8 Cybersecurity Lessons from Sun Tzu — Step-by-Step Guide & Transcript

An Ancient Guide to Cybersecurity: 8 Lessons from The Art of War

0h 14m video Published Sep 8, 2026 Transcribed Sep 15, 2026 IBM Technology IBM Technology
54.1K views 2.6× channel baseline Recent velocity 5.0 views/hour View full performance history →
Intermediate 3 min read For: Cybersecurity professionals and enthusiasts interested in strategic defense principles.
AI Trust Score 75/100
⚠️ Average / Some Fluff

"Delivers exactly what the title promises — eight practical lessons from Sun Tzu applied to cybersecurity, with minimal fluff."

AI Summary

The video explores how Sun Tzu's The Art of War, written 2,500 years ago, can be applied to modern cybersecurity. It presents eight principles from the ancient text, ranging from knowing your enemy to controlling the terrain, and explains how they translate into practical defense strategies.

[01:26]
Know Yourself and Your Enemy

Sun Tzu's principle of knowing yourself and your enemy translates to mapping your attack surface and understanding relative risk.

[09:02]
Control the Terrain

Control the terrain by using network segmentation and DMZs to create choke points and monitor heavily.

[11:06]
Leadership and Buy-In

Leadership must manage up and down, securing buy-in from executives and rallying the team. Security culture flows from the top.

[12:27]
Preserve Resources and Overcome Asymmetry

Defenders have limited resources, while attackers have unlimited time and creativity. Automate routine tasks and use AI to free up humans.

Mentioned in this Video

💡 Key Takeaways

⚖️

Know Yourself and Your Enemy

This is the foundational principle that frames the entire video's approach to cybersecurity.

01:26
🔧

Control the Terrain

Explains how network segmentation and DMZs create choke points for attackers.

09:02
💡

Security Culture Flows from the Top

Highlights that untrained leadership is a bigger vulnerability than unpatched software.

11:33
📊

The Asymmetry of Attack and Defense

Explains why defenders must be right all the time while attackers only need to be right once.

12:27

[00:00] What if I told you that an ancient Chinese military book written 2,500 years ago contained the keys to better cybersecurity? The guy that wrote it predated AI, the internet, computers, and even electricity.

[00:13] But he had already figured out what it took to defend your network. Sounds kind of crazy, right? Well, that guy was Sun Tzu, and his book, The Art of War, has been studied by military leaders for centuries.

[00:27] For this video, I picked out eight principles that we can glean from that historical text and apply them to the way that we defend our most high-tech infrastructures today. Why eight?

[00:39] Well, because in China, eight is considered the luckiest number, and that's because in Mandarin, it sounds similar to the word for prosperity or wealth. I learned when I lived in China years ago that a phone number with an eight in it

[00:52] costs you more than one that didn't have it. And a number with lots of eights, well, that's going to cost you a lot more. Here's one more fun fact. When the Summer Olympics were held in Beijing, they started on the eighth day of the eighth month of the year 2008.

[01:11] And guess when they started? Yep, 8.08 p.m. So they really liked their eights in the Middle Kingdom. So let's honor that tradition and look at eight lessons Sun Tzu taught us about cybersecurity.

[01:26] Sun Tzu wrote, if you know the enemy and know yourself, you need not fear the result of a hundred battles. So what is he talking about here? He says, basically, this is a game of knowledge.

[01:38] It's about knowing yourself and knowing your enemy. So let's start with the knowing yourself part. So from a cybersecurity standpoint, basically, we're going to map our own attack surface.

[01:50] before the adversary does. Because if we know where our weaknesses are, we can fix them. If they find them first, they'll exploit them. Then I need to know the enemy as well, the attacker.

[02:02] I need to know who the threat actors are and study them. I need to know what their tools, what their tactics and procedures and techniques and things of that sort, all the things we call the TTPs,

[02:16] what are they going to do? What are their motivations? Why are they doing all of this stuff? So I take all of that information, that becomes my knowledge, and we refer to that in cybersecurity, modern terms, as threat intelligence.

