Security Without the Pessimism: Cyber Hygiene, The Daily Routine You Actually Need

The Myth of the “Security Checklist”

If you believed every cybersecurity headline, you’d think staying safe online takes a PhD, three apps, and a daily ritual in front of your firewall.

The security industry profits from this complexity. Vendors want you to believe that protection requires their latest tool, their proprietary solution, their 27-step implementation guide. More complexity means more products to sell.

But real security doesn’t look like that. It’s not about chasing every threat or memorizing every acronym. It’s about simple, repeatable habits. It’s the digital version of brushing your teeth.

Here’s the truth they don’t want you to hear: You don’t need to do everything. You just need to do the right things, consistently.

That’s cyber hygiene. And it’s boring on purpose.

The Habits That Actually Matter

Most people already know the broad strokes: use strong passwords, update software, don’t click weird links.

But here’s what actually moves the needle:

  • Multi-Factor Authentication (MFA). Still, the single best defense against credential theft.
  • Software updates. Patches close the doors that attackers love to walk through.
  • Password managers. Better one secure vault than 20 weak logins.
  • Backups. One local, one in the cloud, test them once in a while.
  • Device lock and encryption. Lost phones shouldn’t equal lost data.

That’s it. No mystery. No 27-step plan. Just a few habits that, when done daily, make 95% of attacks irrelevant.

In 2017, Equifax was breached because they didn’t patch a known vulnerability for two months. 147 million records compromised. The fix? A software update they already knew about. That’s not sophisticated hacking, that’s skipped hygiene at a catastrophic scale.

The basics aren’t basic because they’re easy to remember. They’re basic because when you skip them, everything else fails.

Why We Skip Simple Stuff

It’s not that people don’t know what to do. It’s that security doesn’t feel urgent until it’s too late.

You don’t see or feel the benefits of good hygiene, but you definitely avoid the pain of neglect. No one cheers when you floss. But everyone will notice that broccoli in your teeth if you don’t.

But there’s more to it than just invisible benefits. Three psychological forces work against cyber hygiene:

Optimism bias. “It won’t happen to me” is a powerful drug. You read about breaches happening to other people, other companies, other industries. Your brain quietly files those stories under “someone else’s problem.” Until it isn’t.

Decision fatigue. You have 47 accounts, each with different password requirements, different MFA setups, and different update schedules. The sheer volume of security decisions creates paralysis. So you do nothing, or you take shortcuts, the same password everywhere, “remind me later” on every update.

The invisible threat problem. You can see a locked door. You can’t see a botnet probing your network. Physical security has visual feedback like locks, gates, cameras. Digital security is abstract until the moment it fails catastrophically. And by then, it’s too late.

Cyber hygiene fails for the same reason flossing does: it’s easy to skip, hard to see the benefit, and the consequences feel distant. But unlike cavities, breaches don’t announce themselves with pain. They’re silent, patient, and devastating.

The trick is to make it small enough that you’ll actually do it, and easy enough that you won’t skip it.

Where Good Intentions Break Down

Even security-conscious folks sometimes miss the basics. Not because they’re careless, but because these gaps accumulate slowly, invisibly:

Outdated hardware. That router you set up five years ago? It stopped receiving security patches three years ago. Old devices become permanent vulnerabilities.

Shadow data. Files saved “temporarily” on random drives, USB sticks, or that personal Dropbox you forgot you created. Every copy is another attack surface.

Forgotten accounts. That forum you joined in 2014. That trial subscription you never canceled. Dormant logins are open doors with your email and password sitting in some leaked database.

Public Wi-Fi comfort. You use a VPN at the airport but not at the coffee shop. Inconsistent protection is predictable behavior and attackers love predictability.

You don’t have to fix everything today. Just start closing one gap at a time. Audit your accounts quarterly. Replace hardware that can’t be updated. Consolidate your data.

Security isn’t perfection. It’s progress. And progress happens one boring habit at a time.

Think of it this way: cyber hygiene is like compound interest, make small deposits now, get massive protection later. Skip the deposits, and you’re borrowing against a future breach.

