Cringe, Corrected: Hot Takes Fixed by the CIS Controls
Lawrence Cruciana (President · Corporate Information Technologies), Amelia Cruciana (Cyber Security Intern)
BSidesSF 2026 · Day 1 · AMC Theatre 03
Overview
In an era saturated with online information, discerning credible cybersecurity advice from misleading "hot takes" can be a daunting challenge, especially for early-career professionals. The talk "Cringe, Corrected: Hot Takes Fixed by the CIS Controls," presented by the father-daughter duo Lawrence and Amelia Cruciana, tackles this pervasive issue head-on. Lawrence, a seasoned cybersecurity expert and president of Corporate Information Technologies, along with Amelia, a cybersecurity and privacy student and researcher, demonstrate how the CIS Controls (Center for Internet Security Controls) serve as an invaluable framework for evaluating the efficacy of proposed cyber defense strategies found on social media.
Key moments
- 0:40 Introduction to speakers and talk's "Cringe, Corrected" theme
- 2:00 Session goals: learn practical cyber defense with CIS controls
- 2:34 Talk's motivation: correcting false online cybersecurity information
- 3:29 Understanding CIS Controls: framework, structure, and thematic taxonomies
- 4:34 "Offense Informs Defense": bank robbery analogy for CIS strategy
- 6:00 CIS Controls' Implementation Groups (IGs) for risk adaptation
- 7:10 CIS Controls: highly prescriptive, yet very adaptable framework
Cringe, Corrected: Hot Takes Fixed by the CIS Controls
Speakers: Lawrence Cruciana, President, Corporate Information Technologies; Amelia Cruciana, Cybersecurity & Privacy Student & Researcher, Intern
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=PS9hanusVmA
Overview
In an era saturated with online information, discerning credible cybersecurity advice from misleading "hot takes" can be a daunting challenge, especially for early-career professionals. The talk "Cringe, Corrected: Hot Takes Fixed by the CIS Controls," presented by the father-daughter duo Lawrence and Amelia Cruciana, tackles this pervasive issue head-on. Lawrence, a seasoned cybersecurity expert and president of Corporate Information Technologies, along with Amelia, a cybersecurity and privacy student and researcher, demonstrate how the CIS Controls (Center for Internet Security Controls) serve as an invaluable framework for evaluating the efficacy of proposed cyber defense strategies found on social media.
The core premise of their presentation is to introduce the CIS Controls as a practical, risk-informed decision path that cuts through the noise of online misinformation. By applying the structured, prioritized, and real-world-informed guidance of the CIS Controls, organizations and individuals can develop robust cyber defense strategies that are both approachable and highly effective. The speakers emphasize that adopting such a framework not only helps to avoid common pitfalls but also significantly reduces trial and error in implementing meaningful security measures, making cyber defense more accessible and reliable for all practitioners.
This session illuminates the critical need for a foundational understanding of validated security frameworks in a landscape often dominated by anecdotal or misguided advice. Through engaging real-world examples drawn from social media posts, the Crucianas illustrate how seemingly plausible "solutions" can harbor severe vulnerabilities when viewed through the lens of the CIS Controls. Their approach underscores the power of an "offense informs defense" strategy, where insights from successful attacks directly shape proactive security measures, ultimately leading to better outcomes for cyber resilience.
Background
▶ Watch: Introduction to speakers and talk's "Cringe, Corrected" theme (0:40)
The digital age, while connecting us with vast amounts of information, also presents a significant challenge: the proliferation of unverified or outright incorrect advice, particularly in complex fields like cybersecurity. For individuals new to the industry or those without extensive experience, distinguishing between sound security practices and potentially harmful "hot takes" found on social media platforms can be nearly impossible. This informational cacophony often leads to ineffective defenses, wasted resources, and increased organizational risk. The problem is exacerbated by a common tendency to improvise solutions rather than adhering to established, data-driven frameworks.
To counter this, Lawrence and Amelia Cruciana introduce the CIS Controls as a robust, practical, and adaptable cybersecurity framework. Originating as a SANS project, the CIS Controls have evolved into a set of 18 prioritized controls or families, each comprising multiple safeguards designed to address specific security challenges. Unlike many other frameworks, the CIS Controls are uniquely risk-sized, meaning they are adaptable to an organization's specific risk profile and asset value. This adaptability is primarily achieved through Implementation Groups (IGs), organized into IG1, IG2, and IG3. IG1 represents foundational, essential cyber hygiene suitable for smaller organizations with limited resources, while IG2 and IG3 cater to progressively higher-risk environments with more valuable information assets and greater resources. Crucially, the speakers highlight that even implementing IG1 safeguards can mitigate a remarkable 74% of common attacker tools, techniques, and practices (TTPs).
