<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Out of Band]]></title><description><![CDATA[Untangling the web of research, reporting, and AI-generated slop for cybersecurity practitioners and leaders.]]></description><link>https://www.outofband.bootstrapcyber.com</link><image><url>https://substackcdn.com/image/fetch/$s_!znUS!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F531047d8-6464-4aa1-8b87-2dda120cc712_1200x1200.png</url><title>Out of Band</title><link>https://www.outofband.bootstrapcyber.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 25 Jul 2026 13:51:16 GMT</lastBuildDate><atom:link href="https://www.outofband.bootstrapcyber.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Laura Kenner]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[laurakenner@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[laurakenner@substack.com]]></itunes:email><itunes:name><![CDATA[Laura Kenner]]></itunes:name></itunes:owner><itunes:author><![CDATA[Laura Kenner]]></itunes:author><googleplay:owner><![CDATA[laurakenner@substack.com]]></googleplay:owner><googleplay:email><![CDATA[laurakenner@substack.com]]></googleplay:email><googleplay:author><![CDATA[Laura Kenner]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Cybersecurity Job Market's Convenient Fictions]]></title><description><![CDATA[Why an industry that says it's desperate for talent keeps cutting people loose.]]></description><link>https://www.outofband.bootstrapcyber.com/p/the-cybersecurity-job-markets-convenient</link><guid isPermaLink="false">https://www.outofband.bootstrapcyber.com/p/the-cybersecurity-job-markets-convenient</guid><dc:creator><![CDATA[Laura Kenner]]></dc:creator><pubDate>Thu, 09 Jul 2026 20:00:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SiV3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SiV3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SiV3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!SiV3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!SiV3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!SiV3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SiV3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:877803,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.outofband.bootstrapcyber.com/i/206335053?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SiV3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!SiV3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!SiV3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!SiV3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdae64ce-b025-4379-b30d-9e2d0ba10615_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>The Paradox</span></strong></h2><p><span>Cybersecurity has a jobs problem, and it isn&#8217;t the one the industry keeps telling you about.</span></p><p><span>Open LinkedIn on any given week and you&#8217;ll see two stories running side by side, as if they have nothing to do with each other. One says the field is short 4.8 million people and begging for talent. The other is a layoff announcement. Sometimes they&#8217;re posted by the same company, in the same quarter. I&#8217;ve stopped being surprised by it. I&#8217;ve started being angry about it.</span></p><p><span>I do this research because I think the people trying to build a career in this field deserve better than what they&#8217;re currently getting, which is a mix of recycled statistics, vendor talking points, and advice from people who have something to sell them. I have no course to sell. No certification bootcamp, no &#8220;10x your resume in 30 days&#8221; program, no affiliate link waiting at the bottom of this piece. What I have is a degree I paid for, a research background I actually enjoy using, and a low tolerance for organizations that say one thing publicly while their own numbers say another. If that makes this piece less comfortable for a few well-known names in this industry, so be it. I&#8217;d rather be useful to the person reading this than popular with the people I&#8217;m writing about.</span></p><p><span>Here&#8217;s the paradox in the numbers everyone already cites. Indeed&#8217;s Hiring Lab has security postings sitting at 113% of their pre-pandemic baseline. It&#8217;s the only major tech category still above where it was in February 2020 [1]. CyberSeek tracks over half a million open cybersecurity roles in the U.S. alone [2]. The Bureau of Labor Statistics projects 29% growth for information security analysts through 2034, with a median salary north of $124,000 [3]. Read those three numbers on their own, and cybersecurity looks like the last stable island in a tech industry that&#8217;s otherwise cutting headcount everywhere you look.</span></p><p><span>Now read the same industry&#8217;s own workforce data. ISC2&#8217;s 2025 Cybersecurity Workforce Study surveyed over 16,000 practitioners. It found that 32% of large organizations reported layoffs in the past year. 46% reported budget cuts. 49% reported hiring freezes. 41% froze promotions [4]. That&#8217;s nearly half the field&#8217;s largest employers pulling back at the exact moment the industry&#8217;s own marketing insists they&#8217;re desperate to hire.</span></p><p><span>Both of those pictures can&#8217;t true at the same time. I get that the answer is more nuanced and complicated than cherry-picked stats. But complicated isn&#8217;t the same thing as unknowable. I think a lot of the confusion here originates with the people who benefit from it staying confusing. I&#8217;m here to call out who has spent years telling us a version of the truth that happens to boost their bottom line, ie. the organizations who profit off the fantasy. </span></p><p><span>None of this is a case against working in cybersecurity. It&#8217;s a case against believing what you&#8217;re told about working in cybersecurity without asking who&#8217;s telling you, and what they get out of it if you believe them.</span></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><span data-color="#ff00ff" style="color: rgb(255, 0, 255);">Thanks for reading Out of Band! Subscribe for free to receive new posts and support my work.</span></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong><span>The Number That Wasn&#8217;t What It Said It Was</span></strong></h2><p><span>Every cybersecurity recruitment page you&#8217;ve seen probably cites the same number: &#8220;4.8 million unfilled jobs, global, and growing.&#8221; It comes from ISC2&#8217;s Cybersecurity Workforce Study, the largest and most frequently cited survey of the profession. It&#8217;s also a gross misrepresentation of reality.</span></p><p><span>That number is the result of ISC2 researchers asking survey respondents, mostly hiring managers and security leaders, how many additional people their organization would need to </span><em><span>feel fully secure</span></em><span>. The response gets aggregated against an estimate of the existing workforce, and the difference becomes &#8220;the gap.&#8221; It&#8217;s a measure of aspiration, </span><strong><span>not a count of open job requisitions</span></strong><span>. ISC2&#8217;s own CISO, Jon France, said as much on the record in </span><a href="https://www.darkreading.com/vulnerabilities-threats/cybersecurity-workforce-peaked"><span>Dark Reading</span></a><span>: &#8220;For clarity, that doesn&#8217;t mean there is 4.8 million jobs out there&#8221; [5]. He described it instead as an estimate of how much the profession would need to grow to reach the security level respondents believe is necessary.</span></p><p><span>That distinction sat mostly unchallenged for years. It started to crack in October 2024, when Ira Winkler, CISO at CYE, wrote an </span><a href="https://www.infosecurity-magazine.com/news/isc2-gaps-cybersecurity-leadership/"><span>open letter to ISC2&#8217;s board</span></a><span>. Winkler had spent time talking with unemployed cybersecurity professionals frustrated by headlines promising abundant work they couldn&#8217;t find. His letter accused ISC2 of knowingly pushing a false narrative of a plentiful job market [6]. Ben Rothke, a senior information security manager at Experian, made a related point publicly. He tied the criticism directly to the marketing that fuels get-rich-in-cybersecurity training programs [7]. Jon Brandt at ISACA added the practical rebuttal. People can respond to any survey and say they need twenty more people, he said, but unless an organization is actively hiring, that isn&#8217;t a data point worth weighing [8].</span></p><p><span>ISC2 heard the criticism. The </span><a href="https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study"><span>2025 Cybersecurity Workforce Study</span></a><span>, based on a record 16,029 respondents, dropped the workforce gap estimate entirely. The organization reframed the conversation around critical skills needs instead of headcount [9]. Read plainly, that&#8217;s a walk-back. A body with real influence over how tens of thousands of career decisions get made quietly retired its most quoted statistic after practitioners called it out in public.</span></p><p><span>This doesn&#8217;t mean cybersecurity teams are fully staffed, or that hiring is easy. </span><a href="https://app.stationx.net/articles/cybersecurity-skills-gap-statistics"><span>StationX&#8217;s breakdown</span></a><span> of the available data separates what&#8217;s actually being measured into three different problems that keep getting collapsed into one number. A skills gap exists in specific technical areas. A staffing gap is driven mostly by budget rather than a lack of candidates. And a hiring gap shows up wherever employers demand years of experience for roles labeled entry-level [10]. Those are three distinct issues with three distinct solutions. None of them get solved by more people earning a degree or a cert on the promise of a shortage that isn&#8217;t quite what it claims to be.</span></p><p><span>The </span><a href="https://www.csis.org/analysis/cybersecurity-workforce-gap"><span>Center for Strategic and International Studies</span></a><span> raised a version of this same concern years before Winkler&#8217;s letter went public. Their analysis questioned whether cybersecurity workforce development programs and education pipelines were preparing people for the roles the field claims to need [11]. The pattern isn&#8217;t new. What changed is that practitioners finally pushed back enough that the organization behind the number had to answer for it.</span></p><h2><strong><span>&#8220;AI Did It,&#8221; Cybersecurity&#8217;s Version of a Bigger Story</span></strong></h2><p><span>Cybersecurity isn&#8217;t running its own show here. It&#8217;s playing a smaller part in a much bigger production, and the script was written well before anyone in this industry picked up a copy.</span></p><p><span>Between January and June 2026, Challenger, Gray &amp; Christmas tracked U.S. tech employers announcing 139,156 job cuts, an 83% jump over the same period in 2025. AI was named as the reason for four consecutive months, a streak the outplacement firm says has no precedent in its data [12]. Read those layoff announcements and you&#8217;d think artificial intelligence had suddenly become capable of doing the work of six-figure engineers and analysts overnight. Read the people who study labor markets for a living, and a different story shows up.</span></p><p><span>Sam Altman called it &#8220;AI washing.&#8221; He&#8217;s acknowledged that almost every company doing layoffs blames AI whether AI is actually the reason or not [14]. Marc Andreessen was more blunt about the mechanism. He argued companies are using AI as a &#8220;silver bullet excuse&#8221; for correcting pandemic-era overhiring, staffing he estimates left large tech firms 25 to 75 percent overstaffed [13]. Wharton&#8217;s Peter Cappelli explained that companies say AI will cover the work, but most of them haven&#8217;t confirmed that it will. They&#8217;re hoping it does [15]. Deutsche Bank saw this coming in January 2026, predicting that &#8220;AI redundancy washing&#8221; would define the year [16].</span></p><p><span>The receipts back up the skeptics more than the headlines do. Gartner surveyed 350 executives at companies actively deploying AI in May 2026 and found that the firms cutting headcount the most showed no better financial returns than the firms cutting the least. Some of the companies that cut the least actually outperformed the heaviest cutters [17]. Meta is a clean example of the underlying math. The company grew from 48,000 employees in the first quarter of 2020 to more than 87,000 by the third quarter of 2022, hiring aggressively through the zero-interest-rate years before the cuts started. That overhiring needed correcting whether or not a single AI model ever entered the building [18].</span></p><p><span>None of this is abstract for the people losing their footing in cybersecurity specifically. Marketplace&#8217;s reporting followed Megan Osteen, a career-changer who did the coursework, earned a certification, and still couldn&#8217;t find an opening. It also followed JVS, a Bay Area job training nonprofit that pivoted into cybersecurity training when entry-level IT work dried up and is now questioning whether to keep the program running at all [19].</span></p><p><span>Go back to what ISC2&#8217;s own 2025 workforce data showed. Budget cuts overtook talent scarcity as the leading cause of staffing shortages for the first time the study has tracked it [4]. That&#8217;s the same story playing out inside cybersecurity&#8217;s own numbers, just with a security badge pinned to it instead of a general tech one. Companies aren&#8217;t cutting security analysts because a model learned to do their job. They&#8217;re cutting them because the same budget pressure hitting every other tech function is hitting this one too, and &#8220;AI&#8221; is a more comfortable line to put in a press release than &#8220;we hired too many people and now we&#8217;re fixing it.&#8221;</span></p><h2><strong>The On-Ramp is What&#8217;s Actually Collapsing</strong></h2><p>Here&#8217;s where I think a lot of the panic gets aimed at the wrong target. The question people keep asking is whether AI will replace cybersecurity. The better question is what happens to the bottom rung of the ladder once AI can do most of what used to live there?</p><p>Let&#8217;s start with what&#8217;s shrinking. Entry-level cybersecurity postings, the ones asking for under a year of experience, fell from 25% of listings in 2022 to 17% today. Only 15% of new cybersecurity hires are people starting their careers for the first time. More than half, 52%, come from inside the existing talent pool, people already working in cybersecurity moving to a new role. Another 28% convert in from adjacent, non-cyber jobs [20]. Add those together and new entrants are competing for a sliver of a sliver.</p><p>Practitioners see it happening too. In one survey, 52% of cybersecurity professionals said they expect AI to reduce demand specifically for entry-level roles like Tier 1 SOC analysts, the job most people use as their first foothold in the field. Only 2% think AI will eliminate the cybersecurity profession outright [21]. That gap is the difference between a field contracting and a field reshaping itself at the bottom while staying intact everywhere else.</p><p>There&#8217;s a more optimistic read of the same data. An ISC2-linked workforce survey found that 44% of organizations are reconsidering roles and skill requirements because of AI tool adoption, but 31% think AI adoption could create new entry-level roles rather than eliminate them, work adjacent to monitoring and validating AI tools that didn&#8217;t exist before those tools did [22]. This shift is happening in real time and the dust has not settled. No one can be certain right now what the AI-powered workforce will look like, let alone how it will be reflected in job titles.