Make Security Boring (That’s the Point)

The goal isn’t to turn security into a project, it’s to make it routine. Boring. Automatic. The kind of thing you do without thinking, like locking your car.

Here’s a weekly checklist that actually sticks:

  • Monday: Check updates and patches. Five minutes. Coffee in hand. Start the week secure.
  • Wednesday: Backup your files. Set it, forget it, verify it works.
  • Friday: Review new apps or accounts, prune what you don’t use. Close the week by closing gaps.

That’s 10 minutes a week. Three touchpoints. No drama. No heroics.

If you can manage that, you’re already ahead of most organizations. Not because you’re doing something extraordinary because you’re doing something sustainable.

Security should be quiet. The less you think about it, the better it’s working. The moment it becomes a production, it becomes optional.

Culture Over Blame, Turning Awareness Into Habit

People don’t need more fear. They need better routines.

I’ve seen teams transform their security posture not through mandates, but through modeling. One security lead I worked with started every Monday standup by sharing what he patched over the weekend, not as a flex, just as routine. Within a month, the team was comparing notes on password managers and backup strategies. Security became a shared practice, not a compliance checkbox.

Encourage coworkers, friends, or family to treat digital hygiene like health hygiene, it’s a shared standard, not a personal burden. When one person in a household sets up MFA, others notice. When a team lead mentions their weekly backup routine, it normalizes the behavior.

When leaders model small, consistent habits, teams follow. Security doesn’t start in policy documents; it begins in daily rhythm. And rhythm spreads.

Make it normal. Make it boring. Make it easy.

Final Thought

Cyber hygiene isn’t glamorous, but it’s the backbone of every good security posture.
You don’t need to understand encryption or chase every breach headline.
You just need to do the basics, on time, every time.

The security industry wants you to believe protection is complicated because complexity sells. But the truth is simpler and cheaper: consistent habits beat expensive tools every time.

Prevention doesn’t shout. It just works.

That’s not pessimism, that’s just daily discipline. And it’s boring, and effective, on purpose.

The Art of Cyberwar | Part VII | Maneuvering

Chapter VII’s artwork conveys the essence of Sun Tzu’s Maneuvering with clarity and grandeur. A lone commander surveys a vast, unfolding landscape of troops in motion, symbolizing disciplined rhythm rather than frantic pace. The terrain’s natural flow mirrors the movement of cloud-age systems, and the light breaking across the valley evokes strategic awareness dawning before action. It is a rare blend of historical resonance and modern metaphor, a visual philosophy.

Movement After Position

The Principle: “We may take it then that an army without its baggage-train is lost; without provisions it is lost; without bases of supply it is lost.” — Sun Tzu

The Art of Coordinated Movement

A cybersecurity team detects a breach at 2 AM. They have the skills, the tools, and the authority to act. But without coordination, that capability becomes chaos, analysts duplicating work, containment efforts conflicting, and communication breaking down. By dawn, the advantage is gone.

In February 1943, American forces faced German tanks at Kasserine Pass in North Africa. They had the weapons, the numbers, the training. What they lacked was coordination between units and effective air-ground communication. The result? The first major American defeat of WWII was not due to a lack of capability, but to failure to maneuver as a unified force.

Fifteen months later, those same American forces learned the lesson. On June 6, 1944, D-Day coordinated 12 nations, over 7,000 vessels, and 160,000 troops across five beaches in a single operation. Not because they suddenly acquired better weapons, but because they mastered maneuvering. Kasserine Pass taught them that capability without coordination is chaos. Normandy proved that coordination transforms capability into victory.

Eighty years later, the battlefield is digital, but the lesson remains the same.

Sun Tzu called this the difference between movement and maneuvering.

Maneuvering is the discipline of transforming positional advantage into progress without depleting resources. Though movement may appear straightforward (advance, pivot, respond), it demands careful coordination. Without coordination, movement breeds confusion and disorder, undermining any initial advantage.

In Brazilian Jiu-Jitsu, there’s a fundamental principle: position before submission. A novice rushes for the choke. A master secures the proper position, seeks control, applies the proper pressure, isolates the arm, and then the finish is there for the taking. The submission becomes inevitable because the position made it so.

