First Principles of Performance Part IV

The Volume Spectrum

Understanding Maintenance Volume (MV), Minimum Effective Volume (MEV), Maximum Adaptive Volume (MAV), Maximum Recoverable Volume (MRV), and Everything Between

Growth is determined not by how much work you perform, but by how much productive work you can recover from.

Introduction

Walk into almost any Olympic Weightlifting or power lifting gym, CrossFit affiliate, or even the standard Globo gym and you’ll eventually encounter two seemingly opposite philosophies.

One athlete believes progress comes from doing more: more sets, more repetitions, more accessory work, more conditioning, more training days. If some novel amount of work produces results, even more work should produce even better results.

Another takes almost the opposite approach: do as little as necessary to stimulate improvement, then get out and recover.

Curiously, both can point to successful athletes who appear to prove them right.

One can point to the CrossFit athlete training multiple sessions a day, the weightlifter accumulating hundreds of technically demanding repetitions each week, or the bodybuilder thriving on German high volume training. Then another points to an elite powerlifter progressing on surprisingly few max-effort lifts, or an experienced weightlifter whose training becomes more productive after unnecessary volume is removed.

So which approach is correct? Both and neither. Why? Because the question itself is flawed.

The body does not respond to volume in absolute terms. It responds to recoverable stress.

That distinction changes everything.

The objective of training is not to perform the greatest amount of work possible. It is to perform the greatest amount of productive work possible: enough to create the desired adaptation without accumulating so much fatigue that additional work stops contributing meaningfully to it.

There is a difference between training that challenges your capacity and training that simply consumes it.

Understanding where that line exists, and recognizing that it shifts according to the athlete, the adaptation being pursued, the type of training being performed, and where the athlete is in their development, is one of the most valuable skills an athlete or coach can develop.

This is where the Volume Spectrum begins.

More Is Better, Until It Isn’t

One of the oldest assumptions in strength training is beautifully simple: if ten sets build muscle, twenty must build even more. And if twenty works, why not thirty?

The problem is that biological markers rarely, like life, move in straight lines.

The human body is governed by diminishing returns. Initially, increasing training volume can produce greater adaptation. Strength improves, muscle grows, work capacity increases, and technique becomes more refined. But eventually those returns begin to diminish. Progress slows, then plateaus, and if volume continues increasing without sufficient recovery, performance can begin moving backward.

More work has become less productive.

The irony is that many dedicated athletes interpret this decline exactly backward. Feeling stalled, they assume they simply need to work harder, so they add another exercise, another set, another conditioning session, another “finisher.”

Instead of solving the problem, they’ve increased the very stress that caused it.

The Volume Spectrum

Training volume can be understood through four useful landmarks along a continuum. These should not be treated as rigid physiological thresholds or universal numerical prescriptions, but as practical regions that help coaches think about the relationship between training stress and adaptation.

Quick Reference: Training Volume Landmarks

MV (Maintenance Volume): The minimum amount of training needed to maintain current performance and muscle mass. Used during periods of reduced training, deloads, or recovery phases.

MEV (Minimum Effective Volume): The lowest training dose that produces measurable progress or adaptation. Anything below this threshold will not drive improvement.

MAV (Maximum Adaptive Volume): The “sweet spot” where training volume is high enough to maximize gains without causing excess fatigue or risk of overtraining. This is where most productive training occurs.

MRV (Maximum Recoverable Volume): The upper limit of training volume that the body can adapt to and recover from. Exceeding this consistently leads to stagnation, regression, or injury.

In short:

  • MV: Enough to maintain, not improve.
  • MEV: The minimum to make progress.
  • MAV: The most productive range for gains.
  • MRV: The most you can recover from, not to be exceeded.

Maintenance Volume (MV)

Maintenance Volume is exactly what it sounds like: the minimum amount of work required to preserve a current level of adaptation.

Notice what it is not. Maintenance volume is not intended to produce meaningful improvement. It provides enough stimulus to prevent meaningful loss.

This matters more than many athletes realize because maintenance allows training resources to be reallocated. A competitive CrossFit athlete may temporarily reduce upper-body hypertrophy work while emphasizing Olympic lifting. A tactical professional preparing for selection may maintain maximal strength while substantially increasing endurance. An older adult may temporarily reduce overall workload while attempting to preserve existing strength and muscle mass.

Maintaining an adaptation generally requires less training than developing it in the first place. That principle becomes one of the coach’s most valuable tools because no athlete can emphasize everything simultaneously.

Sometimes maintaining one quality is precisely what allows another to improve.

Minimum Effective Volume (MEV)

MEV represents the lowest amount of training necessary to produce measurable improvement. Think of it as crossing the threshold where training moves beyond maintenance and begins providing enough stimulus for further adaptation.

Importantly, MEV is highly individual.

A novice lifter may stimulate meaningful progress with relatively little training. An experienced athlete may require substantially more work simply to continue improving. Training age changes the equation because the stronger, more conditioned, and more experienced you become, the greater the stimulus may need to be before the body has sufficient reason to adapt further.

Success changes the rules.

Maximum Adaptive Volume (MAV)

Maximum Adaptive Volume describes the region where training produces the greatest return relative to the fatigue it creates.

Not necessarily the most work. The best work you can do, achieving the intended stimulus, and recover from.

Most productive training should occur somewhere in this range. Performance improves, strength or work capacity develops, recovery remains manageable, technique stays relatively sharp, and the athlete remains capable of continuing to perform quality training.

That distinction matters. MAV is not defined by exhaustion, it’s defined by adaptation.

Maximum Recoverable Volume (MRV)

Eventually every athlete reaches a point where additional work creates more fatigue than useful adaptation. That upper boundary is Maximum Recoverable Volume.

MRV should not be treated as a target. It’s the ceiling.

Experienced athletes may intentionally approach that ceiling during concentrated training blocks before reducing workload and allowing accumulated fatigue to dissipate. Used carefully, periods of functional overreaching can have a place within training.

Living near or above MRV is another matter.

When training chronically exceeds the athlete’s ability to recover, familiar warning signs can begin appearing: declining performance, slower bar speed, persistent soreness or joint discomfort, deteriorating sleep, reduced motivation, worsening session quality, and increased susceptibility to minor illness.

The dedicated athlete may again interpret these symptoms as evidence that more work is required. Often the opposite is true.

Why These Landmarks Move

One of the biggest mistakes coaches make is treating volume landmarks as fixed numbers.

They aren’t.

Your MEV this year may not resemble your MEV five years from now. Your MRV during a period of low life stress may differ considerably from your MRV during a demanding work cycle, caloric deficit, competition season, or period of poor sleep. The amount of volume you can recover from for one physical quality may also differ substantially from what you can tolerate for another.

These landmarks move because the athlete moves. As the old saying goes, “You can’t be in fight shape all the time.

Training Age

Beginners often require surprisingly little work to improve. Advanced athletes generally require a greater stimulus to continue adapting, while simultaneously becoming capable of creating considerably more stress during each hard working set.

Five sets of squats performed by an athlete squatting 135 pounds do not represent the same physiological event as five sets performed by an athlete squatting 500.

The volume may look identical on paper. The affect on the body is not.

Exercise Selection and Recovery Cost

Not all training stress is created equally.

Three sets of leg extensions, three sets of heavy back squats, three rounds of ring muscle-ups, ten minutes of EMOM barbell cycling, and a 5k row for time all qualify as training volume, but they do not impose the same demand.

Heavy compound lifting can create substantial mechanical and systemic fatigue. High-repetition gymnastics challenge local muscular endurance, connective tissue, grip, coordination, and the ability to maintain movement quality as fatigue (neurological and physical) accumulates.

Repeated cleans or snatches performed under metabolic fatigue combine muscular endurance with technical proficiency, strength, power, timing, and repeated force production. Longer aerobic work may create relatively little mechanical damage while still imposing substantial cardiorespiratory and metabolic demand.

This is why simply counting sets, repetitions, minutes, or meters can become misleading.

Programming volume requires understanding what quality the work is developing, how much useful stimulus it provides, and what it costs the athlete to recover from it.

The body doesn’t count reps, it accumulates stress.

Different Qualities Carry Different Costs

One of the greatest misconceptions in training is assuming every physical quality responds to volume in the same way.

It doesn’t.

Absolute strength and power require exposure to high levels of force and velocity. A strong baseline in movements such as squats, deadlifts, presses, pulls, and Olympic lifts provide a foundation from which explosive force can be expressed.

Muscular endurance requires something different: the local capacity of muscles and the nervous system controlling them to repeatedly produce useful contractions despite accumulating fatigue. In gymnastics, that may mean sustaining pull-ups, push-ups, toes-to-bar, handstand push-ups, or muscle-ups. With a barbell, it may mean repeatedly cycling cleans, snatches, thrusters, or shoulder-to-overhead movements while maintaining enough technical integrity to continue working efficiently.

Cardiorespiratory endurance and stamina place another demand on the athlete. Aerobic and anaerobic metabolism must continually provide energy across efforts lasting seconds, minutes, or hours, while the athlete develops the capacity to sustain output and recover between repeated demands.

Strength, power, muscular endurance, barbell endurance, cardiorespiratory endurance, and stamina coexist, but they are not interchangeable.

