Skip to content
Episode 56

Untitled Episode

September 4th, 2026

1 hr 9 mins 56 secs

Season 3

Your Hosts

About this Episode

Welcome back to the Scinary Information Nexus! This week, Brazos and Joseph hold down the fort for a two-man episode.

We review the new executive order pushing for "free" cybersecurity for critical infrastructure and question how it will actually be funded. We also debate the controversial authorization of private companies launching offensive cyber "hack-backs." Allowing private entities to retaliate against attackers could cause massive collateral damage on shared infrastructure like AWS and Cloudflare.

For the main topic, we answer a viewer question: What do you do if you inherit an organization with no cybersecurity? Brazos explains the governance side with a 5-step foundational plan starting with risk analysis. Joseph offers the technical approach, advocating for immediate network segmentation to stop the bleeding.

From locking down firewalls to dodging the "bystander effect," we outline how to build a security program that continuously improves.

What we cover:

  • The new executive order providing "free" cybersecurity to critical infrastructure
  • The unintended consequences of legalizing corporate "hack-backs"
  • Why risk analysis and strict asset inventory must happen first
  • Governance vs. Action: When to educate leadership vs. when to lock down the firewall
  • Why delegated authority is crucial for enforcing technical controls
  • Deploying critical controls like MFA and backing them up with written policies
  • Avoiding "deferred maintenance" and keeping your security program alive

What is the very first thing you would do if you inherited an unsecured network? Let us know in the comments!


Connect with Scinary Cybersecurity:
https://www.scinary.com
https://x.com/scinarycyber
https://www.linkedin.com/company/scinarycyber/

00:00 Intro
06:45 Free Cyber for Critical Infrastructure
10:15 The Dangers of Offensive Hack-Backs
15:30 Step 1: Risk Analysis & Asset Inventory
25:00 Step 2: Leadership vs Immediate Action
31:30 Step 3: Delegated Authority & IT Roles
51:30 Steps 4 & 5: Controls & Written Policies
59:30 The Final Step: Continuous Improvement

Cybersecurity #InfoSec #HackBack #CriticalInfrastructure #NetworkSecurity #RiskManagement #MFA #CISA #AccessControl