The National Security Agency released its best practices for cyber hygiene yesterday but created some confusion for users in its identification of threats and suggestions of wrong architecture according to AI and cybersecurity expert, Chris Nyhuis, who is CEO of Vigilant:
“My thoughts are that the NSA didn’t get it necessarily wrong but they also didn’t get it right. The guidance names the right threat and then answers it with the wrong architecture. It correctly identifies AI-accelerated living off the land activity as the core problem, then recommends endpoint detection, log aggregation, and behavioral baselines, which are the three things that fail hardest against an attacker using legitimate signed binaries. It tells defenders to baseline traffic and detect anomalies but never requires them to actually capture that traffic. The segmentation guidance leans on next-generation firewalls, and firewalls are themselves an attack surface: they get exploited, misconfigured, and turned into the pivot point. You need collection in front of that control plane, a passive tap and full-stack detection that sees the traffic regardless of whether the enforcement device is trustworthy or still under your control. Behavioral learning has the same problem. AI-driven attackers can pace themselves to the baseline, introduce entropy, and shape their own activity into what the model has already learned to call normal. A system trained to recognize normal is a system an adversary can teach. The answer is not more defensive AI reviewing yesterday’s logs; it is network evidence you actually hold and human forensic validation on top of it. “
Hopefully the NSA hears this feedback and “gets it”. Because advice like this only works if everybody listens.
Related
This entry was posted on September 4, 2026 at 2:25 pm and is filed under Commentary with tags NSA. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
NSA’s Cyber Hygiene Best Practices Name the Right Threats But Answer With Wrong Architecture
The National Security Agency released its best practices for cyber hygiene yesterday but created some confusion for users in its identification of threats and suggestions of wrong architecture according to AI and cybersecurity expert, Chris Nyhuis, who is CEO of Vigilant:
“My thoughts are that the NSA didn’t get it necessarily wrong but they also didn’t get it right. The guidance names the right threat and then answers it with the wrong architecture. It correctly identifies AI-accelerated living off the land activity as the core problem, then recommends endpoint detection, log aggregation, and behavioral baselines, which are the three things that fail hardest against an attacker using legitimate signed binaries. It tells defenders to baseline traffic and detect anomalies but never requires them to actually capture that traffic. The segmentation guidance leans on next-generation firewalls, and firewalls are themselves an attack surface: they get exploited, misconfigured, and turned into the pivot point. You need collection in front of that control plane, a passive tap and full-stack detection that sees the traffic regardless of whether the enforcement device is trustworthy or still under your control. Behavioral learning has the same problem. AI-driven attackers can pace themselves to the baseline, introduce entropy, and shape their own activity into what the model has already learned to call normal. A system trained to recognize normal is a system an adversary can teach. The answer is not more defensive AI reviewing yesterday’s logs; it is network evidence you actually hold and human forensic validation on top of it. “
Hopefully the NSA hears this feedback and “gets it”. Because advice like this only works if everybody listens.
Share this:
Like this:
Related
This entry was posted on September 4, 2026 at 2:25 pm and is filed under Commentary with tags NSA. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.