CYBR.Minded
CYBR.Minded is a cybersecurity podcast for leaders who know risk is not reduced by tools alone. Hosted through the lens of behavioral science, governance, culture, and executive risk, the show explores the human realities behind secure decision-making - from cognitive bias and trust to CISO burnout, board pressure, AI readiness, and the organizational dynamics that shape security outcomes. Built for CISOs, GRC leaders, cyber risk professionals, and board-facing security executives, CYBR.Minded helps listeners look beyond the controls and understand the human side of cybersecurity.
CYBR.Minded
Trust Is the Missing Layer in Cybersecurity with Tammy Moskites
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Why do security programs that appear mature still fail when it comes to trust, alignment, and decision-making? In this episode of CYBR.Minded, Dr. Dustin Sachs sits down with Tammy Moskites, founder and CEO of CyAlliance, to discuss how trust, communication, leadership, and risk translation shape security outcomes. They explore why organizations often mistake trust problems for process problems and how leaders can create environments where better decisions are made before incidents occur.
Things mentioned:
- CyAlliance - https://www.cyalliance.com/
- Thinking, Fast and Slow by Daniel Kahneman - https://www.goodreads.com/en/book/show/11468377-thinking-fast-and-slow
Do you have a question for the host? Reach out to us at media@cscgroupllc.com
In this episode:
- Host: Dr. Dustin Sachs
- Guest: Tammy Moskites
- Director: Bill Brenner
- Producer: Lauren Andrus
- Editor: Ivan Basconcillo
Produced in partnership with Psybercog Labs
Keep up with our Conferences and Events:
Keep up with CYBR.SEC.Media:
Learn About CYBR.SEC.Careers Non-Profit Efforts
Subscribe to the podcast:
Listen to our other shows:
Welcome to Cyberminded, where cybersecurity, behavior, and leadership meet. I'm Dr. Dustin Sachs, and this podcast, co-sponsored by CyberCog Labs and Cybersec Media, asks a simple question. What if the biggest risks in cybersecurity start with how we think, decide, and respond? Each episode is a chance to pause, reflect, and see security through a more human lens. Let's take some time and look beyond the controls to the human side of cybersecurity. Organizations often respond by adding more controls, more dashboards, and more language around accountability. Yet the gap persists. The issue is not always that security leaders lack the right tools. Often it's that cyber risk is being translated through competing incentives, partial trust, and different assumptions about how work actually gets done. So today's overarching question: what changes when we stop treating trust and judgment as soft issues around cybersecurity and start treating them as core operating conditions for whether security works? From a behavioral science standpoint, the people don't make security decisions in a vacuum. They make them under pressure through relationships and side systems of trust, dealing with ambiguity, fatigue, and business trade-offs. And if leaders misread those conditions, they misread the risk. That's why the same control can look strong in policy, but still break down in practice. And as everybody knows, that's the space this podcast is built to explore. Cybersecurity, as we always say, depends on trust tools, policies, and governance, but it also depends on attention, judgment, incentives, trust, communication, and ultimately behavior. Welcome to today's episode of Cyberminded. So, again, one of the kind of overarching questions we'll be talking about today is how can cybersecurity leaders build programs that do more than enforce controls and instead create the trust, translation, and judgment conditions that make security decisions more likely. My guest today is a powerhouse in the industry, Tammy Muskitis, founder and CEO of Psy Alliance. Tammy's a cybersecurity executive whose work sits at the intersection of enterprise security leadership, business alignment, and industry trust. Her career includes senior leadership roles, spanning Accenture Security, Home Depot, and Time Warner Cable. And her public thought leadership has touched machine identity management, leadership development, and the relationship between practitioners, vendors, and the wider business, which makes her an ideal guest for today's conversation on what cyber leadership looks like when we take the human side of security seriously. Tammy, welcome to Cyberminded. Thanks for having me. So before we get into the deeper part of the conversation, I want to start with your perspective on a question that we ask all our guests. When you hear the phrase the human side of cybersecurity, what does that mean to you? And where do you think the industry still kind of misunderstands it?
