top of page
Search
Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess
It is tempting to compare cybersecurity to a chess game. Two adversaries facing each other, plotting strategy and tactics. Move and counter move, anticipating actions and grinding out a win. In reality, in our complex world of dependencies, supply chains, constantly shifting technology platforms and unpredictable attackers, this is all way more haphazard. Indeed, a better analogy is backgammon, where you position yourself for many different possible outcomes to maximize your
Aug 224 min read
A Coming Incident Crisis?
We’re all talking about the tidal wave of vulnerabilities that is upon us, with repeated waves likely coming. As I’ve covered here, we can respond to this in various ways including ramping up speed across our entire defensive stack, which is as much about structural defense-in-depth than just faster patching. I’ve covered that here as well. But, there’s a question as to whether the leading indicator of increasing vulnerabilities will in fact result in an increase in the lagg
Aug 84 min read
Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls
Security breaches are often not the result of awesome attacker capabilities or the sudden emergence of sophisticated zero-day exploits. Instead, what we usually find are the controls designed to stop the attack were believed to be operational but were actually broken or misconfigured at the moment when they were needed. Sometimes they were never fully in place to meet the security team's original intent. So, continuous control monitoring is needed to counter the natural dec
Jul 255 min read
Technology Waves and Security - Is This Time Really Different?
Most people have been through at least one wave of technology transformation. Some of us have been through a few and all carry the wisdom and scars from these. When you’ve experienced these changes you learn to appreciate, as the adage goes, that history might not repeat but it certainly does rhyme. In my working lifetime I caught the tail end of the mainframe to PC transition, the proliferation of client/server and distributed system architectures, wide-spread Internet adop
Jul 119 min read
Sorry, Cyber: You Aren't the Only Ones Saving the Company from Itself
There’s still a bit of a tone in some security circles that we’re somehow unique in constantly having to push back against ill-advised moves, or even outright craziness, from our business, operations, or technology colleagues. But, when you pause and think about all the many functions in your or other organizations you realize this is not so. You quickly see that while great security teams are true enablers of business and reducers of friction, most teams still have to (and
Jun 2712 min read
CISO Version 2.0
Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond. However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some “point releases” on the way. This is simply because version 1 of the role is
Jun 124 min read
The Power of Community: 7 Steps to Fast-Track Your Security Career - Update
Since I wrote the first version of this post some years ago much has changed. Technology changes, market changes, specific industry changes, compounded by more aggressive and numerous threats that continue to reshape and challenge security teams and roles. The way we advance our careers and the way we use communities inside and outside our organization is changing. But there are also constants we can rely on. As we start out, or even when entering a new stage of our careers
May 2915 min read
Do You Really Know What’s Going On?
At some point every leader needs to ask themselves: Do I really know what is going on in my company? Do I even know what is really going on in my own organization? Most leaders do not know the actual truth of what is happening. This is not because people are overtly hiding things or that leaders are ineffective, although sometimes it is both of those, but rather this is because of the “thermocline of truth” that I covered in this post. Organizations are full of cultural, stru
May 1610 min read
The Real Role of the Field CISO
We all need to advance our businesses and that is in many respects about selling. We also need to recognize that security and reliability are increasingly the path to sustainable long term customer success - which is your success. This is where the Field CISOs come in. There are many more people that are becoming, so called, Field CISOs and many more organizations that are creating Field CISO teams under a variety of structures and names. Let’s look at what Field CISOs are,
Apr 414 min read
Organizational Politics & The Security Program
I first wrote the original of this post over 4 years ago. Having seen a new spurt of discussion about organization politics in various on-line and in-person forums I thought it was time for an update. At every stage in your career and in every part of your role you are going to have to deal with organizational politics. People often construe such politics as inherently negative. Yes, there are some organizations that have toxic cultures where organizational politics looks mo
Mar 2118 min read
The CISO's Craft: Watchmaker or Gardener?
Some time ago I saw a comment about the distinction between acting like a “watchmaker” or a “gardener” when undertaking organization transformations. I misplaced the original reference so, unfortunately, I can’t credit appropriately. But, I’ve been thinking a lot about what this would mean in the context of security leadership. Specifically, should the CISO be a watchmaker or a gardener, or both? The Watchmaker CISO: Precision and Control Imagine a master watchmaker, meticulo
Jan 243 min read
2025 Year in Review - Top 10
The most read posts in 2025 coalesced around the concept that successful cybersecurity is fundamentally a function of business leadership, strategic design, and sustainable execution . The unifying themes across the top posts emphasize shifting security from an artisanal, reactive craft to an industrial-scale, proactive capability focused on building scalable, self-reinforcing systems (flywheels). Transformation requires leaders to manage stakeholder expectations carefully, p
Jan 104 min read
Security Leadership Master Class 7 : Contrarian takes
This is the final of the series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master C
Dec 27, 20254 min read
Security Leadership Master Class 6 : When disaster strikes
This is part 6 of a 7 part series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master
Dec 13, 20255 min read
Security Leadership Master Class 5 : Getting hired and doing hiring
This is part 5 of a 7 part series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master
Nov 29, 20255 min read
Security Leadership Master Class 4 : Enhancing a Security Program
This is part 4 of a 7 part series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master
Nov 15, 20256 min read
Security Leadership Master Class 3 : Building a security program
This is part 3 of a 7 part series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing or refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Mas
Nov 1, 20256 min read
Security Leadership Master Class 2 : Dealing with the board and other executives
This is part 2 of this 7 part series grouping together a set of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing or refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadershi
Oct 18, 20254 min read
Security Leadership Master Class 1 : Leveling up your leadership
This is the first of a 7 part series where I’ll group together a set of prior posts into a particular theme that will make it all the...
Oct 4, 20254 min read
Good CISO / Bad CISO
In a first for this blog here is a post I worked on with Mike Aiello , a former colleague from Goldman Sachs and Google and someone, like...
Sep 20, 20255 min read
bottom of page