A CrossFit athlete preparing for competition may intentionally increase muscular endurance, barbell cycling, aerobic development, and repeated-effort aerobic power and capacity training while maintaining rather than maximizing absolute strength.

An Olympic weightlifter may do almost the opposite, allocating considerably more training toward strength, power, technical consistency, and the competition lifts. A tactical professional may require substantial strength alongside loaded movement, cardiorespiratory endurance, muscular stamina, and repeated performance under fatigue.

An older adult may prioritize strength, muscle mass, aerobic capacity, mobility, balance, and resilience because the objective is preserving capability and independence rather than maximizing competitive performance.

None of these athletes are training incorrectly, they’re simply solving different problems. Volume only becomes meaningful when viewed through the adaptation being pursued.

Movement Quality Changes the Cost of Volume

There is another variable that sets and repetitions alone cannot explain: movement quality.

Before deciding that an athlete needs more squats, gymnastics, barbell work, or conditioning, the coach must understand whether the athlete can efficiently perform the movements being prescribed.

Can they squat through the required range of motion while maintaining position? Can they establish a stable overhead position and safely receive a clean or snatch? Do they possess the ankle, hip, thoracic, and shoulder mobility required for the task? Can they maintain trunk control and coordination as fatigue accumulates?

Flexibility and mobility are not decorative qualities simply sprinkled in at the beginning or at the end of a training session. Adequate range of motion allows the athlete to access the positions required for the task(s); mobility adds the ability to control those positions. Coordination, agility, and balance allow the athlete to organize movement, redirect force, transition between tasks, and preserve technical integrity under changing conditions.

These qualities are essential and non-negotiable under fatigue.

Walking on your hands while fresh is one skill. Maintaining a handstand walk after heavy cleans and/or several minutes of high-output conditioning is another. The same principle applies to receiving a snatch in a deep overhead squat, transitioning efficiently through ring muscle-ups, or maintaining clean mechanics while breathing heavily and losing grip strength.

Poor movement quality increases the cost of work. Efficient movement reduces it.

Two athletes can therefore complete exactly the same prescribed volume while experiencing meaningfully different training loads.

Sometimes the fastest way to improve work capacity isn’t adding more work.

It’s reducing wasted movement. Or, what we used refer to in CrossFit as seeking Virtuosity in movement.

Volume Exists in Time

Twenty weekly sets performed in one session are not equivalent to twenty sets distributed across four sessions.

Fatigue accumulates differently. Performance quality changes. Recovery opportunities change.

The same principle applies outside traditional resistance training. Twenty minutes of high-skill gymnastics performed while fresh is not equivalent to twenty minutes performed after heavy barbell work. Six sprint intervals distributed appropriately across a training week do not necessarily impose the same cost as those same intervals performed immediately after a demanding lower-body session.

Volume therefore cannot be separated from frequency, sequencing, and recovery. Where the work occurs matters, what happens before and after it matters. The body does not simply experience training volume. It experiences stress over time.

The Athlete Changes the Equation

Dynamis 

Genetics, sleep, nutrition, age, life stress, occupation, training history, and movement quality all influence the amount and type of training an athlete can productively tolerate.

A firefighter working rotating night shifts may have a very different MRV from a college student sleeping nine hours each night. Two athletes possessing similar strength may tolerate very different amounts of training, and two athletes capable of completing the same workout may require entirely different interventions because their limiting factors are different.

One may lack absolute strength. Another may lack muscular endurance. Another may possess tremendous strength but poor muscular endurance. Another may have excellent local muscular endurance but insufficient aerobic capacity to recover between efforts. Another may simply move inefficiently which can make each training session twice as hard as it needs to be with the most basic of movements like air squats, pushups, pullups or burpees.

That’s why programming that ignores recovery outside the gym ignores half the equation.

And programming that ignores the individual misunderstands the other half.

Autoregulation: Listening Without Guessing

Perhaps the greatest weakness of rigid programming is the assumption that today’s body is identical to yesterday’s.

It isn’t.

Autoregulation recognizes that readiness fluctuates. Instead of blindly completing predetermined workloads regardless of performance, intelligent athletes and coaches adjust training according to relevant objective and subjective information.

Bar speed, repetitions in reserve, perceived exertion, heart-rate recovery, sleep quality, motivation, persistent soreness, session performance, movement quality, and technical deterioration under fatigue can all provide useful information.

No single metric tells the entire story. The purpose is not to replace programming with daily improvisation.

Autoregulation isn’t abandoning structure it’s allowing physiology to inform execution.

Deloads: Adaptation’s Forgotten Partner

One of the greatest misconceptions in training is that progress results from uninterrupted accumulation. It doesn’t. Progress often depends upon strategic reduction.

Deloads intentionally reduce training stress so accumulated fatigue can dissipate while much of the underlying adaptation is preserved. The purpose isn’t simply to rest. It is to restore the athlete’s capacity to perform productive training again.

A deload is not necessarily a step backward. Often it is the point at which accumulated fitness becomes visible beneath accumulated fatigue. We’ll discuss deloading, and its importance in more detail, later in this series

Pacing, Bottlenecks, and Productive Volume

More volume is rarely the solution to poor performance.

Sometimes the athlete needs more strength. Sometimes they need greater muscular endurance, a larger aerobic base, better gymnastic skill, more technical practice, or improved movement economy.

And sometimes they simply need to stop going out too hard. Pacing by itself is a performance skill. Athletes have to learn how much work can be performed now without any degradation in overall performance.

That means learning how quickly your breathing recovers, knowing when to stop just before grip or shoulder failure, or when technically efficient barbell cycling becomes increasingly expensive, and where local muscular fatigue or technical breakdown reliably appears.

Meaning, where is the bottleneck?

An athlete who repeatedly falls apart during the final five minutes of a 20min AMRAP, may not need another conditioning session. They may benefit more from not trying to win the first five minutes.

Likewise, an athlete struggling with high-repetition cleans may assume the problem is conditioning when insufficient absolute strength is making every repetition too expensive. Another athlete may possess enormous strength but lose time because poor economy of motion makes their receiving positions inefficient. Another may possess the engine and strength but lack the coordination required to transition efficiently between gymnastics and other external loading.

The workout reveals the symptom(s) and good assessments identify the cause(s). That distinction matters because training should target the bottleneck, not just accumulate more fatigue around it.

Volume Is a Conversation, Not a Competition

Perhaps the most important lesson from the Volume Spectrum is this: Volume is not something to maximize, it’s something to be optimized.

It’s a training resource to be allocated according to the athlete’s objectives, abilities, limitations, and capacity to recover. The strongest programs are rarely those that demand the most work. They are the ones that consistently produce the greatest useful adaptation relative to their cost.

That balance changes throughout a career. It changes across seasons and according to the physical quality being developed. It changes during periods of occupational stress, poor sleep, illness, caloric restriction, or competition preparation. And it changes as weaknesses become strengths and new bottlenecks emerge.

The best coaches therefore don’t ask: How much volume can this athlete survive?

They ask: How much productive volume can this athlete recover from?

And eventually, they ask an even better question: Where should that volume be spent?

Those are profoundly different questions. One measures work while the other considers adaptation. And that final question brings us to the next principle.

Looking Ahead

By now, we’ve moved far beyond the old argument that strength and conditioning somehow exist in opposition to one another.

We’ve seen that the interference effect is real but contextual. We’ve examined what performance programs actually look like and why athletes with very different objectives still develop many of the same fundamental physical qualities. And now we’ve established that even the amount of training itself exists along a spectrum, from the work required merely to maintain an adaptation to the upper boundary of what the athlete can productively recover from.

But volume alone still cannot tell us what to do.

Knowing that an athlete can recover from twelve hours of training each week tells us nothing about how those twelve hours should be spent.

Should we build absolute strength and power? Develop muscular endurance or barbell cycling skill? Expand cardiorespiratory capacity? Improve flexibility and movement efficiency? Develop coordination, agility, and balance? Improve movement quality or technical skill? Practice pacing? Attack a specific bottleneck?

Or should several of those qualities simply be maintained while training resources are concentrated on the one that matters most right now?

That is where coaching becomes something more than exercise selection.

A bodybuilder, Olympic weightlifter, tactical professional, CrossFit athlete, and older adult may all require some combination of strength, endurance, power, movement competency, and resilience.

But their needs vary in degree and application, not in kind. What changes is the proportion.

What changes is the priority. What also changes is the organization of stress across time.

Good programming does not ask which physical quality is universally best. It asks which quality matters most for this athlete, at this moment, how much of the others must be developed or preserved, where the athlete’s bottlenecks exist, and how those pieces can coexist without obscuring the primary objective.

That is why programming cannot be reduced to exercises written beneath the days of the week, and it certainly isn’t the random accumulation of difficult workouts.

Programming is the deliberate organization of stress in pursuit of adaptation.

It determines what to develop, what to maintain, what to temporarily deprioritize, how much work to perform, when to perform it, when to push, when to pull back, and when the athlete standing in front of you requires something different from what you originally wrote on paper.

In Part V of First Principles of Performance we discover how programming is not the science of writing workouts. It’s the strategic art of organizing adaptation, we bring those pieces together and examine how coaches actually organize adaptation: how strength, power, muscular endurance, cardiorespiratory capacity, movement competency, skill, recovery, and the individual athlete become a coherent training system rather than a collection of disconnected workouts.

