I've spent my career running a security company and working side-by-side with hundreds of CISOs. The pattern I see again and again is simple: great security leaders think like business leaders and lead like coaches. That's what these 52 lessons are about. Each one stands alone, so start wherever you like. Each post is practical, grounded in real experience, and often includes downloadable tools. I hope they challenge you to think.
Bookmark this page. I’ll add to it every Monday.
— Christian
The best Security Leaders are business leaders first, not just security tacticians. In Part 1, I'll dive into some thoughts on why this is true, how to navigate the shift, and a few tools and thinking models that might be helpful along the way.
1. Rebrand Yourself as a Business Leader, Not a Security Leader
The security leaders who earn a seat at the table frame every decision around growth, revenue, and risk. Here's what that shift looks like in practice and why you should rebrand yourself as a business leader.
[Post coming soon]
2. Understand Your Company's Business Model
Understanding your company's business model is critical context to how you will structure and align the security program. But the truth is most security leaders do not have a deep understanding of their business's economic model. In this post we will talk about business models, mapping revenue, and understanding the customers you serve.
[Post coming soon]
3. The One Page Security Strategy: Aligning Security and Business Objectives
The best security strategies align to the business's most important business objectives. Here's how to build a one-page strategy that your team and executives can buy-in on. Includes a free one-page strategy template.
[Post coming soon]
4. How to Make a Business Case for Security and Compliance
Mature Security leaders must master the art of making a business cases for security and compliance initiatives. In this post we'll talk about how to get started and what to avoid.
[Post coming soon]
5. The "Department of No": How to Think About Risk as a Business Leader
Security leaders must have a well rounded view of risk. Not just risk avoidance or mitgating risk, but also when it makes sense to take risk in the pursuit of opportunity. Here's a more mature way to think about risk like a business leader.
[Post coming soon]
6. How to Translate Risk Into Decisions
Executives can't act on a threat briefing. They can act on a clear decision with trade-offs attached. Here's a thinking model to bridge the gap between risks and decision making.
[Post coming soon]
7. Building Executive Ready Scorecards
"We blocked 10,000 attacks" means nothing to your CEO. Instead, you need scorecards that are clear and land well with your intended audience. Here's what to report instead and examples you can steal.
[Post coming soon]
8. The Five Questions Your CEO Actually Wants Answered
Your CEO isn't asking about tools or frameworks. They're asking five business questions, whether they say them out loud or not. Here's what they are and ways to approach answering them.
[Post coming soon]
9. How to Prioritize When Everything Is "Critical"
When every risk is urgent, nothing is. This is a a simple way to force-rank your work and defend the choices you make.
[Post coming soon]
10. Relationships Matter: Befriend the CFO, CRO, and General Counsel Before You Need Them
The worst time to build a relationship is in the middle of a crisis. Here's how to build allies across the executive team.
[Post coming soon]
11. Lessons Learned from One of the Best Security Leaders I know
A client shares how their compliance program became a reason customers chose them over the competition.
[Post coming soon]
12. Security Leaders Need a Peer Group
Every great leader I know has a trusted group of peers they meet with regularly. They hold each other accountable, inspire each other, and create a place for open honest discussion. Here's what that looks like.
[Post coming soon]
Culture isn't soft stuff. It's the engine of your security program.
13. A System to Lead: Security Team Operating System
The best leaders have the unique ability to harness their team's energy to accomplish an important mission. In this post I'll give you a framework to do it. The core idea behind my book, Security Team Operating System, with a free chapter download.
[Post coming soon]
14. Cynicism Is a Leadership Failure
Our industry has a cynical streak, and it quietly drains your team's energy. Great leaders harness that energy in a positive direction instead.
[Post coming soon]
15. Your Team Takes Its Emotional Cues From You
Your mood in the Monday meeting sets the tone for the whole week. Here's how to lead with steadiness when you don't feel steady.
[Post coming soon]
16. How to Hire
Certifications are easy to verify. Ownership is what actually separates great team members from average ones. Here's the only hiring methodology you will ever need.
[Post coming soon]
17. Your First 90 Days Leading a New Security Team
The first three months set the trajectory for years. Includes a free 90-day plan you can use right away.
[Post coming soon]
18. How to Set Expectations and Hold People Accountable
Most people underperform because nobody told them what great looks like. Clear roles, expectations, and scorecards fix that.
[Post coming soon]
19. The Rhythms That Actually Runs a Security Program
Strong programs aren't built on one off heroics. They're built on a predictable cadence of meetings, priorities, and follow-through. Here's a set of rhythms you can copy and make your own.
[Post coming soon]
20. How to Delegate and Elevate
If you're still doing the work you were promoted out of, your team isn't growing. Here's how to let go without letting things slip.
[Post coming soon]
21. How to Give Feedback
Security teams are full of smart, skeptical people. Feedback lands when it's specific, timely, and clearly in their interest.
[Post coming soon]
22. How to Retain Great People (Beyond Pay)
People leave when they stop growing or stop believing the work matters. Here's what keeps great people on your team.
[Post coming soon]
23. Celebrate Wins in a Field That Only Notices Failure
When security works, nothing happens, and nobody notices. Great leaders make the wins visible.