Maneuvering works the same way: structured movement from an established position. Not frenetic action. Coordinated, calculated movement in advance.

Whether in military operations, government, or cybersecurity, the true challenge lies in maintaining momentum while preserving balance. Effective teams favor structured, intentional movement, not just speed.

This is the heart of maneuvering: composure, intent, and clarity. Act from principle, not anxiety.

The Maneuvering Decision Matrix

Sun Tzu understood that effective maneuvering requires reading the moment, knowing when to accelerate, when to pause, and when to let the environment dictate pace.

Modern leaders need the same discernment:

When to Accelerate:

  • The advantage is clear and actionable.
  • Resources are sufficient.
  • Team alignment is strong.
  • Opponent is vulnerable

When to Pause:

  • Visibility is degraded
  • Fatigue is setting in across the team.
  • Purpose has become uncertain.
  • Information remains incomplete

When to Let Environment Dictate:

  • The opponent is making mistakes.
  • Terrain is shifting faster than you can control
  • Patience offers a strategic advantage.
  • Reactive movement would expose weakness.

This isn’t indecision. It’s tactical discipline. The fighter who controls tempo controls the outcome.

Tempo and Terrain

In both war and cybersecurity, timing determines outcomes more than sheer speed. When to act matters more than how quickly you act.

Sun Tzu cautioned that armies advancing too rapidly become fatigued, while those moving too slowly forfeit initiative. Balance requires understanding rhythm, discerning when to accelerate, when to pause, and when to let the environment set the pace.

Today, that terrain is digital.

The modern battlefield consists of networks, cloud environments, and global systems. Effective cybersecurity professionals study the digital landscape to move with intent, not to avoid movement altogether.

In the cloud era, terrain isn’t geography, it’s architecture.

Latency, visibility, and complexity shape what’s possible. The most secure organizations extend beyond perimeter defense by developing a comprehensive understanding of their operational landscape. They design systems where quick tactical movements don’t create strategic vulnerabilities.

The Cyber Battlefield: Coordination Over Chaos

In cybersecurity, effective maneuvering means more than quick patching or immediate responses. It requires aligning teams, especially during high-pressure situations.

  • Incident response represents maneuvering under pressure: containment, communication, and recovery.
  • Threat intelligence involves maneuvering through uncertainty—transforming fragmented information into actionable insights without prematurely acting on incomplete data.
  • Automation functions as the logistical backbone, the supply chain supporting frontline operations. When automation fails, even highly skilled analysts face burnout.

Many security operations centers (SOCs) miss this point. Constant urgency and nonstop action may seem productive, but endless motion risks exhaustion and reduced effectiveness.

Authentic maneuvering is characterized by calm, control, deliberation, and focus.

  • Wing Chun’s centerline theory offers a simple, direct, economical model. SOC analysts don’t need fifty tools—they need the right three, automated properly, with clear escalation paths. Economy of force.
  • The central point: when your playbook drives decisions, you maneuver. When alerts drive decisions, you react.

Cloud Mobility: The Terrain in Flux

The shift to cloud computing redefined what “maneuvering” means. In the old world, servers stayed put. Now, data, workloads, and identities move across providers, borders, and legal frameworks.

In this environment, organizational strength comes not from rigidly restricting movement, but from orchestrating secure and transparent operations.

Cloud maneuvering looks like:

  • Workloads shifting across regions without breaking compliance
  • Data flowing securely through APIs without leaving blind spots
  • Teams pivoting incident response playbooks across hybrid environments in real time

Cloud environments reward planning for motion. Organizations win by designing for agile, secure movement, not by resisting change.

In 2023, a Fortune 500 company’s cloud migration stalled not because of technical limitations, but because their security team designed for a static perimeter. When workloads needed to shift regions for compliance, every move required manual review.

Organizations that assume static conditions are at a disadvantage.

This aligns with the martial principle of flow: Rigid fighters’ break. Rigid systems break faster.

Foreign Policy and the Cost of Motion

Nations, too, confuse movement with progress. America’s 20th-century record is full of lessons in tempo and fatigue.

But no example better illustrates the danger of resource-driven maneuvering than what led to the attack on Pearl Harbor.

