top of page

The Red Thread Weekly Wrapup: Issue #14

Jul 2
4 min read

Updated: Sep 8

Categories: IT Risk Management | Information Security | Penetration Testing


I was recently reviewing a contract for a mid-market manufacturing firm that had just hired their first dedicated security lead. They were proud of the move, and they should be. But when I looked at the job description, it covered everything from firewall management and cloud architecture to PCI compliance and employee training. It was a classic example of a problem I see across almost every industry right now: we are asking single individuals to be an entire department. This week has been a reminder that whether you are a university with half a million records or a local business, the gap between what we expect our systems to do and what they actually do is widening.

The 14-Day Blind Spot

The recent breach at the University of Nottingham involving Oracle PeopleSoft is a sobering case study in why the traditional annual audit is failing. Between May 27 and June 9, a vulnerability existed that no one: not the vendor, not the university, and certainly not their auditors: knew about until it was too late. This 14-day gap allowed an extortion group to walk away with nearly half a million student records.

When I talk to CFOs about risk, they often point to their last assessment report as a shield. But a report is a snapshot of a single moment in time. If that snapshot was taken on May 20, it would have shown a perfectly healthy environment. Seven days later, the world changed. We have to move toward a model where assessments are the baseline, not the ceiling. If your organization is only looking at its technical debt once a year, you are essentially leaving the front door unlocked for 364 days and hoping no one tries the handle. This is why broken risk assessments are such a liability; they provide a false sense of security that evaporates the moment a zero-day appears.

A minimalist dark boardroom scene with a glowing red digital clock highlighting a 14-day range on a black table.

The Utility Infielder Problem

In baseball, a utility infielder is a valuable asset because they can play any position in a pinch. In cybersecurity, the utility infielder is a single point of failure. I frequently see organizations with one person managing six or more security domains. They are the architect, the analyst, the compliance officer, and the help desk all at once.

This is not a strategy; it is a recipe for burnout. When one person is stretched across that many disciplines, they cannot possibly go deep enough into any one of them to catch the subtle anomalies that signal a breach. More importantly, if that person leaves, they take the keys to the kingdom with them. I have seen 26 years of institutional knowledge walk out the door because a board refused to invest in a team or a partner to provide continuity. If your security program relies on the heroics of one person, you don't have a program; you have a ticking clock. True resilience comes from continuous collaboration rather than parachuting in a single expert to solve every problem.

A lone figure stands at a dark boardroom table with multiple red silhouettes overlapping behind them, representing multiple roles.

Moving Beyond "Don’t Click on Shit"

We have spent a decade forcing employees to watch boring ten-minute videos once a year, only to act surprised when they still click on a malicious link in a high-pressure moment. The reality is that annual phishing training is dead. It is too infrequent to change behavior and too generic to be effective.

The shift I am seeing, and one I advocate for, is toward gamification. We need to move from "don't click on shit" as a demand to a culture where identifying a threat is a rewarded skill. When you make security a game: where employees are challenged in real-time with simulated, relevant threats and given immediate positive feedback: you turn your staff into a human firewall. Your team sees more than your software ever will. They know when a vendor’s tone seems slightly off or when a request for a wire transfer feels uncharacteristic. If you understand the intelligence behind your delivered mail, you realize that the goal isn't just to stop the click; it's to build a workforce that understands why the click matters to the company’s bottom line.

A minimalist high-tech visualization of a glowing red fishhook made of data streams in a black void.

From the Basement to the Boardroom

For a long time, the person in charge of security was the "cyber guy" in the basement. They were treated as a cost center, a technical hurdle to be cleared so the "real" business could get done. That era is over. The modern security lead must be a business risk advisor.

If you are a CEO or a COO, you shouldn't be talking to your security team about patches and protocols. You should be talking about business continuity, liability, and reputation. When a breach happens, the board doesn't ask about the technical specifications of the firewall; they ask how much money was lost and who is responsible. This transition requires a shift in language. We have to stop talking in jargon and start talking in terms of risk appetite and strategic alignment. The goal is to move security from a technical silo into the heart of the boardroom. It is about closing the authority gap so that security is no longer an afterthought, but a core component of how the business grows and survives in an increasingly volatile digital landscape.

A transition from a dark industrial basement with server racks to a sleek modern boardroom, separated by a thin red line.

The thread connecting these topics is simple: we cannot keep doing things the way we did five years ago. Whether it is managing a zero-day gap, supporting an overworked lead, or training a workforce, the old methods are no longer sufficient for the speed at which threats evolve.

If you are wondering if your current risk strategy is a baseline or a ceiling, it might be time for a different kind of conversation.

Comments


bottom of page