Who gets to decide what a threat looks like?

In the first blog, i posed the question “What does a threat look like"?” if you don’t want to read it again, i can summarise it,

Something happened → someone identifies the something → a threat is confirmed → the entity responds.

This is the point we left it open to discussion and thought, and the justification of security being more than just detection. I’ve used common Cyber Security analogies here such as DFIR, or Threat Intelligence or even the heady corporate heights of the CISO. Eventually, someone decides this is an incident, but what stage?

  • PowerShell?

  • The Analyst and their trained eye?

  • The Escalation?

  • The Classification?

  • The Assessment?

  • Or, when the organization activated its retainer with CrowdStrike?

There is no absolute point in this process when a flag suddenly appears and becomes a threat, there is a process. There is essentially three actors in this process:

The securitizing actor, “This is a threat!”

The Audience these are the folks responsible for the acceptance of the resultant framing from the securitising actor

  • The SOC

  • The CISO

  • ELT

  • Board

  • Regulators

  • IR Teams

  • Customers?

  • Employees

The secondary term i want to introduce here is the “reference object”, in which who are we protecting?

Data?

$$$$

Reputation?

Customers?


And that’s where I find I revisit the question, “Who gets to decide what is a threat?” It’s not always the first SOC person who is on their 5th Monster of the night. It may land on the CISO desk the next morning and they decide which Golf event to attend, who decides that the threat simply does not carry the same impact as initially thought. The authority is often different when it comes to interpretation, and that’s where power in organisations and this interpretation can be turned into an organisational reality.

This is where language is important and using language such as “unusual activity” can quickly become “suspicious activity” and then possibly even “malicious activity”. Eventually, its plausible it becomes an active incident or god forbid A CYBER ATTACK AND YOU’RE GONNA BE ON BLEEPING COMPUTER, a fate worse than death tbh.

The underlying event is still true which is “Something happened” but what has changed is the interpretation of the potential significance, and the subsquenct acceptance is when the question is asked “does everyone in this organisation have the same ability to define something as a threat?”

Treating security language we’re discussing here is very much born from the Copenhagen School with the following concepts worth understanding

Thanks to our lord and savior ChatGPT

If deciding what constitutes a threat is partly a social (SOC, CISO etc) and organisational process, then the security process we’ve discussed here isn’t even close to being about detecting reality. It’s about constructing a shared interpretation of absolute reality.

So we arrive at the final question,

Who controls that interpretation?

Previous
Previous

What Happens When Looking for Threats Becomes Your Job?

Next
Next

What does a threat look like?