of cybersecurity. Wisdom is &#8220;traceable&#8221; when the organization&#8217;s collective intelligence grows over time because its failures and successes are recorded in a way that provides a roadmap for successors.</p><div><hr></div><p>By framing the wisdom layer this way, you are teaching the board that their job isn't to hold the CISO accountable for the <em>numbers</em> - it&#8217;s to hold themselves accountable for the reality those numbers reveal. Let&#8217;s try on a few examples. One of the most common metrics CISOs are asked about is the percentage of known unpatched vulnerabilities. I like this example because it works at multiple layers.</p><ul><li><p>Survival (managerial)<strong>:</strong> Count of patches applied. (Are we working?)</p></li><li><p>Execution (managerial moving to strategic)<strong>:</strong> % of critical vulnerabilities addressed + explicit assumptions about exploitability and reachability. (Are we working on the right things?)</p></li></ul><p>But if we want to operate at the wisdom level of governance, we need to pivot this question entirely: What classes of vulnerabilities persist and why? What does this say about our organizational, development, or procurement model?</p><p>Instead of asking how fast we can bail water, this layer asks why the boat is made of porous material. It forces the board to look at the &#8220;technical debt&#8221; of procuring cheap, unpatchable software. More appropriate for higher education, it begs the question of how our technical resources are organized as well as the cultural barriers that prevent patching. What this surfaces is that the wisdom-layer metrics force <em>non-security decisions</em> into scope. They expose that cybersecurity outcomes are often downstream of procurement tradeoffs, decentralization, funding models, and academic autonomy, all of which are the real roadblocks to an effective vulnerability management program<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><p>For a second example, let&#8217;s return to the question of a security budget. This question is arguably the most important because it addresses the financial soul of the institution. In the wisdom layer, you are moving away from &#8220;spending money&#8221; toward &#8220;investing in a worldview.&#8221;</p><ul><li><p>Survival (external benchmarking): &#8220;We spend 5% of IT on security, which is the peer average.&#8221; (The goal is to not look like an outlier).</p></li><li><p>Execution (internal proportionality):<strong> </strong>&#8220;We spend $X per active IP or 0.5% of research expenditures.&#8221; (The goal is to prove the spend is mathematically tied to the attack surface).</p></li></ul><p>Instead of looking at the total dollar amount, the wisdom layer looks at the asymmetry of the spend. In essence, we are asking &#8220;if our institutional mission is high-performance research, why is 90% of our security budget spent on administrative compliance and only 10% on protecting the research intellectual property that defines our reputation?&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> This forces the board to realize that &#8220;adequate funding&#8221; isn&#8217;t a single number; it&#8217;s a series of trade-offs. If they choose to under-invest in research security to save money, that is a traceable decision that defines their risk posture and gives you concrete guidance that shapes your program.</p><p>In practice, it can be challenging to take a committee or board that&#8217;s fixated on a specific use-case (EDR as too intrusive) or incident (PII exposure) to the question of proportionality. I&#8217;ve found it very productive to work with one or two members of a governance committee - typically faculty - to seed such a question for you. You, as the CISO or manager, know the answer to the question already: momentum and previous commitments. You sit in central IT and on most campuses it is an administrative engine. They enroll students and cut paychecks. Everything else is an elaboration. But your governance committees or boards must take a broader view of the institution. By operating at the wisdom layer, you force the institution to articulate its values and ensure that cybersecurity is treated as an embedded value in the institutional mission rather than a discrete, isolated IT function.</p><div><hr></div><p>I began by talking about metrics - those classical things we can count. The problem was never that we lacked metrics. It&#8217;s that we used them to avoid judgment rather than demand it. Metrics are not measures of activity, nor even indicators of performance&#8212;they are instruments for making institutional values visible and accountable over time. An institution&#8217;s cybersecurity posture is simply the accumulated record of the risks it chose to accept - and whether it can explain them. If governance refuses to operate at the wisdom layer, then cybersecurity will remain a theater of activity metrics and deferred responsibility.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Obviously these two examples are merely illustrative and not complete. Of course, even something as simple as determining the size of the security budget can be challenging. Often some security functions will be handled outside of security, and some commonly handled outside of security may be handled in-house. At one position I held, the network firewalls and IPSs were largely managed by the networking team. At another, the security team handled all user interactions for ordinary security tickets while at others this is managed by the help desk. We need a canonical definition of what functions get folded into the budget for comparison purposes.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I wrote this in the context of <a href="https://michaelcorn.substack.com/p/open-question-no-2-cybersecurity#:~:text=always%20believed%20that-,smart%20leadership,-expresses%20his%20or">individual leadership</a>. But I think it remains valid, perhaps more so, when working with governing bodies. To be sure, you can&#8217;t simply walk into your first governance meeting as a CISO or CPO and assume a interrogative condescending posture. You&#8217;ll need to frame this and earn some cachet first.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Naturally this will also force you to be prepared to quantify why some percentage of unpatched systems presents a risk worth mitigating to the institution. It&#8217;s not enough to say &#8220;but we&#8217;ll be hacked!&#8221;</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>It also requires you to answer a question such as &#8220;what security architectures are most effective for our specific distributed research environment?&#8221; which you may not have had to do previously.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Radical reciprocity]]></title><description><![CDATA[Notes toward a body of cybersecurity norms]]></description><link>https://michaelcorn.substack.com/p/radical-reciprocity</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/radical-reciprocity</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sun, 26 Apr 2026 04:27:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!z-Yr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z-Yr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z-Yr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!z-Yr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!z-Yr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!z-Yr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z-Yr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg" width="428" height="285.43131868131866" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:428,&quot;bytes&quot;:1473648,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/194534480?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z-Yr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!z-Yr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!z-Yr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!z-Yr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d9e56a3-e514-4992-8906-40fe6075861a_4896x3264.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In several posts<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, I&#8217;ve discussed the role of norms in cybersecurity. I defined the term &#8216;norm&#8217; as: &#8220;a shared expectation about appropriate behavior within a community, sustained not primarily through formal enforcement, but through mutual recognition, reputation, and the prospect of inclusion or exclusion.&#8221; The more I reflect on the concept of a norm, the more I find this a fascinating concept that can be used to explore both the practitioner and societal dimensions of cybersecurity practice. </p><p>Originally, I sat down to write about international norms, and to look for parallels between cybersecurity and norms surrounding traditional war, biological weapons, and arms control. But as a community - the community of readers of this blog - our ability to influence international norms is quite limited. Compounding this is the reality that cyberweapons (and I&#8217;m including both stuxnet and ransomware in this category) are already so widely used it&#8217;s not clear to me what sort of event might change that trajectory. A random piece of malware that inadvertently vents radioactive gas from a plant into a nearby town? A children&#8217;s hospital having all its power and hvac disabled by an attack meant for a military facility? So far cyber attacks lack the visceral impact of <a href="https://en.wikipedia.org/wiki/Chemical_weapons_in_World_War_I">mustard gas in trenches</a>. So I want to think about this a bit more. Instead, in this post I will tackle the notion of cybersecurity norms on a more familiar scale.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>If our ability to effect change on international norms is low (which, tbf, is probably an overestimate) then perhaps it is worth considering norms within our own sphere of influence. I believe there is immense value in codifying a body of norms, even if they lack a formal enforcement mechanism or any hard consequences for violating them.  Most people think &#8220;if you can&#8217;t enforce it, it doesn&#8217;t matter.&#8221; I am arguing for the opposite: <em>the act of codification is a performance of maturity</em><strong>. </strong>It is itself a form of institutional signaling: it clarifies expectations, creates a shared vocabulary for action, and makes deviations legible. Even without enforcement, norms shape behavior by making it observable and comparable. As I&#8217;ve stated many times, any time we act as a community on issues of extra-community significance, we demonstrate to the broader society that we have our act together. Sometimes even a gesture is recognized for its value and initiates a general conversation.</p><div><hr></div><p>I suspect this is a topic that would benefit from examining a couple of use cases and extracting archetypes from them, rather than starting from abstract principles. So let&#8217;s start with an obvious one: ransomware in medical centers or hospitals. While I&#8217;ve been close enough to this to see that professional to professional communications do take place - despite our counsel&#8217;s reluctance - it&#8217;s very ad hoc. What and when you learn of any details about an incident depends on individual personalities, connections, and inclinations as well as the institutional fear of liability. Similarly, the prevalence of ransom payments is opaque, though widely believed to be high<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. Given the immediate impact on patient care and thus actual patient survival, it&#8217;s easy to see how these institutions come to the conclusion that paying, no matter how distasteful, is prudent<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. </p><p>What is it we would like this community (the academic medical center or hospital) to do in these situations? What should be normal behavior? My immediate list would be:</p><ul><li><p>Refusal to pay ransom</p></li><li><p>Sharing attack information within the community as soon as possible, faster than is comfortable.</p></li><li><p>Radical transparency (within bounds)<br>Share <em>actionable</em> details quickly: TTPs, indicators of compromise, initial access vectors, and control failures. Redact only what would materially aid attackers or violate law. The norm is &#8220;useful over polished.&#8221;</p></li><li><p>Minimum viable continuity for peers<br>Share temporary mitigations peers can deploy immediately (e.g., block rules, config changes), even before your full fix is ready.</p></li><li><p>Reciprocity<br>If you benefit from others&#8217; disclosures, you have an obligation to contribute back when it&#8217;s your turn. Make that explicit.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/radical-reciprocity?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/radical-reciprocity?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>Incident driven norms will probably converge regardless of the nature of the incident. So for a second example, let&#8217;s instead ask: how do we operate when nothing is on fire?  