Because knowing the physiology is important, knowing the how and why we utilize MGW is foundational, and how and why knowing all of the movements is elemental. But, knowing how to organize them around the needs of the individual is where knowledge becomes art.

Programming is not simply the science of writing workouts. It is the art of organizing adaptation. As always, the principles remain constant.

The application is the art. And that’s what quality coaching is all about.

First Principles of Cybersecurity: Essays on Leadership, Trust, and Organizational Maturity – Part II

First Principles of Cybersecurity Essays on Leadership, Trust, and Organizational Maturity -- MattShannonSecurityPro.com

Leadership Is a Security Control

The Environment Leaders Create Determines the Level of Security Their Organizations Achieve

Ask ten security professionals to name the most important security controls in a modern organization, and the answers will sound familiar. Multi-factor authentication. Endpoint detection and response. Network segmentation. Encryption. Vulnerability management. Security awareness training.

None of those answers is wrong. Each represents a critical layer in a mature security program.

Yet they all share a common characteristic: they are downstream of another control that receives far less attention but influences every one of them..

Leadership.

This may seem like an unusual assertion. Leadership does not appear on a network diagram. It cannot be licensed, deployed, or patched. It generates no alerts and produces no dashboard filled with metrics. Yet every meaningful security decision within an organization is ultimately shaped by leadership. Before a firewall is purchased, before a policy is written, before an employee completes awareness training, someone has already decided that security matters—or that it does not.

That decision is leadership in action.

Every Organization Is Perfectly Designed to Produce Its Security Culture

There is a saying often attributed to systems theorist W. Edwards Deming: “Every system is perfectly designed to get the results it gets.” Whether or not those were his exact words, the principle remains instructive.

Security culture is no exception.

Organizations rarely arrive at their security posture by accident. Rather, it emerges from thousands of decisions made over time. These are decisions about priorities, incentives, resources, accountability, and acceptable risk. Employees learn what truly matters not by reading policies, but by observing leadership.

If executives insist on secure practices even when they create inconvenience, employees notice.

If managers routinely ask teams to “just make it work” regardless of established procedures, employees notice that, too. Culture is not built through declarations. It is built through repetition.

Leadership determines what is repeated.

According to the 2024 Verizon Data Breach Investigations Report, over 80% of breaches involved a human element, highlighting that culture, behavior, and leadership are as critical as any technical control.

The Strongest Policies Cannot Overcome Weak Priorities.

Many organizations invest considerable effort in writing comprehensive security policies. These documents establish expectations, define responsibilities, and provide consistency across the enterprise. They are necessary.

They are also insufficient. A policy reflects what an organization says it values. Leadership reveals what it actually values.

Consider two organizations with identical password policies.

In the first, executives follow the same authentication requirements as everyone else, allocate time for security training, and treat security concerns as legitimate business discussions. In the second, executives routinely request exceptions, postpone security projects in favor of short-term operational gains, and regard cybersecurity as primarily the IT department’s responsibility.

On paper, the organizations appear identical. In practice, they are fundamentally different.

Policies establish direction and leadership establish credibility.

Employees are remarkably adept at distinguishing between the two.

Leadership Defines Acceptable Risk

One of the most misunderstood aspects of cybersecurity is the belief that the objective is to eliminate risk. It’s not. Every organization accepts risk. The question is whether those decisions are deliberate or accidental.

Leadership determines where that line is drawn. When a board approves funding for identity modernization rather than postponing the investment for another year, it is making a security decision.

When a superintendent supports temporary operational disruption to remediate a critical vulnerability rather than accepting unnecessary exposure, that is a security decision.

When an executive asks not only, “What will this cost?” but also, “What risk does this reduce?” security has become part of organizational decision-making rather than an afterthought.

Security professionals identify and communicate risk. Leadership determines which risks are acceptable.

These responsibilities are distinct, but inseparable.

Trust Is a Preventive Control

Technical controls prevent malicious activity, and leadership often prevents organizational failure.

Employees who trust their leaders report mistakes sooner. They ask questions before making assumptions. They admit uncertainty before uncertainty becomes an incident.

Conversely, organizations that punish honest mistakes often create an environment where employees hide them. The initial phishing email is rarely what causes the greatest damage.

Silence does.

Trust is therefore more than an abstract leadership quality. It is a practical security control that shortens response times, improves communication, and encourages the reporting behaviors upon which effective incident response depends.

Organizations frequently invest millions of dollars in detection technologies while overlooking one of the simplest ways to improve detection: creating an environment where people feel safe speaking up.

Technology Scales Capability. Leadership Scales Behavior.

Technology can authenticate identities, encrypt data, detect anomalies, and automate countless security functions. It can’t establish priorities, create accountability, model integrity, or build trust. Only leadership can accomplish those things.

This is why organizations with modest security budgets, but disciplined leadership often outperform organizations possessing sophisticated technologies but inconsistent governance. The difference is not the tools themselves. It is the environment in which those tools operate.

Technology amplifies capability and leadership amplifies behavior. Given enough time, behavior almost always proves to be the more influential force.

Actionable Steps for Leaders

  • Model security behaviors consistently at every level of the organization.
  • Integrate risk discussions into executive decision-making, not just technical reviews.
  • Foster a culture of psychological safety so employees feel comfortable reporting mistakes and asking questions.
  • Align security policies with actual business practices—avoid policies that are routinely bypassed.
  • Invest in both technology and leadership development to scale capability and culture in tandem.

Final Thoughts: Leadership as the First Control

It is tempting to think of cybersecurity as something managed by the security department. Firewalls belong to network engineers. Endpoint protection belongs to security analysts. Policies belong to governance teams.

Leadership belongs in every decision.

Every decision about priorities, every allocation of resources, every conversation about acceptable risk, and every example set by those entrusted to lead either strengthens or weakens the organization’s security posture.

For that reason, leadership should not be viewed merely as support for cybersecurity.

It should be recognized for what it is.

The first security control.

Key Takeaways:

  • The downstream effects of leadership shape every aspect of an organization’s security posture.
  • While policies and technology matter, leadership determines how they are valued, implemented, and, more importantly, enforced.
  • Trust and culture are practical security controls that improve incident response and reduce risk.
  • Consistent, visible prioritization of security by leaders is more influential than any single technical investment.
  • Security is ultimately a human endeavor, and its success is determined by the actions and environment set by those who lead.
  • This perspective is echoed by leading frameworks, NIST CSF and ISO 27001, which position governance and leadership at the foundation of resilient security programs.

The technologies organizations deploy may change. The threats they face certainly will. But the principle remains constant: every security program ultimately reflects the leadership that built it.

Leadership, then, is not merely support for security; it’s the foundation.

First Principles of Performance –Part I

Cardio Doesn’t Kill Your Gains. Poor Programming Does.

“The first principle isn’t choosing between strength and conditioning. It’s understanding what adaptation you’re trying to create.”

Cardio Doesn’t Kill Your Gains. Poor Programming Does.

The Lion Killer

For decades, one of the most persistent myths in strength training has been deceptively simple:

“If you want to build muscle, avoid cardio.”

It sounds reasonable. After all, endurance athletes tend to be lean, while bodybuilders are muscular. Somewhere along the way, many people concluded that cardiovascular training and muscle growth must exist at opposite ends of the same spectrum.

Like most fitness myths, there’s a grain of truth buried beneath a mountain of oversimplification.

Can excessive endurance training interfere with maximal hypertrophy? Yes.

Can intelligently programmed cardiovascular training improve your health, enhance your recovery, increase your work capacity, and have little meaningful effect on muscle growth?

Also yes. The difference isn’t cardio. It’s programming

The Wrong Question

People often ask, “How much cardio can I do without losing muscle?” It’s the wrong question. The better question is: What adaptation am I trying to produce?

Every training session asks your body to solve a problem. Heavy squats ask it to produce more force. Tempo intervals ask it to become more efficient at clearing lactate.

Sprints demand explosive power. Long easy efforts improve aerobic efficiency.

These aren’t competing identities. They’re simply different physiological adaptations. Understanding that distinction changes everything.

First, Let’s Define “Cardio”

One reason this discussion becomes so confusing is because we use the word cardio as though it’s a type of exercise.

It isn’t. It’s a physiological demand.

Your cardiovascular system doesn’t know whether you’re running, rowing, cycling, carrying sandbags, or performing twenty-rep squats. It only knows that your muscles require oxygen, nutrients, and energy.

Think about workouts like:
– The Standard (Grace – 30 clean and jerks at 135/95, 30 ring muscle ups, Isabel – 30 snatches at 135/95)
– Heavy sled pushes
– Oly complexes of 5 reps or more
– 2k row for time
– 5k run
– Fran
– 20 rep max back squat
– Murph

Nobody finishes those wondering whether their cardiovascular system was challenged. Weight training can absolutely become cardiovascular training depending on how it’s programmed.

Intensity.
Density.
Rest intervals.
Exercise selection.
Volume.

These variables determine the cardiovascular demand, not whether you’re holding a barbell or running shoes. The conversation isn’t “weights versus cardio.”

