Quote for the day:
"Every great story on the planet happened when someone decided not to give up, but kept going no matter what." -- Spryte Loriano
🎧 Listen to the audio debrief on YouTube
▶ Play Audio DigestDuration: 26 mins • Perfect for listening on the go.
Observability should start with business outcomes, not infrastructure
The article, "Observability should start with business outcomes, not
infrastructure" by Vjacheslav Mikitjuk, argues that technical metrics alone are
inadequate for understanding the actual performance of IT systems. The article
points out that while an engineering dashboard might show a system running
efficiently, it could simultaneously be experiencing a serious customer-facing
failure. Therefore, IT teams need to translate technical severity into business
severity to provide management with a clear picture of the impact on customers,
transaction values, and overall business operations. Mikitjuk suggests that
observability needs to follow a chain starting from business outcomes down to
telemetry. This approach involves defining service objectives based on user
experience rather than just infrastructure metrics. He emphasizes that the
translation between technical and business performance should be a shared
responsibility across the organization, involving business leadership, product
owners, and engineering teams. Furthermore, he advises that business
observability must be designed proactively during the service and product design
phases, rather than being an afterthought during an incident. The article also
highlights that observability priorities should be determined by business
criticality, focusing efforts where degradation would have the most significant
consequences. Finally, while AI can assist in interpreting data, it requires the
foundational context of business goals to be truly effective.Redefining Cyber Recovery Requirements in the Era of Modern Cyberattacks
Data embassies and sovereign dispersion
Data embassies and sovereign dispersion present a new approach to managing the
trade-off between data residency and resilience, moving beyond traditional data
localization. Driven by geopolitical instability and cyber threats,
governments—particularly smaller, highly digitized nations like Estonia—are
establishing legally protected digital enclaves on foreign soil. Unlike
multi-region cloud backups subject to host nation laws, genuine data embassies
operate under bilateral treaties granting them diplomatic immunity. They
maintain an active "digital twin" to ensure core civic services, like tax
systems and central bank ledgers, run smoothly during domestic crises such as
cyberattacks or power failures. Gartner anticipates that by 2029, 15% of nations
in unstable regions will have formalized data embassy agreements. Estonia
established the first in 2015, partnering with Luxembourg for its Tier IV data
centers, setting a precedent that requires specific intergovernmental contracts.
Security relies on principles like "encryption as a border," ensuring the origin
state retains decryption keys. While replicating this model is challenging for
private enterprises, IT leaders can adopt similar technical resilience
strategies. By decoupling encryption keys from cloud providers and avoiding
over-reliance on a single vendor or location, businesses can enhance their
operational continuity and mitigate risks associated with physical data
concentration.
How to Handle the Growing Data Complexity Challenge in Cyber Incident Response
The article explains that cyber incident response has become far more complicated than simply handling large volumes of data after a breach. Modern organizations generate information across cloud platforms, collaboration tools, mobile devices, enterprise applications, and third‑party services, creating a sprawling and interconnected data environment. Regulators now expect investigators to identify and analyze a wider range of sensitive information, from traditional personal data to device identifiers, geolocation details, and behavioral patterns. The piece highlights how today’s breaches often involve structured and unstructured data, multimedia files, and systems that store overlapping records, making it difficult to determine what truly matters. Traditional keyword‑based search methods are no longer enough, especially when investigators must uncover “unknown unknowns” hidden across diverse systems. AI‑assisted tools can help by recognizing entities, relationships, and context, but the article stresses that any AI‑driven process must remain legally defensible through documented workflows, validation, and human oversight. Notification decisions—often the hardest part—require consolidating identities, applying jurisdictional rules, and ensuring accuracy at scale. The author concludes that organizations need a disciplined, context‑aware approach to data mining, combining technology, expertise, and defensible processes to understand risk and respond confidently under tight timelines.7 decisions that make an Azure landing zone enterprise-ready
Creating an effective, enterprise-ready Azure landing zone requires thinking
beyond basic reference architectures to build a platform that supports
engineering teams rather than hindering them. The article highlights seven key
design decisions to achieve this balance between security and developer
autonomy. First, treat the landing zone as an operating model—not just a
network—by separating platform resources from application workloads using
management groups and subscriptions to create clear governance boundaries.
Second, opt for Azure Virtual WAN over a self-managed hub-and-spoke setup to
simplify cross-region connectivity and route management. Third, integrate your
security model, such as a next-generation firewall, directly into the routing
architecture from day one rather than bolting it on later. Fourth, implement
governance as guardrails that manage risk without turning routine engineering
tasks into a constant exception process. Fifth, separate your observability
tools for operational health from your SIEM tools for security monitoring to
reduce noise and clarify responsibilities. Sixth, treat CI/CD networking as a
core platform component, using solutions like private GitHub runners to securely
deploy to isolated resources. Finally, ensure an active-active architecture
truly works by making both regions fully production-ready and capable of
independently supporting the workload during a failure.