Here I imagine we begin to describe many of the operational principles for an organization&#8217;s security team. For readability, I&#8217;m paring this down to a minimal operating set - a fuller listing of operating norms is in a footnote<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. </p><ul><li><p>Norm of restraint<br>Just because you can deploy a capability (especially AI-driven) doesn&#8217;t mean you should.</p></li></ul><p>Now we translate principles into day-to-day engineering and operations.</p><ul><li><p>Usability is a security requirement<br>Controls must be workable; persistent bypasses signal design failure.</p></li></ul><p>I&#8217;ve been struck, when joining a new organization as CISO, how few management decisions are truly documented or codified. So we need to ensure decisions are rational, traceable, and improvable.</p><ul><li><p>Institutional memory<br>Preserve decisions, exceptions, and lessons so they survive turnover.</p></li></ul><p>No set of norms would be complete without addressing risk and its relationship to governance. Risk must be visible, owned, and fairly distributed.</p><ul><li><p>No silent risk transfer<br>Risks pushed to others must be explicit and accepted: this must include users.</p></li></ul><p>Finally, and critically for this discussion, we should extend norms beyond the organization.</p><ul><li><p>Ethical use of security capabilities<br>Apply proportionality and respect for privacy, autonomy, and context.</p></li><li><p>Responsible disclosure as a civic duty<br>Enable and participate in coordinated vulnerability disclosure.</p></li><li><p>Reciprocity and community contribution<br>Share insights and artifacts; treat security as a collective defense problem.</p></li></ul><p>At this point, let&#8217;s see if we can identify a modest number of core principles, i.e., operating norms, that combine the two examples above. After spending far too much time building tables and taxonomies in a spreadsheet, I&#8217;ve identified five.</p><p>If we merge the notions of sharing information, reciprocity, and community contribution, we identify collective defense as a norm. Let&#8217;s call it <em>the norm of radical reciprocity</em>. It establishes that if you consume the community&#8217;s safety, you are obligated to produce it. The standard is &#8220;useful over polished.&#8221; It implies that security is not a competitive advantage, but a shared necessity.</p><p>Similarly, if we combine the idea of minimum viable continuity and sharing temporary mitigations, we shift the focus from &#8220;we are safe&#8221; to &#8220;we are helping you be safe,&#8221; even before the incident is contained. It is the rejection of the silo mentality during an incident. This strikes me as a kind of operational empathy, which I&#8217;ll call <em>the norm of active continuity</em>. Fundamentally, your defense should be designed to help your peers survive, not just you.</p><p>I think a key overlooked element is the human-centric dimension of security. If a control is unusable or invisible, it is a failure, not a feature<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>. Here I&#8217;m trying to combine usability as a requirement and no silent risk transfer. Sticking with my naming convention, I&#8217;ll call this <em>the norm of design integrity</em>. It demands that security decisions be explicit and workable for the human beings at the end of the wire. It forbids the transfer of risk to users or peers without their informed consent.</p><p>I think one of the more difficult dimensions to capture is what I&#8217;m going to call <em>the norm of capability restraint</em>. I&#8217;m trying to find a space to acknowledge the existence of a kind of ethical friction in the deployment and use of technology. Just because a tool exists doesn&#8217;t mean it should be used. I think this synthesizes the concept of restraint and the ethical use of capabilities. It introduces the &#8220;Socratic&#8221; pause into engineering - prioritizing proportionality, privacy, and long-term autonomy over the &#8220;<a href="https://michaelcorn.substack.com/p/thought-work-and-ai#:~:text=easily%20passes%20the-,Turing,-test%20is%20seductive">Turing test parlor tricks</a>&#8221; of immediate efficiency.</p><p>Finally, I want to combine the idea of institutional memory with rational/traceable decisions. This gives us a norm of governance. It ensures that the "why" behind a security posture survives the turnover of the people who built it. It treats cybersecurity as a longitudinal practice, not a series of disconnected reactions. Perhaps <em>the norm of institutional accountability</em> - though I&#8217;m not fully comfortable with the term &#8216;accountability&#8217;, which carries too much baggage of &#8216;who to blame&#8217;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>. But ultimately, a decision that isn&#8217;t documented didn&#8217;t happen.</p><p>These aren&#8217;t controls; they&#8217;re commitments. And commitments, unlike controls, are visible to others.</p><div><hr></div><p>Assembling these into an inter-institutional agreement would be challenging. Even as I write this, I can imagine other ways to frame cybersecurity norms. The five norms reflect my own experience - less as a technical problem than as one of communication and organizational politics within a shared community. In that sense, defining cybersecurity norms becomes a kind of civic problem, shaped by the same social and psychological forces that govern any community.</p><p>Any norm in a higher education cybersecurity compact would require careful interpretation, with examples to clarify and guide its application and interpretation. Institutional counsel and insurers would inevitably weigh in - and while that may seem daunting, it is a sign that the norms are being taken seriously. The difficulty of formalizing them is not a weakness; it&#8217;s evidence that they matter.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Specifically in comparison to <a href="https://michaelcorn.substack.com/p/what-can-cybersecurity-learn-from">biosafety</a> and <a href="https://michaelcorn.substack.com/p/the-market-driven-decomposition-of">market shaping</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>See <a href="https://24x7mag.com/standards/safety/cybersecurity/78-of-healthcare-organizations-paid-over-500k-in-ransomware/">https://24x7mag.com/standards/safety/cybersecurity/78-of-healthcare-organizations-paid-over-500k-in-ransomware/</a>. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>The cynical reader might suggest this has as much to do with the cost of downtime for a hospital, which can run into millions of dollars per day. I&#8217;d suggest the liability potential from patients dying eclipses those costs by several orders of magnitude.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>As I was developing my list of operating norms, I found the list growing exponentially in length. None of these should be surprising, but as I reflected on the list, I grew to like it too much to toss. So the entire set is included here. </p><ol><li><p>Secure-by-design, not secure-by-add-on<br>Security is a design constraint; threat modeling and abuse cases are standard.</p></li><li><p>Data stewardship and purpose limitation<br>Minimize collection and retention; define ownership and lifecycle from the outset.</p></li><li><p>Default to least privilege and minimal exposure<br>Access is scarce and time-bound; external exposure must be justified.</p></li><li><p>Norm of restraint<br>Just because you can deploy a capability (especially AI-driven) doesn&#8217;t mean you should.</p></li><li><p>Usability is a security requirement<br>Controls must be workable; persistent bypasses signal design failure.</p></li><li><p>Security as a shared function, not a gate<br>Embed security into engineering and business processes; enable rather than block.</p></li><li><p>Continuous verification (assume drift)<br>Controls degrade; continuously validate configurations, assets, and assumptions.</p></li><li><p>Preparedness as a routine discipline<br>Exercises, recovery tests, and dependency mapping are ongoing - not reactive. We should all own a <a href="https://netflix.github.io/chaosmonkey/">Chaos Monkey</a>.</p></li><li><p>Evidence over intuition<br>Decisions require articulated rationale and context - not just &#8220;best practice.&#8221;</p></li><li><p>Metrics that reflect reality<br>Measure outcomes and risk reduction, not activity.</p></li><li><p>Institutional memory<br>Preserve decisions, exceptions, and lessons so they survive turnover.</p></li><li><p>No silent risk transfer<br>Risks pushed to others must be explicit and accepted.</p></li><li><p>Vendor and supply chain accountability<br>Treat third-party risk as first-order; require transparency and resilience.</p></li><li><p>Transparency about capability and limits<br>Be honest about what you can detect/prevent; avoid security theater.</p></li><li><p>Leadership accountability<br>Executive ownership of cyber risk and explicit trade-off decisions.</p></li><li><p>Ethical use of security capabilities<br>Apply proportionality and respect for privacy, autonomy, and context.</p></li><li><p>Responsible disclosure as a civic duty<br>Enable and participate in coordinated vulnerability disclosure.</p></li><li><p>Reciprocity and community contribution<br>Share insights and artifacts; treat security as a collective defense problem.</p></li></ol></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>I&#8217;m really on the fence about invisibility. Sometimes I think security should be invisible, but sometimes I think I should be taller. Neither is likely.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Perhaps the norm of institutional continuity or the norm of traceable wisdom? Talk about rabbit holes.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Thought work and AI]]></title><description><![CDATA[Questions of cognitive architecture]]></description><link>https://michaelcorn.substack.com/p/thought-work-and-ai</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/thought-work-and-ai</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Mon, 20 Apr 2026 05:57:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Tbqy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tbqy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tbqy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Tbqy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Tbqy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Tbqy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tbqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg" width="304" height="228" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:304,&quot;bytes&quot;:209270,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/194705165?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tbqy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Tbqy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Tbqy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Tbqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa577c5bd-bec7-4ec8-9a85-4ee4e9ed3cf0_4000x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>One of the enduring tensions in higher education has to do with its role. Is education about transmitting knowledge or is it about teaching how to engage in critical thought? The public sees this as a non-issue: higher ed is where you learn stuff and get a degree, a certificate entitling you to a job. But for those of us enmeshed in the mission, it&#8217;s not so clear-cut. For many of us, the noble goals of higher education <em>are</em> the calling.</p><p>Of course this is a false dichotomy; both learning and critical thought are elements of what any college or university is trying to achieve<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. While schools do deliberately try to teach logic, analysis, and critical thinking skills, in practice this is often left to the student to be gleaned from examples. We study the development (and mechanics) of an idea and hopefully learn about how an advancement was conceived, approached, and ultimately resolved. Whether we are studying a piece of music or special relativity, the underlying ways of thinking are often more implicit than explicit in our education.</p><p>I began to think about this in light of the public discourse on AI. I&#8217;m struck by the framing of AI as a replacement for human activity rather than as a tool to enhance human thought. I suppose this isn&#8217;t surprising given the current historical moment of late-stage capitalism and that modern AI is predominantly an artifact of the massive tech firms. Yet it is an unimaginably expensive product without any clear function or ROI;  as such it requires a messianic sales pitch to attract investors. And if there&#8217;s one element of production that seems intractable to optimization, it&#8217;s people - and thus they become the target. But to replace people requires the devaluation of thinking. Which is so neatly tied into that sales pitch: it promises to automate the <em>result</em> (knowledge/output) while ignoring the <em>process</em> (thinking). As <a href="https://michaelcorn.substack.com/p/ai-part-i-listening-to-my-robot-overlord">I&#8217;ve argued before</a>, this only continues to erode respect for thought work - perhaps even pathologizing it as costly and unnecessary.