</p><p>Job postings are a harder thing to argue with than survey sentiment, though. InterviewStack analyzed 5,379 active cybersecurity engineer postings in June 2026 and found that AI-skill requirements show up in 17% of senior and staff-level postings, compared to 9.3% of entry-level ones [23]. If AI skills were genuinely opening a new front door for beginners, you&#8217;d expect that ratio to run the other way. Instead, the people being asked to bring AI fluency to the job are mostly the people who already have the job.</p><p>Cybersecurity isn&#8217;t disappearing. The on-ramp into it is.</p><h2><strong>Nobody Is Tracking Whether the Pipeline Actually Works</strong></h2><p><span>The &#8220;on-ramp&#8221; to a career in cyber is often linked to achieving a degree in the discipline. Which begs the question, of everyone who&#8217;s earned a cybersecurity degree in the last several years, how many are actually working in cybersecurity? I went looking for a real answer. What I found instead is that nobody appears to have built the instrumentation to know.</span></p><p><span>The closest thing to an authoritative source is a federal report from NCSES, the National Center for Science and Engineering Statistics, produced through RTI International. It&#8217;s the kind of unglamorous government research that doesn&#8217;t get cited in recruitment marketing, and reading it, it&#8217;s easy to see why. The report states plainly that only 46% of people working in cybersecurity core occupations hold a degree closely related to their field of work [24]. More than half of the people currently doing this job didn&#8217;t get there through a cybersecurity degree at all.</span></p><p><span>The same report goes further. Its authors warn that counting cybersecurity graduates as a measure of workforce supply likely overestimates the actual pipeline, because completing a cybersecurity degree doesn&#8217;t mean that person ever works in cybersecurity [24]. The federal government&#8217;s own researchers are telling us that the numbers schools and certification bodies use to justify the shortage narrative don&#8217;t hold up under their own methodology.</span></p><p><span>Meanwhile, more people are enrolling than ever. Program completions across all cybersecurity award levels grew from 10,013 in 2016 to 23,746 in 2021, a roughly 19% average annual growth rate that outpaces general degree program growth by a wide margin [25]. More students are walking in the front door of these programs every year. </span><em><span>Nobody is tracking, in any rigorous public way, how many of them walk out the other side into an actual cybersecurity job.</span></em></p><p><span>I&#8217;ll put myself in this data, because I have a cybersecurity degree, circa 2022, but I never became a SOC analyst, a penetration tester, or an incident responder. Instead I landed in technical marketing for a cybersecurity vendor, work I genuinely love and I&#8217;m good at, but not what most people enrolling in these programs picture when they sign up. I got lucky, and I found a lane that used what I learned without requiring me to compete for the shrinking entry-level technical roles. Most people don&#8217;t get that lane handed to them. What they get instead is a degree, a stack of student loans, and a job search that never quite lands where the brochure said it would.</span></p><p><span>This is structural failure in a broken system, and it&#8217;s the missing piece in every conversation about the cybersecurity shortage. The industry has spent years measuring how many people it needs. It has never bothered measuring what happens to the people who show up.</span></p><h2><strong><span>The Schools Selling the Credential Won&#8217;t Publish Their Own Results</span></strong></h2><p><span>There are a handful of schools that show up constantly in cybersecurity career search results and ads when someone searches &#8220;cybersecurity degree online.&#8221; Top of my mind are University of Maryland Global Campus, University of Phoenix, Southern New Hampshire University, and Western Governors University. UMGC is my alma mater. I paid for that degree, and I still believe it was worth doing. But, I&#8217;m not willing to look away from what these schools do and don&#8217;t tell prospective students about what their money actually buys them. Spoiler: it&#8217;s not likely an entry-level role in cybersecurity.</span></p><p><span>Three of the four use nearly identical language to avoid saying anything specific. University of Phoenix&#8217;s cybersecurity careers page states that its cited salary ranges are not specific to students or graduates, and that the university offers no guarantee of &#8220;employment, salary level or career advancement&#8221; [27]. UMGC doesn&#8217;t publish a placement rate or a starting-salary figure for its cybersecurity programs at all. Its marketing leans instead on its NSA-designated Center of Academic Excellence status and an EC-Council partner-of-the-year award [28]. SNHU repeats a nearly identical line across at least four separate program pages, stating that its cited projections aren&#8217;t based on SNHU graduate outcomes and don&#8217;t guarantee actual salary or job growth [29]. That kind of identical, boilerplate language across a school&#8217;s entire site usually isn&#8217;t a voluntary transparency choice. It reads like standardized compliance language, the minimum a school has to say to satisfy federal disclosure rules, dressed up next to national growth statistics that have nothing to do with anyone who actually attended.</span></p><p><span>WGU is the more interesting case, because WGU does publish something. Its retention and graduation page cites a 2024 Harris Poll finding that 87% of graduates report being employed in their degree field, along with a 94% employer satisfaction figure and a 97% rehire-willingness figure [30]. On the surface, that looks like real disclosure, more than the other three schools combined. Then you find the footnote on WGU&#8217;s own cybersecurity program page, sitting right next to that same statistic. It cites a 2024 Harris Poll of 1,655 WGU graduates, and specifies that the survey was sent to &#8220;a representative sample of WGU graduates from all colleges&#8221; [35]. WGU is telling you, in its own words, on the cybersecurity page itself, that the number wasn&#8217;t measured for cybersecurity students. It&#8217;s an institution-wide figure covering business, nursing, teaching, and IT alike, borrowed and placed under a cybersecurity headline as if it belonged there.</span></p><p><span>The federal earnings data that does exist tells a partial story. College Scorecard-derived figures put UMGC&#8217;s Computer Information Systems bachelor&#8217;s graduates at a median of $75,619, above the $61,300 national median for that major. SNHU&#8217;s come in lower, $61,322 for a bachelor&#8217;s and $76,081 for a master&#8217;s. WGU&#8217;s sit highest of the four at $84,242 for the same bachelor&#8217;s category. University of Phoenix&#8217;s numbers vary so much by campus that some of them are built on cohorts of two graduates, which makes &#8220;median&#8221; a technically true but practically meaningless word here [31]. None of these figures isolate cybersecurity specifically. They&#8217;re Computer Information Systems numbers, a broader category that cybersecurity sits inside, because the federal government&#8217;s own data doesn&#8217;t cleanly separate out cybersecurity outcomes any better than these schools do.</span></p><p><span>The bottom line here is that four of the most heavily marketed cybersecurity degree programs in the country cannot show you verified data on what happens to their cybersecurity graduates specifically. Three hide behind a disclaimer. One borrows a number that was never about cybersecurity in the first place and lets you assume otherwise. My own degree came from one of these four schools, and even I can&#8217;t tell you, from anything they&#8217;ve published, how many people who sat in my classes ended up doing this work.</span></p><h2><strong><span>Who&#8217;s Selling the Gap</span></strong></h2><p><span>The schools aren&#8217;t the only ones with a stake in keeping the shortage story alive. I want to widen the lens here, because I&#8217;ve been citing one particular data source throughout this piece without saying who&#8217;s actually behind it. CyberSeek, the tool that tracks over half a million open U.S. cybersecurity jobs, the number I used back in Section 1, is a collaboration between Lightcast, NIST, and CompTIA [36]. CompTIA is a certification-selling trade association. The same organization co-producing the &#8220;neutral&#8221; job-opening count everyone cites, including me, also sells Security+, the certification most frequently recommended as the fix for that opening count. It&#8217;s worth knowing before you treat any single number in this space as disinterested.</span></p><p><span>EC-Council runs the same play from the education side. The organization named UMGC its Academic Partner of the Year in 2023 [37], the same year it was selling the Certified Ethical Hacker exam that UMGC&#8217;s curriculum is partly built around. ISC2, already covered in Section 2, deserves a second mention here. The organization that had to walk back its own 4.8 million figure is also the body behind the CISSP, the single most requested certification in cybersecurity job postings [38]. It&#8217;s diagnosing the shortage and selling the credential meant to fix it, twice over, from the same source.</span></p><p><span>Bootcamps follow the university playbook almost exactly, just with shorter timelines and better marketing copy. Industry-wide figures circulated by Course Report and the NACE Early Career Salary Survey claim 70 to 80 percent job placement within six months, with median starting salaries between $50,000 and $65,000 [39]. Those numbers come from the bootcamps themselves. Nobody outside the industry audits them. It&#8217;s the identical structural problem from Section 6, just wearing a hoodie instead of a cap and gown.</span></p><p><span>That pattern shows up at the individual level too. Evan Lutz built a following in the early 2020s teaching people a specific roadmap: get a Security+ certification in a couple of months, walk in with zero experience, land sixty thousand dollars a year. He&#8217;s said publicly that </span><em><span>the roadmap he built his name on no longer works</span></em><span> [40]. I respect that he corrected course when faced with current reality. Most of the people still selling variations of that same roadmap haven&#8217;t.</span></p><p><span>Search &#8220;how to break into cybersecurity&#8221; and most of what comes back reads like career advice. Read it closely and a lot of it is course marketing wearing blog post clothing [41]. The incentive is the same one running through every section of this piece so far. Convince someone the door is narrower than it is, or wider than it is, whichever version sells more seats.</span></p><p><strong><span>The most expensive bet in the industry.</span></strong></p><p><span>One of these certification factories has been pawning courses at outrageous prices and getting away with it for a very long time. I&#8217;m looking at you, SANS. </span></p><p><span>A single SANS course bundled with its matching GIAC certification runs roughly $9,779, before renewals [42]. SANS&#8217;s own institute arm, SANS.edu, charges $41,650 for a two-year bachelor&#8217;s degree and up to $22,800 for a graduate certificate [43]. </span><em><span>A full year of in-state tuition at most public universities costs less than a single SANS course. </span></em><span>Plus, SANS doesn&#8217;t discount the way most training vendors do. One analysis of the pricing pointed out that this training is realistically priced for the person whose company pays for it, not the person paying for it themselves [44]. That&#8217;s a telling admission. This isn&#8217;t a product built for the job seeker paying out of pocket. It&#8217;s a product built for corporate training budgets, marketed as though an individual could reasonably afford it.</span></p><p><span>In 2026, SANS&#8217;s own workforce report named skills gaps, not headcount, as the industry&#8217;s biggest challenge for the first time in the report&#8217;s three-year history [45]. Read that next to the price tag. </span><em><span>The organization sounding the loudest alarm about a widening skills gap sells one of the most expensive fixes for it in the entire industry.</span></em></p><p><span>None of this means certifications are worthless or that bootcamps never work. Some of them do, for some people. What it means is that almost every voice telling you how urgent this shortage is, and how fast you need to move to close it, has a seat to sell you. That makes them a source you should read the same way you&#8217;d read a car salesman&#8217;s opinion on whether you need a new car.</span></p><h2><strong><span>Still Want a Job in Cyber? Here&#8217;s How.</span></strong></h2><p><span>If you&#8217;ve read this far, you might reasonably ask whether I think anyone should still try to break into cybersecurity right now. My honest answer is, not without a backup plan. Don&#8217;t treat it as your only bet. The entry-level door is narrower than the marketing says, and pretending otherwise doesn&#8217;t help anyone walk through it faster. What I can tell you is what actually seems to move the needle for the people who are getting hired in this market, based on who&#8217;s saying it and how they&#8217;re saying it.</span></p><p><span>Start with the bar itself, because it moved. Matthew Hartman at Merlin Group put it well when he told Dice that the bar for entry has risen. Employers now want candidates who can show hands-on experience and apply AI tools in practical ways, not just recite what a certification taught them [46]. That&#8217;s a real shift, and it&#8217;s a fair one to be frustrated by. It&#8217;s also not optional to ignore.</span></p><p><span>Evan Lutz, the coach I mentioned earlier who&#8217;s walked back his own old roadmap, is proof that the people closest to this market are recalibrating in public. Take that as a signal, not a discouragement.</span></p><p><span>Dr. Gerald Auger, who&#8217;s spent over twenty years in this field, gives advice that I wholly agree with based on my own experience. Hands-on work and genuine community presence beat chasing another certification. Common mistakes he warns against are relying too heavily on job boards, and underinvesting in personal brand and networking [47]. I&#8217;d add one more, based on everything I&#8217;ve learned. Don&#8217;t assume a degree alone is the credential that opens doors. It&#8217;s one input among several, not the whole plan.</span></p><p><span>There&#8217;s a portfolio argument worth taking seriously too. The strongest candidates aren&#8217;t the ones with the most certifications stacked on a resume. They&#8217;re the ones who can produce bounded, specific technical work that another practitioner could review and trust: a documented detection, a real authorization test, a clean technical write-up [48]. That&#8217;s harder to fake than a cert, and it&#8217;s harder to automate away than a checklist.</span></p><p><span>Here&#8217;s where I&#8217;ll say something as a marketer, because it&#8217;s the truth and I live it every day. The job search method that works right now isn&#8217;t throwing applications into an AI-flooded hiring pipeline and hoping volume wins. You have to show up consistently in the rooms where people in this field talk to each other, online and off, and let your work speak before you ever ask anyone for anything. Warm introductions get read. Cold applications get filtered by a system built to filter them. What we marketers call &#8220;personal brand&#8221; is really your professional reputation and you build that by engaging with people in the community, contributing to the conversations, and yes, once in a while giving yourself a public pat on the back for your achievements. It&#8217;s the mechanism that still works when everything else in this market is working against you.