SPEAKER_01It's funny because when you say the human side of cybersecurity, a lot of people sit there and say, oh, it's immediately identity and access management. They instantly think of user IDs and passwords, but it's so much more than that, right? It's the ability to make trustworthy decision making. It's the ability to be able to understand how we interact, not just professionally, but how we interact with other portions of our organization when we're assessing risk, which is a whole nother problem, right? And then there's the human side, which is also there's a piece of identity, right? But it encompasses so much more than what the average person would think of.
SPEAKER_00Yeah, that's great. And it's interesting because in our last episode, we talked with Dr. Calvin Nobles and he mentioned the fact that this question of what does the human side of cybersecurity mean to you. He did some research and found that he interviewed a hundred people and got 17 different answers. And so far we've done this, will be our third episode, and we've gotten three different answers to this question, which is awesome and really exciting because it really shows the kind of what the fact that when you add humans to the mix, it changes perspectives and that perspectives are important. So, Tammy, the topic for today is cyber leadership through the lens of trust and translation. And I want to start with the distinction of that because many organizations still treat this as a tooling problem or a compliance problem first. So, when does it become clear that a cyber issue is not really about technology, but about whether the security team and the business are interpreting risk through the same lens?
SPEAKER_01When you're looking at it from a holistic perspective and they look at organizations have controls and frameworks and dashboards and all those things that they still make poor decisions, but because leaders operate from inconsistent interpretations, so weak translations between teams, low confidence levels, information being presented. So the distinction the leaders really need to understand is do we have protections, policies, processes, technologies in place? And then from a trustworthy decision making, the answer is going to be can leadership reliably understand reality well enough to make sound risk decisions? So I know that was a lot of words, but but when you look at it from that perspective, it gives you, it gives that that appreciation that mature security organizations should evaluate things on multiple different levels to be successful.
SPEAKER_00Yeah. So where do leaders often misdiagnose a trust problem as a process problem?
SPEAKER_01Always. It just made me laugh thinking about it. As you can probably tell, these aren't scripted, so I have to think about answers sometimes to D all of the above. I think that when you think about a trust problem versus a translation and whether controls operate effectively, whether truth travels accurately, right? Can the uncertainty be voiced in a safe manner, right? And then it turns into whether the leadership can actually interpret and remain coherent, right? And whether across multiple layers to make sure that it's is it processed can't permanently compensate for weak trust, right? It just can't, right? So leaders really need to predict organizational behavior around how they respond to the process. So whether the people trust the institution, right, to surface here's reality and here's the damage that could occur. Those are the distinctions I think they need to understand.
SPEAKER_00Yeah, and one of the things that I hear in what you're saying is that security breaks down long before a control picnically fails. It breaks down when people no longer share the assumptions about the urgency or ownership or trade-offs. Everybody points fingers at each other, no one wants to be left holding the potato when the incident happens, and they'll turn to their dashboards, but their dashboards aren't going to reveal any of that.
SPEAKER_01So lack of complete visibility. There's nothing there, right? Leaders don't trust the underlying data anyway, right? The dashboard is a dashboard, right?
SPEAKER_00Exactly. So you've worked across enterprise leadership in the broader cyber ecosystem. What if those vantage points taught you about the gap between what practitioners need, what executives hear, and what outside partners think they're solving?
SPEAKER_01Yeah, it's funny. So when you think about the translation gap, which is one of my favorite things, right? I always put it into operational blind spot, right? So security says, oh my gosh, we have a critical vulnerability, danger, whatever. Then operations here is a maintenance, inconvenience, problems. We have a problem, we gotta make a maintenance window. And then the same translation gap around that same communication is executive says it's handled. I don't have to worry about it, right? And then the board hears, oh, it's low risk. Hey, we got these dashboards, everything else. And then all of a sudden you have the same issue, four different realities about what's going on. When in fact the escalation clarity is unknown, right? So everybody is just like, it's okay. Oh, we spilled grape juice on the carpet, it's okay. That kind of commercial kind of a thing. But in the governance perspective, it could be a failure, but it's not necessarily a tooling favor. So the way that I feel that organizations kind of need to meet through this, controls can exist, but everybody uh risk in a very different way. It's just depending on the different audience.
