SECURETHEORY Advisors
AVAILABLE FOR ENGAGEMENT Book a briefing
/ field notes · the playbook

TOWARDS A
WORLD-CLASS
SECURITY ORG.

A good security function incentivizes smart risk-taking, draws on a diverse set of viewpoints and experiences, and gives back to the community where it can. This is how I build one — the philosophies, the org design, and the metrics that tell you it's working.

> the north star: improve the security posture of the world.

world_class_security_org/
aaron@securetheory:~$ ls world_class_security_org/ philosophies_to_secure_by.cfg org_design_and_talent.md prioritizing_investments.sh incident_management.txt success_metrics.cfg # 25+ years, distilled to practice ✓ 5 files · read in any order
/ contents

Five chapters, read in any order

[01] philosophies_to_secure_by.cfg

Philosophies to Secure By

The four non-negotiables: operate & comply is P0, no aspirational policies, no passive risk-taking, and always assume breach.

read ↗
[02]
org_design_and_talent.md

Org Design, Hiring & Culture

Lead-IC-first orgs, security-first IT, hiring for sharp strengths, and a high-autonomy culture that graduates CISOs.

read ↗
[03]
prioritizing_investments.sh

Prioritizing Investments & Speed

Getting to the right "yes": insure the tail, spend the rest on resilience, and treat each stage as a smaller hoop.

read ↗
[04]
incident_management.txt

Key Lessons of Incident Management

Dozens of board-reported incidents: cadence over cleverness, alignment before the crisis, psychological safety under fire.

read ↗
[05]
success_metrics.cfg

Success Metrics & KPIs

What good looks like: quantitative board-level targets and the qualitative signals of a healthy program.

read ↗
Want this run inside your company?
A 30-minute briefing, no slideware. We'll start with a listening session.
Book a briefing ← Back to site