The Pearl Harbor Lesson: When Resources Force Your Hand

Japan’s attack wasn’t born from ambition, it was forced by logistics. The U.S., Britain, and the Dutch enforced the ABCD embargo, cutting off:

  • Oil
  • Rice
  • Steel
  • Rubber
  • Machine parts

Japan imported 90% of its oil. Cut off from fuel, it faced two choices: fight or run out of energy and food entirely.

Sun Tzu wrote: “Throw your men into death ground, and they will fight.”

Japan was placed on death ground by resource denial. Their maneuver, the attack itself, was coordinated brilliantly. Six aircraft carriers, 353 aircraft, precise timing across multiple strike waves.

Tactically, it was masterful.

But strategically? Admiral Yamamoto knew: “I fear all we have done is awaken a sleeping giant.”

A lingering question remains: was America truly sleeping? WWI had concluded only 20 years earlier. Before WWII, WWI was considered the deadliest war in human history, earning the moniker “The Great War” for its immense scale and death toll of approximately 20 million lives. Its unprecedented destruction set it apart from previous conflicts. So, America was hardly asleep. Back to Pearl Harbor.

The lesson isn’t about the attack’s execution. It’s about what happens when maneuvering is dictated by desperation rather than position. When resources force your hand, even perfect coordination can’t save you.

Sun Tzu’s calculus applies: survival-driven movement, no matter how well-executed, is still reactive. And reactive maneuvering rarely wins wars.

The United States later encountered similar challenges in Vietnam, Iraq, and Afghanistan, where rapid action outpaced strategic learning. Momentum itself became a compelling but hazardous force.

Diplomacy is maneuvering in another realm.

In contrast, contemporary policy frequently equates reaction with strategy, prompting responses to every crisis even when restraint or delay might prove more advantageous.

Sun Tzu’s wisdom cuts through centuries: “If you know neither the terrain nor the season, you march to fatigue, not to victory.”

The Logistics of Cyber Power

For cybersecurity professionals, logistics consists not of physical supplies, but of bandwidth, personnel, and operational clarity.

Sustained operations aren’t feasible if systems are overburdened, personnel remain on constant alert, and every issue is treated as critical.

Good logistics in cyberspace means disciplined prioritization:

  • Which assets are mission-critical?
  • Which alerts deserve escalation?
  • What response cadence prevents burnout?

Sun Tzu would call this “feeding the army.” In today’s language, it’s resource stewardship.

An effective CISO ensures security professionals maintain resilience and don’t become exhausted before adversaries lose their resolve.

The data shows progress. Organizations took an average of 241 days to identify and contain breaches in 2025, down from 287 days in 2021. Not because threats got easier, but because purple-teamers got better at coordinated response. They learned to maneuver.

Maneuvering the Human Factor

The most challenging aspect of coordination isn’t the technical infrastructure; it’s the human element. While individuals contribute creativity, they also introduce unpredictability.

The numbers confirm what practitioners already know: 88% of cybersecurity breaches are caused by human error. Not zero-days. Not sophisticated malware. Human mistakes. The technology isn’t the weak link—the coordination of people using that technology is.

Sun Tzu understood morale as a weapon system. He coordinated hearts and minds before he coordinated units.

The same applies to martial arts and security culture.

  • In Muay Thai, they call it ring generalship, the fighter who controls space controls pace. The same applies to security teams. Leaders who set tempo, who decide when to press and when to absorb pressure, create the conditions for team effectiveness.
  • The most effective cybersecurity teams operate like jazz ensembles, distributed but synchronized. Training, communication, and trust are the modern equivalents of morale.

This is modern maneuvering: achieving precision in movement without relying solely on hierarchical control.

The Risk of Endless Marching

Sun Tzu cautioned that armies remaining in the field for extended periods experience internal decline. This phenomenon appears today as burnout, alert fatigue, and continuous red team exercises that fail to produce lasting improvements.

Organizations that never rest eventually turn on themselves. This applies equally to companies and nations.

Movement should support strategic objectives, not substitute for them. Effective leadership requires recognizing when to pause, regroup, and restore organizational strength.

Without periodic rest, strength deteriorates into strain, and resilience devolves into attrition.