A foundational philosophy underpinning the CIS Controls is the "offense informs defense" strategy. This approach, akin to how the Secret Service analyzes successful bank robberies to inform bank security layouts, leverages real-world attack data to develop effective defenses. Information from sources like the FBI's IC3 (Internet Crime Complaint Center) and the Verizon Data Breach Investigations Report (DBIR) directly informs the inclusion and prioritization of safeguards within the CIS Controls. This ensures that the controls are not theoretical but are instead designed to counter actual, prevalent threats. Furthermore, the CIS Controls are highly prescriptive, asking practitioners to do only one specific thing per safeguard, avoiding the nebulous or "squishy" guidance found in other frameworks. This directness makes them particularly actionable. The legal community's recognition of the CIS Controls' efficacy is also a significant point; several US states have enacted cyber safe harbor laws, offering civil liability protection to organizations that meaningfully implement frameworks like the CIS Controls, underscoring their recognized ability to mitigate risk.
Key Findings
▶ Watch: Talk's motivation: correcting false online cybersecurity information (2:34)
The central finding of "Cringe, Corrected" is that while social media abounds with cybersecurity advice, much of it is either incomplete, contextually inappropriate, or fundamentally flawed. The CIS Controls provide a crucial "filter" or "grounding" mechanism that enables practitioners, especially those early in their careers, to critically evaluate and correct these "hot takes." The talk demonstrates that relying on improvisation or unvetted online suggestions can inadvertently introduce significant vulnerabilities, despite good intentions.
Through specific examples, the speakers highlight several critical insights:
- Outdated Systems are a Primary Vector: Even when implementing modern security mechanisms like FIDO2 passwordless authentication or fail2ban for brute-force protection, deploying them on severely outdated and unsupported operating systems like CentOS 6 creates an insurmountable security gap. The underlying vulnerabilities in such systems negate any advanced controls, making them a "recipe for disaster."
- Critical Infrastructure Requires Robust Layered Defense: The notion that any critical infrastructure, such as VMware ESXi hosts, is inherently "bulletproof" is a dangerous misconception. Directly exposing such systems to the internet without comprehensive controls is an invitation for exploitation, as evidenced by the prevalence of vulnerable ESXi hosts discoverable via tools like Shodan. Effective defense requires proper infrastructure management, access controls, and continuous security awareness training.
- Disabling Security Features is Never a Solution: Confronted with application compatibility issues (e.g., a Chrome update breaking an EMR (Electronic Medical Record) system due to CORS restrictions), the advice to "just turn off web security" is catastrophic. Such actions directly undermine fundamental browser security mechanisms designed to prevent critical attacks like eavesdropping and data alteration, especially in sensitive environments like healthcare.
- Frameworks Beat Improvisation: The overarching finding is that a structured, risk-informed framework like the CIS Controls consistently outperforms ad-hoc, improvised security measures. The controls provide a clear, prioritized path to reduce risk, making cyber defense more efficient and effective by minimizing trial and error.
- High Efficacy of Basic Controls: Even the most fundamental safeguards within Implementation Group 1 (IG1) of the CIS Controls are remarkably effective, addressing 74% of common attacker TTPs. This demonstrates that significant security improvements can be achieved with relatively basic, yet consistently applied, cyber hygiene practices, lowering the barrier to entry for organizations and administrators.
Ultimately, the talk concludes that by anchoring cybersecurity decisions in the proven, prescriptive, and real-world-informed guidance of the CIS Controls, organizations can systematically enhance their defensive posture and avoid the pitfalls of unverified advice.
Technical Deep Dive
▶ Watch: Understanding CIS Controls: framework, structure, and thematic taxonomies (3:29)
The technical foundation of the "Cringe, Corrected" talk rests firmly on the CIS Controls and their "offense informs defense" philosophy. This strategy dictates that defensive measures are directly shaped by an understanding of how successful attacks are executed. For instance, the Secret Service studies bank robberies to inform security layouts and insider threat profiles. In cybersecurity, this translates to analyzing data from sources like the Verizon DBIR and IC3 to identify common attack vectors, victim profiles, and effective countermeasures. This data-driven approach ensures the CIS Controls are not theoretical but are highly effective against prevalent threats.
