Skip to content

Automatic translation from Russian to English. It may contain inaccuracies.

Posts

Situation: a colleague of one of my close friends had his account hacked. His boss respon…

August 14, 2026 at 10:40 AMMax Knyazev is typing…Telegram mirror
Post image 1
Situation: a colleague of one of my close friends had his account hacked. His boss responded with a message that I attached to this post ( thanks to my friends who ask me to post this kind of shit 😅 )

Naturally, from the outside it’s all fun/amusing ( well, except for the poor employee whose account was stolen, his boss also yelled at him in a text ). But let's think: when did we manage to reduce information security to finding the culprit?

If we ignore the emotional component, the thesis is simple. If they break an ordinary person, well, okay, it happens. But if an IT specialist... well, that’s all, it’s a mess, comrades ( demonstration of incompetence, loss of confidence and grounds for dismissal )

Sounds somewhat logical. If a dentist doesn't take care of his teeth, is he a bad doctor? Does an obese nutritionist inspire confidence in you as a specialist? And it’s hard to argue here. But I'll try anyway 😏

The fact is that this approach has a slightly indirect relation to information security specifically.

Let's start with the obvious: there are no unhackable people

You can use unique passwords, MFA, separate devices, carefully check links and still be part of the threat model. Because security is a little broader than a binary assessment:

competent - not hacked

incompetent - hacked


You can avoid clicking on phishing links and receive malware through the supply chain. You can use MFA and experience theft of an authorized session. You can do nothing at all, but become a victim of compromise of another system in which your data is circulating

Yes, an IT specialist, and even more so an IT specialist, should have a higher level of digital hygiene. We accept this as a fact. But increased responsibility does not give immunity to attacks

So I’ll throw in the following, slightly less obvious thought: compromise is always possible

That's why Zero Trust, the principle of least privilege, segmentation, PAM, MFA, EDR and dozens of other funny acronyms exist. If a specialized specialist, by definition, could not be hacked, most of the information security would simply not be needed. The goal of mature information security processes is not to create conditions under which no one will ever be hacked ( this is a utopia ). It is important to ensure that the compromise of one account does not turn into a compromise of the entire organization; it is quickly detected, localized and causes minimal damage.

Therefore, after such an incident, an investigation begins:

what was the initial attack vector?

what protection mechanisms were enabled?

what else could it be affected?

what did the attacker do?

How quickly was the attack discovered?

как не допустить повторения этого сценария?


That’s why we create threat models, risk matrices, etc. Because there is always the possibility of hacking and leakage. There is always an internal attacker, groups and services of hostile states. You cannot think that if a person is a specialist, then by definition it is impossible to carry out an attack through him. If you take care of your health, get checked by doctors and exercise, does that make you immortal and indestructible? Rhetorical question 🙃

And note that I did not include the question in the investigation “Who should be fired now for the very fact of hacking?”

Because a culture in which an employee knows that for the very fact of a successful attack he will be publicly declared incompetent and fired, creates another risk: the next employee, having noticed something like this, will first go not to the security guards, but to cover up the traces of the hack. And this already sucks for everyone

And no, I’m not defending an employee who was hacked. Responsibility is needed. If the investigation reveals a deliberate disregard for security requirements, transfer of the password to third parties, etc., we will have to speak differently ( if you remember whose quote I voiced when I talked about similar things in context of RBPO on podcast с Андреем Кулешовым, напишите в комментариях; I will give a cool book on information security to the first one who answers correctly )

But there is a big logical gap between “a person violated security requirements” and “a person was successfully hacked.” And mature information security begins with the ability to notice it

P.S. From the phrase “there is an article in the Labor Code of the Russian Federation for this,” I screamed out loud 👏

🫡 Website | 🤔 Habr

#information_security
Open original post on Telegram

How this work connects to others

Tap a node once to open its description. Tap it again or tap the description to open the work

Hover over a line to see what connects one work to another

Pinch on a trackpad or use the zoom buttons to change scale. Two-finger scrolling moves the page; press and drag the graph to move it

PostTalkEssayResearchProject
100%

Coordinates

VIEW SECTOR

Galaxy «Internet of Things»
Star cluster «Internet of Things»

Right ascension01ʰ 12ᵐ 09ˢDeclination+83° 42′

Discussion

Comments

Comments are available only to confirmed email subscribers. No separate registration or password is required: a magic link opens a comment session

Join the discussion

Enter the same email that you already used for your site subscription. We will send you a magic link to open comments on this device

There are no approved comments here yet