</span></p><p><span>None of that is a guarantee. Nothing in this piece has been. But if you&#8217;re going to bet real time and real money on breaking into this field, bet on the things that are still true. Hands-on proof over credentials. Relationships over resumes. A backup income plan while you build both.</span></p><h2><strong><span>The Moral of The Story</span></strong></h2><p><span>Every organization named in this piece would tell you they value evidence over hype. That&#8217;s the entire professional identity cybersecurity has built for itself. Read the data, follow the threat, don&#8217;t trust a claim you can&#8217;t verify. I&#8217;m holding them to their own standard.</span></p><p><span>I&#8217;m not the first person to say any of this out loud. Ira Winkler wrote an open letter to ISC2&#8217;s board, and the organization walked back its own headline number within a year. Ben Rothke put his name on a public critique of the training-marketing machine and kept his job at Experian. Neither of them got run out of the industry for saying what a lot of people were already thinking.</span></p><p><span>I know some people reading this are afraid to say any of it themselves. Their employer might be a partner of one of the organizations named here. Their own credentials might come from the certification body they&#8217;d be criticizing. The conference that pays their travel budget every year might stop inviting them to speak. Cybersecurity is a smaller industry than it looks from the outside, and burning a bridge with a group like ISC2 or SANS can follow you for years.</span></p><p><span>I get it. I&#8217;m just not going to let that fear be the reason nobody writes this down, with the sources attached.</span></p><p><span>If you&#8217;re building a career in cybersecurity, or thinking about starting one, you deserve the real picture and not the one that happens to be good for enrollment numbers or certification revenue. Now you have a fuller view and can make informed career decisions of your own.</span></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><span data-color="#ff00ff" style="color: rgb(255, 0, 255);">Thanks for reading Out of Band! Subscribe for free to receive new posts and support my work.</span></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong><span>References</span></strong></h2><p><span>[1] StationX, &#8220;Cybersecurity Job Market Statistics and Trends [2026],&#8221; StationX, 2026. [Online]. Available: https://app.stationx.net/articles/cybersecurity-job-market-statistics</span></p><p><span>[2] CyberSeek data, cited in Programs.com, &#8220;How Many Cybersecurity Job Openings Are There? (2026),&#8221; 2026. [Online]. Available: https://programs.com/resources/open-cybersecurity-jobs/</span></p><p><span>[3] U.S. Bureau of Labor Statistics, &#8220;Information Security Analysts,&#8221; Occupational Outlook Handbook, 2026. [Online]. Available: https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm</span></p><p><span>[4] ISC2, &#8220;2025 Cybersecurity Workforce Study,&#8221; Dec. 2025. [Online]. Available: https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study</span></p><p><span>[5] Dark Reading, &#8220;Has the Cybersecurity Workforce Peaked?&#8221; Nov. 2024. [Online]. Available: https://www.darkreading.com/vulnerabilities-threats/cybersecurity-workforce-peaked</span></p><p><span>[6] Infosecurity Magazine, &#8220;ISC2 Survey Reveals Critical Gaps in Cybersecurity Leadership Skills,&#8221; Dec. 2025. [Online]. Available: https://www.infosecurity-magazine.com/news/isc2-gaps-cybersecurity-leadership/</span></p><p><span>[7] Dark Reading, op. cit. [5] (B. Rothke commentary).</span></p><p><span>[8] Dark Reading, op. cit. [5] (J. Brandt, ISACA, commentary).</span></p><p><span>[9] ISC2, op. cit. [4].</span></p><p><span>[10] StationX, &#8220;Cybersecurity Skills Gap Statistics [2026]: The Real Data,&#8221; 2026. [Online]. Available: https://app.stationx.net/articles/cybersecurity-skills-gap-statistics</span></p><p><span>[11] Center for Strategic and International Studies, &#8220;The Cybersecurity Workforce Gap.&#8221; [Online]. Available: https://www.csis.org/analysis/cybersecurity-workforce-gap</span></p><p><span>[12] TechTimes, &#8220;AI Leads US Job Cuts for Record 4th Month as Tech Claims 31% of H1 Layoffs,&#8221; Jul. 2026. [Online]. Available: https://www.techtimes.com/articles/319588/20260703/ai-leads-us-job-cuts-record-4th-month-tech-claims-31-h1-layoffs.htm</span></p><p><span>[13] TechTimes, op. cit. [12] (M. Andreessen commentary).</span></p><p><span>[14] TechTimes, op. cit. [12] (S. Altman commentary).</span></p><p><span>[15] TechTimes, op. cit. [12] (P. Cappelli commentary).</span></p><p><span>[16] TechTimes, op. cit. [12] (Deutsche Bank analyst commentary).</span></p><p><span>[17] TechTimes, &#8220;Tech Layoffs Hit 1,115 a Day in 2026: Companies Cite AI but Cuts Fail to Boost Returns,&#8221; Jun. 2026. [Online]. Available: https://www.techtimes.com/articles/318466/20260616/tech-layoffs-hit-1115-day-2026-companies-cite-ai-cuts-fail-boost-returns.htm</span></p><p><span>[18] TechTimes, op. cit. [17] (Meta headcount data).</span></p><p><span>[19] Marketplace, &#8220;It&#8217;s a tough time to break into cybersecurity,&#8221; May 2026. [Online]. Available: https://www.marketplace.org/story/2026/05/18/ai-is-making-it-harder-to-get-a-cybersecurity-job</span></p><p><span>[20] Programs.com, &#8220;Cybersecurity Graduate Unemployment &amp; Skills Mismatch Statistics (2026),&#8221; 2026. [Online]. Available: https://programs.com/resources/cybersecurity-graduate-unemployment/</span></p><p><span>[21] AnalyticsInsight, &#8220;How AI is Transforming Cybersecurity Hiring in 2026,&#8221; May 2026. [Online]. Available: https://www.analyticsinsight.net/artificial-intelligence/how-ai-is-transforming-cybersecurity-hiring-in-2026</span></p><p><span>[22] Dark Reading, &#8220;AI Won&#8217;t Wipe-Out Entry-Level Cybersecurity Jobs,&#8221; Jun. 2026. [Online]. Available: https://www.darkreading.com/cybersecurity-operations/ai-wont-wipe-out-entry-level-cybersecurity-jobs</span></p><p><span>[23] InterviewStack, &#8220;Cybersecurity Engineer AI Skills in 2026: Agents Lead, Defense Lags,&#8221; Jun. 2026. [Online]. Available: https://interviewstack.io/blog/how-ai-is-changing-cybersecurity-engineer-2026</span></p><p><span>[24] National Center for Science and Engineering Statistics / RTI International, &#8220;Cybersecurity Workforce Supply and Demand Report.&#8221; [Online]. Available: https://ncses.nsf.gov/760/assets/0/files/ncses-cwdi-supply-demand-report.pdf</span></p><p><span>[25] Gray DI, &#8220;Cyber Breaches Drive Demand For Cybersecurity,&#8221; Dec. 2024. [Online]. Available: https://www.graydi.us/blog/graydata/when-bad-news-is-good-news-cyber-breaches-drive-demand-for-cybersecurity-programs</span></p><p><span>[27] University of Phoenix, &#8220;The Complete Guide to Careers in Cybersecurity and Information Systems.&#8221; [Online]. Available: https://www.phoenix.edu/blog/the-complete-guide-to-careers-in-cybersecurity-and-information-systems.html</span></p><p><span>[28] University of Maryland Global Campus, &#8220;Cybersecurity&#8221; program page. [Online]. Available: https://www.umgc.edu/cybersecurity</span></p><p><span>[29] Southern New Hampshire University, &#8220;Cybersecurity Degree Online Bachelor of Science (BS)&#8221; and &#8220;Is a Cybersecurity Degree Worth It?&#8221; [Online]. Available: https://www.snhu.edu/online-degrees/bachelors/cyber-security ; https://www.snhu.edu/about-us/newsroom/stem/is-a-cybersecurity-degree-worth-it</span></p><p><span>[30] Western Governors University, &#8220;Retention and Graduation Rates at WGU.&#8221; [Online]. Available: https://www.wgu.edu/about/measuring-impact/retention-graduation-rates.html</span></p><p><span>[31] College Factual (College Scorecard-derived earnings data), Computer Information Systems program pages for University of Maryland Global Campus, Southern New Hampshire University, Western Governors University, and University of Phoenix. [Online]. Available: https://www.collegefactual.com/colleges/university-of-maryland-university-college/academic-life/academic-majors/computer-information-sciences/computer-information-systems-cis/ ; https://www.collegefactual.com/colleges/southern-new-hampshire-university/academic-life/academic-majors/computer-information-sciences/computer-information-systems-cis/ ; https://collegefactual.com/colleges/western-governors-university/academic-life/academic-majors/computer-information-sciences/computer-information-systems-cis/bachelors/chart-average-salary.html ; https://www.collegefactual.com/colleges/university-of-phoenix-florida/academic-life/academic-majors/computer-information-sciences/computer-information-systems-cis/</span></p><p><span>[35] Western Governors University, &#8220;Cybersecurity Courses Online &#8211; Bachelor&#8217;s Degree,&#8221; program page footnote citing 2024 Harris Poll methodology. [Online]. Available: https://www.wgu.edu/online-it-degrees/cybersecurity-information-assurance-bachelors-program.html</span></p><p><span>[36] Dark Reading, op. cit. [5] (CyberSeek / CompTIA / Lightcast / NIST collaboration).</span></p><p><span>[37] University of Maryland Global Campus, op. cit. [28] (EC-Council Academic Partner of the Year, 2023).</span></p><p><span>[38] ISC2, op. cit. [4] (CISSP certification data), cross-referenced with StationX, op. cit. [1] (CISSP as most-requested certification in postings).</span></p><p><span>[39] Research.com, &#8220;Cybersecurity Degree vs Bootcamp vs Certificate: Which Path Leads to Better Career Outcomes?&#8221; May 2026. [Online]. Available: https://research.com/advice/cybersecurity-degree-vs-bootcamp-vs-certificate-which-path-leads-to-better-career-outcomes</span></p><p><span>[40] Marketplace, op. cit. [19] (E. Lutz commentary).</span></p><p><span>[41] Pattern observed across vendor &#8220;how to break in&#8221; content, representative examples: FusionCyber (fusioncyber.co) and ITU Online (ituonline.com).</span></p><p><span>[42] Netguardia, &#8220;SANS GIAC Certifications: Which Ones Are Worth the $8K Price Tag?&#8221; Apr. 2026. [Online]. Available: https://netguardia.com/learning-development/certifications/sans-giac-certifications-which-ones-are-worth-the-8k-price-tag/</span></p><p><span>[43] SANS Technology Institute, &#8220;Tuition.&#8221; [Online]. Available: https://www.sans.edu/admissions/tuition</span></p><p><span>[44] Netguardia, op. cit. [42].</span></p><p><span>[45] Industrial Cyber, &#8220;SANS 2026 report flags cybersecurity skills crisis, putting critical infrastructure and OT sectors at measurable breach risk,&#8221; Apr. 2026. [Online]. Available: https://industrialcyber.co/reports/sans-2026-report-flags-cybersecurity-skills-crisis-putting-critical-infrastructure-and-ot-sectors-at-measurable-breach-risk/</span></p><p><span>[46] Dice.com, &#8220;Cybersecurity Careers: Advice for Grads Navigating an AI-Driven Job Market,&#8221; May 2026. [Online]. Available: https://www.dice.com/career-advice/cybersecurity-careers-advice-for-grads-navigating-an-ai-driven-job-market</span></p><p><span>[47] ClearanceJobs, &#8220;Breaking Into Cybersecurity and AI: Career Advice from the Expert,&#8221; Feb. 2026. [Online]. Available: https://news.clearancejobs.com/2026/02/09/breaking-into-cybersecurity-and-ai-career-advice-from-the-expert/</span></p><p><span>[48] Penligent, &#8220;Cybersecurity Jobs in 2026,&#8221; Apr. 2026. [Online]. Available: https://www.penligent.ai/hackinglabs/cybersecurity-jobs-in-2026/</span></p>]]></content:encoded></item><item><title><![CDATA[Forget the Patch. Stop Initial Compromise.]]></title><description><![CDATA[Vulnerabilities are only one way in. Here are five others.]]></description><link>https://www.outofband.bootstrapcyber.com/p/forget-the-patch-stop-initial-compromise</link><guid isPermaLink="false">https://www.outofband.bootstrapcyber.com/p/forget-the-patch-stop-initial-compromise</guid><dc:creator><![CDATA[Laura Kenner]]></dc:creator><pubDate>Wed, 24 Jun 2026 12:00:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!u5bT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u5bT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u5bT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!u5bT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!u5bT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!u5bT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u5bT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:713781,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.outofband.bootstrapcyber.com/i/203328676?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u5bT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!u5bT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!u5bT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!u5bT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe40b53c1-1919-44bd-a711-d328a17376bb_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"></div></div></a></figure></div><p><span>I feel like I&#8217;m stating the obvious here, but stay with me.</span></p><p><span>The industry has spent years building elaborate systems to help organizations figure out which vulnerabilities to patch first. An entire market category worth billions is dedicated to helping teams manage a backlog that only grew faster than they could work through it.</span></p><p><span>Those tools exist precisely because everyone already knew patch-first defense wasn&#8217;t really working. You don&#8217;t build sophisticated triage systems for problems you&#8217;re keeping up with. The whole architecture of modern vulnerability management is, if you squint at it, an admission that we were always losing the race.</span></p><p><span>Mythos made that impossible to ignore. I go into depth in my previous article &#8220;</span><a href="https://www.outofband.bootstrapcyber.com/p/follow-the-research-cybersecurity"><span>Cybersecurity in a Post-Mythos World</span></a><span>,&#8221; if you want more background. The bottom line is, we are never going to patch fast enough. But here&#8217;s what I want to talk about now, because I think a lot of the post-Mythos conversation is missing it.</span></p><p><strong><span>Vulnerability discovery is not how most organizations get breached.</span></strong></p><p><span>The way attackers get in has been evolving for years, and AI just turned up the dial on every vector simultaneously. So while the industry is busy processing the &#8220;vulnpocalypse,&#8221; I want to make sure we&#8217;re also looking at the five other doors attackers are walking through.</span></p><h2><strong><span>You Were Never Going to Patch Your Way Out of This</span></strong></h2><p><span>Of course we still need to patch and perform routine product updates, but more as an exercise in hygiene; not security. Proactive LLM-assisted discovery of vulnerabilities in your own code is probably the way forward here [1]. But, organizing your entire security posture around reactive patching of externally disclosed CVEs is a strategy that was already struggling before AI entered the picture, and now it&#8217;s functionally over.</span></p><p><span>IBM&#8217;s take on the Mythos moment is, &#8220;for the first time in the history of this field, response is now the binding constraint, not discovery.&#8221; [2] When the window between a vulnerability being disclosed and someone weaponizing it is down to hours, a patch cycle measured in days or weeks is not going to save you.</span></p><p><span>Stop treating patching as your primary line of defense. The attackers figured out a long time ago they don&#8217;t have to wait for you to miss one.</span></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><em><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Thanks for reading Out of Band! Subscribe for free to receive new posts and support my work.