It never was.

Where the Myth Came From

The concern isn’t entirely imaginary.

Researchers have long studied what’s known as the interference effect, the observation that combining endurance and resistance training can, under certain conditions, reduce some strength and hypertrophy adaptations compared with resistance training alone.

Notice the language. Can. Under certain conditions.

Not: Always. Those conditions matter.

A competitive marathon runner performing sixty miles each week while trying to maximize leg hypertrophy faces a very different challenge than someone lifting four days a week while adding two thirty-minute conditioning sessions.

Those are not the same training problems. Yet they’re often discussed as though they are.

What Actually Interferes?

For most lifters, muscle isn’t lost because they jogged. It’s lost because recovery becomes the limiting factor.

Poor programming often looks like this:
Heavy lower-body lifting followed immediately by long-distance running.
High-volume conditioning layered on top of already excessive lifting volume.
Poor sleep.
Insufficient calories.
Inadequate protein intake.
Eventually something has to give.
Trying to train near maximally, whether it’s loading or intensity, 4-6 days per week.

If training continually exceeds your ability to recover, progress slows—not because cardio is inherently bad, but because the total stress exceeds your adaptive capacity.

The Research Is More Encouraging Than the Internet

Fortunately, the research is considerably more nuanced than the internet. Much of the fear surrounding cardio comes from laboratory discussions about molecular signaling. You’ll often hear that endurance exercise activates one pathway while resistance training activates another, and that these pathways “fight” each other.

There is truth here. But physiology is rarely as binary as social media suggests.

These signals are temporary. They’re influenced by nutrition, training age, exercise selection and most important, recovery.

And they’re often localized to the tissues being trained rather than acting as a simple on-off switch across the entire body.

More importantly, when researchers look beyond the molecular biology and examine actual training outcomes, the picture becomes much less dramatic.

For the overwhelming majority of recreational lifters, and even many competitive athletes, well-designed conditioning has little meaningful effect on muscle growth.

Programming matters far more than the mere presence of cardiovascular exercise.

I hope the archive of this blog never disappears.

Optimum Performance Training (OPT) James Fitzgerald

Numerous studies support the idea that cardio, when programmed intelligently, does not meaningfully hinder muscle growth. For example, a 2015 meta-analysis by Dr. Brad Schoenfeld and colleagues concluded that combining strength and cardio training results in only a negligible impact on muscle and strength gains, provided programming is sound (Schoenfeld, B.J., Ogborn, D., & Krieger, J.W., 2015, Sports Medicine).

Cardio That Supports Muscle Growth

If hypertrophy is your primary objective, conditioning should complement not compete with your lifting.

Generally speaking, it could look like the following:

  • Shorter, more intense sprint work.
  • Use interval-based conditioning where appropriate.
  • Row.
  • Cycle.
  • Throw med-balls.
  • Use the SkiErg.
  • Carry odd objects.
  • Push and pull sleds.
  • Perform tempo intervals.
  • Carry heavy implements.
  • Include sprint interval training when recovery allows.
  • Separate demanding conditioning from heavy lower-body strength sessions whenever practical.

Most importantly, keep the main thing, the main thing.

Conditioning exists to improve health, increase work capacity, and support recovery, not to leave you so fatigued that tomorrow’s strength session suffers.

Keep the Main Thing the Main Thing

The best programs are surprisingly disciplined. They know exactly what they’re trying to improve. Everything else exists to support that objective, not distract from it.

One of the greatest mistakes athletes make is assuming every session must improve every quality simultaneously.

It doesn’t. Training is about emphasis or specificity to the individual and their goals. Some phases prioritize maximal strength. Some emphasize hypertrophy, aerobic capacity gymnastic or Olympic Weightlifting skill. A skill Ive always referred to as barbell gymnastics because of how skill dependent they are.

The art of coaching isn’t teaching every quality simultaneously. It’s knowing which qualities deserve emphasis today, and which can simply be maintained until tomorrow.

That’s programming.

Paleo - BJJ - white belt - black belt - earned not issued

The First Principle

Cardio doesn’t kill your gains. Poor programming does. If your training reflects clear priorities, if recovery matches workload, if nutrition supports adaptation, if conditioning complements rather than competes with strength, then you can become stronger. You will then become stronger, healthier, and better conditioned.

Not because you avoided cardio, but because you finally stopped asking whether strength and conditioning are enemies.

They never were. They simply need a coach who understands how to make them work together.

The principles remain constant. The application is the art.

If you’re curious why all of this works, not merely what to do, we’ll step out of the weight room and into the physiology laboratory. There we’ll explore the molecular conversation taking place inside skeletal muscle every time you lift, sprint, row, or recover, and discover why the story is far more nuanced than the internet would have you believe.

References

Schoenfeld, B. J., Ogborn, D., & Krieger, J. W. (2015). Effect of concurrent aerobic and strength training on maximal strength, power, and hypertrophy in healthy adults: A systematic review and meta-analysis. Sports Medicine, 45(5), 697–708.

Wilson, J. M., Marin, P. J., Rhea, M. R., Wilson, S. M. C., Loenneke, J. P., & Anderson, J. C. (2012). Concurrent training: A meta-analysis examining interference of aerobic and resistance exercises. Journal of Strength and Conditioning Research, 26(8), 2293–2307.

Security Without the Pessimism | Capstone: The Human Architecture of Resilience

There’s a moment in every incident, and in every life, when things go sideways.
An urgent alert comes in at 2 a.m.
The phone buzzes with something you didn’t want to see.
The room suddenly feels smaller.
Your pulse skyrockets ahead of your ability to reason.

That’s the pivot point.

Not the breach, not the threat actor, not the malware strain. The moment your mind decides whether to rush, freeze, or breathe.

And if the past two decades in cybersecurity have taught us anything, it’s this: The most overlooked control isn’t technical at all — it’s the ability to think clearly under pressure.

You can build the best firewall on earth, layer your identity stack, and lock down every endpoint within reach. But if the wrong person panics at the wrong moment? Your architecture won’t crumble, but your response will.

And the irony is that the same pattern shows up everywhere.
In the gym.
In martial arts.
In American foreign policy across multiple generations.
In corporate culture.
In our personal lives.

Technology changes. Tools evolve.
But human behavior remains the battlefield.

This capstone is about that battlefield, the one beneath all the dashboards and diagrams.
The human architecture of resilience.

Not fear.
Not pessimism.
Not endless warnings.
Just clarity, culture, awareness, and depth.

I. The Calm Before the Click: Thinking Clearly Under Pressure

Cybersecurity professionals often discuss “root cause.”
The CVE.
The misconfig.
The missing patch.
The malicious link.

But if you trace incidents far enough back, you rarely find a purely technical failure.
You find someone who was tired.
Someone who rushed.
Someone is overloaded with tasks, tabs, or alerts.
Someone who clicked before the mind caught up.

Attackers have known this longer than we have.
Social engineering is, at its core, the psychological equivalent of an ambush.
It doesn’t rely on brilliance — it relies on rhythm.
Interrupt someone’s rhythm, and you can make them do almost anything.

History played the same game long before phishing emails existed.

During WWI, the U.S. population had no appetite for a European conflict until the Committee on Public Information mastered message engineering on a national scale.

During Vietnam, selective narratives were used to anchor the Gulf of Tonkin resolution, one of the clearest examples of how urgency overrides discernment.

After 9/11, emotional exhaustion and fear gave the green light to decisions that would shape two decades of conflict, including the push toward Iraq in 2003 on intelligence the government already knew was questionable at best.

The pattern is timeless: pressure → perception drops → people accept what they would normally question.

In cybersecurity, that’s the moment a breach begins. Not when the payload deploys, but the moment someone stops breathing long enough to see clearly.

Martial arts teach this early: when your structure collapses, so does your mind. The fight is rarely won by the strongest, but by the one who stays calm.

Cybersecurity isn’t so different. We need quieter minds, not louder alarms. Consider the Apollo 13 mission: when an oxygen tank exploded in space, it wasn’t advanced technology alone that saved the crew—it was the unwavering composure, clear communication, and problem-solving focus of both astronauts and mission control. Their story remains a testament to the power of preparation, training, and the human spirit under pressure.

Psychological research supports this need for balance: the Yerkes-Dodson Law demonstrates that while a certain level of stress can sharpen performance, too much leads to mistakes and paralysis. It’s not the loudest alarms or the highest stress that produce the best outcomes, but the ability to operate with steady focus under pressure.

II. Security Isn’t a Toolset. It’s a Culture.

This is the part vendors never put in their brochures.
Tools matter, of course they do, but they’re not the foundation.
If a team’s culture is fractured, fearful, or fatigued, the best tool becomes another dashboard no one trusts.

A culture of security is built on three traits: Curiosity. Communication. Psychological safety.

Curiosity is the click buffer. It’s the pause before the action. It’s the “does this feel right?” instinct that catches what technology misses.

Communication is the force multiplier. If people don’t feel comfortable asking questions, you don’t have a security program; you have a façade. The worst breaches happen in organizations where employees believe that reporting something suspicious will get them punished.

Psychological safety is the foundation beneath it all. You cannot build defense through fear.
If people feel judged, they go silent. And silence is where threat actors win.