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p> Imagine if AI were treated less as &#8216;something to be trained to replace our activities&#8217; and more as &#8216;something to synergistically enhance our thinking&#8217;? That is, AI as a tool for augmenting critical thinking rather than replacing cognition. Is this even possible? How can an AI agent support and enhance our own critical thinking, without simply offering up alternative narratives or prose?</p><p>Thus my opening about the role of higher education: is it primarily about transmitting knowledge, or about teaching students how to think? My position on this surely reflects my own point in life - I&#8217;m not in school trying to learn enough to launch a career. So I view this question from a position of privilege. And clearly you want your accountant / doctor / historian / engineer to actually know things. Knowledge is important. Be that as it may, my own experience - especially in graduate school - was not primarily about absorbing knowledge for a career. I studied music history yet ended up working in tech. No factoid from music history has ever come into play as a cybersecurity practitioner. While the factoids were useless, the <em>disciplines</em> of music history (e.g., pattern recognition, writing, analyzing structural tension, understanding historical context) are exactly what you use in cybersecurity, particularly in leadership roles.</p><p>What would an AI agent that supports critical thinking look like? I&#8217;ve no doubt I&#8217;ll soon hear from colleagues who work in pedagogy who will tell me this is well-worn turf and a subject of frequent discussion. Clearly the public discourse surrounding the use of AI has been co-opted by those attempting to market AI en masse, for whom replacing people seems the fast track to profits. To be fair, the parlor trick of an AI that easily passes the Turing test is seductive. But is this truly the best we can do?</p><p>Should we tailor our AIs into mentors? Creatures that can intellectually joust with us, pushing us into new and fertile areas of inquiry? Or are they best used as discovery engines? Surely part of learning to think critically involves the logistics or mechanics of learning. I recall the keen excitement of walking the graduate stacks in school, after finding the target of my search, browsing the books on either side of it, or across the aisle - the power of serendipity gently shaped by the LCC system&#8217;s ontology of knowledge<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. Perhaps with its ability to rely on fully scanned text and not merely metadata, an AI&#8217;s ability to point to connected sources thematically creates a richer web of guided serendipitous discovery. I can imagine that these would be powerful, and I expect that both are being explored academically and commercially.</p><p>I recall, as an undergraduate, attending the physics tutoring sessions. I was struck, while waiting my turn, listening to how the tutor coached a student on solving a particular problem. The approach wasn&#8217;t to simply state the solution; rather it was to ask the student questions that lead to the student asking questions of the problem. The critical thinking lesson was to learn how to interrogate and reshape the problem itself such that the solution simply fell into place. This is not unlike how many advanced math and physics domains are advanced today. An unsolvable theorem is shown to be identical to an apparently unrelated one, using entirely different mathematical techniques and formulations that is understood and solvable. In physics, difficult problems are rarely solved head-on. They are reframed - through symmetry, analogy, or a change of perspective - until they become instances of something already understood.</p><p>An AI mentor could easily provide this sort of coaching, at least for more elementary problems. But could that coaching be extended into less understood or more exploratory domains? How would you need to train an AI to ask Einstein &#8220;what would it look like if you rode a beam of light toward a clock?<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>&#8221; This is question driven thinking that forces a reframing of reality. In a nutshell, it captures Einstein&#8217;s genius. I seem to be leaning into the idea of an AI being a Socratic gadfly. Which is fun since so much of the discourse in higher ed around AI is stuck in the academic integrity space. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/thought-work-and-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/thought-work-and-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>The issue would seem to revolve around the question of how one can learn critical thinking. In my own experience, there seem to be two dimensions to this. First, the kind of guided training I described by watching a good physics tutor at work. We also experience this through textual analysis. Reading sophisticated literature and being guided through the analysis and understanding of it also reinforces critical thinking pathways. I suspect most of us have experienced this. But second, and something I don&#8217;t fully understand, is why knowledge acquired at one point often only becomes meaningful later - when experience supplies the context required to transform recognition into understanding. In other words, understanding is often delayed until experience makes prior knowledge meaningful.</p><p>While I can imagine an AI tutor succeeding at the first dimension, the second seems to be an entirely different beast. I suspect it requires the AI tutor to have some sort of mental model of the learner - and quite a rich one - before it could tactically influence the learner&#8217;s thinking. The real value of AI in education is not as a generator of answers, but as a scaffold for developing critical thinking - and current implementations largely miss this. AI can guide reasoning in the moment, but cannot yet participate in the longitudinal development required for true understanding. The next frontier is AI that models the learner, not just the problem.</p><div><hr></div><p>I&#8217;ve wandered into the weeds, so let's return to the path. It&#8217;s troubling to see institution after institution view &#8216;the challenge of AI&#8217; as either academic integrity or a security and privacy challenge. Thus the race to stand up locally managed LLMs, which are merely localized versions of the giant tech LLMs. This isn&#8217;t unreasonable, for it allows their use within institutional workflows while minimizing the exfiltration of protected data. </p><p>My suspicion is that most institutions of higher education find themselves in a corner. Along one wall is the challenging, scarcely understood, and purely aspirational wall of using AI as a platform to enhance critical thought. The other wall, the demonstration wall, is the absurd pressure institutional leaders are under to demonstrate relevance and currency. The cautious and wise leader is rarely the loudest one in the room, and reward flocks like cicadas to noise. Meanwhile, the floor trembles endlessly to the footsteps of the commercial marketplace with the boundless promises of AGI and with it threatens the collapse of the world order. To ignore the demonstration wall is a mark of failure while the aspirational wall requires creativity and patience. Only marching in time to the vibrations of the floor seems prudent.</p><p>But I would hope universities and colleges would recognize that how AI is framed in most discourse - corporate and academic - reduces humans and their actual thought work to training content creators busy training their own replacements. I would hope to see institutions invest in AI as cognitive scaffolding, e.g., question-driven systems, reflective prompting, or longitudinal learner models. The proper success metric is not a count of workflows that use AI, or speed of service ticket handling, contracts analyzed, or any of the other facile and unimaginative efficiency gains. But rather the more challenging measures of improved reasoning capacity and intellectual maturity. </p><p>Returning to the original tension: education as transmission vs. transformation. It does seem to me that AI can play a truly pivotal role in that it will amplify whichever side institutions choose - either mechanizing knowledge delivery or deepening critical thought. So perhaps the best way to end is with another question: What kind of thinkers do we want to produce - and what tools are we willing to build to get there?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Naturally this should be extended to K-12. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>The Library of Congress Classification system supplanted the Dewey Decimal system we all grew up with.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>More accurately I think he asked &#8220;What would it be like to ride alongside a beam of light?&#8221; which helped lead to the special theory of relativity.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Anthropic's Mythos in a historical context]]></title><description><![CDATA[Is it always a PR stunt?]]></description><link>https://michaelcorn.substack.com/p/anthropics-mythos-in-a-historical</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/anthropics-mythos-in-a-historical</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sun, 12 Apr 2026 21:44:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Da_O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Da_O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Da_O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Da_O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Da_O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Da_O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Da_O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg" width="352" height="243.93406593406593" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1009,&quot;width&quot;:1456,&quot;resizeWidth&quot;:352,&quot;bytes&quot;:640937,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/193899277?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Da_O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Da_O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Da_O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Da_O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb95ff4d-360c-4835-830f-32e40935331a_4630x3210.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The whole, not the parts.</figcaption></figure></div><p>Like every other human who reads, I&#8217;ve been <a href="https://www.nytimes.com/2026/04/10/business/anthropic-claude-mythos-preview-banks.html">inundated by headlines</a> about Anthropic&#8217;s &#8216;new&#8217; Mythos product. If ever anyone doubted that we are still in the golden age of cybersecurity awareness, they should hang their heads in shame<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. Cybersecurity - in one form or another - has been an above-the-fold topic for years now in almost every daily news feed. Supercharged by its alloying with AI, it has become an irresistible story.</p><p>Whether the attention is warranted or simply a product of media fixation, the claims of Anthropic are worth considering - not because Mythos is (or may be) (or is surely not) the inflection point it is being made out to be - but because of what it can tell us about the evolutionary arc of the field. As a backdrop, I tried to summarize my own view of how the field has matured (or at least changed) over my career - and then asked ChatGPT to format it into a table for me<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bC25!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bC25!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 424w, https://substackcdn.com/image/fetch/$s_!bC25!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 848w, https://substackcdn.com/image/fetch/$s_!bC25!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 1272w, https://substackcdn.com/image/fetch/$s_!bC25!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bC25!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png" width="618" height="404.5013736263736" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:953,&quot;width&quot;:1456,&quot;resizeWidth&quot;:618,&quot;bytes&quot;:225647,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/193899277?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bC25!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 424w, https://substackcdn.com/image/fetch/$s_!bC25!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 848w, https://substackcdn.com/image/fetch/$s_!bC25!