[02:30] So this is how we're going to be smarter and be able to fight a better battle. And again, 2,500 years ago, a guy had already figured out just in fact how important that was. The next thing we wrote was the victorious warrior wins first, then goes to war,

[02:47] while the defeated warrior goes to war first and then seeks to win. So this seems counterintuitive, but the idea is that you win first, then you go to war.

[03:01] It seems like it should be the other way around. So you fight and then you win? No, he says it's the other way around. You win before you fight. So the best security basically stops attacks before they ever land in the first place.

[03:16] So what does that mean? How do we translate that into cybersecurity terms? Well, we're going to do things like patching. If I patch my systems, then I'm not vulnerable. If I harden those systems then I removed all of the backdoors that might be in them all the other kinds of capabilities someone might use changed all the defaults and things like that

[03:36] The system is a lot more difficult to break into. I'm going to use preventative capabilities like multi-factor authentication and pass keys. I'm going to adopt things like a zero-trust principle for developing the architecture of this environment where I assume breach, and then I build my defenses around that.

[03:57] So the bottom line is, in security, what we do is about prevention, detection, and response. And what 2,500 years ago had already been figured out is that prevention is better than detection and response.

[04:12] And the way to look at it this way is if you're doing incident response, you've already lost round one. Suther wrote, all warfare is based on deception. Hold out baits and entice the enemy.

[04:25] Deception. Now, what is that about? Well, he says deception is everything. What are examples of this, though, that we could do in cybersecurity? Well, one example is a thing we call a honeypot. It's basically a decoy system that draws the attention of attackers so that they're attracted into our system,

[04:43] but we're sitting over here watching what they're doing. So we can see what kinds of things they're going after and how they're going after them, and then we can modify our defenses by learning from their particular attacks.

[04:55] Another example of this are things called honey tokens. And honey tokens are essentially credentials. These could be passwords. These could be API keys. So an example might be a fake AWS key in a config file.

[05:09] And we put that out there and see who tries to use that because whenever they use it, we know it was never legitimate. So then we'll know that they picked that up and where they picked it up from. Another example of this kind of deception is something we call a canary file.

[05:23] So these are bogus files that serve as early warning systems, sort of like the canary in a coal mine, if you're familiar with that reference. So these could be things like a file called password.xls or salaries.csv.

[05:38] That's the kind of goal that an attacker is going to see and go for. And once they do, then we've attracted them and we can figure out what they're doing. So this is pure Sun Tzu. Lure attackers into revealing themselves while wasting their time on fake targets.

[05:53] That's bad for them and good for us. So another thing he wrote was speed is the essence of war. Speed, and I'll add to it adaptability because he also talked about that. But let's first talk about speed.

[06:07] Attackers move fast. And now with AI, they're going to move even faster. They're going to operate at machine speed. Our defenses can't be operating at human speed.

[06:19] We've got to up the clock speed of the way we do response. AI is going to make this worse. So why don't we use AI to defend against as well? because detection and response are going to have to be faster.

[06:32] Here's a way to look at this. If you consider that an attack occurs here, X marks the spot, then there's some amount of delay time that it takes before we're aware of what's happened.

[06:45] And we call that amount of time the mean time to identify. It's the average time that it takes us to do something like that. Well once we identified now we going to respond and ultimately try to contain this We call that average that it takes us the mean time to contain Well this is actually fairly long for most

[07:07] organizations. It's almost two-thirds of the year for the average data breach we've learned, and it's been that way for a decade. That is going to need to compress. We are going to be able to to operate only as fast as our tools allow

[07:21] and the bad guys will be operating quickly, we're going to have to be adaptable. And our ability to adapt means we can't just rely on the rigid checkbox compliance kind of stuff

[07:35] because those security situations will fail against the adaptive adversaries who are trying new attacks all the time. So do compliance, but don't think that's going to be the full answer. The supreme art of war is to subdue the enemy without fighting.

[07:51] So in other words, pick your battles. One sure way to never lose a fight is don't be there when it happens. So find a way to not be there. Find a way to defend the things that are most important to you because you can't defend everything, which means you need to prioritize.

[08:08] You're going to pick what are the most important things in your organization, which means you need to understand what are your crown jewels and prioritize those. These are the data and systems that actually matter, that are the lifeblood of the organization.

