Cyber Defense Advisors

New Book Challenges Decades of Conventional Cybersecurity Thinking

New Book Challenges Decades of Conventional Cybersecurity Thinking

Cyber Defense Advisors CEO Francis Schmuff Says the Industry’s Biggest Problem Isn’t Technology—It’s Contradictory Advice

What if two cybersecurity experts could give completely opposite recommendations… and both be right?

That’s the provocative question posed in The Dirty Little Contradictions of Cybersecurity, the newly released book by Francis Schmuff, CEO of Cyber Defense Advisors (CDA) and a veteran cybersecurity leader with decades of experience spanning the U.S. Marine Corps, Department of Defense, Fortune 500 organizations, financial services, healthcare, and global SaaS companies.

The book challenges one of the industry’s most deeply rooted assumptions: that there is always a single “best practice” for every cybersecurity problem.

According to Schmuff, there isn’t.

Instead, he argues that many of the fiercest debates in cybersecurity exist because professionals are solving different problems under different assumptions. The result is an industry filled with conflicting guidance, competing frameworks, and organizations struggling to determine which expert to trust.

“Cybersecurity isn’t broken because experts disagree,” says Schmuff. “It’s broken because organizations rarely understand the assumptions behind the advice they’re receiving.”

Introducing the “Assumption Gap”

At the center of the book is a concept Schmuff calls the Assumption Gap.

Whether discussing Zero Trust, Multi-Factor Authentication (MFA), least privilege, cloud security, compliance frameworks, or AI-driven security, the book demonstrates how recommendations that appear contradictory can both be technically correct when viewed in the proper context.

Rather than presenting another checklist of controls, The Dirty Little Contradictions of Cybersecurity teaches readers how to evaluate security decisions based on business objectives, operational realities, risk tolerance, and threat models.

Challenging Cybersecurity’s Sacred Cows

The book tackles some of the industry’s most debated topics, including:

  • Why compliance does not equal security.
  • When Zero Trust may not be the right answer.
  • The hidden costs of “best practices.”
  • Why organizations often receive conflicting guidance from equally qualified experts.
  • How security leaders can make better decisions by understanding assumptions rather than blindly following frameworks.

Schmuff argues that cybersecurity has become overly dependent on universal prescriptions in a world where every organization faces different risks, missions, and constraints.

A Timely Conversation

As organizations race to secure AI systems, defend against increasingly sophisticated cyberattacks, and comply with expanding regulations such as CMMC, NIST SP 800-171, and ISO 27001, cybersecurity leaders are under greater pressure than ever to make defensible decisions.

The Dirty Little Contradictions of Cybersecurity offers a fresh perspective by encouraging readers to think critically instead of accepting conventional wisdom at face value.

For CISOs, IT leaders, security practitioners, compliance professionals, government contractors, and executive decision-makers, the book provides a practical framework for navigating one of cybersecurity’s most overlooked challenges: understanding why experts disagree.

About the Author

Francis Schmuff is the CEO of Cyber Defense Advisors, a cybersecurity consulting firm specializing in CMMC, NIST, penetration testing, risk management, and compliance. Throughout his career, he has helped organizations across the public and private sectors strengthen their cybersecurity posture while balancing operational needs, regulatory requirements, and business objectives.

The Dirty Little Contradictions of Cybersecurity is now available on Amazon.

If you’ve ever wondered why cybersecurity experts seem to disagree on everything, this book explains why—and may permanently change the way you think about security.

Leave feedback about this

  • Quality
  • Price
  • Service