09/04/2026
JUST LAST WEEKEND I wrote an article here on LinkedIn about a question we may not ask often enough when considering data security:
"Was the vulnerability the position this person held—or was the vulnerability created by something that 'CHANGED' in that person's life while the organization's trust and access remained unchanged?" An unsettling thought for and alike.
Then THIS article crosses my screen. Full story linked below in comments section.
groups are reportedly recruiting/compromising employees, contractors and other insiders who already have LEGITIMATE ACCESS to organizational systems. Think about that for a moment...
What if the firewall worked? What if the access controls worked? What if the credentials worked? What if the technology did exactly what it was designed to do? And what if, despite all these measures and investments, the person legitimately holding that access 'BECAME' the vulnerability?
Cybersecurity is obviously important -- no doubt! But sometimes the way AROUND the “cyber” security is actually a HUMAN. Which is why one of the more important questions may not simply be: “How secure is our technology?” But also:
“What may have 'CHANGED' with the people we've authorized to use it?” Because the vulnerability isn't always the control that failed. Sometimes it's the assumption we made about how people would interact with that control.
Physical. Data. Reputational.
Risk is rarely as neatly compartmentalized as our departments and technologies may suggest.
I know someone who can help.