Across American history, the same dynamic appears at scale. Governments that relied on controlling the narrative rather than fostering transparency created long-term instability.
Nations that punished dissent instead of listening to it made poorer decisions, walked into unnecessary conflicts, or ignored early warnings because no one felt safe raising them.

In cybersecurity, the equivalent is leadership that says: “If you click a bad link, come to us immediately, you’re part of the solution, not the problem.”

Culture isn’t a policy. Culture is what happens when no one is watching.

III. The Invisible Threat: Complacency

Complacency is the enemy that feels like a friend. It arrives quietly. It shows up after long stretches of “nothing happened.” It hides behind phrases like:

  • “We’ve never had an incident.”
  • “We’ve always done it this way.”
  • “Our tools would catch that.”

Every major breach you can name—SolarWinds, Equifax, Colonial Pipeline—roots itself in complacency somewhere: A missed update. An over-trusted vendor. An assumption that the environment was safer than it actually was. The 2013 Target data breach is a sobering example: multiple security alarms were triggered, but critical warnings were overlooked amidst noise and unclear processes. The failure wasn’t just technical—it was cultural and human. True resilience is built not on more tools, but on clear communication, shared responsibility, and organizational discipline.

There’s a parallel here, too, in public psychology. Before WWI, the U.S. believed oceans protected it.

Before the Vietnam War, we believed that superior technology guaranteed strategic clarity.
Before 9/11, we believed asymmetrical warfare couldn’t reach our shores.
Before the Iraq invasion, many believed intelligence agencies couldn’t be wrong.

Every time, familiarity dulled skepticism. Certainty replaced awareness.

Threat actors exploit the same weakness in cybersecurity: When we stop questioning our own assumptions, we hand them the keys.

But the solution isn’t paranoia. It’s presence—the discipline to stay aware without fear, engaged without burning out, and to use quiet periods to strengthen fundamentals rather than relax them.

Martial artists call this “maintaining the white belt mentality.” It’s the idea that no matter how skilled you become, your awareness must remain humble. The strike you don’t see coming isn’t the strongest; it’s the one you assumed wouldn’t land.

IV. Defense in Depth Begins With Humans in Depth

Defense in depth is usually presented as a diagram: Layers. Controls. Policies. Logging. Detection.

But the deepest layer is always the human beings behind the console.

Humans who communicate clearly under pressure.
Humans who don’t panic.
Humans who collaborate instead of silo.
Humans who maintain integrity even when no one is watching.

You can’t automate those traits.
You can only cultivate them.

A resilient team has depth:
Depth of character.
Depth of discipline.
Depth of humility.
Depth of trust.

Leadership plays a massive role here.
A leader who panics creates a cascading failure.
A leader who hides incidents creates blind spots.
A leader who blames creates avoidance.

But a leader who stays calm?
A leader who listens?
A leader who respects the intelligence of their team?

That kind of leadership becomes its own security layer, the kind attackers can’t penetrate.

Martial philosophy applies here beautifully:
The master doesn’t fight everything.
The master knows when not to fight.
The master conserves energy, maintains structure, and remains sufficiently present to move precisely when needed.

That’s cybersecurity at its best. Not a flurry of tools or panic-driven responses. But steady awareness, grounded action, and a team that trusts itself. The response to the Stuxnet worm demonstrated the power of multidisciplinary collaboration: security researchers, government agencies, and private-sector teams worked together to analyze, share intelligence, and adapt rapidly. Their coordinated effort underscores that no single individual or technology has all the answers—resilience is a collective achievement.

V. The Four Pillars of Real Resilience

Looking back across this entire series, four fundamentals keep appearing.

1. Calm

The ability to breathe before acting. Security begins in the mind, not the machine.

2. Culture

Tools help. Culture protects. Culture catches what software can’t.

3. Awareness

Not paranoia, presence. The discipline to question, verify, and stay awake to the world around you.

4. Depth

Technical depth is valuable. Human depth is irreplaceable. Depth fuels resilience in every domain: networks, clouds, teams, and nations.

These aren’t pessimistic ideas. These are empowering ideas. They’re principles that make security feel less like fear and more like clarity.

Threat actors depend on confusion. They depend on fatigue. They depend on people who doubt their instincts.

A calm mind. A strong culture. A present awareness. A deep team.

That’s how you win. Not loudly, but with consistency.

VI. Final Thought: Security Is a Human Practice Before It’s a Technical One

If there’s a thesis to Security Without the Pessimism, it’s this: Security isn’t something we bolt onto systems. It’s something we build into ourselves.

The work isn’t glamorous or cinematic. It’s often quiet, slow, and unrecognized. But it matters, because every decision and moment of awareness contributes to something bigger than any one of us, a culture of resilience.

So here’s the takeaway: You don’t need pessimism to stay secure. You just need presence. You need clarity and people who care enough to pause, communicate, and stay humble.

That’s the foundation of a safer digital world, built one calm, aware, disciplined human at a time.

Security Without the Pessimism: Cyber Hygiene, The Daily Routine You Actually Need

The Myth of the “Security Checklist”

If you believed every cybersecurity headline, you’d think staying safe online takes a PhD, three apps, and a daily ritual in front of your firewall.

The security industry profits from this complexity. Vendors want you to believe that protection requires their latest tool, their proprietary solution, their 27-step implementation guide. More complexity means more products to sell.

But real security doesn’t look like that. It’s not about chasing every threat or memorizing every acronym. It’s about simple, repeatable habits. It’s the digital version of brushing your teeth.

Here’s the truth they don’t want you to hear: You don’t need to do everything. You just need to do the right things, consistently.

That’s cyber hygiene. And it’s boring on purpose.

The Habits That Actually Matter

Most people already know the broad strokes: use strong passwords, update software, don’t click weird links.

But here’s what actually moves the needle:

  • Multi-Factor Authentication (MFA). Still, the single best defense against credential theft.
  • Software updates. Patches close the doors that attackers love to walk through.
  • Password managers. Better one secure vault than 20 weak logins.
  • Backups. One local, one in the cloud, test them once in a while.
  • Device lock and encryption. Lost phones shouldn’t equal lost data.

That’s it. No mystery. No 27-step plan. Just a few habits that, when done daily, make 95% of attacks irrelevant.

In 2017, Equifax was breached because they didn’t patch a known vulnerability for two months. 147 million records compromised. The fix? A software update they already knew about. That’s not sophisticated hacking, that’s skipped hygiene at a catastrophic scale.

The basics aren’t basic because they’re easy to remember. They’re basic because when you skip them, everything else fails.

Why We Skip Simple Stuff

It’s not that people don’t know what to do. It’s that security doesn’t feel urgent until it’s too late.

You don’t see or feel the benefits of good hygiene, but you definitely avoid the pain of neglect. No one cheers when you floss. But everyone will notice that broccoli in your teeth if you don’t.

But there’s more to it than just invisible benefits. Three psychological forces work against cyber hygiene:

Optimism bias. “It won’t happen to me” is a powerful drug. You read about breaches happening to other people, other companies, other industries. Your brain quietly files those stories under “someone else’s problem.” Until it isn’t.

Decision fatigue. You have 47 accounts, each with different password requirements, different MFA setups, and different update schedules. The sheer volume of security decisions creates paralysis. So you do nothing, or you take shortcuts, the same password everywhere, “remind me later” on every update.

The invisible threat problem. You can see a locked door. You can’t see a botnet probing your network. Physical security has visual feedback like locks, gates, cameras. Digital security is abstract until the moment it fails catastrophically. And by then, it’s too late.

Cyber hygiene fails for the same reason flossing does: it’s easy to skip, hard to see the benefit, and the consequences feel distant. But unlike cavities, breaches don’t announce themselves with pain. They’re silent, patient, and devastating.

The trick is to make it small enough that you’ll actually do it, and easy enough that you won’t skip it.

Where Good Intentions Break Down

Even security-conscious folks sometimes miss the basics. Not because they’re careless, but because these gaps accumulate slowly, invisibly:

Outdated hardware. That router you set up five years ago? It stopped receiving security patches three years ago. Old devices become permanent vulnerabilities.

Shadow data. Files saved “temporarily” on random drives, USB sticks, or that personal Dropbox you forgot you created. Every copy is another attack surface.

Forgotten accounts. That forum you joined in 2014. That trial subscription you never canceled. Dormant logins are open doors with your email and password sitting in some leaked database.

Public Wi-Fi comfort. You use a VPN at the airport but not at the coffee shop. Inconsistent protection is predictable behavior and attackers love predictability.

You don’t have to fix everything today. Just start closing one gap at a time. Audit your accounts quarterly. Replace hardware that can’t be updated. Consolidate your data.

Security isn’t perfection. It’s progress. And progress happens one boring habit at a time.

Think of it this way: cyber hygiene is like compound interest, make small deposits now, get massive protection later. Skip the deposits, and you’re borrowing against a future breach.

Make Security Boring (That’s the Point)

The goal isn’t to turn security into a project, it’s to make it routine. Boring. Automatic. The kind of thing you do without thinking, like locking your car.

Here’s a weekly checklist that actually sticks:

  • Monday: Check updates and patches. Five minutes. Coffee in hand. Start the week secure.
  • Wednesday: Backup your files. Set it, forget it, verify it works.
  • Friday: Review new apps or accounts, prune what you don’t use. Close the week by closing gaps.