AI adoption in OT security accelerates as legacy infrastructure and poor data expose readiness gaps
Many industrial organizations are eager to implement AI for operational technology (OT) security, but their current infrastructure often isn't ready. A recent survey highlights that while nearly 88% of organizations are using or planning to use AI, under 8% have deployed it across multiple functions. The main hurdles are poor data quality and the challenges of integrating AI with legacy systems. Most industrial facilities were built long before AI was a consideration, resulting in control systems that produce inconsistent data. Experts point out that legacy environments frequently lack the necessary identity and access management infrastructure and cloud connectivity required for modern AI models. This gap is especially problematic because AI depends on high-quality data and complete asset context to function accurately. Without these, AI tools can produce incorrect assumptions, leading to false positives or missed threats. Furthermore, poor data quality in OT can have serious physical consequences, including equipment damage or safety incidents. To make AI work effectively and safely in these environments, organizations must first focus on improving their architectural foundations. This includes better data normalization, consistent telemetry, and modernized security architectures that provide a stronger base for AI-enabled tools.Operational Technology Scope Expands as Security Matures
The article describes how operational technology (OT) security has matured as
industrial organizations face more frequent and costly cyber incidents.
According to Honeywell’s 2026 OT Cybersecurity Benchmark Report, major attacks
now cause an average of 16 hours of downtime, with losses reaching up to
$500,000 per hour. As a result, companies across energy, manufacturing,
healthcare, maritime, and other critical sectors are shifting from a narrow,
technology‑centric mindset to a broader focus on business resilience. Leaders
increasingly view OT security as essential to safety, uptime, and service
continuity, especially as digital connectivity expands across industrial control
systems, field devices, building management systems, IoT sensors, and medical
equipment. The report shows that organizations with mature programs detect and
respond to threats faster, largely because they maintain strong asset
inventories and continuous monitoring. Yet visibility remains a major gap: only
one‑third have integrated OT systems into a centralized SOC, and just one‑fifth
continuously monitor IoT devices. Legacy systems, staffing shortages, and budget
constraints add further strain. Many organizations are adopting AI for detection
and monitoring, though fully autonomous decision‑making remains rare. The
article concludes that resilience depends on extending security across every
connected system and closing visibility gaps that still hinder effective
response.
I Wasn’t Trying to Predict the Future. I Was Trying to Build One I Could Tolerate
The article is a reflective piece in which the author explains that his work with AI did not begin as an attempt to predict the future but as a practical response to a narrowing set of acceptable options. He frames his journey not as a heroic narrative but as a form of “niche construction,” a security practice focused on shaping an environment that can support more viable futures. Throughout his career in cybersecurity, supply‑chain assurance, information sharing, and industrial systems, he learned that security is rarely about protecting a single object. Instead, it is about maintaining the conditions that allow systems to survive and adapt. He illustrates this through stories of living on self‑built boats, where survival depended on constant maintenance, awareness, and the ability to respond to change. When his own circumstances tightened in 2025, he turned to a large language model as one of the few available tools and began a sustained, iterative collaboration that produced frameworks, documents, code, and new institutional structures. He describes this as building a generative set—an evolving system that creates new possibilities rather than following a fixed plan. The article concludes that meaningful security often comes from constructing environments where better futures can emerge, not from defending the present in isolation.CISOs can no longer ignore the nation-state threat
The accelerating use of AI by nation-state actors is forcing Chief Information
Security Officers (CISOs) to rethink their threat models and treat geopolitical
threats as urgent enterprise risks. Historically, CISOs focused on quickly
expelling adversaries from networks, while government agencies preferred to
monitor them for intelligence. However, AI is now lowering the barrier to entry,
allowing even amateur cybercriminals to launch sophisticated attacks that mimic
nation-state activity. This shift blurs the line between national security
threats and ordinary business risks. A major challenge for organizations is
recognizing their own strategic value to foreign adversaries. Companies in
seemingly benign industries, such as agriculture, can become targets if they
possess valuable intellectual property or supply chain access. AI worsens this
by compressing the time between a vulnerability's discovery and its exploitation
to mere seconds, making traditional patching processes insufficient. To adapt,
security leaders must recognize that AI enables faster, broader pre-positioning
by attackers within organizational assets. Experts advise CISOs to prepare for
fully autonomous attacks, plan to operate through compromises during major
disruptions, and focus on core security controls like zero trust and
multi-factor authentication. Crucially, CISOs need board-level support and
funding to implement these necessary resilience measures.













/vnd/media/media_files/2026/09/19/ai-led-soc-infrastructure-shifts-from-data-to-outcomes-2026-09-19-22-11-44.jpg)