</mark></em></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong><span>Five Other Doors</span></strong></h2><h3><strong><span>1. The Human Layer</span></strong></h3><p><span>The oldest attack surface there is, and it keeps working because humans are still humans.</span></p><p><span>Phishing. Vishing. Social engineering. Fake websites. Impersonation. AI didn&#8217;t invent any of these. What AI did was remove the friction that made them expensive to run at scale.</span></p><p><span>Before, convincing spear phishing required skilled operators with real time to invest. Deepfakes were nation-state territory. Building a convincing fake site took effort. That&#8217;s all gone now.</span></p><p><span>AI powers over 80% of social engineering activity today [3]. AI-generated phishing emails hit a 54% click-through rate compared to 12% for human-crafted ones. That&#8217;s a 4.5x multiplier at 95% lower cost [4]. Voice cloning from three seconds of audio is a commodity. In 2024, an engineering firm called Arup wired $25.6 million after a video call where everyone on screen except the victim was an AI-generated deepfake [5]. These are old tricks, now with super powers.</span></p><p><span>The fact remains, AI is not yet the root cause of most breaches [6]. The weaknesses AI exploits were already there. It just made the attacks cheaper and more convincing. The doors were already unlocked.</span></p><p><strong><span>What to do:</span></strong><span> Phishing-resistant MFA based on FIDO2 or passkeys &#8212; not app-based TOTP, which is vulnerable to adversary-in-the-middle attacks. Strong identity verification at the help desk that goes beyond knowledge-based questions. Out-of-band verification for high-value financial transactions, because voice and video are no longer reliable identity signals. The defense exists and is underdeployed.</span></p><h3><strong><span>2. The Web, Content, and Prompt Injection Layer</span></strong></h3><p><span>This one is genuinely new, and the industry has not fully reckoned with it yet.</span></p><p><span>Your AI agents browse the web, read documents, process emails, and query databases on your behalf. Every piece of external content they touch is a potential injection vector. And they cannot tell the difference between legitimate content and content containing hidden instructions designed to make them do something they shouldn&#8217;t. The Five Eyes joint guidance called prompt injection the most persistent and difficult-to-fix threat in agentic AI stemming from a fundamental design constraint of language models [7]. This is just how these systems work.</span></p><p><span>MCP (Model Context Protocol) is the connective tissue of the agentic ecosystem. It enables agents to connect to tools, data sources, and external services. Anthropic introduced it in late 2024 as the standard for connecting AI agents to external tools and services. Google, Microsoft, and OpenAI adopted it quickly. Gartner projects 75% of API gateway vendors will have MCP features by end of 2026 [18]. It&#8217;s becoming the connective tissue of the agentic ecosystem faster than anyone expected.</span></p><p><span>A few specific flavors worth knowing: </span></p><ul><li><p><strong><span>Tool poisoning</span></strong><span> is when malicious instructions get embedded in a tool&#8217;s description, the text an agent reads to understand what to do. The agent follows those instructions because it trusts the description. </span></p></li><li><p><strong><span>Rug pull attacks</span></strong><span> are when a tool behaves legitimately during review, then changes behavior afterward. Most governance processes evaluate tools once at onboarding. </span></p></li><li><p><strong><span>Cross-tool contamination</span></strong><span> is when one compromised MCP server influences the behavior of other legitimate tools through a shared reasoning context.</span></p></li></ul><p><span>None of these are fixable with a patch because none of them are bugs. They&#8217;re properties of how agents process trust. The CSA&#8217;s MCP Security Crisis report documented a systemic architectural flaw affecting an estimated 200,000 vulnerable instances across a supply chain of 150 million package downloads, a design default in every official MCP SDK [9]. Most downstream developers don&#8217;t know it yet.</span></p><p><strong><span>What to do:</span></strong><span> You can&#8217;t patch it, but you can architect for it. Sandbox your agents. Constrain what they&#8217;re architecturally capable of, not just what they&#8217;re permitted to do. Implement human review for high-stakes actions before they execute. Treat every external data source your agent touches as untrusted by default.</span></p><h3><strong><span>3. The Identity and Access Layer</span></strong></h3><p><span>AI agents are identities. They authenticate to your cloud environment through service accounts, IAM roles, and API keys, the same as any other non-human identity in your environment. And because an agent that can&#8217;t interact with your data and systems isn&#8217;t particularly useful, they get access. Often a lot of it.</span></p><p><span>92% of cloud identities with access to sensitive permissions have not used those permissions in over 90 days [10]. Those identities exist across your environment right now, loaded with access granted at setup and never revisited. AI agents inherit these same overpermissioned patterns because they&#8217;re added into environments where over-privilege is already the norm.</span></p><p><span>AI agents amplify the risk because they&#8217;re genuinely good at lateral movement. An agent with broad cloud permissions can enumerate what&#8217;s accessible, pivot across connected systems, query data stores, trigger downstream actions, and chain those operations autonomously. The problem is they may not use access paths in the ways you intended, with potentially harmful consequences.</span></p><p><span>There are documented kill chains from 2025 where the only &#8220;exploit&#8221; was a valid overprivileged credential combined with an agent that could act on it. No malware required. No sophisticated technique. Just an identity with too much access and a system designed to use it [10].</span></p><p><strong><span>What to do:</span></strong><span> Constraining capability at the identity layer, not just the policy layer. Policies can be misconfigured, inherited, or quietly expanded. Architectural constraints on what an identity can structurally </span><em><span>do</span></em><span> are harder to bypass. Active blocking of permissions that aren&#8217;t being used. Just-in-time issuance for anything sensitive instead of standing elevated access. Gartner has named Non-Human Identity security as a foundational control layer for the agentic era [11]. The goal is a smaller blast radius when a credential is inevitably exposed.</span></p><h3><strong><span>4. The Software Supply Chain and Secrets Layer</span></strong></h3><p><span>This one has been around forever. It&#8217;s just gotten worse faster.</span></p><p><span>API keys committed to public repos. Database passwords in config files. AWS credentials that accidentally made it into version control. GitGuardian found 28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34% year-over-year increase and the largest single-year jump they&#8217;ve ever recorded [12]. This happens because developers scaffold projects, wire integrations, test API calls, and commit working code before anyone has sorted out where credentials should live, who owns them, or how they rotate.</span></p><p><span>To make matters worse, AI-assisted commits leak secrets at 3.2% versus a 1.5% baseline, roughly double [12]. And 64% of valid secrets from 2022 are still active and exploitable today [12]. That&#8217;s four years of keys sitting in the wild, never rotated.</span></p><p><span>A leaked credential in 2020 required a human attacker to manually figure out what to do with it. In 2026, that same credential can set off an AI agent that autonomously enumerates access, exfiltrates data, pivots through SaaS integrations, and documents everything for the next phase of the attack, all before anyone notices something is wrong.</span></p><p><strong><span>What to do:</span></strong><span> Secrets scanning in CI/CD before commit. Short-lived credentials everywhere that matters. MCP configuration files treated with the same care as production secrets. Git history audited, not just current code. Credential rotation as a standing practice, not an incident response step.</span></p><h3><strong><span>5. The Third-Party Integrations Layer</span></strong></h3><p><span>Most organizations don&#8217;t primarily run their own code anymore. They run SaaS. And their AI agents are doing work inside that SaaS, taking actions and moving data across platforms in ways that are genuinely difficult to monitor.</span></p><p><span>Most third-party AI tools entered organizations the same way SaaS always has, through browser-based apps, OAuth integrations, and user-driven adoption rather than centralized IT approval [13]. The governance infrastructure for SaaS was already stretched. Agents multiplied the connections, automated the actions, and made the data movement harder to track.</span></p><p><span>Breaches with third-party involvement increased 60% year over year [6]. One in three enterprises experienced a security incident involving AI agents in the past year [14]. 30.8% experienced unauthorized data exfiltration through SaaS-to-AI integrations, and 83.4% say their current tools can&#8217;t reliably distinguish between human and non-human behavioral patterns [14].</span></p><p><span>This is where credentials get used, where prompt injection arrives through documents and emails, where leaked secrets do real damage, and where the blast radius of any initial compromise expands through connected integrations. It connects back to every other layer. And most organizations haven&#8217;t extended their security thinking to cover it yet.</span></p><p><strong><span>What to do:</span></strong><span> Start with inventory. The Five Eyes recommend enumerating all agentic deployments before anything else [7]. Build an allow-list of approved integrations to include MCP servers, OAuth connections, and SaaS tools, and treat non-listed connections as blocked by default. Use behavioral monitoring to understand what normal looks like for an agent and spot when something is off. The challenge here is applying enforcement. What this layer requires is the ability to intercept agent actions before they complete.</span></p><h2><strong><span>The Point</span></strong></h2><p><span>Stop initial compromise. We&#8217;re not going to win this battle by patching faster or scoring CVEs better. We need to stop the attacker from walking through the front door in the first place, as much as reasonably possible.</span></p><p><span>Patching vulnerabilities is, how do I say, like using mouthwash after brushing your teeth. It&#8217;s helpful. It&#8217;s good hygiene. It just isn&#8217;t the primary line of defense anymore. Admittedly, &#8220;defense&#8221; in this brave new world is feeling like a lot of spend with little worth. Still, layers. Defense in depth. You know the drill.</span></p><p><span>The next obvious move is to assume breach. Because, the fact is, vulns </span><em><span>will </span></em><span>be discovered and exploited. Credentials </span><em><span>will</span></em><span> be compromised. The question becomes what happens next. How do you reduce blast radius, limit what an attacker or a compromised agent can do once they&#8217;re in, and minimize the damage before anyone notices? That&#8217;s where I&#8217;m headed.</span></p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/p/forget-the-patch-stop-initial-compromise?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption"><em><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Thanks for reading Out of Band! This post is public so feel free to share it.</mark></em></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/p/forget-the-patch-stop-initial-compromise?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.outofband.bootstrapcyber.com/p/forget-the-patch-stop-initial-compromise?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2><strong><span>References</span></strong></h2><p><span>[1] Anthropic Red Team, &#8220;Mythos Preview: Technical Disclosure,&#8221; Anthropic, Apr. 2026.</span><a href="https://red.anthropic.com/2026/mythos-preview/"><span> https://red.anthropic.com/2026/mythos-preview/</span></a></p><p><span>[2] IBM, &#8220;The Mythos Moment When Discovery Outpaces Defense,&#8221; IBM Think Insights, Apr. 2026.</span><a href="https://www.ibm.com/think/insights/the-mythos-moment-when-discovery-outpaces-defense"><span> https://www.ibm.com/think/insights/the-mythos-moment-when-discovery-outpaces-defense</span></a></p><p><span>[3] Abnormal Security, cited in StationX, &#8220;Social Engineering Statistics 2026,&#8221; StationX, May 2026.</span><a href="https://app.stationx.net/articles/social-engineering-statistics"><span> https://app.stationx.net/articles/social-engineering-statistics</span></a></p><p><span>[4] Brightside AI, cited in Vectra AI, &#8220;AI Scams in 2026: How They Work and How to Detect Them,&#8221; Vectra AI, Mar. 2026.</span><a href="https://www.vectra.ai/topics/ai-scams"><span> https://www.vectra.ai/topics/ai-scams</span></a></p><p><span>[5] Vectra AI, &#8220;Social Engineering Attacks: Types, Examples, and Defense,&#8221; Vectra AI, 2026.</span><a href="https://www.vectra.ai/topics/social-engineering"><span> https://www.vectra.ai/topics/social-engineering</span></a></p><p><span>[6] Verizon, &#8220;2026 Data Breach Investigations Report,&#8221; Verizon, 2026.</span><a href="https://www.verizon.com/business/resources/reports/dbir/"><span> https://www.verizon.com/business/resources/reports/dbir/</span></a></p><p><span>[7] CISA, NSA, ASD ACSC, Canadian Centre for Cyber Security, NCSC-NZ, NCSC-UK, &#8220;Careful Adoption of Agentic AI Services,&#8221; Joint Guidance, Apr. 30, 2026.</span><a href="https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF"><span> https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF</span></a></p><p><span>[8] CSO Online, &#8220;MCP is Fueling Agentic AI -- and Introducing New Security Risks,&#8221; CSO Online, Sept. 11, 2025.</span><a href="https://www.csoonline.com/article/4015222/mcp-uses-and-risks.html"><span> https://www.csoonline.com/article/4015222/mcp-uses-and-risks.html</span></a></p><p><span>[9] Cloud Security Alliance, &#8220;MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure,&#8221; CSA Labs, May 4, 2026.</span><a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/"><span> https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/</span></a></p><p><span>[10] Sonrai Security, &#8220;Cloud Access Risk Report: Overprivileged and Zombie Identities Data,&#8221; Sonrai Security, 2026.</span><a href="https://sonraisecurity.com/cloud-access-data-report/"><span> https://sonraisecurity.com/cloud-access-data-report/</span></a></p><p><span>[11] Gartner, Inc., &#8220;Gartner Identifies the Top Cybersecurity Trends for 2026,&#8221; Press Release, Feb. 5, 2026.</span><a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026"><span> https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026</span></a></p><p><span>[12] GitGuardian, &#8220;State of Secrets Sprawl 2026,&#8221; GitGuardian, Mar. 17, 2026.</span><a href="https://www.gitguardian.com/state-of-secrets-sprawl-report-2026"><span> https://www.gitguardian.com/state-of-secrets-sprawl-report-2026</span></a></p><p><span>[13] Cloud Security Alliance, &#8220;Why SaaS and AI Security Will Look Very Different in 2026,&#8221; CSA Blog, Jan. 29, 2026.