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 1272w, https://substackcdn.com/image/fetch/$s_!bC25!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07da9541-01ab-4d2f-9ad8-9954b56e9459_1614x1056.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As an aside, I found creating this a useful exercise. It forced me to confront how often my unconscious thinking fell back to the traditional emphasis column, pushing me to reframe my thinking to align with the emerging approach column.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>So where does the ironically named Mythos fit into this historical perspective? And what impact is the publicity having? Regardless of its practical impact on cybersecurity, is the attention it&#8217;s drawing to product vulnerabilities a net positive or negative?</p><p>There is a consistent flavor to the coverage of Mythos. At a very low-cost, Mythos was able to uncover a number of vulnerabilities, some quite old, in a variety of products. Of course, many AI tools do this - and many of those models are far cheaper than Mythos. The professional coverage<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> is a bit more balanced than the popular press, calling out that patching software remains a far more elusive goal than identifying vulnerabilities. It does you no good to have clean drinking water if your pipes are made of lead.</p><p>Of course, Anthropic&#8217;s own pronouncements on the strength of Mythos are of the same ilk as Musk&#8217;s plans for going to Mars. &#8220;We hope this will show why we view this as a watershed moment for security, and why we have chosen to begin a coordinated effort to reinforce the world&#8217;s cyber defenses.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>&#8221; It&#8217;s not a code scanner, but a watershed event with a global impact. Sigh. I should have named this blog the Newer New Testament<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> but apparently I lack the bullshit gene.</p><p>Naturally the first thought many of us had upon reading about Mythos wasn&#8217;t &#8220;boy, this is going to solve our problems!&#8221; but rather, &#8220;oh boy, this is going to create a lot of problems!&#8221; Why? Because the same technology that can identify weaknesses we need to shore up can be used to identify weaknesses adversaries will target. Yes, the glass half-empty mindset still comes naturally to many of us. Yet, to be honest, while I&#8217;d welcome advances in code scanning that improve code quality, I&#8217;m actually rather ambivalent about it. We know from experience that 1. many well-documented vulnerabilities simply don&#8217;t have patches available; and 2. many if not most organizations have poor patching practices.</p><p>As I&#8217;ve <a href="https://michaelcorn.substack.com/p/open-question-no-3-fundamentally">talked about elsewhere</a>, the former simply won&#8217;t be addressed until the entire incentive structure of product development is changed, including legal consequences for the sale of flawed products. The latter is, however, a different kind of beast. With over 30,000 vulnerabilities uncovered every year, it&#8217;s frankly unrealistic to expect an organization to devote the time and absorb the disruptions that would occur if they truly tried to patch everything - especially in a timely fashion. Even if we restrict ourselves to &#8216;critical&#8217; vulnerabilities, the problem isn&#8217;t that simple. Every organization needs to place even a critical and easily exploitable vulnerability into their local context. Do you even use the vulnerable software? Is it exposed in a manner where it could be exploited? Are other compensating controls in place that lower the risk or the impact?</p><p>There&#8217;s simply no way for a code scanner like Mythos to know these things. I&#8217;ve no doubt that the entire market space of dynamically contextualizing vulnerabilities<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a> will benefit from some of the advanced capabilities of machine learning. But that statement has always been true.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/anthropics-mythos-in-a-historical?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/anthropics-mythos-in-a-historical?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>We should also ask how the Mythos coverage reinforces or establishes perceptions about cybersecurity. It may be necessary to burnish each tool in the cyber toolkit, but resilience in an organization isn&#8217;t a consequence of any specific tool or process. It&#8217;s the coordinated operation of these elements that allows an organization to thrive despite the cyber onslaught. Focusing on Mythos as a paradigm shift could be helpful if, for example, it draws attention to the weakness of the broader software supply chain. However, I fear it is more likely that the coverage reinforces a fragmentary view of cybersecurity and cyber tools.</p><p>With this, we finally get an answer to the question I raised above about where Mythos fits into this historical perspective. It&#8217;s difficult to sell a lifestyle; it&#8217;s easy to sell a supplement. It&#8217;s even more difficult to adopt a lifestyle than swallow a supplement. Mythos may be terrific or it may be underwhelming - but regardless of where it falls on that spectrum it is merely another iteration of a point solution in a universe of points.</p><div><hr></div><p>It&#8217;s worth asking what it might mean if Mythos were perfect; a magic tricorder able to scan software and uncover every possible vulnerability. A perfect tool owned entirely by one vendor, who would suddenly be able to hold the global economy hostage; a vendor able to intimidate hostile governments by offering its findings to only friendly ones. A true monopoly of cyber knowledge. What would we all pay for this?</p><p>I&#8217;m reminded that most of the medications I take are generic versions of successful commercial products. Medications are protected by a patent for a period of 20 years. Since drug development and approval typically takes 7-8 years, this grants companies around 12 years of exclusivity - though there are a number of nuances to how and when exclusivity is applied. Why is this done? Why aren&#8217;t the inventors / discoverers granted permanent IP protections? There are several reasons. By allowing for a period of exclusive profit companies are able to not just recoup development costs, but generate a profit, thus, in theory, incentivizing future research. But importantly, by transitioning drugs to generic formulations, society as a whole benefits both from large scale manufacturing and wide availability. Globally, millions of lives benefit from this wrinkle in the regulatory fabric.</p><p>If we were faced with a perfect Mythos product, is it ethical to allow it to be solely controlled by one company? Should there be an equivalent process to the one for drugs to transition to generic for powerful cybersecurity tools? We cyber practitioners love to point out the fundamental role cybersecurity has in our modern, digitally mediated society. No longer are we focused solely on PII, but now the battle space is one of national infrastructure: the operation of water, power, and economic facilities. Isn&#8217;t our health equally dependent on digital resilience as it is on the availability of generic medications? This feels like a more difficult thread to explain to the public and regulators, but surely one we need to tackle.</p><p>I can&#8217;t entirely blame the popular press for how they cover Mythos. The issue may be software security, but the story is the product. We see this same pattern in almost every headline - the issue may be corruption in general, but the story is the individual being bribed. Nor is it surprising that Anthropic engages in near messianic language in their press about Mythos - they are, after all, creating a marketing myth. But we should take this as an opportunity to revisit how we frame cybersecurity when we do talk to the press, and we should engage our legislators in conversations about how the regulatory landscape for cybersecurity needs a remodeling. If I were to add a row to the table above labeled &#8220;Regulatory Approach&#8221;, I fear it would still be focused on consumers instead of producers and under the heading of &#8220;Emerging Approach&#8221; simply say &#8220;more of the same.&#8221;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>The golden age began when the Russians were asked, and responded to, a treasonous request to help swing the 2016 election.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Incidentally, as long as you don&#8217;t mind a screenshot, this is a terrific use of the LLM models. Much faster than wrestling with <a href="https://app.datawrapper.de/signin">Datawrapper</a>, for example.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>For example, <a href="https://venturebeat.com/security/mythos-detection-ceiling-security-teams-new-playbook">https://venturebeat.com/security/mythos-detection-ceiling-security-teams-new-playbook</a> and <a href="https://www.fierce-network.com/broadband/anthropics-mythos-cybersecurity-breakthrough-or-just-criti-hype">https://www.fierce-network.com/broadband/anthropics-mythos-cybersecurity-breakthrough-or-just-criti-hype</a> are quite typical.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p><a href="https://red.anthropic.com/2026/mythos-preview/">https://red.anthropic.com/2026/mythos-preview/</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>I want to follow up with a discussion of norms - for example, while Anthropic is marketing its largesse in giving away $100 million in free usage credits for Mythos, I notice an absence of social intention in its statements. Despite what may or may not be a sincere belief that this is &#8220;doing good&#8221;, why not offer Mythos for free or heavily discounted to medical device and software manufacturers? This is just one example, but I&#8217;ll save the norms discussion for a dedicated post.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Not to downplay the value here, but <em>every single</em> logging and vulnerability analytical tool I&#8217;ve ever deployed at enterprise scale has made at least mild claims of doing this.</p></div></div>]]></content:encoded></item><item><title><![CDATA[The market-driven decomposition of security]]></title><description><![CDATA[Coherence vs. entropy]]></description><link>https://michaelcorn.substack.com/p/the-market-driven-decomposition-of</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/the-market-driven-decomposition-of</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Sun, 05 Apr 2026 05:52:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VnqS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VnqS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VnqS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VnqS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VnqS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VnqS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VnqS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg" width="408" height="272.0934065934066" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:408,&quot;bytes&quot;:520703,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/193002668?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VnqS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VnqS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VnqS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VnqS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf0b363-2c42-4d6f-90fb-287992b10ba1_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>It turns out a torn meniscus can truly disrupt the best laid plans. So no traveling until my wife&#8217;s knee has healed up and I&#8217;m back to the regular posting cadence. </p></div><p>I was struck by a comment a colleague made the other day that part of what troubles cybersecurity is &#8220;vendor sprawl&#8221;. It must have been kismet, for I had just spent a couple of hours falling down a rabbit hole, researching the market for IP address reputation services<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. This post is the resulting confluence of these two moments. As I reflect on the question of vendor sprawl, I think this is less a problem of too many vendors and more a problem of how the cybersecurity marketplace itself is structured.</p><p>Of course, the wise question to ask - if you&#8217;re in the market for one of these commercial services - is why. Why devote time and resources to a specific security control over any of the others in similarly rich markets? But this is just one expression of what I take to be meant by vendor sprawl: that for nearly every element of your environment, there exists a corresponding marketplace. Tools to analyze and optimize firewall rules? Check. Real-time vulnerability scanning? Check. Endpoint protection, DDoS mitigation, phishing detection, deception networks, certificate testing, code analysis&#8212;each with its own ecosystem of vendors.