SECURETHEORY Advisors
AVAILABLE FOR ENGAGEMENT Book a briefing
security culture / prioritizing_investments.sh
03
/ prioritizing investments & moving at speed

Spend on resilience, not on fear

I don't try to quantify risk for cybersecurity events. I buy enough insurance to cover a 90th-percentile event — maybe 99th if the company has unlimited liability caps in contract or a large number of mega-caps — and put the rest of my money and time into building resilience into the business.

The number of companies that have failed due to a cybersecurity event is greatly eclipsed by those that failed due to low feature-development velocity. Cybersecurity investments should be based on business priorities and known threats.

p90
insured event · the rest → resilience
> insure the tail
> invest the middle
> protect velocity

> Getting to the right "yes"

When security concerns could slow product development, the goal is always to get to the right "yes." I treat each stage as a successively smaller hoop to jump through.

1
Legal & regulatory gate

In initial product development, does the effort implicate major legal or regulatory hurdles that would require massive added program expense — e.g., FedRAMP compliance?

2
Technical gate

Do we need to build in a new language the team isn't familiar with, or on a cloud provider we don't have experience with? Building that expertise takes time and money.

3
Architecture deep-dive

Finally, the deep-dive architecture reviews: do the design patterns match what we know? If not, we bring in 3rd-party experts to help.

← [02] · PREV
Org Design, Hiring & Culture
NEXT · [04] →
Key Lessons of Incident Management