Corporate & Thought Leadership

The SOC Van Pelt Report: What Kubiak’s Aura Gamble Teaches Security Teams

by SOC Van Pelt

Klint Kubiak called the win before fixing the run game that was still broken — security teams make the exact same bet.

Klint Kubiak wasn’t just confident at halftime. He was holding a 13-10 lead over Patrick Mahomes and the Chiefs, with a rushing attack that had managed 17 total yards in two quarters, and he still looked into a camera and told the entire country his team was “going to win”. Not that they were going to try. It was said to be a matter of fact. That’s not just confidence. That’s an aura gamble, and aura gambles don’t get much bigger than, “I’m beating Mahomes,” said out loud, on live TV, with your run game still gasping for air.

I’d guess Andy Reid had that clip queued up and playing in the locker room before the Chiefs even took the field for the third quarter. As if a championship-caliber team trying to claw back from a 6-11 season needed more motivation to walk into the second half. Nothing refills a veteran coach’s tank quite like a rookie head coach handing him a halftime speech for free.

But the guarantee itself isn’t really a mistake here. The mistake is what Kubiak said two sentences before it, and then didn’t follow through on.

The Problem He Named and Then Walked Past

Asked about the rushing game at halftime, Kubiak didn’t dodge it. “Gotta be better,” he said, then immediately pivoted to “but you know what, we’re winning,” in the same breath, like a guy noticing a flat tire and saying, “Well, the car's still running.” He identified the exact weakness that was still live, out loud, on national television, and declared the game decided anyway. That’s the security equivalent of flagging a known vulnerability in a report and then telling the client the system is secure, because nothing bad had happened yet.

 

bold.webp

The Weakness That Stayed Unpatched

The Raiders backed Kubiak's talk up for a while, which almost made the statement look like genius instead of vibes. And the results are often the difference with a statement like that. If you win, you’re a genius. If you lose, well, you might have blogs like this written about you. The Raiders took a 19-17 lead with just over five minutes left in the fourth quarter, so this isn’t a story about a talent gap hiding under bravado. Then the exact thing Kubiak had named as broken came due, right on schedule, like it had been waiting for an invitation. On fourth down with two yards to go, Las Vegas declined a field goal to keep the drive alive and ran the ball, the same run game that had produced 17 yards at halftime, straight into a Chiefs front that stuffed it like it owed them money. 

The drive died. 

Kansas City took over and ended up winning 30-27.

That fourth down disappointment wasn’t a random bad break. It was the first-half flaw getting tested again at the highest-leverage moment of the game, failing for the same reason it was failing in the first half, this time with much starker consequences.

For the Raiders, this just means going to 3-1 with the Patriots, Bills and Rams all on deck. Their young head coach gambled his aura away on live television, and the lesson that followed was a mildly embarrassing one. If your security team makes the same bet and loses it, nobody’s writing a cute recap. It’s lost data, lost trust and lost money.

Here’s How This Translates to Your Cybersecurity Strategy

“We stopped the attack” and “we’re secure” are not the same sentence, and conflating them is exactly what Kubiak did. A 13-10 halftime lead is not the result, it's a status update, and the game still has two quarters left to decide whether it holds. A team that repels one wave but doesn't go back and actually fixes the specific gap the attacker found is holding that status update and calling it a final score.

This is the known-vulnerability problem in its purest form, minus the TV cameras. Security teams flag weaknesses in audits and pentests constantly, candidly, specifically, the same way Kubiak said 'gotta be better' about his run game. Then the patch doesn't happen, or happens halfway, a compensating control goes in instead of the actual fix, a ticket gets marked 'resolved' after a partial remediation, and everyone moves on because the scoreboard still looks fine in the moment. The failure isn't a lack of awareness. Kubiak was completely aware. The failure is in not closing the gap, and in never checking back to confirm it's actually closed.

A lead is a snapshot of what's worked so far. It's not a conclusion about what's fixed or proof that you can't be attacked. The Raiders had a real lead, built on real execution, right up until the exact weakness they'd named out loud came looking for them again.

And much like football, cybersecurity isn't a one-half game. You need protection through all four quarters, every year, not just the ones where nothing's gone wrong yet. Just because you haven't been breached by the end of Q2 doesn't mean you've beaten every threat out there. It might just mean no one's tested the weakness you already know about. The fix for that isn't more confidence. It's going back, verifying the patch actually closed the gap, and re-testing the exact vector that got flagged, the same question Kubiak had the right answer to at halftime and the wrong response for. 

Kubiak knew they needed to be better, and he just found out that aura doesn't convert on fourth-and-2.

Share This Article

An Article By

SOC Van Pelt

Sports & Cybersecurity Analyst

SOC Van Pelt is SonicWall’s resident sports and cybersecurity expert, bridging the gap between high-stakes game day strategy and enterprise threat defense. Whether breaking down why a chaotic network misconfiguration looks suspiciously like a prevent defense or arguing that IT teams should just take the field goal, SOC Van Pelt translates complex security lessons into a language real people actually want to read.

Related Articles

  • The SOC Van Pelt Report: What the Rams and Chargers Teach Us About Security Spending
    Read More
  • In the Film Room: Drake Maye, Hero Ball and Why Security Teams Should Take the Field Goal
    Read More