Skip to content
← Field Notes
Essay

Security a 24/7 operation can actually live with

Security leadership is a negotiation with a business that does not stop. A bypassed control is worse than no control.

2 min read leadershiprisksecurity-program

It’s tempting to treat security leadership as a list of controls. In practice it’s a negotiation with a business that does not stop.

Early on I’d have called a control that the business routed around a failure of the business. I’ve come to think it’s usually a failure of the control. A plant that runs around the clock, a process that can’t take a maintenance window, a workforce that isn’t sitting at desks. These aren’t obstacles to the security program. They are the environment. A control that ignores them doesn’t get adopted; it gets bypassed. And a bypassed control is worse than no control, because it also teaches everyone that your judgment can be ignored.

So the question I ask of any control isn’t “is this strong?” It’s “is this strong and survivable here?” MFA that locks out a night shift with no help desk just turns into an outage with a security label on it. Segmentation nobody can operate gets a hole punched through it inside a month. The strongest control you can’t run is weaker than the merely-good one you can.

None of that is an argument for going soft. It’s an argument for doing the harder work: understanding the operation well enough that the secure path is also the workable one, and spending your political capital on the few places where it genuinely has to hurt. You get a finite number of “no, we do this the hard way” calls in a year. Spend them where the risk is real, make everything else fit the way people actually work, and you end up with a program that’s still standing twelve months later. That’s the only kind that protects anything.

Security that the business resents is on a timer. The moment there’s pressure (a deadline, an outage, a new executive who wants to move fast) the resented control is the first thing sacrificed, and you’re not in the room to defend it. Security the business has absorbed into “how we do things” survives that pressure, because by then it isn’t your control. It’s theirs. Getting there is slower and less satisfying than issuing mandates, and it’s most of the job.