That’s 10 minutes a week. Three touchpoints. No drama. No heroics.

If you can manage that, you’re already ahead of most organizations. Not because you’re doing something extraordinary because you’re doing something sustainable.

Security should be quiet. The less you think about it, the better it’s working. The moment it becomes a production, it becomes optional.

Culture Over Blame, Turning Awareness Into Habit

People don’t need more fear. They need better routines.

I’ve seen teams transform their security posture not through mandates, but through modeling. One security lead I worked with started every Monday standup by sharing what he patched over the weekend, not as a flex, just as routine. Within a month, the team was comparing notes on password managers and backup strategies. Security became a shared practice, not a compliance checkbox.

Encourage coworkers, friends, or family to treat digital hygiene like health hygiene, it’s a shared standard, not a personal burden. When one person in a household sets up MFA, others notice. When a team lead mentions their weekly backup routine, it normalizes the behavior.

When leaders model small, consistent habits, teams follow. Security doesn’t start in policy documents; it begins in daily rhythm. And rhythm spreads.

Make it normal. Make it boring. Make it easy.

Final Thought

Cyber hygiene isn’t glamorous, but it’s the backbone of every good security posture.
You don’t need to understand encryption or chase every breach headline.
You just need to do the basics, on time, every time.

The security industry wants you to believe protection is complicated because complexity sells. But the truth is simpler and cheaper: consistent habits beat expensive tools every time.

Prevention doesn’t shout. It just works.

That’s not pessimism, that’s just daily discipline. And it’s boring, and effective, on purpose.

Security Without the Pessimism: The VPN Comfort Myth

The Digital Blanket We All Love

Few tools in cybersecurity inspire more misplaced comfort than the VPN.

We picture it as an invisibility cloak or a tunnel of safety where no one can see us, track us, or touch our data. Turn it on, and suddenly you’re “secure.”

That feeling of control is powerful, especially in a world that never stops reminding you how unsafe the internet supposedly is.

But here’s the quiet truth: a VPN protects you from some things, not from everything.
It’s a tool, not a shield.

What VPNs Actually Do

At its core, a VPN (Virtual Private Network) encrypts your internet traffic and routes it through a secure server. It hides your IP address and protects your data from casual snooping, especially on public Wi-Fi.

That’s useful, but not magic.

VPNs do not:

  • Protect you from phishing or malware
  • Stop you from logging into fake sites
  • Prevent data collection once you’re signed in somewhere

If your VPN provider keeps logs or has weak security, your trust shifts from the ISP to them.

So yes, a VPN helps. But only if you understand where its power ends.

Safety Theater for the Digital Age

VPNs scratch a deep psychological itch: the need to feel safe, even when we can’t verify it.

They’re the digital equivalent of locking your front door but leaving the windows open, a visible act that soothes anxiety without addressing every risk.

That invincibility leads many to take more risks online. This risk compensation means perceived safety can spark riskier behavior.

Real security isn’t about hiding. It’s about awareness.

Where Comfort Becomes Complacency

The most significant problems with VPN use aren’t technical; they’re behavioral.

  • Blind trust in providers. Some “free” VPNs monetize your data rather than protect it.
  • Performance trade-offs. Slower speeds lead people to disable it, often forgetting to turn it back on.
  • Assumed anonymity. Logging into your personal accounts still links behavior to identity.
  • Neglected basics. Users skip updates or MFA because “I’ve got a VPN.”

The tool becomes a crutch, and that comfort can cost you more than the subscription.

Layer, Don’t Lean

A VPN should be part of a layered defense, not its foundation.

Here’s how to use it wisely:

  • Choose providers with no-log policies and independent audits
  • Keep software updated. VPNs rely on encryption protocols that age fast
  • Use MFA everywhere. A VPN won’t save a stolen password
  • Understand context. VPNs are best for travel, remote work, and untrusted networks — not daily browsing at home

Security isn’t about hiding behind one tool. It’s about stacking the right ones.

Culture Over Blame — Moving Past Security Myths

The VPN story mirrors how we approach most security advice: quick fixes over long habits.

Instead of mocking people for misunderstanding what VPNs do, we can use that comfort as a bridge: “Good start. Now let’s talk about the rest.”

Awareness grows when education feels empowering rather than condescending. The goal isn’t to shame people for feeling safe; it’s to help them feel safe for the right reasons.

Final Thought

A VPN isn’t a vault; it’s just a smaller door to the same big house. Use it, respect it, but don’t mistake a single layer for complete protection.

Real protection isn’t invisible. It’s intentional. That’s not pessimism, that’s just good sense.

The Art of Cyberwar | Part VII | Maneuvering

Chapter VII’s artwork conveys the essence of Sun Tzu’s Maneuvering with clarity and grandeur. A lone commander surveys a vast, unfolding landscape of troops in motion, symbolizing disciplined rhythm rather than frantic pace. The terrain’s natural flow mirrors the movement of cloud-age systems, and the light breaking across the valley evokes strategic awareness dawning before action. It is a rare blend of historical resonance and modern metaphor, a visual philosophy.

Movement After Position

The Principle: “We may take it then that an army without its baggage-train is lost; without provisions it is lost; without bases of supply it is lost.” — Sun Tzu

The Art of Coordinated Movement

A cybersecurity team detects a breach at 2 AM. They have the skills, the tools, and the authority to act. But without coordination, that capability becomes chaos, analysts duplicating work, containment efforts conflicting, and communication breaking down. By dawn, the advantage is gone.

In February 1943, American forces faced German tanks at Kasserine Pass in North Africa. They had the weapons, the numbers, the training. What they lacked was coordination between units and effective air-ground communication. The result? The first major American defeat of WWII was not due to a lack of capability, but to failure to maneuver as a unified force.

Fifteen months later, those same American forces learned the lesson. On June 6, 1944, D-Day coordinated 12 nations, over 7,000 vessels, and 160,000 troops across five beaches in a single operation. Not because they suddenly acquired better weapons, but because they mastered maneuvering. Kasserine Pass taught them that capability without coordination is chaos. Normandy proved that coordination transforms capability into victory.

Eighty years later, the battlefield is digital, but the lesson remains the same.

Sun Tzu called this the difference between movement and maneuvering.

Maneuvering is the discipline of transforming positional advantage into progress without depleting resources. Though movement may appear straightforward (advance, pivot, respond), it demands careful coordination. Without coordination, movement breeds confusion and disorder, undermining any initial advantage.

In Brazilian Jiu-Jitsu, there’s a fundamental principle: position before submission. A novice rushes for the choke. A master secures the proper position, seeks control, applies the proper pressure, isolates the arm, and then the finish is there for the taking. The submission becomes inevitable because the position made it so.

Maneuvering works the same way: structured movement from an established position. Not frenetic action. Coordinated, calculated movement in advance.

Whether in military operations, government, or cybersecurity, the true challenge lies in maintaining momentum while preserving balance. Effective teams favor structured, intentional movement, not just speed.

This is the heart of maneuvering: composure, intent, and clarity. Act from principle, not anxiety.

The Maneuvering Decision Matrix

Sun Tzu understood that effective maneuvering requires reading the moment, knowing when to accelerate, when to pause, and when to let the environment dictate pace.

Modern leaders need the same discernment:

When to Accelerate:

  • The advantage is clear and actionable.
  • Resources are sufficient.
  • Team alignment is strong.
  • Opponent is vulnerable

When to Pause:

  • Visibility is degraded
  • Fatigue is setting in across the team.
  • Purpose has become uncertain.
  • Information remains incomplete

When to Let Environment Dictate:

  • The opponent is making mistakes.
  • Terrain is shifting faster than you can control
  • Patience offers a strategic advantage.
  • Reactive movement would expose weakness.

This isn’t indecision. It’s tactical discipline. The fighter who controls tempo controls the outcome.

Tempo and Terrain

In both war and cybersecurity, timing determines outcomes more than sheer speed. When to act matters more than how quickly you act.

Sun Tzu cautioned that armies advancing too rapidly become fatigued, while those moving too slowly forfeit initiative. Balance requires understanding rhythm, discerning when to accelerate, when to pause, and when to let the environment set the pace.

Today, that terrain is digital.

The modern battlefield consists of networks, cloud environments, and global systems. Effective cybersecurity professionals study the digital landscape to move with intent, not to avoid movement altogether.

In the cloud era, terrain isn’t geography, it’s architecture.

Latency, visibility, and complexity shape what’s possible. The most secure organizations extend beyond perimeter defense by developing a comprehensive understanding of their operational landscape. They design systems where quick tactical movements don’t create strategic vulnerabilities.

The Cyber Battlefield: Coordination Over Chaos

In cybersecurity, effective maneuvering means more than quick patching or immediate responses. It requires aligning teams, especially during high-pressure situations.

  • Incident response represents maneuvering under pressure: containment, communication, and recovery.
  • Threat intelligence involves maneuvering through uncertainty—transforming fragmented information into actionable insights without prematurely acting on incomplete data.
  • Automation functions as the logistical backbone, the supply chain supporting frontline operations. When automation fails, even highly skilled analysts face burnout.