SPEAKER_00Before we go further, this episode is supported by Cybercog Labs. At CyberCog Labs, we help cybersecurity and risk leaders look beyond control design to understand where human behavior is shaping cyber risk. Because the issue is not that a control does not exist, it's that the control breaks down when real people encounter pressure, ambiguity, competing priorities, unclear incentives, or decision fatigue. Visit us at cybercog.com. That's P-S Y B-E-R-C-O-G.com. Now, with that in mind, let's get into the problem beneath the problem. Yeah, it depends on the perspective that you're coming from and what your outcome is. The board of directors, they're all worried about share their value. The CEO and CFO are worried about bottom line numbers. So you've got all of these competing interests and getting them to align is important. And that's where this idea of having a system of trust amongst everybody is so important. Of trust as part of the operating environment. What conditions make secure behavior and good judgment harder than leaders might assume?
SPEAKER_01I think a little bit is around how they take a look at it, right? So when you're measuring alignment versus compliance, the different leadership layers are going to assess things as a cyber risk, but they're not going to understand the severity, the readiness, all the other things, and most importantly, the business impact. Right. So I think that what happens is they focus on escalation integrity and measure confidence versus evidence. I think that the governance acknowledges that uncertainty. So the judgment, the security capability is a more of a win, right? They don't trust based off of mature, fine controls, right? But in addition to the organization's ability to understand accurately, especially when it's under pressure.
SPEAKER_00The one kind of theme I think I hear in this first part of the conversation is that cyber performance is shaped not only by controls, but by whether people trust the signals, whether they understand the context, and ultimately whether they believe that security choices make sense inside their day-to-day and their perspective on things. So I want to move from the conceptual distinctions to what leaders can actually do. So most organizations, as we talk about on the show all the time, is most organizations can measure training completion, they can measure the ticket volume, they can measure control coverage, they can even measure audit. But those metrics don't tell whether or not there's decision quality trust or whether operating resilience is really improving. So, what should a CISO or a risk leader or board-facing security executive measure differently if they want to know whether the organization is getting better at cyber judgment, not just busier with more cyber activity?
SPEAKER_01Telling me. What I mean about that, like I said, is not just the severity, but how they move that information upward and across channels. I think if we measure those pieces, they should evaluate whether controls operate effectively. Trying to think of some good ways of going through that. I guess process problems is a good way of for reporting, right? Is delayed escalations, anything around the governance, around those excessive uplayers. I'm just trying to think of good ways.
SPEAKER_00Yeah, no, those are all really great. And so I'll come at this a little bit differently. I'm going to hand you a magic wand. And what is one leadership behavior or governance routine or reporting question that you would wave your wand and magic and materially improve how the business and the security function make decisions together?
SPEAKER_01I wish that they just were coherent.
SPEAKER_00That actually We all are you talking English and I'm talking French? Like, yeah.
SPEAKER_01Yeah, some people are talking just still ones and zeros, and people just don't get that, right? So I think of whether people trust the institution enough to surface whether reality is really there before damage occurs. I think that judgment is a security capability that in the cyberspace that it's not defined by technical controls, right? It's really about the organization being able to understand reality.
SPEAKER_00Yeah, and I think the practical synthesis of all of this is that leaders need to stop using the fact that we've done something or we've taken some action or whatever as a proxy for I'm confident that we're secure, because better governance, better outcomes really come from how decisions are made, where the translation, as you've said, is breaking down. And as you've said, whether the organization can surface friction safely before that friction causes risk.
SPEAKER_01And you look at excessive governance, right? You just mentioned that when decisions slow down, leaders said, Oh, let's add steering committees, let's add additional levels of approval, let's do risk sign-offs, let's do this. And it just compensates for low trust and a judgment of quality. So you're looking at it like a healthy organization should be able to distribute that authority. You don't want low trust, right? You want good, sound judgment and adding excessive layers of governance.
