Managing Your Security Function in the Always-On Security Environment: A Board Playbook
Boards often hire CISOs to "prevent breaches and maintain compliance." In always-on security environments, that's the wrong job description. The real job is: "Build a team that learns faster than the threat landscape changes."
That requires you, the Board, to engage in different hiring, different measurement, different patience, and different incentives. You don't want to incentivize the wrong behaviors, and you definitely don't want to repeat past mistakes with cybersecurity leadership.
Here are two models that sound the same, but they incentivize almost opposite behaviors.
The Prevention Model (what Boards usually want):
Minimize incidents through defensive posture
Follow best-in-class frameworks (NIST, ISO, etc.)
Measure: "Did we get breached? Are we compliant?"
Reward: Avoiding bad things
Risk tolerance: Low
The Learning Model (what the always-on security environment requires):
Detect novel threats fast, respond faster, extract lessons
Build team judgment, resilience, and adaptive mastery capacity
Measure: "How fast do we respond? How quickly does MTTR shrink? Are playbooks improving?"
Reward: Getting smarter each quarter
Risk tolerance: Higher (must allow space for experimentation and occasional failure-to-catch followed by containment)
Here's what happens when Boards optimize for Prevention while hiring for Learning:
At 90 days, the new CISO is still restructuring the team for learning velocity. To impatient Boards, this looks like weakness. Cyber-defenders are threat hunting instead of triaging faster. Budget goes to team development instead of flashy tools. Compliance metrics stay flat. Novel attacks slip through because the team is building judgment, not just executing playbooks.
Most Boards fire this person by month 12, and if not, at month 18.
Then they hire a Prevention-optimized CISO and the cycle repeats.
The irony: Prevention-optimized CISOs feel safer to boards. And they are...for a year. Then the threat landscape shifts and your team hasn't learned how to adapt. [Want proof? When was the first time you heard about the Anthropic Mythos model and what it could do? And -- be honest -- did you hear about it from your CISO?] Novel attacks that competitors caught easily surprise you. Your cyber-defenders, trained only to execute playbooks, don't have the judgment to handle anomalies. High turnover means knowledge walks out the door.
You end up paying more for the same result: reactive response to threats you didn't anticipate.
Here's the Board problem: You're not choosing between a good CISO and a bad one. You're choosing between two fundamentally different strategies. Most Boards don't realize they're making that choice.
You Are Measuring the Wrong Things
When your security team reports quarterly results, you're probably asking:
"How many breaches did we have?"
"Are we compliant with frameworks?"
"What's our incident response time?"
"Are we staying within budget?"
None of these metrics tell you whether your team is actually learning, growing, adapting, and anticipating.
Here's what you should be asking instead:
Velocity: Is mean time to respond to novel threats shrinking year-over-year? How does that compare to peer organizations? (This tells you if your team is actually getting smarter at novel threats, not just faster at routine incidents.)
Judgment: Are false positives declining? What's the justification rate for escalations? Is analyst retention stable or improving? (Good judgment leaves when people burn out. If your best people are leaving, you're degrading the capacity you need.)
Learning: Are repeat attacks succeeding twice? Do your playbooks materially change quarter to quarter? Can your CISO articulate what the team learned from last quarter's incidents? (If you're seeing the same attack twice and falling for it again, you have a learning problem not a detection problem.)
The old metrics (breaches, compliance) tell you about your defensive posture. The new metrics tell you about your adaptive capacity. In always-on security environments, adaptive capacity is what matters.
But Boards reward the old metrics because it's what they know, so CISOs optimize for them. And the team never builds learning velocity.
Hire and keep a CISO who understands this difference. Give them room to build. Measure what actually matters. Hold them accountable for new models and metrics. Resist the urge to swap them out when the first novel attack slips through.
Ask us how to structure your security function for learning velocity, not just incident avoidance.
(image credit: Lucien Alphonse Legros and John Cameron Grant, Public domain, via Wikimedia Commons)

Comments
Post a Comment