The CIS Controls are structured into 18 thematic categories, or families, each containing specific safeguards that prescribe a single, actionable task. These safeguards are further organized into three Implementation Groups (IG1, IG2, IG3), providing a risk-sized approach. IG1 focuses on essential cyber hygiene for organizations facing general cyber risks, while IG2 and IG3 progressively address higher risk profiles and more complex environments.
The speakers illustrate the application of these controls by dissecting three "hot takes" from social media:
1. The CentOS 6 Dilemma:
A post suggests that moving to passwordless authentication with FIDO2 and implementing fail2ban is a sufficient defense, aligning with Control 4 (Secure Configuration). However, the critical detail missed is the use of CentOS 6, an operating system that reached end-of-life (EOL) in November 2020. While FIDO2 and fail2ban are good practices for secure configuration (Control 4.3 for secure protocols like SSH, Control 4.6 for asset management), the underlying operating system's age and lack of patches introduce massive vulnerabilities.
The corrective technical application points directly to Control 7 (Vulnerability Management). This control mandates continuous vulnerability assessment and patching. Since CentOS 6 is EOL, it cannot receive security updates, making it impossible to meet Control 7's requirements. An attacker would likely bypass any advanced authentication by exploiting unpatched vulnerabilities in the ancient OS, making the system a "recipe for disaster." Additionally, Control 5 (Account Management), specifically 5.1 (maintaining a centralized record of accounts), is also relevant for managing authentication mechanisms effectively.
2. The "VMware is Bulletproof" Fallacy:
Another post, highly upvoted, claims VMware is "bulletproof," implying its ESXi hosts can be directly exposed to the internet. This claim is immediately debunked by easily accessible information, including public scans via Shodan revealing thousands of vulnerable ESXi hosts directly connected to the internet. VMware, as critical infrastructure, has a well-documented history of security vulnerabilities, making direct internet exposure extremely risky.
Amelia initially suggests Control 14 (Security Awareness and Skills Training) and Control 17 (Incident Response) as potential mitigations, which are valid for preparing personnel. However, Lawrence and Amelia emphasize that the core issue lies in infrastructure management. The corrective technical application involves Control 12 (Network Infrastructure Management) for properly segmenting and protecting critical infrastructure, and Control 6 (Access Control Management) for strictly limiting administrative access. These controls dictate that critical systems like ESXi should never be directly exposed to the internet without multiple layers of defense, proper network segmentation, and robust access controls.
3. The "Just Turn It Off" Solution:
The final "hot take" addresses a Chrome update breaking an EMR (Electronic Medical Record) system, with the proposed solution being to "disable web security" to bypass CORS (Cross-Origin Resource Sharing) issues. CORS is a fundamental web browser security mechanism that restricts web pages from making requests to a different domain than the one that served the web page. It's a critical defense against cross-site request forgery (CSRF) and eavesdropping or data alteration in session between a workstation and a server. Disabling it, especially in a clinical EMR environment, would have severe consequences for patient data privacy and integrity.
The controls invoked here are multifaceted. Control 16 (Application Software Security) is paramount, highlighting the vendor's responsibility to conduct sufficient regression and end-user testing to ensure compatibility with modern browser security standards. The EMR vendor should build security into their software development lifecycle (SDLC) from the start. If temporary exclusions are absolutely necessary, Control 9 (Email and Web Browser Protections) dictates that they must be "pretty tightly scoped." Finally, Control 15 (Service Provider Management) emphasizes the need to drive vendor selection based on their adherence to modern security standards, requiring them to maintain compliance with protections like CORS. The idea of disabling a core web security feature for functionality is a critical security flaw that CIS Controls would never endorse.
These examples underscore the CIS Controls' ability to provide a clear, prescriptive, and technically sound framework for evaluating and implementing robust cybersecurity defenses, moving beyond superficial or dangerous "hot takes."
Demo / Proof of Concept
▶ Watch: CIS Controls' Implementation Groups (IGs) for risk adaptation (6:00)
While "Cringe, Corrected" did not feature a traditional live software or hardware demonstration, the entire presentation served as a compelling proof of concept for applying the CIS Controls to real-world cybersecurity dilemmas. The "demo" comprised a series of three social media "hot takes"—actual posts with highly engaged, often misleading, responses—that the speakers systematically deconstructed and corrected using the CIS Controls framework. This approach effectively demonstrated the controls' utility as a diagnostic and prescriptive tool for practical cyber defense.
