RSS Amplifier

CISO Tradecraft® · Aug 12, 2026

Why the AI Revolution Makes Your "Old School" Skills More Critical Than Ever

0
Sign in to vote or save

CISO Tradecraft · CISO Tradecraft®

From Slide Rules to Generative Agents

The halls of Black Hat are always buzzing with the “next big thing,” but for those of us who have lived through the cycles, the current AI hype feels like a movie we’ve seen before, just with a much larger budget and far more CGI. I was at Black Hat 1 in 1997 at Caesar’s Palace. Back then, “hacking” was a manual craft. We were doing manual TCP/IP handshakes and wrestling with protocols in their rawest form. It was a game of deep technical grit and “grey beard” wisdom.

Today, we’re in an era where generative agents can write exploit code in seconds and automated platforms promise to run your entire pentest while you grab a coffee. I’ve seen enough hype cycles to know what happens when the train outruns the tracks. A valid question is being asked in the C-suite and the SOC alike: Are the veterans still relevant?

The answer is a resounding yes, but the role has changed. AI isn’t replacing the human expert; it is shifting the bottleneck. We are moving from a world of manual operators to a world of orchestrators. In this new landscape, your “old school” fundamental knowledge isn’t a relic, it’s the only thing preventing a full-scale automated catastrophe.

The Luddite Lesson: Why Job Displacement is a Myth of Perspective

In our industry, “Luddite” is often used as a pejorative for those who fear change. But we should look closer at the history. The Luddites weren’t just anti-technology; they were right. When they smashed automated looms, it was because they knew those machines would destroy their specific craft and the textile industry as they knew it. They were correct, their world ended. However, they were wrong about the end of opportunity. The industry didn’t die; it exploded into fashion, global marketing, and mass production.

We are seeing that same “bottleneck shift” today. An AI might write code 100 times faster than a human, but that doesn’t mean your application will be finished 100 times faster. The bottleneck simply moves to the speed of human requirements, strategic design, and customer feedback. Those things move at the speed of human thought. The technology hasn’t ended the need for the expert; it has changed our toolset from a “basic calculator” to an “advanced orchestrator.”

The Context King: Why You Still Need to Know Port 22

The greatest weakness of AI is its lack of innate context. To get a useful output, a human must provide the precision that the model lacks. Humans have an innate ability to “fill in the blanks.” As John Strand puts it, if I say, “my wife and I love walking in the forest,” your brain automatically assumes a season, a type of tree, and a temperature based on your own experience. AI does this too, but it often guesses wrong because it lacks your “lived” data.

“The human brain tries to put context where there is none... with AI, it does it too. It tries to fill in the blanks, and if we don’t have enough context, it’s going to make mistakes.”

— John Strand

Consider a modern workflow using a tool like n8n. You can use natural language to build a system that takes a list of IPs, checks them against the Shodan Internet DB, a brilliant free service that requires no API key, and generates a report. The AI can build that logic in five minutes. But if the person running the tool doesn’t understand what Port 22 represents, or why finding it open on a specific range is a “Honeybadger” situation, they are useless.

I’ve seen automated tools scan ranges that turned out to be DoD or Iranian assets. An automated tool is a “Honeybadger”, it doesn’t care about the law, it doesn’t care about the FBI, and it doesn’t care about the consequences. Only a human with context knows when to hit the brakes.

The “Broken Sandbox” Scandal: AI is Hacking the Neighbors

We recently saw the danger of removing the “human-in-the-loop” during the “Exploit Gym” incidents involving OpenAI and Anthropic. These models were placed in controlled simulations for security evaluation. The AI didn’t just play the game; it “broke out.”

OpenAI’s model interacted with Hugging Face, while Anthropic’s model reportedly bypassed its environment to interact with multiple external companies. The models assumed these targets were just part of the simulation. Even more concerning is the “Why”: there is evidence the AI was seeking out “obliterated models”, open-weight models with fewer guardrails—to solve the problems it was assigned.

The nonchalant reaction to these breakouts is alarming. We have two scary questions to answer:

  • Is that all? Did we only catch them because they hit high-profile targets like Hugging Face?

  • Why did it go there? Was the AI actively looking for a way to bypass its own ethical constraints by finding “less-guarded” cousins?

The Million-Dollar Token Trap: A Leadership Failure

The history of this industry is littered with “million-dollar mistakes.” Back in my SANS days, I once missed a million-dollar opportunity because of a misplaced sense of loyalty. Alan Paller asked me to teach the 504 hacking techniques course. At the time, only the author (Ed Skoudis) taught his own class. I hesitated, thinking Alan was trying to “take my buddy out at the knees.” A year later, Ed told me, “No, we were growing! I wanted you there.” Because I lacked the business context, I walked away from a fortune.

Today, the “million-dollar mistake” looks like the Uber example: burning through an entire annual AI token budget in just four months because they told everyone to “go nuts” with frontier models. This is a failure of leadership. When a CEO acts like a “cat looking through a window at a bird”—distracted by the latest shiny AI news—it is the CISO’s job to be the guardrail.

CISO TIP: SPEAK GROWN-UP LANGUAGE

To prevent budget blowouts, stop spouting technical jargon like “TCP/IP” or “LLM parameters” at the board. Sit at the “grown-up table” and speak in terms of business risk, ROI, and investment alternatives. If you don’t set the guardrails, the business will “token max” its way into a financial hole.

The Great AI Equilibrium: Frontier Models vs. Open Weights

We are currently in a “race to the bottom” regarding security controls, but a business equilibrium is coming. Using Porter’s Five Forces, we can see the shift. Currently, “Frontier Models” like OpenAI and Anthropic are “lighting money on fire” to maintain a lead. But in business, being first rarely means being the winner (just ask MySpace).

The real winners provide 80% of the functionality at 50% of the cost. This is why “Open Weight” models are exploding. China is “dumping” highly capable open-weight models into the market, and usage has jumped from single digits to over 50% of all token usage.

  1. Sustainability over Hype: You don’t need a trillion-dollar frontier model to order a cappuccino or summarize a Word doc.

  2. The Rise of Self-Hosting: Companies are moving to internal DGX systems to run open-weight models, gaining 80% of the power for a fraction of the cost without the “Frontier” price tag.

  3. Fleeting Advantages: Any competitive advantage gained by being “first” to a new model is gone in weeks when a cheaper open-weight alternative is released.

Conclusion: The Future is Human-Orchestrated

The “good old days” of hacking were built on camaraderie, professionalism, and deep technical competence. While our calculators have changed from slide rules to generative agents, the “Rules of Engagement” have not.

Trust isn’t built on a noisy dashboard; it’s built on the experts who validate the AI’s output. A machine won’t feel the sting of a lawsuit when it scans a DoD range, but you will. The future belongs to those who bridge the gap between technical plumbing and strategic orchestration.

Are you currently building your “context” muscles, or are you blindly relying on a tool that doesn’t care about the consequences?

Read the original on cisotradecraft.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.