TOWARDS A
WORLD-CLASS
SECURITY ORG.
A good security function incentivizes smart risk-taking, draws on a diverse set of viewpoints and experiences, and gives back to the community where it can. This is how I build one — the philosophies, the org design, and the metrics that tell you it's working.
> the north star: improve the security posture of the world. ▋
Five chapters, read in any order
Philosophies to Secure By
The four non-negotiables: operate & comply is P0, no aspirational policies, no passive risk-taking, and always assume breach.
Org Design, Hiring & Culture
Lead-IC-first orgs, security-first IT, hiring for sharp strengths, and a high-autonomy culture that graduates CISOs.
read ↗Prioritizing Investments & Speed
Getting to the right "yes": insure the tail, spend the rest on resilience, and treat each stage as a smaller hoop.
read ↗Key Lessons of Incident Management
Dozens of board-reported incidents: cadence over cleverness, alignment before the crisis, psychological safety under fire.
read ↗Success Metrics & KPIs
What good looks like: quantitative board-level targets and the qualitative signals of a healthy program.
read ↗