Skip to content

The Cognitive Pearl Harbor: Winn Schwartau Says Cybersecurity Must Learn to Ignore

CYBR.SEC.CON 2026 opening keynote argues that critical thinking is no longer enough in an age of AI, algorithms and information overload. Security starts with knowing what deserves our attention.

For decades, cybersecurity has focused on filtering hostile traffic, blocking malicious code and separating trustworthy signals from noise. Winn Schwartau believes humans now need to get much better at doing the same thing.

Schwartau, a longtime information warfare researcher, author and director of the Cognitive Security Institute, opened CYBR.SEC.CON 2026 with “The Cognitive Pearl Harbor,” a keynote examining what happens when human beings encounter more information, manipulation and machine-generated content than their brains can reasonably process.

His central argument is deceptively simple: Before we can think critically about information, we have to decide what deserves to be thought about at all. Schwartau calls that process Critical Ignoring.

Full Coverage of CYBR.SEC.CON:

CYBR.SEC.CON 2026: News, Speakers, Agenda & Coverage
Follow CYBR.SEC.CON. 2026 in Houston with the latest news, speakers, keynotes, agenda, cybersecurity tracks, AI.SEC.CON. highlights, interviews and event coverage.

The problem is no longer merely misinformation or disinformation. It is volume. Humans are being bombarded with information while algorithms increasingly determine what they see, what attracts their attention and, potentially, what they believe.

The consequences Schwartau identifies include anxiety, confusion, attention and memory problems, loss of trust, poor decision-making, distraction and growing uncertainty about whether the people and information encountered online are even real.

The stakes increase as AI makes producing and distributing content easier.

“TMI creates fertile ground for BS,” one of Schwartau's slides argues. Human-generated misinformation is already difficult enough to navigate; AI and bots can act as powerful amplifiers.

From Electronic Pearl Harbor to Cognitive Pearl Harbor

There is some history behind Schwartau's choice of title. In congressional testimony on June 27, 1991, Schwartau warned about the possibility of an “Electronic Pearl Harbor,” years before cybersecurity became the sprawling industry it is today. His latest argument shifts the target from networks and infrastructure toward something even more fundamental: the human mind.

In Schwartau's model, a conventional Pearl Harbor produces a sudden physical impact. An Electronic Pearl Harbor similarly culminates in disruption after preparation and reconnaissance in cyberspace.

A Cognitive Pearl Harbor can work differently. It may be slow, subtle and persistent, using information and influence to produce an eventual shift in belief, compliance or perception. The actors could include nation-states, organizations or online communities. That makes the attack surface enormous.

“They who control the technology control the narrative,” Schwartau says in the presentation. “They who control the narrative control your beliefs.”

Related:

Have We Already Had a Cognitive Pearl Harbor?
Winn Schwartau warned of a “Digital Pearl Harbor” decades ago and is now raising a more unsettling possibility: the real attack may already be underway, targeting human perception itself.
Cognitive Warfare Has Entered the SOC. What it is, How to Respond
Information overload, cognitive warfare, and nonstop digital noise are turning human attention into a vulnerable attack surface.

Humans weren't built for this

Schwartau's argument starts with a biological limitation. Human beings evolved to survive threats in the physical world, not to process an effectively endless stream of digital information. Adaptation, therefore, becomes a security requirement. His prescription is to strengthen what he calls our “cognitive immune systems.”

Our existing senses already perform an enormous amount of filtering. We do not consciously process everything our eyes, ears and other senses encounter. The brain discards information constantly so that limited cognitive resources can be directed toward what matters.

Schwartau argues that the information environment now requires a similar defense mechanism. That is where Critical Ignoring enters the picture.

Critical thinking requires time, attention, mental energy and an open mind. Trying to apply it to everything flowing across screens, social networks, AI systems, messaging platforms and news feeds is impossible.

Critical Ignoring is the triage layer that comes first.

Schwartau's framework asks people to make quick assessments: Do I care about this? Do I have time for it? Do I trust the source? Is this a person, bot or AI? Is an algorithm steering me toward something? Is an emotional trigger being deliberately exploited? Does the claim make enough sense to warrant further attention?

Only information that clears those filters needs to consume the heavier cognitive resources required for critical thinking. In Schwartau's model, a strong mental “System 1” performs that rapid filtering and knows when to engage the slower, more analytical “System 2.”

The idea should sound familiar to security practitioners. Enterprise networks already do it.

Firewalls, DNS filters, endpoint controls, reputation services, threat intelligence, DLP, SIEM, SOAR, zero trust, bot detection and other technologies exist partly because defenders cannot manually inspect every byte entering an environment. Security architecture filters, prioritizes and rejects enormous quantities of information before asking a human to make a decision.

Schwartau is essentially asking why we don't build our cognitive defenses with the same assumption.

The danger of cognitive surrender

The alternative is what Schwartau calls Cognitive Surrender: becoming so overloaded, distracted or dependent on technology that humans gradually hand over the process of deciding what deserves trust.

AI makes that concern particularly timely.

One slide in the keynote highlights research in which participants consulting AI were overwhelmingly willing to accept its responses without scrutinizing them, including when those responses were faulty. Schwartau frames that behavior as a failure to engage the slower analytical processes necessary to question the machine.

Cognitive surrender also creates an enterprise security problem.

An attacker does not necessarily have to destroy systems if they can destroy trust. Schwartau connects enterprise cognitive surrender to manipulation of what people believe about an organization, declining confidence in leadership, customer losses and ultimately threats to organizational survival.

That expands cybersecurity beyond protecting confidentiality, integrity and availability. The integrity of human perception becomes part of the threat model.

Building a cognitive defense

Schwartau does not suggest that organizations can solve this problem by simply telling employees to “think critically.”

The keynote instead advocates building resilience before manipulation succeeds.

One approach is prebunking — exposing people to the techniques used in manipulation so they become better at recognizing them when encountered later. The presentation describes prebunking as a research-backed, scalable strategy for building cognitive resilience while calling for additional research, real-world testing, interdisciplinary cooperation and even experimental cognitive cyber ranges.

The broader objective is to make cognitive defense more automatic: filter the noise, recognize manipulation, interrupt emotional reactions and deliberately engage deeper analysis when something actually deserves it.

That ultimately brings Schwartau back to the same problem cybersecurity has wrestled with for decades.

There is too much incoming data. Defenders cannot investigate all of it. Humans cannot think deeply about all of it. AI is only accelerating the imbalance.

The question, then, is no longer simply whether we can distinguish truth from falsehood.

It is whether we can learn to decide — quickly and deliberately — what is worth our attention in the first place.

For Schwartau, that ability may determine whether the AI era produces stronger cognitive defenses or something much closer to the Cognitive Pearl Harbor he fears.

HOU.SEC.CON CTA

Latest