The Bridge to Variation

The final lesson of maneuvering emphasizes humility: movement does not constitute mastery; it serves as its test.

Any army, individual, or system that acquires the ability to move must subsequently develop adaptability: the capacity to alter rhythm, diversify tactics, and confound adversaries who anticipate predictability.

Leading us back to the initial principle: “We may take it then that an army without its baggage-train is lost; without provisions it is lost; without bases of supply it is lost.”

Maneuvering determines survival. Variation determines victory.

But first, you must learn to move without falling apart. Master coordination before you attempt improvisation. Secure your supply lines before you advance.

Because, as Sun Tzu understood, an army that moves with discipline can adapt. An army that moves with chaos can only collapse. The next chapter explores variation, but only those who’ve mastered maneuvering will recognize when to use it.

The Art of Cyberwar, Part V | Energy | The Use of Force

the art of cyberwar part V energy and the use of force. matt shannon cloud security.

The principles:
In all fighting, the direct method may be used for joining battle, but indirect methods will be needed in order to secure victory.

Indirect tactics, efficiently applied, are inexhaustible as Heaven and Earth, unending as the flow of rivers and streams; like the sun and moon, they end only to begin anew; like the four seasons, they pass away to return once more.

The Power of Controlled Motion

Sun Tzu’s fifth chapter deals with energy, not as brute strength, but as direct application of force.

He warned that a commander must know when to cultivate and store power and when to release it. Misapplied use of Energy burns itself out. However, when energy is focused, it bends the world to its will.

It’s an idea that translates effortlessly to today’s digital battlefield. Nations, like networks, often fail not because of a lack of capability, but because of a lack of control.

True mastery isn’t in how much force you can deploy. It’s in knowing how little you need to. It’s akin to the idea that, sure, you can kill a fly with a hammer, but is it the most effective tool at your disposal?

The Cost of Unchecked Energy

American Diplomatic and Military History is full of examples of lawmakers mistaking our capacity for clarity.

In Korea, overwhelming U.S. power pushed back North Korean forces, only to overextend toward China’s border and trigger an entirely new front. And thus, we have burdened ourselves with maintaining the “38th parallel” ever since.

In Vietnam, energy became inertia, force applied endlessly without definition, draining political and moral capital alike. If only the “peacemakers” at the Treaty of Versailles had let Ho Chi Minh deliver his speech on the Rights of Man, perhaps there would have been no quagmire in Southeast Asia to begin with. A guerrilla war that would take nearly 60,000 American lives and lead to what became known as the “Vietnam Syndrome.”

In Iraq, “shock and awe” demonstrated that a singular “tactical victory” can be swift, while a strategic victory remains elusive. Notwithstanding the entire list of false pretenses that led to the invasion of Iraq to begin with.

Each conflict began with a belief in momentum and ended with war fatigue. Demonstrating once again, force without direction always collapses under its own weight.

The lesson isn’t that force is wrong; it’s that force, when misapplied and unguided, becomes self-consuming. Power is not infinite. Neither is attention, money, or public trust.

The Cyber Equivalent: Sprawl and Burnout

Organizations repeat these same mistakes in digital form.

A breach occurs, and the reflex is to rush to acquire new tools, policies, and budgets, thereby triggering a cyberwar “surge.”

New dashboards, new alert monitoring, and new vendors lead to a surge in activity, while clarity plummets.

This is cyber energy without strategy, effort disconnected from insight.

As Sun Tzu also said: Amid the turmoil and tumult of battle, there may be seeming disorder and yet no real disorder at all; amid confusion and chaos, your array may be without head or tail, yet it will be proof against defeat.

Teams exhaust themselves chasing incidents instead of patterns. Leaders demand constant escalation, not realizing that perpetual crisis is its own vulnerability.

The result mirrors the national trap: motion is mistaken for genuine progress. The ability to endure is mistaken for endurance.

Energy as Rhythm, Not Frenzy

Sun Tzu described two forms of force:

  • Normal energy — the steady discipline that sustains the fight.
  • Extraordinary energy — the precise, unexpected burst that wins it.

In cybersecurity, the equivalent is security posture and precision in the application of policies.