Many security operations centers (SOCs) miss this point. Constant urgency and nonstop action may seem productive, but endless motion risks exhaustion and reduced effectiveness.

Authentic maneuvering is characterized by calm, control, deliberation, and focus.

  • Wing Chun’s centerline theory offers a simple, direct, economical model. SOC analysts don’t need fifty tools—they need the right three, automated properly, with clear escalation paths. Economy of force.
  • The central point: when your playbook drives decisions, you maneuver. When alerts drive decisions, you react.

Cloud Mobility: The Terrain in Flux

The shift to cloud computing redefined what “maneuvering” means. In the old world, servers stayed put. Now, data, workloads, and identities move across providers, borders, and legal frameworks.

In this environment, organizational strength comes not from rigidly restricting movement, but from orchestrating secure and transparent operations.

Cloud maneuvering looks like:

  • Workloads shifting across regions without breaking compliance
  • Data flowing securely through APIs without leaving blind spots
  • Teams pivoting incident response playbooks across hybrid environments in real time

Cloud environments reward planning for motion. Organizations win by designing for agile, secure movement, not by resisting change.

In 2023, a Fortune 500 company’s cloud migration stalled not because of technical limitations, but because their security team designed for a static perimeter. When workloads needed to shift regions for compliance, every move required manual review.

Organizations that assume static conditions are at a disadvantage.

This aligns with the martial principle of flow: Rigid fighters’ break. Rigid systems break faster.

Foreign Policy and the Cost of Motion

Nations, too, confuse movement with progress. America’s 20th-century record is full of lessons in tempo and fatigue.

But no example better illustrates the danger of resource-driven maneuvering than what led to the attack on Pearl Harbor.

The Pearl Harbor Lesson: When Resources Force Your Hand

Japan’s attack wasn’t born from ambition, it was forced by logistics. The U.S., Britain, and the Dutch enforced the ABCD embargo, cutting off:

  • Oil
  • Rice
  • Steel
  • Rubber
  • Machine parts

Japan imported 90% of its oil. Cut off from fuel, it faced two choices: fight or run out of energy and food entirely.

Sun Tzu wrote: “Throw your men into death ground, and they will fight.”

Japan was placed on death ground by resource denial. Their maneuver, the attack itself, was coordinated brilliantly. Six aircraft carriers, 353 aircraft, precise timing across multiple strike waves.

Tactically, it was masterful.

But strategically? Admiral Yamamoto knew: “I fear all we have done is awaken a sleeping giant.”

A lingering question remains: was America truly sleeping? WWI had concluded only 20 years earlier. Before WWII, WWI was considered the deadliest war in human history, earning the moniker “The Great War” for its immense scale and death toll of approximately 20 million lives. Its unprecedented destruction set it apart from previous conflicts. So, America was hardly asleep. Back to Pearl Harbor.

The lesson isn’t about the attack’s execution. It’s about what happens when maneuvering is dictated by desperation rather than position. When resources force your hand, even perfect coordination can’t save you.

Sun Tzu’s calculus applies: survival-driven movement, no matter how well-executed, is still reactive. And reactive maneuvering rarely wins wars.

The United States later encountered similar challenges in Vietnam, Iraq, and Afghanistan, where rapid action outpaced strategic learning. Momentum itself became a compelling but hazardous force.

Diplomacy is maneuvering in another realm.

In contrast, contemporary policy frequently equates reaction with strategy, prompting responses to every crisis even when restraint or delay might prove more advantageous.

Sun Tzu’s wisdom cuts through centuries: “If you know neither the terrain nor the season, you march to fatigue, not to victory.”

The Logistics of Cyber Power

For cybersecurity professionals, logistics consists not of physical supplies, but of bandwidth, personnel, and operational clarity.

Sustained operations aren’t feasible if systems are overburdened, personnel remain on constant alert, and every issue is treated as critical.

Good logistics in cyberspace means disciplined prioritization:

  • Which assets are mission-critical?
  • Which alerts deserve escalation?
  • What response cadence prevents burnout?

Sun Tzu would call this “feeding the army.” In today’s language, it’s resource stewardship.

An effective CISO ensures security professionals maintain resilience and don’t become exhausted before adversaries lose their resolve.

The data shows progress. Organizations took an average of 241 days to identify and contain breaches in 2025, down from 287 days in 2021. Not because threats got easier, but because purple-teamers got better at coordinated response. They learned to maneuver.

Maneuvering the Human Factor

The most challenging aspect of coordination isn’t the technical infrastructure; it’s the human element. While individuals contribute creativity, they also introduce unpredictability.

The numbers confirm what practitioners already know: 88% of cybersecurity breaches are caused by human error. Not zero-days. Not sophisticated malware. Human mistakes. The technology isn’t the weak link—the coordination of people using that technology is.

Sun Tzu understood morale as a weapon system. He coordinated hearts and minds before he coordinated units.

The same applies to martial arts and security culture.

  • In Muay Thai, they call it ring generalship, the fighter who controls space controls pace. The same applies to security teams. Leaders who set tempo, who decide when to press and when to absorb pressure, create the conditions for team effectiveness.
  • The most effective cybersecurity teams operate like jazz ensembles, distributed but synchronized. Training, communication, and trust are the modern equivalents of morale.

This is modern maneuvering: achieving precision in movement without relying solely on hierarchical control.

The Risk of Endless Marching

Sun Tzu cautioned that armies remaining in the field for extended periods experience internal decline. This phenomenon appears today as burnout, alert fatigue, and continuous red team exercises that fail to produce lasting improvements.

Organizations that never rest eventually turn on themselves. This applies equally to companies and nations.

Movement should support strategic objectives, not substitute for them. Effective leadership requires recognizing when to pause, regroup, and restore organizational strength.

Without periodic rest, strength deteriorates into strain, and resilience devolves into attrition.

The Bridge to Variation

The final lesson of maneuvering emphasizes humility: movement does not constitute mastery; it serves as its test.

Any army, individual, or system that acquires the ability to move must subsequently develop adaptability: the capacity to alter rhythm, diversify tactics, and confound adversaries who anticipate predictability.

Leading us back to the initial principle: “We may take it then that an army without its baggage-train is lost; without provisions it is lost; without bases of supply it is lost.”

Maneuvering determines survival. Variation determines victory.

But first, you must learn to move without falling apart. Master coordination before you attempt improvisation. Secure your supply lines before you advance.

Because, as Sun Tzu understood, an army that moves with discipline can adapt. An army that moves with chaos can only collapse. The next chapter explores variation, but only those who’ve mastered maneuvering will recognize when to use it.

Meal Prep for Real Life: How to Cook Once, Eat All Week

Meal prep isn’t just for the ultra-disciplined or Insta-famous. Sure, you’ve seen those photos: Tupperware lined up like soldiers, meals color-coded, macros counted. But let’s be real, that’s not most people’s life.

What if you could meal prep without spending eight hours every Sunday or needing a second fridge? Real meal prep isn’t about perfection; it’s about persistence and readiness. It’s about building a system that fits your training, work, and flexibility needs. When you fuel your life with intention, everything else sharpens into place.

Step One: Choose Your “Prep Style”

There are three main approaches to meal prep, and the one that’s best for you depends on your schedule and personality:

  1. Batch Prep (Traditional): Make full meals ahead of time. Roast a tray of chicken thighs, cook up a pot of rice, and steam some broccoli. Stack them, label them, done. Good for those who like structure and predictability.
  2. Buffet Prep (Modular): Prep components instead of full meals. Think proteins (ground beef, eggs), starches (sweet potatoes, oats), and fats (olive oil, avocado). Mix and match daily based on cravings or training demands.
  3. Half-Prep (Hybrid): Prep only the time-consuming tasks, like chopping vegetables or marinating proteins, so cooking during the week is more efficient but still flexible.

Step Two: Focus on Your Macro Anchors

Every meal should hit three pillars:

  • Protein: This is your building block. Prep double what you think you need. Think grilled chicken, grass-fed, slow-cooked pork shoulder, hard-boiled eggs, and Greek yogurt.
  • Smart Carbs: These are your fuel tanks. Rotate between your favorite veggies, white rice, potatoes, and fruit. Make them in bulk and store flat in zip-top bags to save space.
  • Healthy Fats: Olive oil, nuts, avocado, seeds. Never forget flavor is fuel, too. Keep these on hand for fast drizzles or topping swaps.

Make meals that tick the macro boxes without requiring a calculator. Example?

  • Ground turkey (who doesn’t love leftovers?) + sautéed kale + roasted sweet potato + a sprinkle of feta and olive oil.
  • Scrambled eggs + pepper and onions + chopped spinach + avocado.

Easily repeatable, nourishing, and delicious.

Step Three: Make Friends with Your Freezer

Your freezer isn’t just for waffles and ice cream. It’s your long-term meal prep MVP. Here’s how to make it work for you:

  • Buy bulk frozen vegetables and fruits.
  • Freeze leftover portions of chili, stew, or curry in single-serve containers.
  • Portion “smoothie” bags with fruits, nut butters, and protein powder. Blend them up and freeze them ahead of time – easy-peasy.
  • Store cooked rice or roasted veggies flat in freezer bags for quick reheats.

Pro tip: Label and date everything. No mystery meals!

