by SOC Van Pelt

Lane Kiffin didn't scout Ole Miss this offseason. He built the whole thing, then had to go play against it. It's the coaching equivalent of writing the incident response plan, handing it to someone else and then getting breached by the exact scenario you wrote the plan for.
Kiffin hired Pete Golding as his defensive coordinator back in 2023, poaching him from Alabama's staff. He recruited Trinidad Chambliss out of Division II Ferris State in the spring of 2025, expecting a depth-chart backup and getting a Heisman-caliber starter instead. When Kiffin left for LSU after the 2025 season, Golding got promoted to head coach and kept almost the entire defensive staff intact. Kiffin reportedly even tried to convince Chambliss to follow him to Baton Rouge this offseason. Chambliss said no and stayed in Oxford. If you've ever inherited a system from someone who left the company, and that person still technically knows every backdoor and default password in it, you already understand the setup here. Except in this version, the person who left is the one trying to break back in.
So when Kiffin walked into Vaught-Hemingway Stadium this past Saturday for the Magnolia Bowl, he wasn't facing a mystery opponent. He was facing his own roster construction, his own coaching hire, and his own quarterback pickup, all running the exact program he built, just with somebody else's name on the headset. This is basically a live-fire pen test against your own former infrastructure, conducted by the guy who used to hold the admin credentials.
Here's where the "we know this threat" problem actually shows up on tape, not just in theory. LSU clawed all the way back from a deficit with 17 unanswered points, briefly making it look like the inside knowledge was paying off, like the incident had been contained. Then, with 6:14 left on the clock, Chambliss did exactly what Chambliss does: he put his head down and ran it in from 14 yards out to put Ole Miss up 30-24. Ole Miss converted the two-point try after, which ended up being the actual margin of victory. Final score: Ole Miss 32, LSU 24, in front of a record 70,033 fans and a full College GameDay production.
Chambliss finished with 363 passing yards. LSU's Sam Leavitt threw for 158. This wasn't Kiffin getting outcoached by a stranger. It was Kiffin getting beat by the exact player he identified as a diamond in the rough, running the exact style of aggressive, opportunistic offense Kiffin's staff installed in him a year earlier, against a defensive system built by a coordinator Kiffin hired himself. Knowing a threat actor's preferred move, down to the exact play, is not a control. It's a scouting report. LSU had the scouting report. They still didn't have an answer when it mattered, the same way a team can have a full profile on a known ransomware group's tactics and still get walked through the door by that exact group's oldest trick.
Recognizing a threat gets you a name for what's coming. It doesn't get you a patch, a segmented network, or a response plan that holds up once the pressure is real, and that gap is exactly where LSU's defense lived in the fourth quarter.
This shows up in security programs constantly, and it usually looks the same way: a team has genuinely good threat intelligence on an adversary, a ransomware group's known tactics, a phishing kit's tells, a specific CVE's exploitation pattern, and treats that intelligence as if it were a mitigation. It isn't. Intelligence tells you what to expect. It doesn't test whether your controls actually stop it when it shows up on your network at 4 p.m. on a Friday. Kiffin had game tape, scouting reports, and personal knowledge of exactly how Chambliss operates under pressure. What he didn't have on the field was a defense that had actually been drilled against that specific scenario until it held.
The fix isn't more awareness. It's turning that awareness into something that gets tested, not just filed away, before the actor shows up again.
The other layer is the insider-knowledge problem, and it cuts both ways. Kiffin knew Ole Miss's system because he built it, and that knowledge didn't transfer into an advantage once he was on the other side of it. Security teams face a version of this constantly with departing employees, contractors, and vendors, people who still know exactly how the environment is configured long after they've lost any reason to protect it. Knowing the architecture intimately is not the same as that knowledge staying safely on your side of the fence. If your offboarding process doesn't assume that departing insiders retain real, usable knowledge of how to get back in, you're playing Kiffin's exact game, minus the years to prepare a better answer.
Familiarity is not coverage. Scouting is not defense. And a threat you already “know” is not a threat you get to file under "handled."
Share This Article

An Article By
An Article By
SOC Van Pelt
Sports & Cybersecurity Analyst
SOC Van Pelt
Sports & Cybersecurity Analyst
SOC Van Pelt is SonicWall’s resident sports and cybersecurity expert, bridging the gap between high-stakes game day strategy and enterprise threat defense. Whether breaking down why a chaotic network misconfiguration looks suspiciously like a prevent defense or arguing that IT teams should just take the field goal, SOC Van Pelt translates complex security lessons into a language real people actually want to read.