[Post coming soon]
24. When Your High Performer Is a Culture Problem
A brilliant jerk costs you more than they deliver. How to spot a brilliant jerk, how to address it before it spreads, and when to fire them.
[Post coming soon]
25. Your Team Needs Core Values
It probably feels awkward to talk about values and acceptable behaviors. But I'm going to advocate that you not only talk about them, but you document them. Here's why and how to do it. Includes a free team charter template.
[Post coming soon]
26. One of the Best Security Leaders I Know Shares How to Turn Around a Burned-Out Security Team
A security leader shares how they build culture on their team and how they rebuilt energy and trust on a team that was running on empty.
[Post coming soon]
Your influence is only as strong as your credibility with the people above you.
27. What Boards Want from Their Security Leader
Boards aren't looking for technical detail. They want to know the risk is understood, managed, and in the right hands.
[Post coming soon]
28. How to Structure a 15-Minute Board Presentation
A simple structure that respects the board's time and leaves them confident in your program. Includes a free board reporting template.
[Post coming soon]
29. Different Kind of Board Members and How to Manage Them
How you approach reporting to the board or executive team will depend on the interest, perspectives, and personalities of the people you are working with. Here are the common archetypes and tips for working with each. Prepare like this and your board presentation will land, no matter the topic.
[Post coming soon]
30. Visual Presentations Tools That Work for Security Leaders
There are a lot of ways to present data and information to executives and boards. I am going to give you a few examples I've seen work in the field and when to deploy them.
[Post coming soon]
31. How to Brief Executives on an Incident Without Panicking the Room
The way you communicate during an incident shapes how leadership sees you for years. Calm, clear, and honest wins every time.
[Post coming soon]
32. Managing Up When Your Boss Doesn't Understand Security
You don't need your boss to be a security expert. You need them to trust your judgment, and that's something you can build.
[Post coming soon]
33. Building Allies on the Board or Audit Committee
One informed champion in the boardroom changes everything. How to find and develop that relationship.
[Post coming soon]
34. When the Business Accepts a Risk You Disagree With
Document it, respect the decision, and don't sulk. How you handle disagreement defines your credibility.
[Post coming soon]
35. How to Earn Influence Even Without Authority
Reporting lines and titles help, but they don't create influence. Here's what does.
[Post coming soon]
36. Build a Security Budget the CFO Will Approve
CFOs don't fund fear. They fund clear business cases. Includes a free budget one-pager.
[Post coming soon]
37. Offer Options and Consequences, Not Ultimatums
The good, better, best approach turns a budget fight into a business conversation.
[Post coming soon]
38. How to Answer "Are We Secure?"
It's the most common question security leaders get, and the one they most often answer poorly. Here's a better response.
[Post coming soon]
39. Guest Post: What a CEO Wants From Their Security Leader
An executive shares what separates the security leaders they trust from the ones they tolerate.
[Post coming soon]
Anyone can lead when things are calm. Pressure shows you who you really are.
40. Muscle Memory: Pressure Reveals Your Default Operating System
When the stakes rise, teams fall back on their habits. The time to build those habits is before the pressure hits.
[Post coming soon]
41. The First 24 Hours of an Incident Are a Leadership Test
The technical response matters, but the leadership response decides how your team and company remember it.
[Post coming soon]
42. Audit Season Without the Fire Drill
If every audit feels like an emergency, the problem isn't the audit. How to make audit readiness a normal part of the year.
[Post coming soon]
43. A Personal Operating System to Prevent Burnout
Telling people to take care of themselves doesn't fix a broken workload. Leaders have to fix the system.
[Post coming soon]
44. Saying No and Protecting Your Calendar
Your time is your most limited resource. Guard it with discipline without feeling guilty.
[Post coming soon]
45. Learn to Say No to Good Ideas
Your biggest threat to focus isn't bad ideas. It's too many good ones. Here's how to stay focused and avoid shiny objects.
[Post coming soon]
46. When Your Tool or Vendor Bet Goes Wrong
Every leader makes a bad bet eventually. Owning it quickly builds more credibility than defending it. Here's how to fail fast without ego or harming your reputation.
[Post coming soon]
47. Leading Through Budget Cuts, Layoffs, or an Acquisition
Hard moments test trust more than anything else. How to lead your team through change with honesty and steadiness.
[Post coming soon]
48. Who's Coaching You?
Security leaders spend their time developing others and rarely invest in themselves. Here's how to build your own development plan.
[Post coming soon]
49. Build a Peer Network Before You Need One
The best advice rarely comes from a vendor or a conference keynote. It comes from peers who've faced the same problem.
[Post coming soon]
50. Set Next Year's Priorities in One Afternoon
A simple annual planning process that gets you and your team aligned fast. Includes a free annual planning worksheet.
[Post coming soon]
51. Guest Post: Lessons From a Security Leader's Hardest Year
A security leader reflects on the year that tested them most, and what they'd do differently.
[Post coming soon]
52. 52 Weeks In: What I Believe About Security Leadership
A closing reflection on a year of lessons, and the few ideas that matter most.
[Post coming soon]
These tools come straight from the work we do with security leaders every day. Download them as they're released.