</span><a href="https://cloudsecurityalliance.org/blog/2026/01/29/why-saas-and-ai-security-will-look-very-different-in-2026"><span> https://cloudsecurityalliance.org/blog/2026/01/29/why-saas-and-ai-security-will-look-very-different-in-2026</span></a></p><p><span>[14] K. Huang, &#8220;The Agentic Ecosystem Security Gap: What 500 CISOs Just Told Us About the Breach You Haven&#8217;t Had Yet,&#8221; Agentic AI (Substack), Apr. 14, 2026.</span></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:194136624,&quot;url&quot;:&quot;https://kenhuangus.substack.com/p/the-agentic-ecosystem-security-gap&quot;,&quot;publication_id&quot;:1796302,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;Agentic AI &quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rWke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5395d473-3e5f-4ef3-aca5-241ffc64c82e_505x505.png&quot;,&quot;title&quot;:&quot;The Agentic Ecosystem Security Gap: What 500 CISOs Just Told Us About the Breach You Haven&#8217;t Had Yet&quot;,&quot;truncated_body_text&quot;:&quot;Recently I read a very interesting article shared by Elias Terman from Vorlon.&quot;,&quot;date&quot;:&quot;2026-04-14T13:01:55.347Z&quot;,&quot;like_count&quot;:20,&quot;comment_count&quot;:1,&quot;bylines&quot;:[{&quot;id&quot;:1160339,&quot;name&quot;:&quot;Ken Huang&quot;,&quot;handle&quot;:&quot;kenhuangus&quot;,&quot;previous_name&quot;:&quot;ken&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;bio&quot;:null,&quot;profile_set_up_at&quot;:&quot;2022-12-14T20:47:13.840Z&quot;,&quot;reader_installed_at&quot;:&quot;2025-01-02T21:15:15.019Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:1779815,&quot;user_id&quot;:1160339,&quot;publication_id&quot;:1796302,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:1796302,&quot;name&quot;:&quot;Agentic AI &quot;,&quot;subdomain&quot;:&quot;kenhuangus&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;I share my thoughts on anything related to Agentic AI and Agentic AI Security topics.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5395d473-3e5f-4ef3-aca5-241ffc64c82e_505x505.png&quot;,&quot;author_id&quot;:1160339,&quot;primary_user_id&quot;:1160339,&quot;theme_var_background_pop&quot;:&quot;#99A2F1&quot;,&quot;created_at&quot;:&quot;2023-07-11T21:55:42.778Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;ken&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100,&quot;status&quot;:{&quot;bestsellerTier&quot;:100,&quot;subscriberTier&quot;:null,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;bestseller&quot;,&quot;tier&quot;:100},&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://kenhuangus.substack.com/p/the-agentic-ecosystem-security-gap?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!rWke!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5395d473-3e5f-4ef3-aca5-241ffc64c82e_505x505.png" loading="lazy"><span class="embedded-post-publication-name">Agentic AI </span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">The Agentic Ecosystem Security Gap: What 500 CISOs Just Told Us About the Breach You Haven&#8217;t Had Yet</div></div><div class="embedded-post-body">Recently I read a very interesting article shared by Elias Terman from Vorlon&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">3 months ago &#183; 20 likes &#183; 1 comment &#183; Ken Huang</div></a></div>]]></content:encoded></item><item><title><![CDATA[You Thought Ransomware Was a Nightmare? Try Sustained Attrition.]]></title><description><![CDATA[Since the idea of agentic-powered &#8220;sustained attrition&#8221; attacks hit me, it has literally kept me up at night.]]></description><link>https://www.outofband.bootstrapcyber.com/p/you-thought-ransomware-was-a-nightmare</link><guid isPermaLink="false">https://www.outofband.bootstrapcyber.com/p/you-thought-ransomware-was-a-nightmare</guid><dc:creator><![CDATA[Laura Kenner]]></dc:creator><pubDate>Thu, 28 May 2026 16:32:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3xyk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3xyk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3xyk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!3xyk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!3xyk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!3xyk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3xyk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:391715,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.outofband.bootstrapcyber.com/i/199616357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3xyk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!3xyk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!3xyk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!3xyk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9d2d6c7-4cb6-4141-ae8b-8309ff099012_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Since the idea of agentic-powered &#8220;sustained attrition&#8221; attacks hit me, it has literally kept me up at night. Not in a vague, ambient anxiety kind of way. In the specific, wide-awake-at-3-AM kind of way where you keep turning a problem over because you can&#8217;t find the answer and you&#8217;re not sure anyone else has found it either.</p><p>Understanding a problem can feel like progress, even when the solution isn&#8217;t obvious yet. I&#8217;ve spent weeks deep in research about <a href="https://www.outofband.bootstrapcyber.com/p/follow-the-research-cybersecurity?r=45g2ds">cybersecurity in a post-Mythos world</a>, specifically on backup, recovery, and business continuity, when this potential scenario surfaced in my mind. All the playing pieces are on the board. The game is being written as we speak.</p><p>I wish my investigation of this possibility resulted in finding a viable solution. I came up mostly empty. I think the security community needs eyes on this problem, before the scenario I&#8217;m about to describe starts to hit the news cycle at scale. I believe there are smart people working on problems just like this. I hope practitioners, researchers, insurers, regulators, and vendors will start building toward a response.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to Out of Band free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>The Scenario That Woke Me Up</strong></h2><p>Let me describe what sustained attrition looks like in practice. I hope to be useful to defenders without being a how-to for attackers. The goal is to paint the picture clearly enough that security teams can start designing against it.</p><p>It is 2:47 AM on a Tuesday. An AI agent deployed by an external adversary identifies an entry point. The credential was a valid API key sitting in a public MCP configuration file on GitHub, active for over a year, never rotated. The agent gains a foothold and immediately does what agentic systems do. It enumerates what systems are reachable, what agents are running with what permissions, and where the backup infrastructure lives. It discovers paths that lead to your crown jewels. The reconnaissance happens continuously and automatically, not in a defined pre-attack phase.</p><p>Your monitoring detects anomalous behavior at 3:15 AM. The alert fires. An on-call engineer wakes up. Incident response begins. Containment. Isolation. The start of a recovery process that, even with best-in-class tooling, will take hours. For large environments with significant data volumes, days.</p><p>Here is what the agent is doing during your recovery.</p><p>It already mapped three alternative entry points during the initial enumeration. Two of those paths are still open because the isolation was incomplete in the chaos of 3 AM response. The agent isn&#8217;t waiting for a human decision to try the next one. It adapted, and it persisted.</p><p>Attack 2 lands at 6:30 AM. Your team hasn&#8217;t finished recovering from Attack 1. Now they are managing two simultaneous incidents. The first is in mid-restoration, and now another one is just beginning. A senior engineer is making prioritization decisions. Was the clean recovery point for the systems affected in Attack 1 verified, or did someone assume it was clean because the verification step got skipped in the pressure of a second active incident?</p><p>The agent doesn&#8217;t have this problem. It doesn&#8217;t get tired. It doesn&#8217;t skip verification steps. It doesn&#8217;t make the mistakes that humans make at hour six of a sustained response. The asymmetry is total, and it compounds with every cycle.</p><p>Shall I state the obvious here? This is bad. Like how Egon from Ghostbusters explains that crossing the streams of their proton packs would be &#8220;bad.&#8221; Like, total protonic reversal and every molecule in your body exploding at the speed of light kind of bad. I&#8217;m being a touch dramatic. But you get my point.</p><h2><strong>The Building Blocks Are Already Here</strong></h2><p>This isn&#8217;t just the fever dream of a cybersecurity-educated marketer. The components exist and are documented in the wild.</p><p>On November 13, 2025, Anthropic published a disclosure that should have stopped the security industry cold:<a href="https://www.anthropic.com/news/disrupting-AI-espionage"> &#8220;Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign&#8221;</a> [1]. In mid-September 2025, Anthropic detected a Chinese state-sponsored group that had jailbroken Claude Code and used it to autonomously infiltrate roughly thirty global targets including large tech companies, financial institutions, chemical manufacturers, and government agencies. The attack was not AI-assisted. It was AI-executed.</p><p>The specifics matter for what I am about to argue.</p><p>The attackers broke their campaign into small, seemingly innocent tasks that Claude executed without being given the full context of their malicious purpose. At peak activity, the AI made thousands of requests, often multiple per second. <em>The threat actor performed 80 to 90 percent of the campaign using AI</em>, with human intervention required only sporadically, for approximately four to six critical decision points per hacking campaign. That is a nearly fully autonomous attack, with humans providing strategic direction and little else.</p><p>Later, in the final phase, the attackers had Claude produce comprehensive documentation of the attack to include files of stolen credentials, analyzed systems, and identified high-privilege accounts, specifically to assist in planning the next stage of operations. The agent was not just executing the current attack. It was actively preparing the next one while the current campaign was still running.</p><p>That is the &#8220;attrition model,&#8221; documented in a primary Anthropic disclosure, in September 2025.</p><p><a href="https://www.malwarebytes.com/resources/files/2026/02/malwarebytes-2026-state-of-malware-report.pdf">Malwarebytes&#8217; 2026 State of Malware report</a> documents the broader shift in attack economics: AI agents can now run multiple simultaneous intrusions autonomously, create exploits from patches in minutes, and outperform elite human researchers. Small crews or single operators can now execute reconnaissance, lateral movement, and extortion at a scale and speed previously reserved for large, experienced intrusion teams [2].</p><p>The persistence property is the key differentiator. <a href="https://blog.barracuda.com/2026/02/27/agentic-ai-the-next-frontier-in-cybersecurity/">Barracuda&#8217;s 2026 threat analysis</a> found that agentic AI can plan, adapt, and persist autonomously, turning multi-stage attacks into continuous operations. It doesn&#8217;t stop after a failed attempt. It continues trying until it finishes the operation or is shut down. The agent must be purged completely to be contained [3].</p><p>Read that last sentence again. <em>The agent must be purged completely to be contained.</em> Not just the encrypted files restored. Not just the compromised account reset. The agent and every foothold it had established must be identified and eliminated. That is a fundamentally different containment requirement than anything current incident response playbooks are built around.</p><p>The government and critical infrastructure attack data further substantiates this threat. Since March 2026, an Iranian-affiliated APT group has disrupted programmable logic controllers deployed across multiple US critical infrastructure sectors including government services, water and wastewater systems, and energy, causing operational disruption and financial loss [4]. CISA and allied agencies confirmed these efforts were designed to &#8220;cause disruptive effects within the United States.&#8221;</p><p>My point is that persistent, AI-augmented operational disruption against critical infrastructure is happening now.</p><h2><strong>The Leverage This Creates for Attackers</strong></h2><p>The attacker in this scenario doesn&#8217;t need to encrypt anything. They don&#8217;t need to exfiltrate anything. They only need to demonstrate that they can keep you offline indefinitely. One successful attrition cycle, where Attack 2 lands before full recovery from Attack 1, is proof of concept. Then the demand arrives.</p><p>The demand isn&#8217;t &#8220;pay us to decrypt your data.&#8221; It&#8217;s &#8220;pay us and we stop.&#8221;</p><p>That demand is backed by demonstrated capability, not just a threat. And the amount they can credibly demand is not &#8220;what is your data worth to you?&#8221; It&#8217;s &#8220;what is every hour of operational unavailability costing you, with no natural endpoint?&#8221; For a large enterprise at $14,056 per minute of downtime, the math is catastrophic. For a healthcare system that cannot process patient records, a financial institution that cannot execute transactions, or a logistics company that cannot move product, it&#8217;s game over.</p><p><a href="https://industrialcyber.co/reports/intel-471-reports-extortion-breaches-surged-63-in-2025-with-sustained-activity-expected-in-2026/">Intel 471</a> found extortion breaches surged 63% in 2025, with Qilin RaaS introducing &#8220;structured data analysis audits designed to increase leverage over targets.&#8221; The extortion ecosystem is innovating on leverage mechanisms. The attrition model is the logical next innovation in that progression [5].</p><p>The victim&#8217;s negotiating position in this scenario is weaker than any ransomware situation, because there is no recovery path that resolves the underlying threat. You can restore from backups after ransomware and be done with it. You cannot restore your way out of an adversary who can reliably trigger the next incident before you finish recovering from the last one. The leverage is not in the data. It is in the cadence.</p><p><a href="https://cyberresilience.com/blog/cybersecurity-and-insurance-predictions-2026/">Resilience Insurance predicted</a> that the extortion-only model with no encryption, only pure operational disruption as leverage, may represent the majority of extortion incidents by the end of 2026. We are already watching this transition happen. The attrition model is where it leads when AI removes the cost constraint on repeated attacks [6].</p><h2><strong>The Reference Point Everyone Is Working From</strong></h2><p>Ransomware has been the defining threat model of the last decade. It has a known playbook. Security teams have practiced it. Cyber insurance was built around it. Regulators have guidance for it. Negotiators specialize in it.</p><p>The ransomware model is the attacker gets in, identifies and encrypts your data, disables backup agents, erases recovery points, and presents a demand. You can pay the ransom or restore from backups. Either way, there is a defined endpoint. The attack is over. The damage is quantifiable. The clock starts on recovery.</p><p>That model, as damaging as it has been, assumes that the attacker wants a transaction. They want payment. Once they have it, or once you&#8217;ve restored and they&#8217;ve moved on, the incident concludes.