SPEAKER_00It's just Yeah, the last thing you want when it when an alert comes in or when there's an incident is the analyst saying, I'm sorry, I gotta go talk to my manager who's gonna have to talk to his manager, who's gonna have to talk to his manager, who's gonna have to talk to his manager to then have a meeting to figure out what we're gonna do. You've gotta be able to move and you've got to have that trust and that belief that your team is going to operate at the peak of efficiency. And that's why we do things like tabletop exercises. It's why we train our people, but it's also why we build the systems so that when an incident occurs, there's already a support system, a safety net, a way to approach things that everybody knows so that it makes it easier to make that decision in that time of increased pressure and stress.
SPEAKER_01Yeah, and right. I'm sorry, go ahead. Go ahead, please talk about the governance a little bit more. I think what they're saying is around the alignment across the leadership layers has always become the problem, right? Oh, I can't do that. And I think that from a good leadership, a good executive will empower their staff to do their job, right? And make quality decisions. And just like you said, we all do tabletop exercises, right? But we have to trust the authority. And although there are some boundaries, right, you gotta make sure that these people don't have any fear and political consequence, right? I'm doing my job. They have to ensure that their leadership are saying, hey, I'm giving you the confidence to go ahead and get this done, right? Because what you see all the time is that decision latency is gonna kill you, right? Especially if there's something that's basically you've kicked up a war room or whatever you want to say. But confidence versus evidence tracking is crazy. Go, right? We'll have mistakes after the incident. We gotta move.
SPEAKER_00There's a viable reason why there's a whole lessons learned section at the end of an incident, you know.
SPEAKER_01We call it post-mortem. Some people call them most incidents, post-incident. Now we used to call them post-mortems, but people didn't like the word mortem at the end.
SPEAKER_00Yeah, yeah. We have some, we that's a whole separate conversation about the language we use in cybersecurity that I've talked about before, but that could be a whole episode in and of itself. Given everything we've discussed about trust leadership and cyber judgment, I want to close with the question that we ask every guest on Cyberminded. What's one place where the cybersecurity field needs to slow down and think more carefully?
SPEAKER_01I was thinking about this because I do listen to what you're talking about. I think what people need to focus on from a security perspective is focus less on probably the measure of confidence levels around versus evidence. So making sure that you have strong governance that acknowledges uncertainty, right? And adds that uncertainty into projects and makes sure the organizational agility is you're able to move fluently. But I also want to add that it's really important to have trust. And trust is up, down, and backwards, right? Trust in your leadership, trust in your staff, trust in your policies and procedures internally.
SPEAKER_00And because without that, you're not gonna succeed in any Yeah, and it's really about figuring out when we always talk about this concept of thinking fast and slow, the Daniel Kahneman phrase. And there are times where it's perfectly appropriate to think fast. If there's a fire in your house, thinking fast is probably an important thing. But when you're trying to make a decision that's going to impact the viability of your organization or an incident, or should we pay a ransom, maybe slowing down and thinking about it, but also having that level of trust and having those systems in place is super important.
SPEAKER_01You're right. Many process problems are actually trust problems and things. So delayed isolation, softened reporting, all that. I think all of that excessive governance we talked about, dashboard overload, all of that just indicates low trust in an organization on information flow. It's not really a lack process. So I think leaders kind of need to think differently across the layers, but because you're all assessing the same risks, right? We just kind of do the severity and the readiness a little bit differently.
SPEAKER_00Yeah, couldn't have summed it up better myself. Today's conversation really challenged the assumption that cybersecurity effectiveness can be read directly from controls or maturity language. Tammy, you've helped us examine the role trust, translation, and leadership judgment play in whether security decisions actually hold up in the real world. As we always talk about, the human side of cybersecurity is not just about awareness or user behavior. It's about or how organizations shape judgment, incentives, communication, and confidence around risk. So my thanks to you, Tammy, for joining the conversation and to CyberCog Labs and Cybersec Media for supporting the show as we end every episode. Until next time, look beyond the controls and pay attention to the human side of cybersecurity. Thanks, everyone.