What I’m Reading: From Alien Life to Zero Trust, Insider Threats and a Bridge Too Far

Last December, I posted about some of the books I’d been reading, so here’s the summer update. There’s no grand theme to the list. We’ve got alien life, talking farm animals, 1920s Long Island, a Soviet ballistic missile submarine and one of the most ambitious military operations of World War II. Pretty normal summer reading. But here’s the problem with working in cybersecurity for too long: eventually you start finding cybersecurity lessons in everything. So that’s what we’re going to do.

John Spiegel

8/25/20266 min read

I've always been a reader. That probably started with my parents. There were always books around the house, and I regularly saw them buried in one. Somewhere along the way that stuck with me, and for most of my life I've tried to keep a book nearby.

Last December, I posted about some of the books I’d been reading, so here’s the summer update. There’s no grand theme to the list. We’ve got alien life, talking farm animals, 1920s Long Island, a Soviet ballistic missile submarine and one of the most ambitious military operations of World War II. Pretty normal summer reading.

But here’s the problem with working in cybersecurity for too long: eventually you start finding cybersecurity lessons in everything. So that’s what we’re going to do.

Project Hail Mary: The Mission Is More Important Than the Technology

First up is Andy Weir’s Project Hail Mary. It took some pressure from a coworker to finally get me to read this one. There may even have been a challenge involved at RSA. Fine. Challenge accepted. And I did it properly: book first.

I’m not going to give away the plot because this is one of those stories that’s much better when you discover it yourself. Weir’s use of science is fascinating, but what really worked for me was the cooperation between the two central characters. And, yes, I’ll admit it: the ending may have put a little moisture in my eyes.

So what does a science-fiction novel about an impossible mission have to do with cybersecurity? Quite a lot, actually, but the biggest lesson for me is that the mission is more important than the technology.

The Hail Mary isn’t there to showcase cool technology. Every technical decision ultimately serves one mission: save humanity. Cybersecurity should work the same way. We have an industry that loves technology—EDR, SSE, SIEM, identity platforms, microsegmentation, AI security, another dashboard, another agent and another acronym—but none of those things are the mission.

The question should always be: What problem are we solving, and does this technology help us solve it? Technology isn’t the objective. The business outcome is.

Animal Farm: All Users Are Untrusted, but Some Are More Untrusted Than Others

Next, George Orwell’s Animal Farm. I first read this one in middle school and loved it. That was another time, when actual communists existed and perhaps the world seemed a little simpler. We’re not going down that rabbit hole today. If you’ve never read it, you should. Consider that my challenge to you.

Reading it again through a cybersecurity lens, one line inevitably comes to mind: All users are untrusted, but some users are more untrusted than others. Yes, I took some liberties with Orwell.

In Zero Trust, users should be treated consistently, but risk is contextual. A privileged administrator accessing critical infrastructure represents a very different risk from an employee checking email. The verification, controls and monitoring should reflect that difference. The danger begins when those differences become unquestioned privilege rather than deliberately managed access.

And that’s where Animal Farm gets particularly relevant to cybersecurity. Privilege grows, exceptions appear and rules change. Eventually, the environment you’re operating bears very little resemblance to the principles you started with.

Sound familiar?

The Great Gatsby: Looking Secure vs. Being Secure

Next up, F. Scott Fitzgerald’s The Great Gatsby. You know the story. You’ve probably read the book, watched one of the movies or both. I’ve read it twice, and Gatsby staring across the bay at the green light has always stuck with me. I could probably write an entire article about the green lights I’ve chased during my own life. Maybe another day.

Instead, let’s look at Gatsby himself. He constructs an extraordinary image of success: the mansion, wealth, status, extravagant parties and this carefully cultivated identity. From the outside, everything looks amazing. Underneath, things are considerably more fragile.

Cybersecurity programs can suffer from the Great Gatsby problem. Pass the audits, buy the market-leading security platforms, build the SOC, create beautiful dashboards, achieve the compliance certifications and put Zero Trust on the strategy slide. Everything looks impressive, but are you actually secure?

The real measure isn’t how good the cybersecurity program looks from the outside. It’s whether you understand what needs protecting, control who can access it, recognize when something abnormal is happening and can continue operating when something inevitably goes wrong.

An impressive façade means very little if the foundations underneath it aren’t sound.