</p><p><a href="https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/">Palo Alto&#8217;s Unit 42 2026 Global Incident Response Report</a>, analyzing over 750 major cyber incidents across 50 countries, documents that encryption-based extortion declined 15% as more attackers skip encryption entirely and move to operational disruption as their primary leverage mechanism. The industry is already shifting away from the model we&#8217;ve practiced for [7].</p><p><a href="https://www.vikingcloud.com/blog/7-cybersecurity-trends-that-will-define-2026">VikingCloud describes</a> where it&#8217;s heading: &#8220;Ransomware gangs have figured out that <em>encrypting files is only one way to hold a business hostage</em>. They prioritize availability, not just data. If 800 stores go down for six hours, the financial impact far exceeds the ransom amount&#8221; [8].</p><p>And Resilience Insurance&#8217;s Tom Egglestone tells us that &#8220;Cyber extortion is entering its next phase. By 2026, attacks will no longer rely solely on encryption or data theft but will combine multiple tactics in sequence. Adversaries are discovering that the most effective leverage comes from sustained, multi-layered disruption that touches every part of an organisation&#8217;s operations&#8221; [6].</p><p>This is the direction of travel. The threat model everyone has been preparing for is already being replaced by something worse.</p><h2><strong>Why Current Backup, Recovery, and Business Continuity Plans Would Be Useless</strong></h2><p>This is the rabbit hole I found as I was thinking about the business continuity problem when agentic adversaries enter the picture.</p><p>Current backup and recovery architectures are designed to survive one bad event with immutable backups, clean recovery points, cleanroom restoration environments, and rapid identification of uncompromised data. These are all valuable, necessary, and partially effective for a single catastrophic event. They are not designed for sustained attrition attacks.</p><p><a href="https://www.commvault.com/blogs/cleanroom-recovery-innovations-enable-a-new-era-in-cyber-resilience">Commvault&#8217;s cleanroom recovery</a> creates an on-demand, secure, isolated environment where organizations can test recovery plans, conduct forensic investigations, and execute production recoveries without risking further disruption [9]. That is a good approach for single-event resilience. But a cleanroom gives you clean data to restore to. It doesn&#8217;t solve the problem that the environment you are restoring into is being actively probed for the next attack while you are still in the cleanroom. What if the restoration and the next attack are running in parallel?</p><p><a href="https://www.keiseruniversity.edu/business-continuity-vs-disaster-recovery/">Keiser University&#8217;s BCDR analysis</a> notes that disaster recovery and business continuity &#8220;skyrocketed from not even in the top 10 in 2024 to number three in 2025&#8221; among CISO priorities, and that the average cost of downtime is $14,056 per minute. Organizations are paying attention to this. But paying attention to single-event recovery speed is a different problem from designing for repeated attack cycles [10].</p><p>Current Recovery Point Objective and Recovery Time Objective frameworks were designed for one bad day. They tell you how much data you can afford to lose and how quickly you need to restore. They do not tell you what to do when the next attack arrives before the current restoration is complete. They do not account for a scenario where the question is &#8220;what is our RTO relative to the attacker&#8217;s next strike cadence?&#8221;</p><p>When it comes to business continuity plans, what does your organization do while primary systems are in recovery? Most organizations have given this insufficient thought for a single event, let alone what it should look like when a campaign of continuous attacks renders backup and recovery methods useless.</p><p>Like I said, I don&#8217;t have the full answer to this. I don&#8217;t think anyone does yet. The vendors building recovery tooling are doing important work. Veeam&#8217;s Intelligent ResOps, Cohesity&#8217;s clean room, Commvault&#8217;s synthetic recovery, and Rubrik&#8217;s threat hunting are real innovations addressing real problems. But they are all solving for single-event resilience. The sustained attrition scenario is a different engineering problem, and I don&#8217;t see evidence that anyone has fully designed for it yet.</p><h2><strong>The Government and Critical Infrastructure Dimension</strong></h2><p>I cannot help imagining another terrible use case for this type of attack.</p><p>A private company facing operational attrition loses revenue, reputation, and customer trust. That is serious. It is potentially existential for smaller organizations. It is recoverable over time for larger ones.</p><p>A government agency facing operational attrition loses the ability to deliver services that citizens depend on. The downstream human cost of extended operational unavailability is not measured in dollars. It is measured in people who don&#8217;t receive medical care, emergency response that doesn&#8217;t arrive, critical infrastructure that stops functioning.</p><p>The <a href="https://industrialcyber.co/reports/odni-report-us-critical-infrastructure-faces-escalating-cyber-risks-from-china-russia-iran-and-north-korea/">ODNI&#8217;s Annual Threat Assessment 2026</a> makes the geopolitical context explicit. China, Russia, Iran, and North Korea are all actively targeting US critical infrastructure. Ransomware groups are shifting to faster, high-volume attacks. AI&#8217;s influence is deepening across offensive operations [11].</p><p>On April 23, 2026, the Executive Office of the President issued a memorandum to heads of all executive departments warning of threats from foreign entities engaged in &#8220;deliberate, industrial-scale campaigns&#8221; to attack US systems [12].</p><p>The <a href="https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/securing-cloud-infrastructure-ai/">Atlantic Council adds</a> an institutional vulnerability that compounds the threat: CISA is operating without a confirmed director, has seen significant workforce reductions, CIRCIA&#8217;s final rule has been delayed to May 2026, and the Cybersecurity Information Sharing Act lapsed in September 2025 with only a temporary extension. <em>The threat is escalating at precisely the moment institutional capacity to respond has been weakened</em> [13].</p><p>The scenario of a coordinated, AI-orchestrated attrition campaign against multiple government agencies simultaneously, making critical services unavailable on demand, is not science fiction. It is a logical application of capabilities that are documented in the wild today, directed at a target set that is publicly acknowledged to be under sustained attack, at a moment when the defensive institutional infrastructure is under-resourced.</p><p>I find that genuinely frightening. I think you should too.</p><h2><strong>The Insurance Gap Nobody Has Closed</strong></h2><p>Cyber insurance was built for the ransomware model involving a defined incident, quantifiable loss, and a recoverable situation.<a href="https://www.techtarget.com/searchcio/feature/Why-cyber-insurance-wont-cover-the-next-generation-of-attacks"> TechTarget&#8217;s analysis</a> of the next generation of attacks is that cyber insurance won&#8217;t cover them. Full stop. The GAO has identified a gap in the Terrorism Risk Insurance Program. Cyberattacks must be violent or coercive to qualify, which is a threshold most state-sponsored operations don&#8217;t meet. 23% of private-sector organizations already rate their cyber resilience as insufficient [14].</p><p>Insurers are now defining &#8220;widespread events&#8221; in ways that limit aggregate exposure, adding exclusions that may restrict coverage when multiple policyholders are affected simultaneously [15]. A coordinated attrition campaign that affects multiple organizations through shared infrastructure fits exactly this exclusion.</p><p>The attrition scenario breaks every assumption insurance was built around. When does the incident start? When does it end? What is the quantifiable loss when the attacker never encrypts anything, only keeps triggering recovery cycles? How do you file a claim for &#8220;we were intermittently unavailable for three weeks due to repeated AI-orchestrated attacks with no defined endpoint&#8221;?</p><p>The answer is you probably can&#8217;t. Not under any policy that currently exists. And there is no federal backstop for it.</p><h2><strong>Starting Points, Not Solutions</strong></h2><p>I have not found a viable solution to the attrition problem. I did find starting points. These are ways to begin thinking and building that are better than what most organizations are doing right now. The full solution requires innovation that hasn&#8217;t happened yet.</p><p><strong>Ask the question nobody is asking about your RTO.</strong> Your Recovery Time Objective was designed for one event. Ask instead: what is our RTO relative to likely attack cadence? A four-hour RTO is excellent if attacks arrive every three days. It is operationally useless if attacks arrive every two hours. You cannot answer this question until you ask it.</p><p><strong>Map your Minimum Viable Operations before an incident.</strong> What does your organization need to function at the bare minimum while primary systems are in recovery? What can you do manually, in degraded mode, or through alternate channels? What are the three to five systems or processes that, if you could only keep those running, you could survive? In a sustained attrition scenario, this answer is the difference between functioning and collapse.</p><p><strong>Treat backup infrastructure as outside the blast radius of your entire agentic environment.</strong> Policy-isolated isn&#8217;t going to cut it. We need architecturally isolated with separate credentials and separate network paths. No agent in your production environment should be able to reach your backup infrastructure. If any agent can reach it, assume it eventually will. Immutability is necessary but not sufficient. An immutable backup system that is reachable for enumeration is still giving an attacker a map.</p><p><strong>Use short-lived credentials everywhere that touches recovery.</strong> This means every backup service account, recovery tool, and administrative credential that touches backup infrastructure. A credential that expires in fifteen minutes has a fraction of the usefulness of one valid for four years when the scenario involves repeated exploitation cycles. <a href="https://www.gitguardian.com/state-of-secrets-sprawl-report-2026">GitGuardian found</a> that 64% of valid secrets from 2022 are still active and exploitable in 2026. That is the population of credentials sitting in your environment that an agentic attacker can use to reset after each recovery cycle [16].</p><p><strong>Test recovery under realistic degraded conditions.</strong> Organizations that regularly test disaster recovery plans recover 50% faster from cyber incidents. But the relevant test for attrition isn&#8217;t a scheduled, fully-staffed DR drill under calm conditions. It&#8217;s a simulated second incident arriving before the first one is resolved. It&#8217;s a deliberately understaffed response team making decisions under pressure at hour six. It&#8217;s a verification step that gets skipped. Test the conditions you will actually face, not the conditions under which your plan works perfectly.</p><p><strong>Pre-authorize containment actions and build playbooks for sustained incidents.</strong> The <a href="https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF">Five Eyes guidance</a> is that human approval loops are too slow for machine-speed attack cadence. Decisions that can be pre-authorized should be. Playbooks for sustained multi-incident scenarios should exist before they are needed [17].</p><p><strong>Have the board conversation about the cost model.</strong> The financial model for attrition is categorically different from ransomware. There is no ransom payment to budget for. There is no defined recovery point after which normal operations resume. The cost is pure operational loss with no natural endpoint. Boards that have modeled one catastrophic event have not modeled thirty-six hours of intermittent unavailability with no endpoint. Those are different numbers. They need to be in front of the people making investment decisions.</p><h2><strong>A Call to the Community</strong></h2><p>The thought of an agentic-powered adversary running repeated attack sequences against an organization or a government agency, while current backup, recovery, and business continuity plans prove completely inadequate to the cadence of the attack is, to me, one of the most urgent unsolved problems in security today.</p><p>And it is unsolved. Some vendors are working on pieces of it. The researchers are circling adjacent problems. The regulators are writing frameworks for single-event resilience that don&#8217;t contemplate this scenario. The insurance industry is acknowledging coverage gaps without designing products for what comes next.</p><p>If you are thinking about this, I want to hear from you. If your organization is working on it, I want to know. If you have TTPs that defenders can use today, even partial ones, share them. The community needs them.</p><p>The operational attrition threat model needs dedicated attention from people with the expertise and resources to build defenses against it. I&#8217;ve described it as clearly as I can. Now I&#8217;m asking the people who can actually build the response to take it seriously.</p><p>Because the alternative, waiting until this scenario plays out at scale against a major enterprise or a critical government agency, is not a risk I&#8217;m comfortable accepting.</p><p>-- Laura Kenner</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Out of Band! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/p/you-thought-ransomware-was-a-nightmare?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.outofband.bootstrapcyber.com/p/you-thought-ransomware-was-a-nightmare?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><div><hr></div><h2><strong>References</strong></h2><p>[1] Anthropic, &#8220;Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign,&#8221; Anthropic News, Nov. 13, 2025.<a href="https://www.anthropic.com/news/disrupting-AI-espionage"> https://www.anthropic.com/news/disrupting-AI-espionage</a></p><p>[2] Malwarebytes, &#8220;2026 State of Malware Report,&#8221; Malwarebytes, 2026.<a href="https://www.malwarebytes.com/resources/files/2026/02/malwarebytes-2026-state-of-malware-report.pdf"> https://www.malwarebytes.com/resources/files/2026/02/malwarebytes-2026-state-of-malware-report.pdf</a></p><p>[3] Barracuda, &#8220;Agentic AI: The Next Frontier in Cybersecurity,&#8221; Barracuda Blog, Feb. 2026.<a href="https://blog.barracuda.com/2026/02/27/agentic-ai-the-next-frontier-in-cybersecurity/"> https://blog.barracuda.com/2026/02/27/agentic-ai-the-next-frontier-in-cybersecurity/</a></p><p>[4] Industrial Cyber, &#8220;Ongoing cyberattacks targeting internet-connected PLCs disrupt US critical infrastructure,&#8221; Industrial Cyber, Apr. 8, 2026.<a href="https://industrialcyber.co/cisa/ongoing-cyberattacks-targeting-internet-connected-plcs-disrupt-us-critical-infrastructure-agencies-warn/"> https://industrialcyber.co/cisa/ongoing-cyberattacks-targeting-internet-connected-plcs-disrupt-us-critical-infrastructure-agencies-warn/</a></p><p>[5] Intel 471, &#8220;2026 Cyber Threat Trends &amp; Outlook,&#8221; Intel 471, Feb. 2026.<a href="https://industrialcyber.co/reports/intel-471-reports-extortion-breaches-surged-63-in-2025-with-sustained-activity-expected-in-2026/"> https://industrialcyber.co/reports/intel-471-reports-extortion-breaches-surged-63-in-2025-with-sustained-activity-expected-in-2026/</a></p><p>[6] T. Egglestone, &#8220;Cybersecurity and Insurance Predictions for 2026,&#8221; Resilience, Feb. 24, 2026.