Normal energy is the quiet work of patching, monitoring, and awareness training. Extraordinary energy is the calm, swift, and accurate incident response that turns chaos into closure.

Both are needed. But one cannot exist without the other. A team that never rests has no energy left to strike when it matters most.

It’s the same in martial arts.

In Wing Chun:
Normal energy = quality structure and energy sensitivity.
Extraordinary energy = the skill to deliver a singular, intercepting strike that ends the exchange.

Muay Thai:
Normal energy = footwork, guard, pacing.
Extraordinary energy = the slashing elbow, a stabbing teep, or perfectly placed knee.

BJJ:
Normal training energy = position, pressure, framing.
Extraordinary training energy = the ability to feel a submission triggered by feeling the opponent’s mistake. Or in Mandarin it’s an old idea called Wu Wei, or effortless action. Meaning, I don’t present the opportunity to attack; the enemy presents it to me, like water finding a leak in the dam.

A Security Team that never rests has no energy left for anything extraordinary.

Good CISOs, like good generals, good fighters, and good grapplers, understand rhythm. They know when to conserve strength so that action, when it comes, is clean and effective.

As Master Tzu also knew, “When he utilises combined energy, his fighting men become as it were like unto rolling logs or stones.” Leading to, … “the energy developed by good fighting men is as the momentum of a round stone rolled down a mountain thousands of feet in height. So important is the subject of energy.

Diplomacy and the Misuse of Force

In diplomacy, the same physics apply. The U.S. has often wielded immense power but uneven patience.

Moments like the Marshall Plan and the Cuban Missile Crisis demonstrated the value of precision, employing limited force, clear objectives, and a proportional response.

But elsewhere, the misapplication of force became diplomatic impotence on full display. Prolonged occupations and open-ended interventions constantly drain strategic reserves of will and trust.

Every drone strike, every unconstitutional data collection program, every new cyber warfare doctrine carries a similar risk: that power’s convenience will overshadow its consequence.

The Taoist counterpoint from Lao Tzu still resonates to this day:

“He who knows when to stop never finds himself in trouble.”

Knowing when not to act is the highest use of force. It’s the difference between control and compulsion.

The Lesson for Cyber Strategy

A strong digital defense isn’t constant action, it’s intelligent action.

Practical translation:

  • Automate the repeatable.
  • Escalate only with context.
  • Protect attention as aggressively as data.
  • Reserve extraordinary effort for extraordinary situations.

Energy mismanaged becomes sprawl. Energy focused becomes resilience.

It’s never the size of the arsenal. It’s the precision of the response.

Momentum and the Myth of Constant Action

Modern life rewards constant motion, refresh, respond, and reply.
In cybersecurity and foreign policy alike, stillness feels dangerous to the untrained mind.

But strategy lives in the pause between movements. Quality fighting skills are always more effective when you can strike on the half-beat, a fundamental separator on the mats, and on digital and physical battlefields.

Force has a short half-life. When it’s used endlessly, it decays quickly and fades into the ether. When it’s reserved for the right moment, it changes everything.

A breach contained quietly is often a bigger victory than a public takedown.
A crisis de-escalated without violence often preserves more stability than any show of strength.

Knowing When to “Flow With the Go”

As one of the greatest living legends in Brazilian Jiu-Jitsu, Rickson Gracie once said, “In Jiu Jitsu we flow with the go.”

Meaning:

  • don’t fight force with tension
  • stay aware but not trapped by focus
  • stay smooth and adaptive
  • flow with the opponent’s energy
  • let well-trained instinct and structure guide you

That metaphor fits the digital era perfectly. The best blue or purple teamers, like the best leaders, don’t fight the current; they learn to read it and swim with it, not against it.

Lao Tzu would say that “the soft overcomes the hard,” not through weakness but adaptability. Force channeled through awareness is stronger than force spent in anger.

In warfare and cybersecurity alike, energy is a currency. Spend it recklessly and you’ll be empty when it matters. Spend it wisely and you’ll be leading on the battlefield.

Final Reflection

Knowing how to use force is knowing its limits.
Sun Tzu and Lao Tzu shared the same truth from opposite angles:
Power must be balanced by patience.
Energy must be stored as much as it is spent.