The Hunt for Red October: Trust, but Verify

How about some Cold War? This one started because a coworker reminded me that HPE owns Cray, and Cray’s roots take us back to Chippewa Falls, Wisconsin. Raise a Leinenkugel’s, everyone. Red is my go-to, by the way.

That somehow led me back to Tom Clancy’s The Hunt for Red October. In my opinion, it’s Clancy’s best book. You probably know the plot whether you’ve read it—which I recommend—or watched Sean Connery order, “One ping only.” So I’ll save you the plot summary.

There are dozens of cybersecurity lessons in Red October, but the classic Cold War proverb wins: Trust, but verify.

Captain Marko Ramius is one of the Soviet Navy’s most trusted commanders. He has legitimate authority and legitimate access to one of the Soviet Union’s most strategically important assets. Critically, he also gains control of both nuclear missile keys, defeating the separation of duties intended to prevent one individual from controlling the submarine’s most dangerous capability.

Think about that from a cybersecurity perspective. Ramius doesn’t steal someone’s password, exploit a vulnerability or break through the perimeter. He’s already authenticated, authorized and trusted. He’s the ultimate insider threat precisely because the system trusts him.

That’s an important Zero Trust lesson: authentication proves identity. It doesn’t prove intent. No user—regardless of title, privilege or history—should be so trusted that they can bypass the controls protecting the organization’s crown jewels.

And in our emerging world of Agentic AI, that question becomes even more interesting. What happens when the highly privileged identity isn’t human? Especially when your agent comes back and explains, “He slipped on some spilled tea and hit his head.”

Nothing suspicious there.

A Bridge Too Far: Is Your Zero Trust Program Trying to Do Too Much?

Last up is Cornelius Ryan’s A Bridge Too Far. I first read this one in eighth grade and have been fascinated by Operation Market Garden ever since. It was the classic Hail Mary operation: seize a succession of bridges through the Netherlands, drive XXX Corps north along the airborne corridor, cross the Rhine at Arnhem and potentially create a route into Germany. End the war by Christmas.

And every time you read the book or watch the movie, some irrational part of you wants the outcome to change. Come on, 1st Para. Just capture that last bridge. XXX Corps, what are you waiting for? Are we stopping for tea again?

There are so many cybersecurity lessons in Market Garden that I’m going to spend considerably more time on this one. But let’s start with one: Is your Zero Trust program trying to do too much?

Market Garden was extraordinarily ambitious. Success depended upon multiple difficult objectives—the bridges—being achieved on time and in sequence. Zero Trust programs can create exactly the same problem. Transform identity, modernize the network, segment applications, change endpoint security, classify the data, implement new access policies and modernize legacy applications. And let’s do it all simultaneously.

Every individual objective may make perfect sense. Collectively, however, you’ve created an operation where success depends upon an enormous number of interconnected things going right at approximately the right time.

Eventually, one of the bridges isn’t there when you arrive.

Successful Zero Trust isn’t about lacking ambition. It’s about balancing ambition with what your organization can realistically deploy, operate and sustain. And if this particular problem sounds familiar, here’s the shameless plug: we wrote a book about it, Zero Trust Done Right. Link - https://www.amazon.com/Zero-Trust-Done-Right-Practitioners/dp/B0GQKCN4TN

Next Stop: Holland

A Bridge Too Far isn’t finished for me. Next week, I’m traveling through the Market Garden battlefields in the Netherlands. I want to see the terrain, stand at the bridges, travel the route of Hell’s Highway, look at the distances around Nijmegen and walk Arnhem.

One of the things that fascinates me about Market Garden is the difference between how achievable something can look on a map and what it looks like when you’re actually standing on the ground. There’s another cybersecurity lesson hiding in there: architecture diagrams are wonderfully clean; deployment rarely is.

So I’ll be writing more about Market Garden, leadership, dependencies, communications, resilience and what an operation from 1944 can teach us about deploying Zero Trust today. Lessons from the field—and from the actual places where they happened.

Get ready. I'll be posting on LinkedIn and my personal blog site - https://jspiegel.tech/blog-cybersecurity

And what am I reading now? William Manchester’s The Last Lion, covering the life of Winston Churchill. It’s long. Very long. But so far, amazing.

Maybe you’ll get a book report in a few months.