<a href="https://cyberresilience.com/blog/cybersecurity-and-insurance-predictions-2026/"> https://cyberresilience.com/blog/cybersecurity-and-insurance-predictions-2026/</a></p><p>[7] Palo Alto Networks Unit 42, &#8220;2026 Global Incident Response Report,&#8221; Feb. 2026.<a href="https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/"> https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/</a></p><p>[8] VikingCloud, &#8220;7 Cybersecurity Trends That Will Define 2026,&#8221; VikingCloud Blog, Jan. 12, 2026.<a href="https://www.vikingcloud.com/blog/7-cybersecurity-trends-that-will-define-2026"> https://www.vikingcloud.com/blog/7-cybersecurity-trends-that-will-define-2026</a></p><p>[9] Commvault, &#8220;Cleanroom Recovery Innovations Enable a New Era in Cyber Resilience,&#8221; Commvault Blog, Nov. 19, 2025.<a href="https://www.commvault.com/blogs/cleanroom-recovery-innovations-enable-a-new-era-in-cyber-resilience"> https://www.commvault.com/blogs/cleanroom-recovery-innovations-enable-a-new-era-in-cyber-resilience</a></p><p>[10] Keiser University, &#8220;Business Continuity vs Disaster Recovery,&#8221; Keiser University Blog, Feb. 25, 2026.<a href="https://www.keiseruniversity.edu/business-continuity-vs-disaster-recovery/"> https://www.keiseruniversity.edu/business-continuity-vs-disaster-recovery/</a></p><p>[11] ODNI, &#8220;Annual Threat Assessment 2026,&#8221; Office of the Director of National Intelligence, Mar. 2026.<a href="https://industrialcyber.co/reports/odni-report-us-critical-infrastructure-faces-escalating-cyber-risks-from-china-russia-iran-and-north-korea/"> https://industrialcyber.co/reports/odni-report-us-critical-infrastructure-faces-escalating-cyber-risks-from-china-russia-iran-and-north-korea/</a></p><p>[12] Epstein Becker Green, &#8220;Critical Infrastructure at Risk: Project Glasswing Urges Attention to AI-Driven Cyber-Risks,&#8221; Workforce Bulletin, May 2026.<a href="https://www.workforcebulletin.com/critical-infrastructure-at-risk-project-glasswing-urges-attention-to-ai-driven-cyber-risks"> https://www.workforcebulletin.com/critical-infrastructure-at-risk-project-glasswing-urges-attention-to-ai-driven-cyber-risks</a></p><p>[13] Atlantic Council, &#8220;Securing Cloud Infrastructure for AI,&#8221; Issue Brief, Mar. 31, 2026.<a href="https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/securing-cloud-infrastructure-ai/"> https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/securing-cloud-infrastructure-ai/</a></p><p>[14] TechTarget, &#8220;Why Cyber Insurance Won&#8217;t Cover the Next Generation of Attacks,&#8221; TechTarget, Mar. 26, 2026.<a href="https://www.techtarget.com/searchcio/feature/Why-cyber-insurance-wont-cover-the-next-generation-of-attacks"> https://www.techtarget.com/searchcio/feature/Why-cyber-insurance-wont-cover-the-next-generation-of-attacks</a></p><p>[15] Insurance Thought Leadership, &#8220;Cyber Insurance Exclusions to Expect in 2026,&#8221; Dec. 4, 2025.<a href="https://www.insurancethoughtleadership.com/cyber/cyber-insurance-exclusions-expect-2026"> https://www.insurancethoughtleadership.com/cyber/cyber-insurance-exclusions-expect-2026</a></p><p>[16] GitGuardian, &#8220;State of Secrets Sprawl 2026,&#8221; GitGuardian, Mar. 17, 2026.<a href="https://www.gitguardian.com/state-of-secrets-sprawl-report-2026"> https://www.gitguardian.com/state-of-secrets-sprawl-report-2026</a></p><p>[17] CISA, NSA, ASD ACSC, Canadian Centre for Cyber Security, NCSC-NZ, NCSC-UK, &#8220;Careful Adoption of Agentic AI Services,&#8221; Joint Guidance, Apr. 30, 2026.<a href="https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF"> https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF</a></p><p>[18] Resilience, &#8220;Cyber Risk Shifts From Disruption to Long-Tail Losses,&#8221; Insurance Journal, Feb. 25, 2026.<a href="https://www.insurancejournal.com/news/national/2026/02/25/859511.htm"> https://www.insurancejournal.com/news/national/2026/02/25/859511.htm</a></p><p>[19] Defense One, &#8220;Pro-Iran hackers appear to increase critical infrastructure cyberattacks,&#8221; Defense One, Apr. 17, 2026.<a href="https://www.defenseone.com/threats/2026/04/iran-hackers-infrastructure-cyberattacks/412941/"> https://www.defenseone.com/threats/2026/04/iran-hackers-infrastructure-cyberattacks/412941/</a></p><p>[20] Object First, &#8220;Object First Survey: 89% of IT Leaders Fear AI-Powered Cyberattacks Will Cost Them Their Data,&#8221; Press Release, Mar. 31, 2026.<a href="https://www.businesswire.com/news/home/20260331825488/en"> https://www.businesswire.com/news/home/20260331825488/en</a></p><p>[21] Veeam, cited in TechRadar, &#8220;Ransomware attackers are going after backup storage to force you to pay up,&#8221; TechRadar, 2025.<a href="https://www.techradar.com/news/ransomware-attackers-are-going-after-backup-storage-to-force-you-to-pay-up"> https://www.techradar.com/news/ransomware-attackers-are-going-after-backup-storage-to-force-you-to-pay-up</a></p><p>[22] Vantagepoint, &#8220;Cyber Resilience: Building Business Continuity in an Era of Inevitable Breaches,&#8221; Mar. 18, 2026.<a href="https://vantagepoint.io/blog/sf/cyber-resilience-building-business-continuity-in-an-era-of-inevitable-breaches"> https://vantagepoint.io/blog/sf/cyber-resilience-building-business-continuity-in-an-era-of-inevitable-breaches</a></p><p>[23] CSA CISO Community et al., &#8220;The &#8216;AI Vulnerability Storm&#8217;: Building a &#8216;Mythos-ready&#8217; Security Program,&#8221; v1.0, May 1, 2026.<a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/mythosreadyv1.0.pdf"> https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/mythosreadyv1.0.pdf</a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Follow the Research: Cybersecurity in a Post-Mythos World]]></title><description><![CDATA[I&#8217;ve spent the last several weeks deep in the research on Claude Mythos, Project Glasswing, and what the security community is saying about what comes next.]]></description><link>https://www.outofband.bootstrapcyber.com/p/follow-the-research-cybersecurity</link><guid isPermaLink="false">https://www.outofband.bootstrapcyber.com/p/follow-the-research-cybersecurity</guid><dc:creator><![CDATA[Laura Kenner]]></dc:creator><pubDate>Thu, 28 May 2026 01:02:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wFF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wFF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wFF1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!wFF1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!wFF1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!wFF1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wFF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:982298,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.outofband.bootstrapcyber.com/i/199540209?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wFF1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!wFF1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!wFF1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!wFF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48d32d6d-8c9a-47aa-9665-140144ca9d7f_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;ve spent the last several weeks deep in the research on Claude Mythos, Project Glasswing, and what the security community is saying about what comes next. The most honest, well-sourced voices in cybersecurity are all circling the same uncomfortable question. What now?</p><p>This piece is my attempt to synthesize what I found. My goal is to give you enough grounding in the evidence that you can think through the implications yourself, and enough links that you can go further on your own. Practical recommendations will follow in separate articles. This one is about understanding the problem clearly first.</p><p>This is a long one because there&#8217;s a lot to cover, so hang in there. Turn on that screen reader and let&#8217;s do this.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.outofband.bootstrapcyber.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>About Mythos</strong></h2><p>On April 7, 2026, Anthropic announced<a href="https://www.anthropic.com/glasswing"> Claude Mythos (Preview)</a> alongside Project Glasswing, described as possibly the largest multi-party vulnerability coordination effort in history [1]. The reaction was immediate and unusually broad, reaching boardrooms, legislative offices, and national security agencies within days.</p><p>By May 1, six national cybersecurity agencies had issued the first-ever joint guidance specifically on agentic AI security: CISA, the NSA, Australia&#8217;s ASD ACSC, the Canadian Centre for Cyber Security, New Zealand&#8217;s NCSC, and the UK&#8217;s NCSC all signed on to<a href="https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF"> &#8220;Careful Adoption of Agentic AI Services&#8221;</a> [2]. When six governments move that fast on something, it&#8217;s worth paying attention to why.</p><p>So what did Mythos actually demonstrate? Three things, specifically.</p><ol><li><p><strong>Discovery velocity changed.</strong> Mythos generated 181 working Firefox exploits under conditions where Claude Opus 4.6 succeeded only twice [3]. It autonomously identified a 27-year-old vulnerability in OpenBSD, a 16-year-old flaw in FFmpeg that had survived five million automated test runs, and a remote code execution vulnerability in FreeBSD. These weren&#8217;t edge cases found under ideal conditions. The<a href="https://red.anthropic.com/2026/mythos-preview/"> Anthropic red team technical disclosure</a> is worth reading in full.</p></li><li><p><strong>The skill floor collapsed.</strong> A 3.6 billion parameter model costing $0.11 per million tokens can now detect complex bug classes [4]. Mythos-class capability isn&#8217;t confined to Anthropic or well-resourced state actors.<a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier"> AISLE&#8217;s &#8220;jagged frontier&#8221; analysis</a> shows that many of the vulnerability classes Mythos identifies can be reproduced by small, inexpensive open-weight models [5]. The controlled access Glasswing established is time-limited.</p></li><li><p><strong>Chained exploitation became accessible.</strong> Mythos identifies vulnerabilities composed of multiple primitives chained together -- scenarios requiring multiple memory corruption bugs combined into a single exploit path -- in a single prompt, without scaffolding [3]. Prior to this, chained exploitation required patient, skilled adversaries with time to burn. That constraint no longer applies.</p></li></ol><p>The autonomous exploitation rate trajectory tells the story clearly: GPT-5 achieved 18% in September 2025, Claude Sonnet 4.5 achieved 22% the same month, GPT-5.4 hit 90% by March 2026, and Claude Opus 4.6 hit 98% by February 2026 [4]. That is not a gradual progression. That is a cliff.</p><h2><strong>The Problem Mythos Exposed, Not Created</strong></h2><p>The<a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/mythosreadyv1.0.pdf"> CSA CISO Community briefing</a>, co-authored by Gadi Evron, Robert T. Lee of SANS, and contributions from Jen Easterly, Bruce Schneier, Heather Adkins, Phil Venables, and roughly seventy CISO reviewers, frames the situation this way: Current patch cycles, response processes, and risk metrics are not ready for AI-driven discovery and exploitation of vulnerabilities [1]. Mythos exposed a structural failure that was already present.</p><p>The evidence for that pre-existing failure is substantial.</p><p>The<a href="https://nvd.nist.gov/"> National Vulnerability Database</a> enriched a record 42,000 CVEs in 2025. CVE submissions increased by 263% in the same period [4]. FIRST forecasts up to 100,000 new CVEs in 2026. On April 15, 2026, NIST formally acknowledged the math wasn&#8217;t working by shifting to a risk-based enrichment model, immediately moving 29,000 backlogged CVEs to &#8220;Not Scheduled&#8221; status. The system built to track vulnerabilities at scale has thrown in the towel.</p><p>Chris Hughes of<a href="https://www.resilientcyber.io/"> Resilient Cyber</a> presented a structural equation at the CSA Agentic AI Security Summit [4]: 14 billion GitHub commits projected for 2026, multiplied by a 2.74x AI bug rate, divided by a 4-hour exploit window. He calls the result &#8220;the Vulnpocalypse.&#8221; It&#8217;s a pointed way of describing something that is, unfortunately, just math.</p><p>The<a href="https://zerodayclock.com/"> Zero Day Clock</a>, launched in March 2026 by Sergej Epp and others, tracks median time from vulnerability disclosure to confirmed exploitation using 3,529 CVE-exploit pairs [6]. The trend line is unambiguous: 771 days in 2018, 10.8 months in 2021, 4 hours in 2024.<a href="https://www.ibm.com/think/insights/the-mythos-moment-when-discovery-outpaces-defense"> IBM&#8217;s analysis</a> of the Mythos moment concludes that, for the first time, response is now the binding constraint, not discovery [7].</p><p>The entire market category of risk-based vulnerability management (EPSS, CISA KEV, CTEM) exists because <strong>the security industry implicitly acknowledged decades ago that complete patching was unachievable</strong>. Mythos makes that acknowledgment explicit and urgent.</p><h2><strong>What Glasswing Doesn&#8217;t Solve</strong></h2><p>Project Glasswing is, as described, likely the largest coordinated vulnerability disclosure effort in history. But, let&#8217;s be clear about what it is and what it isn&#8217;t.</p><p>Glasswing is a discovery and hardening initiative applied to code. It patches software in the systems of participating vendors. As of late April 2026, VulnCheck found only one CVE directly credited to Glasswing in the public record: CVE-2026-4747 [8]. Chris Hughes&#8217; conclusion: fewer than 1% of vulnerabilities found by Mythos have been patched [8].<a href="https://www.picussecurity.com/resource/blog/anthropics-project-glasswing-paradox"> Picus Security</a> arrives at the same place independently. <strong>Glasswing solved the finding problem, but nobody solved the fixing problem</strong> [9].</p><p>Beyond the remediation gap, there are three layers Glasswing simply doesn&#8217;t touch.</p><p><strong>The human layer.</strong> Social engineering attacks require no CVE, no exploit, and no vulnerability scanner. In 2023, MGM Resorts lost approximately $100 million when attackers who did not exploit a single technical vulnerability called the help desk, impersonated an employee, and convinced an agent to reset credentials [10]. That same year, a 3CX employee installed a trojanized software package on a personal computer, initiating the first confirmed cascading supply chain compromise [11]. No amount of code hardening addresses this. As code from participating vendors gets cleaner, the path of least resistance shifts toward the humans and trust chains underneath.</p><p><strong>The coverage gap.</strong> The CSA briefing warns that the world&#8217;s exploitable attack surface is vastly larger than what any curated partner ecosystem can cover [1]. The 40 vendors in the Glasswing early access program represent a fraction of the software dependencies running in any medium or large organization. Everyone outside that consortium remains fully exposed.</p><p><strong>The agentic ecosystem itself.</strong> This is the one I think is getting the least attention.<a href="https://disesdi.substack.com/p/mythos-legends-and-outright-lies"> Disesdi Shoshana Cox</a>, AI Policy Lead at the OWASP AI Exchange and a practitioner I&#8217;ve been following closely, explains that most organizations deploying AI agents lack proper access controls, experimentation logging, data and inference monitoring, and AI-specific threat models [12]. The result is two sets of systems effectively unguarded. Classical infrastructure and AI infrastructure are both now exploitable, and connected.