We Built Technology Because We Are Human
In the previous blog post, I explored an uncomfortable idea inspired by Lyutsifer Safin and Erich Fromm.
Perhaps the greatest cybersecurity vulnerability is not hidden inside software.
Perhaps it is our willingness to surrender the responsibility of thinking.
That idea naturally raises another question.
If intelligent people understand cyber risks, why do intelligent organizations continue making preventable mistakes?
The answer, I believe, is not incompetence.
It is trust.
Not trust itself, but the way trust quietly transforms over time.
Technology was never created to replace human judgment.
We built technology because human beings have limits.
We become tired.
We overlook details.
We miss patterns.
We cannot process millions of security events every day.
Automation exists because our attention is finite.
Artificial intelligence exists because modern cybersecurity produces more information than any analyst can realistically understand.
Technology is not the problem.
The problem begins when assistance slowly becomes authority.
When we stop asking,
"What does the system recommend?"
and start believing,
"The system must be right."
That single shift changes everything.
Technology is no longer a tool.
It becomes something we obey.
Trust Is Not the Enemy
Cybersecurity cannot exist without trust.
Every day we trust operating systems, cloud providers, cryptographic algorithms, software vendors, consultants, auditors, and colleagues.
Without trust, modern digital society would simply stop functioning.
The objective has never been to eliminate trust.
The objective is to understand how trust changes.
Healthy trust is active.
It asks questions.
It verifies assumptions.
It expects accountability.
Passive trust asks nothing.
It quietly assumes someone else has already done the thinking.
The most dangerous moment in cybersecurity is not when trust exists.
It is when trust no longer requires verification.
The Trust Ladder
Over time, I have come to think of organizational trust as progressing through five stages.
Level 1: Healthy Trust
"We trust because we understand."
Evidence is continuously examined.
Questions are encouraged.
Verification is normal.
Level 2: Verified Trust
"We trust because we have validated."
Audits.
Testing.
Independent reviews.
Continuous monitoring.
Trust remains active.
Level 3: Assumed Trust
"We trust because it has always worked."
Success quietly becomes expectation.
Curiosity begins to fade.
Level 4: Blind Trust
"We trust because someone else approved it."
Authority replaces understanding.
The organization mistakes reassurance for resilience.
Level 5: Delegated Responsibility
"We trust because the system is thinking for us."
This is where cybersecurity quietly changes.
Technology no longer supports judgment.
It replaces it.
Ironically, organizations often believe they have become more mature.
In reality, they may simply have become more dependent.
A Dashboard Is Not Reality
Walk into almost any Security Operations Center and you will find dashboards everywhere.
Risk scores.
Threat intelligence.
Exposure metrics.
Compliance percentages.
Executive summaries.
They are useful.
They are necessary.
But they are not reality.
Every dashboard is a model.
Every metric is a simplification.
Every visualization compresses countless assumptions into something the human mind can quickly understand.
Green.
Amber.
Red.
None of those colours actually exist inside your network.
They exist only inside the model someone designed to describe it.
This reminds me of Plato's Allegory of the Cave.
Plato argued that people often mistake shadows for reality because the shadows are all they have ever seen.
Cybersecurity faces a similar temptation.
Sometimes we mistake dashboards for understanding.
The dashboard is not the infrastructure.
The dashboard is our interpretation of the infrastructure.
Confusing those two things creates the illusion of certainty.
The New Frontier Is Epistemic Security
Most conversations in cybersecurity focus on protecting systems.
Firewalls.
Identity.
Cloud infrastructure.
Applications.
Endpoints.
Artificial intelligence.
These are all important.
Yet another question receives far less attention.
How do we know that what we believe about our environment is actually true?
Philosophers call this epistemology, the study of knowledge.
Perhaps cybersecurity needs to embrace its own version of it.
I call it Epistemic Security.
Not protecting computers.
Protecting the quality of our understanding.
Every alert.
Every vulnerability scanner.
Every AI assistant.
Every dashboard.
Every threat intelligence feed.
Answers the same question.
"What appears to be happening?"
Very few answer another.
"How certain are we that our understanding is correct?"
Those are fundamentally different questions.
The first is technological.
The second is philosophical.
Artificial Intelligence Changes the Nature of Trust
Artificial intelligence has become one of the most remarkable tools ever introduced into cybersecurity.
It can summarize incidents.
Recommend mitigations.
Generate reports.
Correlate events.
Accelerate investigations.
None of these capabilities concern me.
What concerns me is something much quieter.
Confidence.
Generative AI rarely sounds uncertain.
Its responses are fluent.
Structured.
Persuasive.
Sometimes even elegant.
Humans naturally associate confidence with competence.
That tendency has always existed.
Artificial intelligence simply amplifies it.
The greatest danger is not that AI occasionally produces incorrect answers.
The greatest danger is that people stop asking whether those answers deserve to be trusted.
The moment verification disappears, trust becomes passive.
Every Major Breach Begins with an Assumption
Cybersecurity incidents rarely begin with sophisticated malware.
More often, they begin with a sentence.
"We thought someone else was monitoring that."
"We assumed the vendor had already tested it."
"The report looked fine."
"The AI marked it as low risk."
"Nothing had happened before."
Attackers exploit software.
Before that, they exploit assumptions.
Technology rarely creates complacency.
It simply magnifies it.
Final Thoughts
In Escape from Freedom, Erich Fromm argued that people often seek certainty because responsibility is uncomfortable.
Lyutsifer Safin expressed the same observation in a single sentence.
"We want to be told how to live."
Cybersecurity presents us with a modern version of that same temptation.
We increasingly want to be told what is secure.
What is vulnerable.
What is malicious.
What deserves our attention.
Technology can certainly help answer those questions.
It should never answer them alone.
Perhaps the future of cybersecurity will not be determined by who develops the most intelligent artificial intelligence.
Perhaps it will belong to those who remain intellectually curious long after everyone else has become comfortable.
Because security has never depended on how much we trust technology.
It has always depended on whether we remember that trust itself requires continuous thought.
A Question to Reflect On
The next time you feel reassured by a green dashboard, an audit report, a vendor certification, or an AI recommendation, pause for a moment and ask yourself:
Am I trusting this because I understand it, or because it allows me to stop thinking?
The answer may reveal more about your organization's security posture than any vulnerability assessment ever could.

Post a Comment
0Comments