</p><p>It&#8217;s incredibly seductive. You hit the vendor floor at a conference and every single vendor makes a compelling case for why their flavor of whatever they&#8217;re selling will improve your security posture tenfold. And maybe it will - too often constraints in staffing and budgets mean that your homegrown alternative is <em>just</em> enough to be effective. In consultant speak, crawling is sufficient, walking or running is aspirational. Surely (says the addiction) we could optimize this by investing in some professional tool. Perhaps running isn&#8217;t aspirational, it merely requires writing a larger check.</p><p>Of course, your staff are not idiots. When they Macgyver a solution they&#8217;re usually doing so in a fashion so it&#8217;s manageable in what limited time they have available. They&#8217;re automation engines. When you buy a tool, it inevitably requires more staff time. Ignoring configuration and deployment, you&#8217;ll need to integrate its outputs and detections with your other tools, and often there&#8217;s a UX that&#8217;s designed, god help us, to have eyeballs on it, rather than to deeply integrate with your logging and analysis tools. Call it the integration tax, which leads to integration fatigue. Those lovely screens showing attacks, or blocks, or attack analysis - the same screens that issued that siren call across the vendor floor and gave you a come-hither stare, are actually impediments to getting work done. The context switching burden alone acts like a 3% tax on your staff&#8217;s time<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. It&#8217;s worth remembering this as you drool over these tools. As a CISO, you may view them in terms of how they fit into your mitigation portfolio. But how they fit into the capacity and workflow of your team is probably a wiser perspective. Strategy vs. management in a nutshell.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Essentially what might be called &#8216;vendor sprawl&#8217; I see as the market-driven decomposition of security: an infinite number of addressable niches and the fragmentation of controls. I suspect there is a divide here between commercial organizations and higher ed. More of these niche solutions are adopted in environments where the coupling between investment and risk reduction is more explicit, if not driven by compliance. In higher education we&#8217;ve valorized macgyvering to the point of wearing it like a badge of honor. </p><p>Perhaps this is worth unpacking. We can ask what drives a market, and in the case of cybersecurity, is that driving it into a shape apposite to the operating style of higher education? To my eyes, and this has been consistent over my entire career, the vendor market has been shaped by the deeper pockets of the commercial sector. Our attempts to influence it (through programs like <a href="https://internet2.edu/cloud/internet2-net-plus-services/">Internet2 Netplus</a> or those vendor higher ed advisory committees) rarely influence product in any meaningful degree, but are focused on contractual and pricing terms. &#8220;We want what they&#8217;re having, but cheaper since we&#8217;re non-profits&#8221; seems to be our strategy for vendors. I suspect there&#8217;s an opportunity for us to have a conversation about what it is we truly need from the market. Is it more bundled solutions? More platforms and fewer point solutions? Are there specific practice spaces (such as backups or MFA) that need to expand as an alternative to the continued proliferation of niche solutions? I don&#8217;t see that we, as a community, have addressed the question - but rather we fall back on the ossified practice of holding our hats in hand and asking for a few crumbs.</p><p>But I do think it&#8217;s worth pausing for a second and noting that all of this vendor sprawl isn&#8217;t accidental. It&#8217;s structural: a feature of our economy where any notion of planning has been replaced by an embrace of the free market, for better or worse<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. For those building their operational portfolio, the upside is largely positive. For every risk you decide to address, the market offers you a host of options. In the best of cases the vendor is providing an analytical depth for the challenge that you and your team probably don&#8217;t have the capacity to reach on your own.</p><p>But it&#8217;s difficult to get away from the resource demand these solutions create, and the integration fatigue they introduce as you attempt to adopt them into your tool ecosystem. Worse, they become a sunk cost that few of us are willing to abandon easily, not to mention the cost of changing solutions as the market shifts and new approaches eclipse older ones. Vendor sprawl can cynically be viewed as a system for creating technical debt across the cyber ecosystem. I think it&#8217;s more helpful, however, to see this as a critique of cybersecurity as a market-assembled system that cannot keep up with its own fragmentation. Woe to the organization that, with the best of intentions, plows ahead na&#239;vely trusting that system.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/the-market-driven-decomposition-of?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/the-market-driven-decomposition-of?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>You should be able to tell that I&#8217;m trying to have it both ways. As an inveterate noodler, I like and am attracted to these niche solutions. There&#8217;s a veneer of corporate professionalism to many of them that our homegrown solutions appear to lack - though admittedly that lack is often presentational rather than substantive.  On the other hand, embracing the vended market runs the risk of using successful marketing as a proxy for the thought work necessary for risk assessment and subsequent strategy development.</p><p>I see three primary consequences to the arguments I&#8217;ve been making. It may be that we need to re-architect security to use fewer, more integrated systems. I don&#8217;t have hard data on this, but my observations of the field suggest many of us are embracing this, what I&#8217;ll call the &#8216;design argument&#8217; as an approach to managing vendor sprawl. Second, could it be as simple as needing stricter prioritization and a refusal to buy additional tools that aren&#8217;t at the top of the prioritization list? Given the historical underfunding of cybersecurity, this &#8216;operational discipline argument&#8217; may already be widely practiced.</p><p>However, design and discipline are partial responses<em>. </em>More importantly, as I&#8217;ve discussed above, the challenge of vendor sprawl is inherent to the system; we manage, not solve it. There&#8217;s probably an interesting conversation to have about this from the institutional-scale perspective. Given the real costs of vendor solutions - and thus the &#8216;tax&#8217; of vendor sprawl - there is a security poverty line, i.e., a minimal investment burden necessary for an organization to maintain viable security. What are organizations to do when they fall below that poverty line, lacking the funding to spend above it, and the resources to develop below it?</p><div><hr></div><p>I can see two possible areas for action. First, we need to begin to press for a more strategic form of regulation. Most conversations around cybersecurity regulations focus on controls - which ones you need to implement. This really isn&#8217;t surprising since it has a long history and thus a lot of momentum, and the primary work coming from NIST has been control oriented. It&#8217;s useful, however, to consider the nature of influence a regulator can have in a market economy. By creating regulations around specific practices, the market will - at least to some degree - coalesce around those practices. For example, if the Feds expanded the mandatory use of phishing-resistant MFA from Federal systems to <em>all</em> commercial services, that would require the MFA vendors to double down on support for phishing-resistant tools. Further, the sheer scale of market demand would induce new vendors to enter that space. This is to say, we need market steering regulations as much as we need them for corporate practice.</p><p>Second, it&#8217;s worth revisiting the notion of market norms. A norm is a shared expectation about appropriate behavior within a community, sustained not primarily through formal enforcement, but through mutual recognition, reputation, and the prospect of inclusion or exclusion. Norms sit between law and preference: they are not codified like regulation, but they are stronger than individual choice because they are collectively reinforced.</p><p>In a market context, norms function as informal governance mechanisms<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. Ideally, they shape what &#8220;good behavior&#8221; looks like beyond contractual minimums. Further, norms can reduce transaction costs by establishing baseline expectations and ultimately create reputational consequences for deviation (even when contracts are technically satisfied). Norms are generally unwritten rules that determine what vendors can get away with versus what would cost them trust, access, or legitimacy.</p><p>We as a community lack these norms. While someone who regularly works with vendor agreements can see how norms have become more emergent over the last 15 years or so, they remain focused on procurement terms. The conversation I&#8217;d suggest we engage in is around those market shaping norms that influence how and what solutions are presented to higher ed. If vendor sprawl is a structural feature of the market, then norms are one of the few levers we have to shape what that market produces. If sprawl is inevitable, norms can determine whether the market produces fragmentation or composable coherence.</p><p>I feel obligated to provide some examples of market shaping norms, no doubt someone with an economics background will comment on how weak these are, but here we go.</p><ul><li><p>Solutions that require standalone human attention surfaces (i.e., new dashboards) are viewed as incomplete or immature.</p></li><li><p>A tool that cannot demonstrate deep, low-friction integration into a heterogeneous environment is not considered viable&#8212;regardless of analytic sophistication.</p></li><li><p>A solution must demonstrate that it reduces total system complexity, not just adds capability.</p></li><li><p>Marginal improvements in a narrow domain are not valued unless they contribute to broader system coherence.</p></li><li><p>Solutions must explicitly account for human operational capacity as a first-class constraint.</p></li><li><p>Products must assume decentralized governance and partial adoption&#8212;not idealized, centralized control.</p></li><li><p>Tools that optimize existing controls (rather than reduce or consolidate them) are treated with suspicion unless they demonstrably eliminate other dependencies.</p></li></ul><p>I think this is a reasonable starting point for discussion. The kind of norms I&#8217;m discussing must operate at the level of product legitimacy, not vendor etiquette. Ideally a strong norm will invalidate entire categories of tools or force redesign of existing ones.</p><p>Vendor sprawl, then, is not a failure of discipline or a temporary excess of choice. It is the natural output of a market that decomposes security into ever more granular problems and sells their solutions back to us. The question is not whether to participate in that market - we already do - but on what terms.</p><p>If we treat each tool as an isolated improvement, we inherit fragmentation and the operational drag that comes with it. If, instead, we begin to assert expectations - through regulation, through norms, and through our own purchasing behavior - we may be able to shape a market that produces coherence rather than entropy. The difference is not in how many tools we buy, but in whether the system they form is one we can actually operate.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>If you&#8217;re not of the tribe, let me explain what a reputation service is for IP addresses. Essentially there&#8217;s a market for lists of IP addresses known to be &#8220;bad&#8221;, that is, known to be serving malware or launching attacks and probes. With upteenzillion IP addresses in use, it&#8217;s hard to believe this can be effective, but surprisingly it is, and every organization uses these to some degree. One list to block entirely at your network boundary - another of malicious domains to use with your DNS service - still others that you integrate into your logging and analysis protocols. Most of your major security technologies and ISACs come with or provide their own curated lists and there&#8217;s a market for commercial lists (some quite good). Further, there are a few vendors who claim to analyze IP addresses dynamically in near-real time.