- CISO Series Newsletter
- Posts
- Join us tomorrow for "Hacking Leadership Skills"
Join us tomorrow for "Hacking Leadership Skills"
Join us TOMORROW, Friday [06-26-26], for "Hacking Leadership Skills"
Join us Friday, June 26, 2026, for “Hacking Leadership Skills: An hour of critical thinking about how to build influence before you have authority.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guests Andy Ellis, principal, Duha, and Joey Johnson, former CISO, Premise Health. We'll have fun conversation and games, plus at the end of the hour we'll do our meetup in breakout rooms.
Defense in Depth
Is the "Attackers Only Need to Be Right Once" a Misnomer?

The hard part for attackers is figuring out HOW to be right only once.
One of the first phrases we learn in cybersecurity is "The good guys have to be right all the time, but the bad guys only have to be right once." But has that moved from truism to outdated cliche?
Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and George Finney, CISO, University of Texas System. Joining is Sean Walls, CISO, Bob’s Discount Furniture.
Listen to the full episode here.
Asymmetric accounting
The saying isn't really about how attacks unfold. It's about how success and failure get measured. Rick Carville, CISO at Great Canadian Entertainment, acknowledged that real-world attacks typically involve multiple steps and that a well-secured system won't usually fall to a single flaw. But the familiar phrase, he said, "is more about the burden of defense than how attacks unfold." His proposed update: "Attackers need persistence, but defenders need resilience." Matthew Rosenquist of Cybersecurity Insights articulated the underlying imbalance. "Attackers only need to succeed once to be characterized as triumphant," he said, "while the expectations for defenders are they must not fail even once, in overall efforts to deny the attackers a win, to be viewed as successful." The asymmetry is baked in by default.
Sometimes it really is that easy
The argument that attackers need to chain multiple vulnerabilities just doesn't reflect reality. Jan van Dijke of SonicBee has seen organizations compromised with a single open RDP port, a single leaked set of admin credentials, and a single employee falling for CEO fraud. "You make it sound like CVEs are the only way hackers get in, which is clearly not the case," he said. Sedric Louissaint of CLA described taking over an organization's Active Directory because the domain admin was using a password like "Password123!" "Sometimes it is that easy," he said. As a red teamer, he more commonly chains vulnerabilities together: misconfigurations, known vulnerabilities, occasionally a new zero day. But the single-point failure scenario is real enough to keep the saying honest.
The spirit of the saying
Dismissing the phrase entirely misses what it was trying to say. Drew Simonis, CISO-in-residence at Insight Partners, acknowledged it is no longer literally true but argued that "the spirit of the comment, that attackers have some advantage due to the complexity of technology systems, remains figuratively true for many." Defenders can use that same complexity to build their own advantage, he said, but most don't. "Instead of creating a minefield, most defenders are focused on creating a tidy display case of goodies." Brian Zimmerman of US Cyber Command argued the saying is being taken out of context. "The hacker has nothing to lose except failing at getting in; they can try as often as possible," he said. The defender has one infrastructure to protect and can't make sustained mistakes.
The cheapest way in
Technical defenses can be bypassed entirely by going around them. "Even with strong infrastructure, attackers often bypass technical defenses by exploiting people — through phishing, deepfakes, or insider threats," said Satish Govindappa of Indrasol. Multiple technical failures may be required to breach a well-built system, he said, but "sometimes just one well-placed manipulation can open the door." Noam Zolberg of Cubic drew the economic contrast sharply. Breaching layered technical security requires a talented, experienced attacker with considerable investment in time and tools. "Hacking user minds and cognition," he said, "is by far less expensive and requires a lesser skill set. That's why the biggest attack surface is us, humans and our ill-equipped minds and poor habits."
Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you’re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.
Huge thanks to our sponsor, Native
Subscribe to Defense in Depth podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.
Reddit AMA – "I've Ripped and Replaced a Security Product. Ask Me Anything."
Our monthly AMA on r/cybersecurity on Reddit is ongoing! Our topic is "I've ripped and replaced a security product. Ask me anything."
Every security team eventually faces it: a product that once solved a real problem but no longer earns its place in the stack. Whether it's a legacy SIEM, a VPN that outlived its purpose, or an identity platform too entrenched to touch, the decision to rip and replace is never simple. Our panel of security leaders has been there, and they're here all week to share what they learned.
Please ask questions for our participants here.
This month's participants are:
Bil Harmer, (u/wilharm3), CISO, Supabase
Steve Zalewski, (u/cybersecsteve), co-host, Defense in Depth
Adam Glick, (u/CISOAdam), CISO, PSG Equity
Joshua Scott, (u/threatrelic), CISO, Hydrolix
Howard Holton, (u/cxo-analyst), outgoing CEO, GigaOm
Thanks to all of our participants for contributing!
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Tom Hollingsworth, organizer, Tech Field Day and Sara Madden, CISO, Convera. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, GuardSquare
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cyber chatter from around the web...
Jump in on these conversations
"Anyone else feels like the cyber security space is oversaturated?" (More here)
"What's your biggest "I'm speaking another language" moment in security?" (More here)
"These workers thought they were getting an extra day off. Turns out it was just a 'cruel' test" (More here)
Coming up on Super Cyber Friday:
[06-26-26] “Hacking Leadership Skills“
[07-10-26] “Hacking M&A“
Register for and add all of these events to your calendar on our Events Page.
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.