Scenario 1: The CentOS 6 Authentication "Upgrade"
The first hot take presented a user excited about moving to passwordless authentication with FIDO2 and implementing fail2ban to reduce the attack surface. Amelia initially mapped this to Control 4 (Secure Configuration), specifically 4.3 (secure protocols like SSH) and 4.6 (securely managing assets). The "cringe" moment, however, was Lawrence's astute observation of the underlying CentOS 6 operating system, which is 15 years old and long past its end-of-life. This immediately shifted the focus to Control 7 (Vulnerability Management). The demonstration highlighted that even advanced authentication mechanisms are rendered ineffective if the foundational system is riddled with unpatched vulnerabilities. The point was powerfully made that Control 7 cannot be met on an EOL system, overriding any perceived benefits of the other controls. This showcased how the CIS Controls force a holistic security perspective, preventing tunnel vision on isolated improvements.
Scenario 2: "VMware is Bulletproof" and Direct Internet Exposure
The second hot take was a highly upvoted post claiming VMware is "bulletproof," implying its ESXi hosts could be directly connected to the internet. Amelia initially considered Control 14 (Security Awareness and Skills Training) and Control 17 (Incident Response) as relevant, acknowledging the need for preparedness. The "correction" phase demonstrated the immediate flaw: VMware ESXi is critical infrastructure with a significant history of vulnerabilities. The speakers pointed out that a quick search on Shodan would reveal numerous exposed and vulnerable ESXi instances. The application of Control 12 (Network Infrastructure Management) and Control 6 (Access Control Management) became paramount. This segment effectively demonstrated that simply believing a technology is secure is insufficient; robust network segmentation, proper access controls, and a realistic assessment of exposure are mandatory. The "demo" here was the stark contrast between a naive belief and the hard reality revealed by public intelligence and the comprehensive requirements of the CIS Controls.
Scenario 3: Disabling Web Security for EMR Functionality
The final "hot take" involved a Chrome update breaking an EMR (Electronic Medical Record) system, with the proposed solution being to "just turn off web security" to bypass CORS (Cross-Origin Resource Sharing) issues. Amelia initially linked this to Control 16 (Application Software Security), emphasizing the vendor's role in testing. The "cringe" element was the dangerous advice to disable a critical security feature. The correction vividly explained CORS as a vital defense against eavesdropping and data alteration, especially critical in a clinical EMR environment. The demonstration here involved a multi-control approach: Control 16 for vendor responsibility and secure SDLC (Software Development Life Cycle), Control 9 (Email and Web Browser Protections) for tightly scoped exceptions (if any), and Control 15 (Service Provider Management) for requiring vendors to comply with modern security standards. This scenario powerfully demonstrated how the CIS Controls provide a layered, vendor-inclusive perspective, preventing quick-fix solutions that introduce catastrophic risks.
In essence, the entire talk served as a pedagogical demonstration, using concrete examples to prove the CIS Controls' efficacy as a vital tool for critical analysis and robust defense building in the face of widespread cybersecurity misinformation.
Defensive Implications
▶ Watch: CIS Controls: highly prescriptive, yet very adaptable framework (7:10)
The "Cringe, Corrected" talk offers profound defensive implications for organizations and individuals striving to enhance their cybersecurity posture. The central message is clear: a structured, data-driven framework like the CIS Controls is indispensable for effective cyber defense, far surpassing the efficacy of improvised solutions or unvetted online advice.
For cyber defenders and system administrators, the primary implication is a call to action to adopt the CIS Controls as a foundational framework. The speakers highlight that even implementing Implementation Group 1 (IG1) safeguards can mitigate 74% of common attacker TTPs (Tools, Techniques, and Practices). This statistic alone provides a powerful, data-driven argument for executive buy-in, which Lawrence Cruciana identifies as critical for driving cultural change within an organization. By starting with IG1, organizations can achieve significant risk reduction with minimal investment, as many required tools are often already present. The controls reduce the level of effort and trial-and-error, lowering the barrier to entry for even early-career professionals to implement meaningful defenses. Furthermore, Control 15 (Service Provider Management) empowers young system administrators to strengthen their supply chain by demanding security compliance from vendors, elevating their position and awareness within the company.
For software developers, particularly those in early-stage or startup companies, Control 16 (Application Software Security) holds significant weight. This control advocates for embedding security into the Software Development Life Cycle (SDLC) from its inception, rather than treating it as an afterthought. By utilizing the Implementation Groups, developers can progressively build security into their products in a risk-informed manner, ensuring that security is a default function. This approach not only enhances the defensibility of the software but also levels up the overall cyber defense capability of the product being built.