[08:22] You want to protect everything, but you probably can't protect everything equally. So make sure that you understand what those are. And how do you decide what these priorities are? Well, it's through risk analysis.

[08:34] You understand what is the relative risk if any of these things are compromised, and then that way you're basing it on real data and real understanding. So it's risk-based security instead of security fear.

[08:48] The next thing he said was, he who occupies the field of battle first and awaits his enemy is at ease. He who comes later and rushes into battle is weary. Another way to say that is you need to control the terrain.

[09:02] You need to control the positioning. You want to seize the high ground so that you can see the incoming attacks when they're coming in. So how could you do this? Well, extensive monitoring is a big part of this.

[09:16] You want to be able to see all the things that are happening in all the corners of your environment. Well, that's going to be too much data. So what do you do about that? Well, you could use something like AI to help filter out the signal from the noise

[09:29] so that you understand when the real attacks are coming and you're in a position to see all of that. So you're going to protect your network with network segmentation and DMZs. What are those things? Well, if you think about if this is public Internet and this is your internal network, well, put a zone in between that we call a DMZ, demilitarized zone.

[09:51] Again, borrowing from military terminology, but this is an untrusted zone, so I don't know what's going on there. This is my relatively trusted zone. If you believe in zero trust, there's no such thing as real trust until you've verified every single thing there.

[10:07] But this is relatively verified. and this is where we have the big questions. So that's an advantage of this kind of network segmentation is an attack that happens here is not an attack that happens here and hopefully we have choke points that make it harder.

[10:23] We going to force the attacker through these choke points where we then have eyes in the sky looking down and we can monitor those things heavily and know what to be looking for The general is the fortress of the state If the fortress is complete at all points

[10:39] the state will be strong. So, in other words, the defender, the shield, the bulwark of the state. So, leadership basically decides the outcome, is what Sun Tzu is saying. Another way of saying this

[10:52] is where there's no vision, the people perish. That's from another ancient text. So the job of the leader is to convey that within the team. They need to rally the forces and get all the people bought in.

[11:06] The morale of the forces that are fighting, they need to be all in unison on this. Equally important, though, if we're talking in cybersecurity terms, a chief information security officer here, who would be the leader in this case,

[11:21] they need to have the buy-in from the top as well. So they're not running everything, and the military general is not the king. So it's just as important that we get buy-in from the people above.

[11:33] Security culture flows from the top to the bottom. And you could make the argument that untrained leadership is a bigger vulnerability than unpatched software, because bad decisions and poor funding are going to follow from that.

[11:48] So we really have to, if you're the leader, if you're the general in this example, you've got to both manage up and down so that you get buy-in for the whole team.

[12:00] Then another thing that Sun Tzu wrote was he will win who knows how to handle both superior and inferior forces. Another way of saying that is preserve your resources. Don't waste anything.

[12:12] because if you do, then the bad guys will have the advantage because you'll spend all of the resources, scarce resources you have on those particular attacks. Bottom line is that the defenders have limited budget

[12:27] and limited amount of time and limited resources. Attackers, well, they don't suffer from those same constraints. Collectively, they have unlimited budget and unlimited time

[12:39] and unlimited creativity. So they actually have an advantage in that regard. That's why you have to be very cautious about how you're preserving your resources and using them very wisely.

[12:51] And the bottom line is the defenders have to be right all the time and the bad guys only have to be right once. So there's an asymmetry to all of this, which again means we need to be able to conserve.

[13:03] How are you going to be able to accomplish and overcome that asymmetry? Well, one way is every chance you get, you want to automate or leverage AI in order to do some of the routine stuff that humans would normally be focusing on.

[13:18] But then that frees them up to be able to look at other things and do more creative work. What can you learn about cybersecurity from a Chinese military leader who lived 2,500 years ago and never once even touched a keyboard?

[13:31] Turns out quite a lot. Some things never change, and classic warfare wisdom is just one example of that. But now you've got eight timeless lessons to help you design better defenses for your modern infrastructures.

[13:46] And to Sun Tzu, I say, xie xie. That means thank you.

More from IBM Technology

View all

⚡ Saved you 0h 14m reading this? Transcribe any YouTube video for free — no signup needed.