SolarWinds security chief urges 'hacker mindset' as AI shortens exploit windows
SolarWinds' chief information security officer, writing in TechRadar, says AI has cut the time between finding a vulnerability and exploiting it to minutes or seconds, and calls for visibility, observability and secure-by-design practices.
The executive wrote that two things can be counted on in cybersecurity: threats never stop evolving, and every organization will eventually find itself in the bullseye. Automated tools have removed the time defenders once had to understand an attack, assess the risk and decide what to do next, the article said, leaving resilience as the priority for whatever is thrown at a company.
According to the piece, that preparation starts with accepting a simple reality: you cannot defend what you cannot see. Visibility, the CISO argued, is one of the most important capabilities an organization can develop. When teams understand what exists within their environment, how those systems interact and what normal activity looks like, they are in a stronger position to identify unusual behavior before it develops into something more serious.
Observability takes that further by giving security teams the context they need to make informed decisions quickly, especially when time is working against them. As the article put it, visibility tells you what is happening, while observability helps you understand why it is happening. The executive said the distinction is crucial because organizations now operate across on-premises infrastructure, cloud environments, networks and a growing number of connected technologies, and that distributed footprint makes it significantly harder to see where risks sit or where an attacker could exploit a weakness.
Drawing on his own time in offensive cyber operations in the intelligence community, the SolarWinds CISO wrote that the most effective way to understand risk is to think like the adversary. He said he starts by asking how someone would attack an organization and then works backwards to identify and close gaps, because attackers look for weaknesses in people, processes and technologies and take the easiest route to their objective first. He urged security leaders to adopt the same approach, continuously asking where an attacker would start, how they would move through the organization and which controls would slow them down or stop them altogether.
For that to work, the article said, resilience has to be designed into how an organization operates. At SolarWinds, internal and external teams conduct continuous product, enterprise, spear-phishing and physical penetration testing. The company also trains staff across the business to stay vigilant, with the aim of giving employees the instinct to report something suspicious online, and it tries to make reporting easy so events can be analyzed quickly and targeting better understood.
The executive also said the company has invested heavily in Secure by Design so the products it delivers are as secure as possible in practice, meaning every piece of code can be traced back to its source and its integrity verified throughout development. He compared the process to maintaining a chain of custody for evidence, with software components tracked from origin through verification and protection across the entire build. The approach, he added, is increasingly being adopted across the industry as organizations recognize the importance of software integrity, traceability and transparency throughout the development lifecycle.
The article concluded on the two certainties it opened with, stating that a cybersecurity incident is a matter of when, not if, and that AI is accelerating the pace of attacks while broadening their blast radius. Organizations, the CISO wrote, need to know their environments well enough to reduce unnecessary risk.