Beyond specific roles, several broader defensive implications emerge:
- Prioritize Foundational Security: The talk strongly emphasizes that ignoring fundamental controls, such as Control 7 (Vulnerability Management) through patching and updating, or Control 4 (Secure Configuration), can negate the benefits of more advanced security measures. A strong foundation is paramount.
- Critical Evaluation of Information: Organizations must cultivate a culture of critical evaluation. The CIS Controls provide a reliable "filter" to discern valid security advice from dangerous misinformation, preventing the adoption of "hot takes" that could introduce severe vulnerabilities.
- Layered Defense and Risk Assessment: The examples demonstrate the necessity of layered defenses and thorough risk assessments for critical infrastructure like VMware ESXi. Directly exposing such systems without proper network infrastructure management (Control 12) and access control management (Control 6) is an unacceptable risk.
- Vendor Accountability: The emphasis on Control 15 (Service Provider Management) underscores the importance of holding vendors accountable for adhering to modern security standards, especially for critical applications like EMR systems. Organizations should drive vendor selection processes with security compliance as a core requirement.
- Embrace "Offense Informs Defense": By understanding how real-world attacks succeed, defenders can proactively implement safeguards that directly counter those TTPs, leading to more effective and resilient security strategies.
In summary, the defensive implications of "Cringe, Corrected" advocate for a shift from reactive, ad-hoc security to a proactive, structured, and risk-informed approach guided by the CIS Controls, fostering a more secure and resilient cyber ecosystem.
Key Takeaways
- CIS Controls as a Guiding Framework: The CIS Controls provide a prioritized, risk-sized, and real-world-informed framework that acts as an essential filter against the vast amount of misleading cybersecurity advice found online.
- High Efficacy of Basic Controls: Even implementing the foundational safeguards of Implementation Group 1 (IG1) can significantly reduce risk, mitigating 74% of common attacker tools, techniques, and practices (TTPs).
- "Offense Informs Defense" is Crucial: Leveraging insights from real-world attacks (e.g., from Verizon DBIR, IC3) to shape defensive strategies is a highly effective approach to cybersecurity.
- Foundational Security Overrides Advanced Features: Advanced security implementations are negated if fundamental controls, such as patching end-of-life systems (Control 7) or securing critical infrastructure (Control 12), are ignored.
- Never Disable Core Security Features: Disabling critical web security mechanisms like CORS (Cross-Origin Resource Sharing) for functionality, especially in sensitive environments, introduces catastrophic risks and is never a valid solution.
- Strategic Vendor Management: Organizations must drive vendor selection and management processes (Control 15) to ensure third-party software and service providers adhere to modern security standards and secure development practices (Control 16).
About the Speaker(s)
Lawrence Cruciana is the founder and president of Corporate Information Technologies (Corp InfoTech), an organization recognized for running one of the top cybersecurity managed services in the US. With over two decades of experience, Lawrence has worked extensively in regulated, high-consequence environments. He has been closely aligned with the CIS Controls since before their formal inception as a SANS project, authoring hundreds of cybersecurity programs. His organization holds the distinction of being the first to complete CIS accreditation, highlighting his deep expertise and commitment to the framework.
Amelia Cruciana is a cybersecurity and privacy student and researcher, focusing on practical privacy-preserving security. Currently, she works as a cybersecurity intern, gaining hands-on experience in alert triage. Amelia's research and application of the CIS Controls are specifically tailored to make them understandable and actionable for non-traditional practitioners and early-career security professionals. This presentation marked her debut as a speaker at B-Sides, demonstrating her passion for data protection and privacy, particularly concerning social media, and her commitment to making cybersecurity more accessible.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A well-meaning father-daughter talk that frames CIS Controls as the answer to social media misinformation — competent delivery, genuine passion, but the substance doesn't clear the bar for a security conference talk. The 'hot takes' are shallow and the corrections are textbook-level, not practitioner-level.
Heather Calloway (CISO) — WEAK
A well-intentioned practitioner session that does exactly what it sets out to do — help early-career professionals apply CIS Controls to bad social media advice — but that audience ceiling is also its ceiling. The content is competent and occasionally useful, but it doesn't produce anything a working security leader doesn't already know, and it stops well short of the institutional, governance, or program-level implications that would make it worth a CISO's hour.