#securitygovernance — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securitygovernance, aggregated by home.social.
-
Totalforsvar and Cybersecurity
Cybersecurity is a team sport in which the most important player is the user. An informed user is therefore one of the cheapest and most effective security measures any organization can implement.
This may sound straightforward, yet it follows the same principle underpinning national defense strategies such as the Norwegian concept of Totalforsvar (Total Defence). In simple terms, a nation’s ability to defend itself is not determined solely by its armed forces but by the combined capabilities and capacities of society as a whole. The distinction is important: capabilities describe what can be done, while capacities describe how much can be done.
By extension, much of what is accepted as common wisdom within the cybersecurity community is true. Security is as much a matter of culture as it is of the systems designed to protect it. The quickest route to any asset you wish to defend is often through the people who already have access to it.
Incidentally, this appears to be a problem intrinsically tied to the way Western societies have organized themselves.
To paraphrase Allen Dulles—former Director of the CIA and author of The Craft of Intelligence—an open society inevitably places many of its decisions, capabilities, and even aspects of its defense under public scrutiny which makes access to information on how to attack us more accessible to a potential adversary.
This is not paranoia; it is simply a recognition that information is more readily available to us than it was to, say, a citizen of the USSR or Maoist China. Even today where information remains restricted, it is generally far easier to access than in more closed societies. Therefore, as a society, we are constantly exposed to OSINT strategies that, to thrive, depend on an uninformed public.
Social cohesion is an important deterrent in such cases. If we all know that there is a dangerous adversary searching for a particular piece of information, it becomes easier to recognize the threat and prevent access to it.
The patching of information systems also depends on similar principles, where collectively reported incidents shape the measures eventually implemented. Therefore, the more users actively collaborate around a system, the more robust that system becomes.
This is even more visible in open-source software communities, which are not only aware of this mechanism but also dependent on it to function. The difference is that their participants have an arguably greater interest in, and competence with, technology than the average user, making their actions more effective despite their relatively small numbers.
As we continue to digitalize and integrate our lives into the digital space, we may need to make the relationship between security and individuals far more explicit if we wish to safeguard the systems of tomorrow.
Our protection depends on it.
Notes:
- OSINT- Open Source Intelligence: Information in the public domain that can be collected and utilized by an adversary to carry an attack.
- Patching- Updating a system to reduce or eliminate previous weaknesses.
Coming soon!
📕 The Pocket AI Governance Guide
Building on the ideas explored in these articles, my upcoming book examines AI governance, digital resilience, cybersecurity, and the institutional challenges emerging in an AI-driven world.
📘 The Pocket AI Guide is available now for readers looking for a practical introduction to artificial intelligence.
📙 Amazon US: https://a.co/d/gCHHDax
📗 Europe (Amazon Germany): https://amzn.eu/d/3cmlIqa
(Also available through other Amazon stores.)Explore the free articles and resources available on this website.
#cyberDefense #cyberResilience #cyberThreats #Cybersecurity #cybersecurityAwareness #digitalInfrastructure #digitalSociety #informationSecurity #informationWarfare #nationalResilience #OpenSourceIntelligence #openSourceSoftware #OSINT #publicResilience #securityCulture #securityGovernance #socialCohesion #TotalDefence #Totalforsvar #WesternSocieties -
Most AI failures are not “AI problems.”
They are mainly governance problems: unclear accountability, weak data controls, and security gaps.If you work in AI / data / cybersecurity, comment one control you believe every organization must implement in 2026.
#AIGovernance #DataGovernance #Cybersecurity #TrustworthyAI #SecurityGovernance
-
Security Review Philosophy: Collaboration Over Compliance
A two-decade banking security architect walks through how an application review request actually becomes a risk decision. -
Security Review Philosophy: Collaboration Over Compliance
A two-decade banking security architect walks through how an application review request actually becomes a risk decision.