The Offensive and Defensive Review


During the COVID lockdowns, I decided to learn about cybersecurity as a way to fill in the time. I even signed up to sit the notorious 24-hour OSCP exam, although I never actually sat it, as I soon discovered cybersecurity wasn't for me.

One thing I did take from the experience, however, was the concept of offensive and defensive security.

Offensive (or red team) cybersecurity experts spend their days finding vulnerabilities in systems before hackers can exploit them. Defensive (or blue team) experts monitor for threats and respond when they arise.

I was reminded of this recently when a client asked me to review the statistical content of a slide deck he was preparing for a pitch to his own stakeholders. Working through it, I found myself completing both an offensive and a defensive pass.

In the offensive pass, I read the slides the way a hostile stakeholder would. Several things stood out immediately - places where my client had been vague about sample size requirements, for instance, that were practically begging for difficult questions.

Left unaddressed, those gaps would have undermined his credibility at exactly the wrong moment.

In the defensive pass, I looked for issues my client hadn't yet considered. The most significant was this: because the model was predicting rare events, false positives would inevitably outnumber true positives.

If that's not flagged upfront, stakeholders will eventually notice, and when they do, the credibility damage is far worse than if you'd simply named it from the start.

Both passes are worth doing every time you present analytical work to stakeholders.

The offensive pass forces you to find the weaknesses a hostile critic would exploit. The defensive pass forces you to think through the implications of your own work before your stakeholders do.

The goal isn't to make your work look perfect. It's to demonstrate that you've thought harder about it than anyone else in the room.

Talk again soon,

Dr Genevieve Hayes

Data Science Impact Algorithm

Twice weekly, I share proven strategies to help data scientists get noticed, promoted, and valued. No theory — just practical steps to transform your technical expertise into business impact and the freedom to call your own shots.

Read more from Data Science Impact Algorithm

When I’m looking for guests for my podcast, the first place I turn is invariably my bookcase. The authors of data science books have already demonstrated their authority in the field to the point of developing their own original IP. That makes them ideally suited to a podcast about data science expertise. And it’s no coincidence that many of those authors started off by writing blogs. It turns out conference organisers do something similar. When Cynthia Dunlop, who helps organise two major...

A couple of years back, I watched a TV series called The Fear Index. The series focused on a hedge-fund manager who had developed an AI system to optimise fund profits. Of course, as you would expect for a TV show - 🚨Spoiler Alert🚨 - everything falls apart when the AI starts taking highly illegal and frequently fatal actions in order to drive the market and achieve its goals. I enjoyed the show immensely, but at the time, felt it was far-fetched. However, recent reports of an OpenAI agent...

It’s no secret that many data scientists chose this profession in part because they enjoyed maths and wanted to avoid writing essays. When I was managing a data team, my team members would happily spend hours writing code. But ask them to write up what they’d done and suddenly everyone was too busy. Getting them to document their results in the form of a report was a lot like pulling teeth. And I understood why - to them, writing felt like a distraction from the “real” work. But over time, I...