</p><h2><strong>Where the Research Points</strong></h2><p>I want to be careful here not to turn a research synthesis into a vendor recommendations list. The practical &#8220;where to focus&#8221; articles are coming separately. But the research does point clearly in certain directions, and it would be intellectually dishonest not to say so.</p><p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026">Gartner named agentic AI oversight the number-one cybersecurity trend for 2026</a> [13]. Their January 2026 report<a href="https://www.beyondtrust.com/resources/research/gartner-how-to-secure-enterprise-agentic-ai-ambition"> &#8220;How to Secure Enterprise Agentic AI Ambition&#8221;</a> by Jeremy D&#8217;Hoinne and Dionisio Zumerle identifies Non-Human Identity security as the foundational control layer for machine actors [14]. The Five Eyes guidance makes the same call, identifying privilege risk as the first and most consequential risk category for agentic deployments [2].</p><p>I&#8217;d encourage you to read the Five Eyes guidance yourself. Six national cybersecurity agencies collectively saying &#8220;<strong>prioritize resilience, reversibility and risk containment over efficiency gains</strong>&#8220; is a meaningful signal. That is a government-level statement that prevention-first thinking is no longer the primary frame.</p><p><a href="https://genai.owasp.org/initiatives/agentic-security-initiative/">OWASP&#8217;s Agentic Top 10 for 2026</a> [15], particularly ASI02 (Tool Misuse and Exploitation) and ASI03 (Identity and Privilege Abuse), maps the specific threat categories that matter most in this environment.</p><p><a href="https://kenhuangus.substack.com/p/what-a-secure-harness-for-agentic">Ken Huang&#8217;s secure harness architecture</a> and<a href="https://disesdi.substack.com/p/mythos-legends-and-outright-lies"> Shoshana Cox&#8217;s least capability principle</a>, developed independently from different analytical traditions, converge on the same insight. Least privilege (giving an identity only the permissions it needs) is necessary but not sufficient when the identity in question is an AI agent operating autonomously [12][16]. The additional requirement is <strong>least capability, </strong>which is<strong> </strong>an architectural constraint on what an agent can structurally <em>do</em>, not merely what it is <em>permitted</em> to do. Permissions can be misconfigured, inherited, escalated, or exploited. Architecture is harder to bypass.</p><p>I found a lack of new strategy around backup and recovery in a post-Mythos world, and that bothers me. The established attacker playbook against backup infrastructure is equally executable by a compromised AI agent using valid credentials, indistinguishable from legitimate administrative activity [17][18][19]. Immutability needs to be architectural, not a configuration setting. And there&#8217;s a threat scenario the literature hasn&#8217;t fully addressed yet, but I think it should be. How would a backup/restoration cycle be possible if it&#8217;s not a single catastrophic event, but repeated disruption cycles triggered faster than restoration can complete? Current RPO and RTO frameworks were designed for one bad day. They don&#8217;t account for ten consecutive ones. I&#8217;m treating this as its own research project. Stay tuned.</p><h2><strong>Voices I&#8217;m Following and Recommend</strong></h2><p>The research on this topic is genuinely good. These are the people and organizations whose work I found most substantive:</p><p><a href="https://www.resilientcyber.io/">Chris Hughes / Resilient Cyber</a> - The most consistently rigorous independent analyst voice on this topic. His newsletter issues 92-96 are the best ongoing coverage of Mythos implications I&#8217;ve found.</p><p><a href="https://disesdi.substack.com/">Disesdi Shoshana Cox / Angles of Attack</a> - Technically credible, openly skeptical of vendor hype, regulatory-forward. The only voice I found explicitly connecting Mythos to the standards and policy conversations happening in Washington right now, including the formation of MOSAIC (Multi-Organization Secure AI Coordination).</p><p><a href="https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html">Bruce Schneier</a> - The essential skeptic. Called Glasswing &#8220;very much a PR play by Anthropic -- and it worked.&#8221; Worth reading for the counterargument, especially because Schneier is also a contributing author on the CSA briefing. He can hold both views at once.</p><p><a href="https://cetas.turing.ac.uk/publications/claude-mythos-future-cybersecurity">CETaS / Alan Turing Institute</a> - Chris Hicks, Connor Attridge, Ardi Janjeva, and Carolyn Ashurst produced the most rigorous academic treatment of Mythos I found [20].</p><p><a href="https://www.weforum.org/press/2026/05/new-report-shows-how-ai-gives-cybersecurity-competitive-advantage/">WEF &#8220;AI and Cyber: Empowering Defenders&#8221;</a> - Published May 4, 2026, in collaboration with KPMG. 94% of cyber leaders identify AI as the defining force in their field. Draws on 20 real-world case studies across 84 organizations [21].</p><p>The<a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/mythosreadyv1.0.pdf"> CSA CISO Community v1.0 briefing</a> remains the anchor document for this topic. If you read nothing else, read that.</p><h2><strong>Not the End</strong></h2><p>I started this research expecting to write about Mythos as a new threat. What I found instead is that Mythos is more like a floodlight pointed at an old one.</p><p>The security industry was built around an organizing premise. You find vulnerabilities, patch them before attackers exploit them, and that was <em>always </em>partially unachievable at scale. The tools that proliferated around that premise (CVSS, NVD, periodic pen tests, reactive patch management) were <em>responses to an impossible problem</em>, not solutions to it. Mythos didn&#8217;t make that premise impossible. It made the impossibility undeniable.</p><p>What comes after this reckoning? The research points toward a security posture organized around limiting damage rather than preventing entry. Some examples include limiting blast radius by design, identity governance for machine actors, and behavioral detection calibrated for non-human speed. I&#8217;d also like to see plans for recovery architectures that don&#8217;t assume a single bad event on a human timeline.</p><p>Those are topics I will dig into next. If you&#8217;ve found sources or research I should have included, I want to hear about it. That&#8217;s what the community is for.</p><p>-- Laura Kenner</p><div><hr></div><h2><strong>References</strong></h2><p>[1] CSA CISO Community, SANS, [un]prompted, and OWASP Gen AI Security Project, &#8220;The &#8216;AI Vulnerability Storm&#8217;: Building a &#8216;Mythos-ready&#8217; Security Program,&#8221; Cloud Security Alliance, v1.0, May 1, 2026. https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/mythosreadyv1.0.pdf</p><p>[2] CISA, NSA, ASD ACSC, Canadian Centre for Cyber Security, NCSC-NZ, NCSC-UK, &#8220;Careful Adoption of Agentic AI Services,&#8221; Joint Guidance, Apr. 30, 2026. https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF</p><p>[3] Anthropic Red Team, &#8220;Mythos Preview: Technical Disclosure,&#8221; Anthropic, Apr. 2026. https://red.anthropic.com/2026/mythos-preview/</p><p>[4] C. Hughes, &#8220;The Vulnpocalypse Is Here. Now What?&#8221; Presentation, CSA Agentic AI Security Summit, May 2026. [Slide deck, on file]</p><p>[5] AISLE, &#8220;AI Cybersecurity After Mythos: The Jagged Frontier,&#8221; AISLE, Apr. 2026. https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier</p><p>[6] S. Epp et al., Zero Day Clock, Mar. 2026. https://zerodayclock.com</p><p>[7] IBM, &#8220;The Mythos Moment When Discovery Outpaces Defense,&#8221; IBM Think Insights, Apr. 2026. https://www.ibm.com/think/insights/the-mythos-moment-when-discovery-outpaces-defense</p><p>[8] C. Hughes, Resilient Cyber Newsletter, Issues #92-#96, Apr.-May 2026. https://www.resilientcyber.io</p><p>[9] Picus Security, &#8220;The Glasswing Paradox: The Thing That Can Break Everything Is Also The Thing That Fixes Everything,&#8221; Picus Security Blog, Apr. 2026. https://www.picussecurity.com/resource/blog/anthropics-project-glasswing-paradox</p><p>[10] Trusona, &#8220;Prevent the Next $100M MGM-Style Breach,&#8221; Trusona Blog, Oct. 9, 2025. https://www.trusona.com/blog/prevent-mgm-style-breach</p><p>[11] 3CX, &#8220;Security Update Thursday 20 April 2023 -- Initial Intrusion Vector Found,&#8221; 3CX Blog, Apr. 20, 2023. https://www.3cx.com/blog/news/mandiant-security-update2/</p><p>[12] D. S. Cox, &#8220;Mythos, Legends, and Outright Lies,&#8221; Angles of Attack: The AI Security Intelligence Brief, Edition 49, May 6, 2026. https://disesdi.substack.com/p/mythos-legends-and-outright-lies</p><p>[13] Gartner, Inc., &#8220;Gartner Identifies the Top Cybersecurity Trends for 2026,&#8221; Press Release, Feb. 5, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026</p><p>[14] J. D&#8217;Hoinne and D. Zumerle, &#8220;How to Secure Enterprise Agentic AI Ambition,&#8221; Gartner Research, Jan. 5, 2026. [Gartner client access]</p><p>[15] OWASP GenAI Security Project, &#8220;OWASP Top 10 for Agentic Applications 2026,&#8221; Agentic Security Initiative, Dec. 2025. https://genai.owasp.org/initiatives/agentic-security-initiative/</p><p>[16] K. Huang, &#8220;What a Secure Harness for Agentic AI Actually Is,&#8221; Agentic AI (Substack), May 6, 2026. https://kenhuangus.substack.com/p/what-a-secure-harness-for-agentic</p><p>[17] S. Rao, &#8220;Why Ransomware Attacks Succeed Even When Backups Exist,&#8221; BleepingComputer, sponsored by Acronis, May 2026. https://www.bleepingcomputer.com/news/security/why-ransomware-attacks-succeed-even-when-backups-exist/</p><p>[18] Object First, &#8220;Object First Survey: 89% of IT Leaders Fear AI-Powered Cyberattacks Will Cost Them Their Data,&#8221; Press Release, Mar. 31, 2026. https://www.businesswire.com/news/home/20260331825488/en</p><p>[19] Veeam, cited in TechRadar, &#8220;Ransomware attackers are going after backup storage to force you to pay up,&#8221; TechRadar, 2025. https://www.techradar.com/news/ransomware-attackers-are-going-after-backup-storage-to-force-you-to-pay-up</p><p>[20] C. Hicks, C. Attridge, A. Janjeva and C. Ashurst, &#8220;Claude Mythos: What Does Anthropic&#8217;s New Model Mean for the Future of Cybersecurity?&#8221; CETaS Expert Analysis, Apr. 2026. https://cetas.turing.ac.uk/publications/claude-mythos-future-cybersecurity</p><p>[21] World Economic Forum and KPMG, &#8220;AI and Cyber: Empowering Defenders,&#8221; WEF White Paper, May 4, 2026. https://www.weforum.org/press/2026/05/new-report-shows-how-ai-gives-cybersecurity-competitive-advantage/</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Out of Band! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/p/follow-the-research-cybersecurity?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.outofband.bootstrapcyber.com/p/follow-the-research-cybersecurity?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Welcome to Out of Band ]]></title><description><![CDATA[Here's what you're in for]]></description><link>https://www.outofband.bootstrapcyber.com/p/welcome-to-out-of-band</link><guid isPermaLink="false">https://www.outofband.bootstrapcyber.com/p/welcome-to-out-of-band</guid><dc:creator><![CDATA[Laura Kenner]]></dc:creator><pubDate>Wed, 27 May 2026 15:56:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!T4Hz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T4Hz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T4Hz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!T4Hz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!T4Hz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!T4Hz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T4Hz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180448,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.outofband.bootstrapcyber.com/i/199479761?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T4Hz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!T4Hz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!T4Hz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!T4Hz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdafddaa-0e96-494a-bbe7-09671d2aaac1_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Welcome. I&#8217;m genuinely glad you&#8217;re here. Let me tell you what this is and why it exists.</p><h3><strong>Why Out of Band exists</strong></h3><p>There&#8217;s no shortage of cybersecurity news. There&#8217;s a real shortage of people willing to say what they actually think about it without a vendor contract, a conference sponsorship, or a marketing budget shaping the narrative.</p><p>Out of Band is my attempt to fix that.</p><p>I spend a lot of time researching, producing video, and talking with practitioners. This is where I write down what I&#8217;m thinking after all of that. It&#8217;s my perspective on what it means for the people in the trenches.</p><h3><strong>What to expect</strong></h3><p>Out of Band is built around deep research. Each research piece kicks off a series of follow-on articles that dig into the subtopics, the implications, and the questions raised.</p><p>You&#8217;ll get two types of pieces here:</p><p><em>Straight research</em>: This is where I like to start. I may start with a thesis or be inspired by the &#8220;talk on the street&#8221; (usually LinkedIn) and I dig in. I gather as much data as I can from as many sources as I can, and then piece together my original analysis. These take time and they show it. Properly cited, linked, unsponsored.</p><p><em>Colorful POV</em>: After doing the research and ruminating on it a bit, I generally have more thoughts to share. A lot of times I have more questions than answers. Sometimes I want to test my ideas against community feedback. I share my thought process so we can have these important conversations.</p><h3><strong>Who I am</strong></h3><p>I&#8217;m Laura Kenner, founder of Bootstrap Cyber. I came to cybersecurity from an unrelated field (medical office admin). I had a mid-life crisis and went for a total career change. I achieved a BS in Computer Networking and Cybersecurity, as well as CCNA, CompTIA Network+, and Security+ certifications. I &#8220;broke into&#8221; the field via my first job in a technical marketing role for a cybersecurity vendor. I now run content, social, and video strategy for cybersecurity startups.</p><p>The combination of a cybersecurity education and content marketing experience has given me a very unique perspective. I can read the research, understand what practitioners are dealing with, and translate it into something useful, maybe even entertaining.</p><p>I also started Bootstrap Cyber Media LLC as a channel for the practitioners, the boots on the ground, doing the work every day. It&#8217;s my side hustle, my passion project, and I love it. Try to stop me.</p><p>My written content mostly lives here on Substack. My video content lives on YouTube. And the community page is on LinkedIn. Please connect, follow, subscribe!</p><h3><strong>One ask</strong></h3><p>I&#8217;m just getting started here. Comments are most welcome, even when you disagree. I appreciate feedback and I read everything. I look forward to the conversations more than the subscribes.</p><p>Welcome to Out of Band.</p><p>&#8212; Laura Kenner</p><p>Bootstrap Cyber Media LLC at https://www.bootstrapcyber.com </p><p>YouTube at http://www.youtube.com/@BootstrapCyber </p><p>LinkedIn at https://www.linkedin.com/company/bootstrap-cyber </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.outofband.bootstrapcyber.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Out of Band! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>