History punishes those who forget this. So does network and security architecture.

The art isn’t in using force; it’s in knowing when the situation calls for little, none, or overwhelming force.

That’s not mysticism. That’s strategic maintenance. And it’s as accurate in security architecture as it is on the battlefield.

All of these lessons point us directly back to our opening principles: “In all fighting, the direct method may be used for joining battle, but indirect methods will be needed to secure victory.” And, “Indirect tactics, efficiently applied, are inexhaustible as Heaven and Earth, unending as the flow of rivers and streams; like the sun and moon, they end only to begin anew; like the four seasons, they pass away to return once more.

The wise strategist learns to move the same way.

Hard Truths, Not Hashtags: 5 Nutrition Myths That Won’t Die

When you’ve trained on the mats, coached clients through cleans, kettlebell swings, and meal prep execution, and watched everyday athletes chase their performance goals, you start to see the myths vs reality.

The claims that sound sexy.

Some strategies seem fresh and innovative.

And there are promises that seem too good to be true and usually are.

Here are five of the most persistent nutrition myths that still persist in fitness culture to this day. These myths can hold back your progress, make your habits harder, and limit your performance.

Let’s put these myths to rest.

Myth 1: Carbs Make You Fat, So Avoid Them
The belief that carbohydrates are always “bad” is one of the oldest myths in fitness. Over time, people started to think of “carbs” as just donuts and soda, forgetting that fruits, vegetables, rice, and oats are also carbohydrates.

Carbohydrates are your body’s preferred fuel source for high-intensity movement. In sprinting, lifting, grappling, and EMOMs. When you cut carbs too aggressively, especially around training, you’re cutting the fuel that keeps the engine running and ready for its highest performance.

Of course, someone who doesn’t move much and eats 400 grams of sugary carbs every day will gain fat. But if you’re an athlete training 4 to 6 times a week and still avoiding fruit, you’re likely to struggle with recovery, mental clarity, and performance.

Carbs are not the problem. The real issues are poor timing, portion sizes, and choosing the wrong sources. It’s important to know the difference.

Myth 2: More Protein Equals More Muscle
It’s easy to think of protein as a magic solution for building muscle. But the idea that you can just drink more shakes and automatically grow isn’t true. Your body can only use a certain amount of protein at a time, and anything extra just adds calories.

If your training lacks volume, intensity, or progression, no amount of protein will magically build muscle. If your sleep is poor, your recovery window is compromised. And if your stress is off the charts, you’ll break down more than you build.

Think of protein as a critical piece of the puzzle, but not the only one. Focus on consistent daily intake (spread across meals), quality sources (whole food > processed powders), and real recovery habits. You don’t get stronger just by eating. You get stronger by absorbing nutrients after solid training and real rest.

Myth 3: Fat Slows You Down, Avoid It
Fat was blamed during the low-fat trends of the 1980s and 1990s, and some people still avoid it. Even now, many choose “fat-free” salad dressing and worry that eating an avocado will hurt their progress.

The truth is, healthy fats are needed for hormone production, joint health, cell repair, and brain function. Athletes who avoid fat for too long often have trouble sleeping, joint pain, low libido, or hormone problems.

You don’t have to add butter to your coffee or eat only bacon to benefit from fat. But if you’re training hard and still eating like it’s the 1990s, you’re missing out on better performance.

Balance your macronutrients to build a strong foundation.

Myth 4: You Shouldn’t Eat After 7 PM
This one sticks around like gym chalk on a black shirt. The belief is: eating late = fat gain. But what the science actually says is this: calorie balance, nutrient timing, and daily movement matter far more than the clock.

If you train in the evening, work a night shift, or just eat dinner late, you’re not hurting your progress. It’s your routine. The real problem is eating junk food late at night, snacking without thinking, stress-eating, or skipping meals earlier.

For athletes, skipping a meal after training just because it’s late can lead to poor recovery and insufficient sleep. Your body doesn’t track time; it just needs the right fuel.

Myth 5: Supplements Replace Meals
Supplements have become a billion-dollar industry promising shortcuts. But the truth? They’re called supplements for a reason. They supplement a well-rounded diet. They don’t replace one.