</p><p>I&#8217;m not sure most CISOs have spent a lot of time worry about optimizing their use of block lists, they&#8217;re so integrated into so many security appliances they&#8217;re almost invisible. But given that they&#8217;re a coarse way of imposing a data ingress policy (what&#8217;s allowed into your network) and detecting malicious egress, perhaps this space warrants more attention than we give it. If you <em>really</em> want a rabbit hole to explore, every few years someone proposes some new mathematically clever approach to <a href="https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=11002475">identifying &#8216;badness&#8217;</a> by algorithmically <a href="https://www.ll.mit.edu/sites/default/files/publication/doc/2018-04/2013_05_26_Carter_ICASSP_FP.pdf">examining IP addresses</a>. Fun reads, but it&#8217;s hard to treat them as more than cyber fiction or magical thinking.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>By context switching I mean moving from UX to UX. Incidentally, I made up the 3% number. Feel free to choose an alternative; 25% actually seems more reasonable.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>As I like to refer to it, the triumph of capitalism over democracy. The birth of this observation clearly has its roots in the political economy writ large - it&#8217;s why China seems far more nimble than the US. For the Chinese central planning is systemic, whereas in the US it&#8217;s viewed with suspicion and deliberately undercut to allow unfettered profit. I&#8217;m extending the critique into the cybersecurity space while recognizing that there is an upside. Just as the market economy has resulted in vast investment in evolving a device like mobile phones, it has created this overwhelmingly rich ecosystem for security solutions. The question is whether vendor sprawl can be tamed - at least locally - or is it doomed to induce uncoordinated procurement in complex systems?</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>This is by no means a novel idea. I found it repeatedly while doing research on market norms.</p></div></div>]]></content:encoded></item><item><title><![CDATA[What can cybersecurity learn from biosecurity?]]></title><description><![CDATA[It takes more than chicken soup]]></description><link>https://michaelcorn.substack.com/p/what-can-cybersecurity-learn-from</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/what-can-cybersecurity-learn-from</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Wed, 01 Apr 2026 00:24:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Pklr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pklr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pklr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Pklr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Pklr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Pklr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pklr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg" width="342" height="234.8901098901099" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1000,&quot;width&quot;:1456,&quot;resizeWidth&quot;:342,&quot;bytes&quot;:335220,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/192658418?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pklr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Pklr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Pklr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Pklr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642cb7c1-98bb-43d2-a418-a658b76b0d53_4166x2862.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><div class="pullquote"><p>NB: I will be traveling for a couple of weeks without access to a keyboard, so it&#8217;s unlikely I&#8217;ll post any new pieces for a bit. I think this piece needs a follow up on cybersecurity norms.</p></div><p>The Bulletin of the Atomic Scientists (BoAS) published an interesting piece the other day, &#8220;<a href="https://thebulletin.org/2026/03/what-can-biosecurity-learn-from-cybersecurity-a-lot/">What can biosecurity learn from cybersecurity? A lot.</a>&#8221; Part of why it struck me is that I&#8217;ve always thought about this from the opposite direction. Having spent a fair amount of time on a campus biosafety committee, I&#8217;ve been struck by the lessons we could learn from how biosafety is managed in a large environment as we try to figure out how to scale up our own support for research. With multiple labs, specialized equipment and HVAC requirements - not to mention, you know, Ebola - it seems like our own support and compliance models could borrow a lot from it.</p><p>I really can&#8217;t recommend strongly enough that if your organization deals with biosafety issues<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, you reach out to the good people overseeing it and ask to participate. If nothing else you can point out that a successful cyberattack could result in those overpressure blowers failing, allowing disease-carrying mosquitoes to escape. You&#8217;ll find they have rigorous (and audited) protocols for everything from incident reporting and handling, to training and standards compliance, all issues you&#8217;re probably facing in your cyber domain<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><p>As I read through the BoAS piece, it surfaces several non-obvious lessons for cybersecurity&#8212;particularly as it matures into a domain with societal, not just technical, consequences. Viewed through the lens of institutional practice, several of the article&#8217;s arguments take on a different emphasis.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>First, norms have both power and limits. It&#8217;s striking how a web of treaties, arms control, and international agreements surround the world of bioweapons. Of course, none of these were established until after these weapons were put into place. Cybersecurity, on the other hand, seems unable to establish equally durable norms around state behavior and acceptable use.</p><p>The lesson here is that norm-building matters, despite the imperfect and difficult nature of enforcement. The shared expectations that become established, such as &#8220;don&#8217;t target hospitals&#8221; do shape behavior and beliefs. Yet for us in cybersecurity there seems to be little or no equivalent to the bioweapons paradigm (or kinetic weapons for that matter). The article&#8217;s implication here is that biosecurity demonstrates that norms built for discrete visible threats can become misaligned when risk is diffuse and systemic; surely this is a line we walk regularly as cyber practitioners. Nevertheless, I find this framing valuable to reflect upon.</p><p>For me, the implication is that cyber should be investing in international norms, but design them for continuous, ambiguous activity, not just &#8220;red line&#8221; events.</p><p>Second, as the BoAS piece points out, biosecurity remains heavily anchored to the weapons paradigm (which it says is inherited from nuclear strategy). Cybersecurity has largely (though not entirely) moved past this. Instead, as the article argues, we focus on the dimensions of capabilities, access, vulnerabilities, and effects, which are many of the core dimensions of the classic TARA (Threat Agent Risk Analysis) model. If there&#8217;s a takeaway here, it&#8217;s that we need to preserve this capabilities-based approach, and resist drifting into rigid categories (e.g., &#8220;nation-state vs criminal&#8221;) which can become limiting. That is we should maintain a capabilities-and-effects lens, and resist re-simplifying threats into overly discrete categories as our field matures.</p><p>Third, I was particularly interested in the discussion of how to tier risks. Biosecurity tends to oscillate between catastrophic scenarios (i.e., bioweapons) and benign research. Consequently, the article highlights intermediate risks, such as lab accidents, misuse of common tools, and the erosion of norms. This struck me because we cybersecurity practitioners have developed a more mature understanding of this spectrum. For example, the progression from commodity ransomware to advanced persistent threat to cyber-physical attacks. </p><p>Nevertheless, I wonder if we&#8217;re still underestimating systemic, low-grade risk accumulation, such as chronic misconfiguration, supply chain fragility, and the erosion of norms (e.g., the normalization of ransomware payments). Obviously we do worry about these things, but we should ask how we might approach this class of risk cohesively. Perhaps we should create or further formalize &#8220;middle-layer risk governance&#8221;. A space that is not just high-end adversaries, nor simple hygiene, but the accumulation of small, plausible failures with large aggregate impact.</p><p>The piece also draws attention to the notion of what it calls &#8220;distributed capability&#8221; which should be recognizable to all cybersecurity practitioners. Both biosecurity and cybersecurity share a few consistent features. Not only is capability widely distributed, but barriers to entry are lower than in traditional military domains, and small groups can have disproportionate impact. While biosecurity is now aggressively dealing with these, cybersecurity has long confronted them. Yet we too often act as if central authority is sufficient and that perimeters are meaningful.</p><p>I&#8217;m struck by how the implications here for cybersecurity may actually be more mature in the research security space. Clearly we must continue shifting toward federated security models, shared responsibility architectures, and in particular ensure that security is embedded in ecosystems, not merely enforced from the center. This strikes me as particularly true in a world where we need to treat persistent compromise as a baseline condition, not an exception.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/what-can-cybersecurity-learn-from?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/what-can-cybersecurity-learn-from?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>It follows from the observation on research security that infrastructure interdependence is the real risk surface. That statement seems to encapsulate so much of our struggle within our university environments where everything is interconnected at the bits, wires, and services level, yet independent and entrepreneurial at the decision-making and governance level.</p><p>The article&#8217;s most forward-looking point is the convergence of digital and biological systems. It points out that health systems depend on digital infrastructure, biological research depends on software, data, and supply chains and consequently failures cascade across domains<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. Thus it is important for us to think in terms of <em>societal infrastructure</em>, not IT systems. Something that can be challenging to focus on amidst the chaos of ordinary operations and planning.</p><p>Thus, it seems that a mature cybersecurity strategy should step back and try to map dependencies beyond IT, extending those traces to include, for example, health infrastructure, supply chains, and research ecosystems. This sort of mapping immediately should lead us to map cross-domain cascading failures, and to factor these into broader resilience planning at the institutional or societal level.</p><p>It&#8217;s this question of how and who steps back that&#8217;s particularly challenging. One could distill almost the entire article into the observation that governance must match the system, not the threat. While biosecurity seems to be trying to move in this direction, it&#8217;s confronting a core misalignment, historically its governance was built for discrete threats, while reality is now defined by continuous, distributed risk. It feels to me like cyber may be further along this path. We&#8217;ve spent decades evolving governance to match its environment, through continuous monitoring, iterative risk management, and adaptive controls. But we also run the risk of allowing cyber governance to ossify. There is certainly a strong stream pushing us toward compliance-driven models, static frameworks, and checkbox risk management in our space. Cybersecurity governance must be designed to be adaptive (dynamic, not static), fully integrated into decision-making (not parallel to it), and capable of handling gray-zone activity, not just incidents.</p><div><hr></div><p>Cybersecurity&#8217;s biggest takeaway from biosecurity is not technical - it&#8217;s strategic self-awareness. What the article seems to say is that biosecurity shows what happens when a field is anchored to outdated paradigms, relies on governance that lags behind technological reality (hello AI!), and that norms are strong but too narrowly scoped. </p><p>Cybersecurity, by contrast, has developed more adaptive approaches to persistent risk, intrinsic ambiguity, and distributed capabilities. But we are not immune from this same drift. Fundamentally, the challenge for us is not just managing threats - it is continually updating the frame through which threats are understood. Building on the BoAS article, one can say that if cybersecurity fails to do that, it risks becoming what biosecurity is now struggling to evolve beyond: a system optimized for a world that no longer exists.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>This will include many more mundane labs that deal with corrosive or poisonous chemicals, not merely ultra-dangerous diseases.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>It&#8217;s also startling to see how seriously the researchers take these protocols and processes. Something you really never see in our cybersecurity space.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>I&#8217;m lightly paraphrasing here, largely reusing the article&#8217;s phrasing and logic.</p></div></div>]]></content:encoded></item><item><title><![CDATA[How should an organization respond to a breach?]]></title><description><![CDATA[Not with a strongly worded letter.]]></description><link>https://michaelcorn.substack.com/p/how-should-an-organization-respond</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/how-should-an-organization-respond</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Mon, 23 Mar 2026 18:38:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fIbA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fIbA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fIbA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fIbA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fIbA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fIbA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fIbA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg" width="306" height="214.5782967032967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1021,&quot;width&quot;:1456,&quot;resizeWidth&quot;:306,&quot;bytes&quot;:101893,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/191310790?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fIbA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fIbA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fIbA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fIbA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4031c194-ef7e-4bab-8221-8450ad295d76_4065x2851.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Everyone follows the leader.</figcaption></figure></div><p>So your CIO and counsel come to you with information no one wants to hear. A significant data breach has been discovered, and due to state law, it&#8217;s a notifiable event. That is to say, whether notification to affected individuals is the right thing to do or not, it&#8217;s out of your hands and you&#8217;re required to issue notices. OK, you trust your people, and notification is the right approach, but what do you do in response?</p><p>It&#8217;s important to note that I&#8217;m not talking about the incident response. Let&#8217;s assume your team has that under control - they know what to do to contain, analyze, and handle the incident from discovery to the inevitable offer of identity monitoring services from the credit bureaus. That&#8217;s a given.</p><p>But the question I&#8217;ll focus on is: <em>what do <strong>you</strong> do</em>? As the organizational head, whose actions define the its response, what should you do beyond allowing your team to unspool their processes? You&#8217;ve probably already started part of this conversation: what resources or investment do you need to prevent this from happening again? That is, what is the role of executive judgment once legal, technical, and contractual processes have taken over?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>There are a couple of givens that you might not have considered. First, your team isn&#8217;t actually handling the incident. At every major institution (I am speaking primarily to major universities) an outside firm has been brought in, and with it, an attorney who&#8217;s actually running the show. Their goal, bluntly, isn&#8217;t to &#8220;do the right thing&#8221; or &#8220;support the affected community&#8221;; rather, their goal - the reason you&#8217;ve hired them - is to minimize institutional liability. That&#8217;s not necessarily a bad thing, it simply is how these things are handled today. Liability minimization is a <em>governing incentive</em>, not a moral failure. </p><p>Secondly, as with any major incident, you are rapidly approaching a point where your team will make that request for resources. They&#8217;ll offer up any number of initiatives, process improvements, or policy recommendations in response to the specifics of the incident at hand. What you may not realize is that this is precisely the critical juncture that offers you an opportunity for differentiation. Do you allow that ask to arrive as a proffered bundle of tactical responses to a situation, or do you pivot to the strategic? This is the inflection point that separates leadership from management.</p><div><hr></div><p>This is challenging; in many domains, and certainly for cybersecurity, we tend to view incidents as a &#8220;crisis of technology.&#8221; However, by allowing the response to be handled by outside counsel and relying solely on an established incident response playbook, organizational leadership is suffering from a &#8220;crisis of agency&#8221;. This is our true issue. The machinery of honed practice often displaces the agency required for strategic leadership. The position I&#8217;m arguing for here is not to eliminate that machinery, but to recognize that it is a category error to see it - and the tactical requests it makes - as strategy. Operational response does not equal strategic direction.</p><p>In general, I&#8217;d like to see an organization respond by moving from incident-specific controls and towards improving their systemic risk posture. Too often I&#8217;ve seen the response to incidents instinctively lean into compliance thresholds and not true resilience objectives. At one of my last positions, a primary metrics identified in response to a number of high-profile breaches was to insist on 100% compliance with security training mandates. Your house is on fire, the firefighters have no water, but you&#8217;re being yelled at for forgetting how to perform the fireman&#8217;s carry.</p><p>I and others have made the case that breaches are inevitable, that they&#8217;re the cost of doing business. This is true, and worth remembering if you think they can be eliminated. But true institutional resilience isn&#8217;t going to &#8220;prevent this from happening again&#8221;; it will instead minimize its impact and more importantly, your goal should be to reduce the class of failures. As a leader, your responsibilities should focus on interrogating the incentives, not just the controls.</p><p>When I think about interrogating incentives, three dimensions come to mind. First, vendor risk allocation. This is how risk is distributed, priced, and enforced between your institution and the third parties you depend on - primarily through contracts, procurement standards, and ongoing governance. Right now, most organizations <em>think</em> they&#8217;re managing vendor risk, but in practice they&#8217;re often absorbing it. Organizations generally rely on outsourcing critical services. Those services are governed by contracts where cybersecurity is addressed through broad and often non-binding terms<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. Any liability identified in contracts is typically capped, and often at amounts far below the actual potential costs. Ultimately the institution remains accountable for the downstream consequences - its reputational and notification costs, as well as regulatory impact are absorbed by default. To my eyes, this looks less like an unintended consequence than a system design failure<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/how-should-an-organization-respond?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/how-should-an-organization-respond?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>Second, internal funding models should be interrogated. As every CISO will tell you, they operate within a zero-sum game of the central IT budget. While the CIO controlling that budget may support and try to resource the security office to the best of their ability, the incentive for the CIO is not better cybersecurity. This is fundamentally the structural tension CISOs and CIOs live with. Better and more effective cybersecurity practices are generally invisible when successful. No one gets rewarded for an absence of problems. That is, its success is non-legible (measured as an absence of incidents) and therefore it is structurally under-incentivized.</p><p>Third and finally, accountability structures are notoriously obtuse at universities. For cybersecurity it may be tempting to hold the CISO or CIO specifically accountable when a breach or major incident occurs. But this ignores their limited span of control. The mechanisms that hold individuals and units accountable for their engagement with and adoption of cybersecurity practices are highly diffuse and woven throughout academic and administrative structures. Thus, responsibility may be shared, but accountability is rarely concrete.</p><div><hr></div><p>Clearly there are many ways an experienced organizational leader can approach responding to a data breach. The three areas I detail above each have some obvious interventions. For vendors, refuse to sign misaligned contracts, tier risk, and work hard to enforce vendor liability. This sounds straightforward but your teams will insist that only the preferred product is capable of meeting your institution&#8217;s needs. This is never true. Product choice is typically made based on existing vendor partnerships or preferences, user-interface biases, or the trendiness of the product.</p><p>As to funding, carve out protected security investment and work with your team to define risk appetite explicitly. Recognize that your team has been trained to undersize resource requests based on what they think is reasonably likely to be funded. I do not recommend inundating your team with emergency resources. Rather, consider a sustained growth model, allowing the team to allocate those resources across staffing and technology according to need. This could look like a protected 10% increase in the security budget annually for five years. With a long time horizon, you enable your team to shift from tactical response to strategic maturation.</p><p>Accountability involves tying security participation to existing authority structures. While they can work, I&#8217;ve never been a fan of creating a new &#8220;Security Governance Council&#8221; or something of that ilk. Rather, integrating cybersecurity into the ordinary governance structure of your deans and unit heads is more likely to ensure broad and persistent engagement. But this too will fail without your direct participation. Middle managers focus on their leader&#8217;s priorities. Regularly asking deans a few probing questions about their unit&#8217;s participation in security initiatives and their internal resource allocation to security may be the single most effective action you can take.</p><p>The common thread in all of this is agency. Incidents trigger well-developed machinery - legal, technical, procedural - that is necessary but not sufficient. Leadership is required where that machinery cannot operate: in setting direction, shaping incentives, and defining what the organization is optimizing for. If you cede that ground, the response will be at best competent, and yet incomplete.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>This ignores that few institutions even try to hold vendors accountable for security incidents since the cost of changing vendors is too onerous.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p><a href="https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/">https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/</a>.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Cybersecurity and the valorization of misinformation]]></title><description><![CDATA[Epistemic collapse seems inevitable]]></description><link>https://michaelcorn.substack.com/p/cybersecurity-and-the-valorization</link><guid isPermaLink="false">https://michaelcorn.substack.com/p/cybersecurity-and-the-valorization</guid><dc:creator><![CDATA[Michael Corn]]></dc:creator><pubDate>Fri, 13 Mar 2026 04:29:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QR_L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QR_L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QR_L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QR_L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QR_L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QR_L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QR_L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg" width="218" height="327" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2184,&quot;width&quot;:1456,&quot;resizeWidth&quot;:218,&quot;bytes&quot;:663812,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://michaelcorn.substack.com/i/190665331?