If your diet isn’t steady, you don’t drink enough water, and your sleep is poor, no supplement will fix your performance.

Whey protein is fine when you’re on the go. Electrolytes help when training volume is high. But if you’re leaning on powders, bars, or mystery potions more than you’re eating real food? You’re missing the point.

Eating real food leads to real results. Supplements are optional, but hard work, recovery, and whole foods are essential.

Bonus Myth That Needs to Be Busted Once and For All

You Need BCAAs to Build Muscle and Recover
Branched-chain amino acids (BCAAs) have been marketed like magic, drink this neon liquid, build more muscle, recover faster, dominate your workouts. But if you’re eating enough complete protein daily (think eggs, meat, fish, dairy, or quality whey), you’re already getting all the BCAAs your body needs.

The truth is, BCAAs are only three out of nine essential amino acids, and they don’t work alone. Building and repairing muscle needs all of them. Taking BCAAs instead of full protein is like bringing only a few bricks to a construction site and expecting to build a whole building.

This myth sticks around because supplement companies make a lot of money from BCAAs. They’re cheap to produce, easy to flavor, and simple to market to people who want quick fixes or think more is always better. Unless you train for hours without eating or have a very low protein diet, BCAAs aren’t necessary.

The bottom line: If you get enough protein each day, you don’t need BCAAs. Save your money and enjoy a good meal instead.

Why This Actually Matters
I’ve been in boardrooms, meal prep kitchens, and war rooms. I’ve been a fighter and sat across from fighters who measure life in rounds, and clients who measure progress in PRs.

The pattern is always the same:
Myths confuse, limit, and delay growth. But once you break your nutrition down into simple truths, reality & function over fad, you become harder to fool, harder to distract, harder to derail.

Field Notes: Your Mission This Week
Pick one myth above you’re still believing. Write it down. Then spend 10 minutes challenging it with real information.
Swap one habit: Still avoiding carbs around workouts? Try a simple “safe” carb on a heavy day. Watch how recovery and hunger change.
Track one metric: Not the scale. Maybe energy, sleep, or workout quality. Let that be your barometer, not guilt.
Talk it out: Share one busted myth with someone—client, teammate, or partner. Watch the shift when you trade confusion for clarity.

Nutrition is more than just eating. It’s about being ready for training, workouts, and daily life with the right fuel to help you succeed, not hold you back.

Forty Point Two

3, 2, 1 get some!

Five weeks ago, I pulled a 41.3-second 250 meter row. Today, I hit 40.2. Just over a second faster.

Most wouldn’t notice the difference, but if you’ve ever chased improvement in anything, lifting, rowing, writing, or career-related, you know what that second really means.

It’s not one test. It’s everything between the test and the retest.

Early mornings. Late nights. Lifting after focusing on a screen all day, securing cloud configs, writing incident reports, and drafting security policies. Endless meetings, collaborating with stakeholders, or staying disciplined enough to meal prep when convenience is whispering your name.

The first test showed where I was. The weeks that followed demonstrated what I was willing to do to get a little bit better every day.

That one second didn’t come from luck. It came from honesty. From taking stock of where my form slipped when fatigue hit, where breathing got shallow, where my leg drive gave too early, and where comfort started whispering, “Hey man, you’ve done enough.”

It came from the same place real growth always hides: the re-tests, not the first runs. Every domain follows the same law: test, learn, refine, retest. That’s how systems harden. That’s how people do, too.

The next time you test something, whether it’s a lift, a sprint, IAM permissions, or a personal limit, remember this: progress rarely looks dramatic as it happens. It might seem minor, but the one second I cut over five weeks shows the value of steady effort. Others might have said, “Hey man, that 41.3 is pretty damn good for a man your age.” For me, that will never be enough.

What “the science” says:

  • Power output was 673 Watts
  • VO2 Max is 68.5 ml/kg/min
  • Faster than 95% of male rowers your age
  • 89% faster than all male rowers

No matter what, 41.3 → 40.2 is proof that attention to detail and small improvements over time are earned, never issued, and that’s the real story.