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QR_L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QR_L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QR_L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QR_L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8da5c740-f952-472c-a712-c776f1096e98_4000x6000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Are we in a moment where there is a crisis of the authority of information? And if so, how does this epistemic breakdown affect cybersecurity practice? I find myself reflecting on this question after reading a rather <a href="https://luciantruscott.substack.com/p/inside-the-pure-babble-of-the-trump">brutal piece</a> on the absence of good faith actors in our civic space. It forced me to think about one of my remaining <a href="https://michaelcorn.substack.com/p/where-to-begin">open questions</a>, number 8, the &#8220;Untrustworthiness of the Federal Government as a partner.&#8221; When I wrote that, I was really focusing on the dismantling of the federal mechanisms that underpinned national cybersecurity efforts, i.e., threat intelligence. This is the good work we are all used to, coming from the DOD, CISA, and the intelligence community in identifying, analyzing, and disseminating attack TTPs. Further, with the weaponization of the federal bureaucracy to target minority populations and political opponents, the moral imperative is to think through how we can help protect the victims of this harassment.</p><p>However, as I think about the issue, particularly in light of the author&#8217;s observation that &#8220;we have reached a point where information has no value,&#8221; I have to ask what this means for us, as cybersecurity and privacy practitioners. I don&#8217;t want to rehash here what others have said so eloquently; that is, to detail the space between statement and reality. As we confront this raw reality every day in our news feeds, the crassness and shameless grift of it wounds us all. Instead, perhaps as salve for that wound, I&#8217;d rather ask some questions. How will we know when this erosion of reality<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> begins to affect our space, that of cybersecurity practice? Will we be able to recognize it? Has it already happened that we&#8217;re so busy with the daily struggle, that the erosion has become normalized and we&#8217;re effectively blind to its pernicious effect? Essentially, what happens to cybersecurity practice when the broader epistemic environment collapses?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Some of the cognitive dissonance that this gives rise to stems from the hard, practical nature of technical cybersecurity. Cybersecurity operations depend on empirical<strong> </strong>signals and measurable events<strong>.</strong> An intrusion detection signature is a set of specific actions - ports opened, accounts used, vulnerabilities exploited - and like a stone dropped on your foot they are testably real. They work or they don&#8217;t; they&#8217;re detected or they&#8217;re absent. A DDoS generates packets that have an effect on a system. No political machinations can change that. In at least this dimension of cybersecurity, we are all realists.</p><p>Of course, in practice, it&#8217;s not quite that simple. It is partly true that technical cyber remains epistemically stable, but experts know the interpretive layer is enormous<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. Even understanding an intrusion detection alert requires contextualization and nuanced understanding, that is, interpretation. All of these signals and measurable events must be interpreted and trusted within institutions<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. And institutions themselves depend on shared epistemic norms. </p><p>Perhaps I should define epistemic norm. By this, I mean those shared rules or standards a community uses to determine what counts as valid knowledge, credible evidence, and justified belief. They govern how people decide whether something is true, reliable, or worth believing. With this definition we can reformulate my question: as those epistemic norms collapse - our institutions&#8217; ability to separate credible from non-credible data - how will our function as security and privacy professionals be impacted?</p><p>My suspicion is that we need to look elsewhere from the deeply technical dimensions of cybersecurity and focus first on those of strategy and policy. These seem to be the most susceptible to political interference. If the political landscape is largely shaped by misinformation (or even disinformation a.k.a. propaganda) then this will impact national priorities. We&#8217;ve already seen this in the cyber space with the &#8220;standing down&#8221; of federal resources fighting Russian cyber activities and misinformation more generally. Simply stating as national policy &#8220;the Russians aren&#8217;t engaged in election interference&#8221; doesn&#8217;t impact Russian activities. But it will impact our response to them.</p><p>We&#8217;ll see fewer alerts, less analysis, and quite possibly the introduction of supply chain risks. The latter would stem from the status of certain vendors in the supply chain. Epistemic collapse implies a distortion of policy priorities; priorities that impact vendor restrictions and thus introduce supply chain risk. Potentially positive contributors (such as Claude) are forbidden, while potentially negative contributors are allowed to persist (Palantir)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. These are explicitly political policy decisions made, not for the general health of democracy, but for the benefit of a small number of individuals at its expense. &#8220;Russia, if you're listening, I hope you're able to find the 30,000 emails that are missing, I think you will probably be rewarded mightily by our press.&#8221; Statement to consequence in 24 hours<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>.</p><p>The more general question for us is to what degree do we allow national priorities to shape or determine our local decisions? And if the priority is based on misinformation, how are we to respond? I suspect part of the answer is that our leadership is awash in the misinformation flood. As with all of us, even the most intelligent and critically thinking among them are still susceptible to its influence, particularly since they likely lack the domain expertise for cyber and geopolitics necessary to insulate themselves from it.</p><p>In response, we should step up to this challenge and actively work to clarify for our leadership how civic political discourse combined with geopolitical reality influences our cybersecurity strategy. This is not some variation of &#8220;speaking truth to power&#8221;, but rather embracing our role of mediating between the reality of cybersecurity and the misinformation-sphere. We need to be clear on how our posture is built on first principles and empirical evidence. But be prepared to have a response ready when drivel <a href="https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf">like this</a> is sent to you with the question &#8220;how does this affect us?&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/p/cybersecurity-and-the-valorization?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/p/cybersecurity-and-the-valorization?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>Throughout this blog, I&#8217;ve spoken often about <a href="https://michaelcorn.substack.com/p/the-cult-of-process-improvement">thought work</a> and how central it is to effective cybersecurity. Yet we find ourselves floating in an ocean of misinformation<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a>. Critically, we need to ask, if the epistemic ecosystem itself is under collapse, how will that trickle down into our own ways of doing thought work? <em>How do we introduce resilience into our own critical thinking about cybersecurity?</em> This is incredibly challenging and the threat is quite insidious, particularly due to the scale of disinformation. I see no liferafts<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a> and it&#8217;s hard to imagine that it hasn&#8217;t already damaged us.</p><p>My instinct is to try and pivot from an attitude of response, watching for the corrosion and then taking action, to one of anticipation and preemption. To begin with, this means having a clear path you&#8217;re following, established through deliberation and clarity of thought, rather than one of reacting to the chaos surrounding you. Have you established and codified a formal cybersecurity strategy - a playbook for the near- to midterm that will provide crisp guidance requiring minimal interpretation? To some degree this is a strategy of insulation, one that will minimize the opportunities for epistemic collapse to interfere with your program.</p><div><hr></div><p>I can see an entire portfolio of research ideas stemming from the challenge of epistemic collapse or corruption. These revolve around the notion that cybersecurity organizations should strive to preserve epistemic integrity. What are the institutional designs that resist epistemic corruption? What are the analytical methods that remain robust under misinformation pressure? We tend to bandy around the term &#8216;governance&#8217; to refer to the institutional oversight of a function. But we need to remember that we, as cybersecurity leaders and privacy professionals, are ourselves agents of governance - we govern through our management and strategic capacity. As such we mediate between reality and institutional decisions. And it is in this spirit that the true research question is better stated as <em>how to create epistemic resilience in cybersecurity governance</em>.</p><p>Essentially this is a call to action for the academic and professional community to treat epistemic integrity as a formal requirement of modern security. Surely this call must go beyond merely cybersecurity and extend to the entire space of information sciences. But for us in cybersecurity, we must embrace the call to protect not only systems and data but the epistemic foundations that allow us to understand threats in the first place.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://michaelcorn.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://michaelcorn.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I have to confess that I&#8217;m struck by this phrase, &#8220;erosion of reality&#8221; - it seems to imply that the lies we are told actually do change reality. Which feels like a surrender, acknowledging the concrete power of the lie and the liars. But if we&#8217;ve learned no other lesson from the last decade, it is that lies do have power, the power to shape how people view, see, understand, and respond to the world. We valorized it as &#8216;marketing,&#8217; but as we now see, it pathologizes everything it touches.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>For example, attribution disputes, threat actor naming, geopolitical framing, intelligence confidence levels, and risk prioritization all operate in the interpretive layer. Signals may be empirical, but knowledge about those signals is socially mediated.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>This is why so many organizations struggle with MSSPs (managed security service providers) who use intrusion detection systems to produce a flood of low value alerts to the customer organization. Most of which get tossed with scarcely a glance.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>These truly are just the first two examples that popped into my head. I&#8217;m sure there are better ones.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p><a href="https://www.pbs.org/newshour/politics/trump-asked-russia-to-find-clintons-emails-on-or-around-the-same-day-russians-targeted-her-accounts">https://www.pbs.org/newshour/politics/trump-asked-russia-to-find-clintons-emails-on-or-around-the-same-day-russians-targeted-her-accounts</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>I&#8217;ll probably have a post up on this before too long.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>For decades, anyone driving through much of the country has been subjected to a blanket of right-wing radio: conspiracy theories, voter fraud, patriotism defined by guns and Jesus, and racist anti-welfare themes. This is no longer the fringe, but federal policy and it saturates every form of media.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>Part of what allows the misinformation sphere to thrive is the sheer amount of work it takes to counter it. There is a cost to verification. For us professionally, it means that if we can&#8217;t trust the norms, every professional has to verify everything from scratch. This creates an &#8220;authentication tax.&#8221; I suspect our reference librarian colleagues have been paying this tariff for decades.</p></div></div>]]></content:encoded></item></channel></rss>