Step Four: Build In the “Rescue Meals”

Life happens. You’ll miss a prep day, forget your lunch, or get stuck in traffic. That’s when “rescue meals” save the day:

  • Package tuna or salmon + cucumber and tomato slices + olive oil
  • Grilled steak + half a sweet potato with a dash of cinnamon + two slices of crispy bacon.
  • Hard-boiled eggs + fruit of your choice + handful of almonds

Not fancy. But fast, macro-friendly, and better than skipping meals or panic-ordering pizza.

Step Five: Keep it Repeatable

The secret to success isn’t variety, it’s consistency. Most people thrive on 2-3 breakfast options, 3-4 go-to lunches, and 4-5 dinner templates. Boring? Maybe. But boring builds bodies. Save your culinary creativity for the weekends if that’s your thing.

Meal prep isn’t about being a hero. It’s about staying disciplined and staying in the fight.

The win is showing up to train with fuel already in the tank. The win is making your life easier, one container at a time. Prep is something to be proud of and it’s a version of self-respect you can see every day.

Pick your style and start prepping, your future self will thank you.

Security Without the Skepticism: Password Managers – Modern-Day Trust Issues in a Zero-Trust World


Trusting the One Tool Rule Them All

Cybersecurity presents a paradox: we are taught to be wary of everyone online, yet we’re expected to trust one application with all our passwords.

That’s a BIG ask.

Password managers claim to offer both convenience and security. They eliminate the need for sticky notes, memory tricks, and risky repeated logins. Yet, handing over the credentials to your digital life may feel risky, as if you’re leaving your house key under someone else’s doormat.

Even people who are good with technology feel this hesitation. Trusting one place with everything can seem like putting all your eggs in one basket.

How Password Managers Actually Work

At their best, password managers create a secure vault for your passwords. This vault is protected by a master password that only you know.

They use zero-knowledge encryption, so even the company that stores your vault cannot see your data.

That’s how it’s supposed to work. In reality, people hesitate because of things like:

  • High-profile breaches (e.g., LastPass, 2022)
  • Syncing fears (“What if my vault gets intercepted?”)
  • Human error (“What if I forget my master password?”)

Even though the underlying technology is strong, public trust wavers each time a major breach is reported. People remember negative headlines more than encryption details.

Control vs. Convenience

Using a password manager isn’t just a technical choice; it’s also a psychological one.

Humans like to be in control, especially when it comes to security. We equate manual effort with safety. Typing passwords ourselves feels safer than letting software do it, even when we know the software is objectively smarter than we are.

However, for many, convenience ultimately prevails: after trying a password manager, the newfound ease often surpasses early distrust.

This dynamic shows that modern security requires balance: people want independence, but security improves with some delegation to trusted tools.

When Trust Breaks Down

No password manager is immune to risk, but relying on weaker alternatives such as reused passwords or predictable patterns leaves you even more vulnerable. Minimizing trust is about minimizing risk, not eliminating it.

If a vault provider is breached, attackers still face encryption. But if you reuse one password across five sites, there’s no barrier at all.

So, it’s less about trusting the tool absolutely, and more about managing where that trust sits:

  • Choose providers with open security audits.
  • Enable MFA on your vault.
  • Keep the master password offline, not saved, not synced.

The core issue isn’t the tool itself, but the risk of blind faith. Sometimes, people subconsciously seek blind faith from such tools.

Zero-Trust Starts with You

Zero-trust isn’t just a corporate buzzword; it’s a mindset. Assume every system can fail. Build layers so failures aren’t fatal.

For password managers, apply zero-trust this way:

  • Separate critical credentials (server logins, service accounts, etc.) from general logins.
  • Regularly export and back up encrypted copies to an offline location.
  • Keep MFA active everywhere.

Aim for persistence and resilience, not perfection.

Culture Over Blame

We often criticize people for using sticky notes, but we don’t always show them better ways.

Security maturity grows when using a password manager feels normal, not nerdy. Encourage colleagues and family to use them and to question them. Healthy skepticism keeps systems honest.

A culture of curiosity always beats compliance.

Final Thought

Zero-trust is about choosing where to place your trust, not avoiding it altogether. Good judgment is at the heart of modern security.

Password managers aren’t a magic fix. They’re just one important layer of security, and they work well if you stay alert.

In the end, good security comes from making careful, informed choices about trust, not just believing in technology without question.

That’s not being skeptical, that’s working to overcome modern-day trust issues in a zero-trust world.

The Art of Cyberwar | Part VI | Weak Points and Strong

matt shannon art of cyberware chapter VI weak points an strong

The principle:
“So in war, the way is to avoid what is strong and to strike at what is weak.”

Strength and Weakness Are Temporary

Sun Tzu emphasized that strength and weakness are dynamic rather than static. Although this principle may seem self-evident, it is often overlooked in practice. Many individuals disregard straightforward strategies, mistakenly believing that complexity is required. This oversight often leads to the violation of previous strategic principles or “lessons learned”, indicating a lack of genuine understanding.

It is essential to recognize that what appears robust today may become fragile in the future, while seemingly vulnerable elements can become decisive with time and increased awareness.

Power, whether military or digital, shifts with context.

The critical factor is not the quantity of resources, but the ability to perceive the entire operational landscape. Vulnerabilities arise not only from an adversary’s strengths, but also from areas where situational awareness is lacking and the speed at which adaptation occurs when new realities emerge.

In contemporary contexts, both nations and security architects often neglect this fundamental principle. There is a tendency to focus on constructing increasingly formidable defenses rather than developing adaptive strategies. Regardless of the scale of these defenses, adversaries require only minor vulnerabilities to compromise their effectiveness. Always remember, your adversaries only need to find a tiny leak in the walls to bring the entire system down.

Predictability: The Modern Weakness

Even the most secure fortresses eventually become familiar terrain for attackers. Cyber adversaries do not rely on brute force; instead, they employ strategic analysis. They examine organizational habits and exploit vulnerabilities such as unpatched servers, unmanaged privileged or service accounts, unchanged passwords, and the susceptibility of executives to social engineering.

Their success depends not on force, but on the predictability of organizational behaviors.

Nations exhibit similar vulnerabilities. Bureaucratic routines solidify into doctrine, which can devolve into dogma. Adversaries exploit these predictable patterns, waiting for repetition before executing successful attacks.

Historical events, such as the Pearl Harbor attack, the September 11 attacks, the Gulf of Tonkin incident, and numerous cyber intrusions, demonstrate that deficiencies in critical thinking, complacency, rigidity, and hubris significantly increase the likelihood of successful surprise attacks.

When Comfort Masquerades as Strength

Many organizations and governments allocate excessive resources to familiar areas, fostering a false sense of security. This environment allows risks to proliferate unnoticed, undermining overall resilience.

Cybersecurity teams often spend millions fortifying infrastructure while leaving users untrained.

Organizations frequently monitor technical metrics while neglecting human behavior. The most significant vulnerabilities often arise from areas presumed to be under adequate management.

System failures are typically attributable not to insufficient funding, but to misaligned priorities.

This pattern is evident at the national level as well. Large militaries and substantial budgets often obscure underlying fragilities, including slow adaptation, reliance on outdated assumptions, unstable alliances, and insufficient strategic foresight regarding emerging forms of conflict.

Historical Lessons of Misguided Strength

The First World War began with nations convinced that industrial might and rigid plans guaranteed victory. Those plans dissolved within months under the weight of modern weapons and static thinking.

During the Vietnam War, a major power misinterpreted its capacity for endurance as a guarantee of superiority. The Viet Cong’s guerrilla tactics transformed conventional advantages into significant liabilities.

Even the rapid success of Operation Desert Storm fostered complacency. Efficiency was mistaken for enduring security, and the perceived triumph was erroneously interpreted as evidence of invincibility.

Each era reaffirms the principle that the most conspicuous assets are not necessarily the most powerful.

Flexibility as True Power

Sun Tzu’s insight was to conceptualize power as dynamic movement. He advocated that a general should emulate water, seeking the path of least resistance and adapting to the terrain.

Within the cyber domain, the operational landscape evolves rapidly, with new threats, actors, and vulnerabilities emerging on a continual basis.

In this context, strength is defined by agility:

  • Rotate keys and credentials regularly.
  • Automate but verify.
  • Decentralize authority so teams can act without waiting for hierarchy.

The most effective defenders are those who demonstrate the greatest adaptability, learning and evolving more rapidly than adversaries can adjust their tactics.


Lao Tzu’s Echo

Lao Tzu put it simply:

“Water overcomes the stone not by strength, but by persistence.”

Endurance surpasses dominance. Properly understood, flexibility is not a sign of weakness but of resilience, characterized by the capacity to absorb disruption and recover to an original state.

In the digital context, resilience is reflected in recovery planning, redundancy, and organizational culture. The true measure of strength is not the infrequency of failure, but the speed of recovery following a compromise.


Turning Weakness Into Insight

All systems possess inherent flaws. Denial of these vulnerabilities allows them to remain concealed until a crisis occurs. Proactive defenders employ audits, red-team exercises, and transparent communication to identify weaknesses at an early stage.

Transparency transforms potential liabilities into opportunities for organizational learning.

Nations could use the same humility.

Public acknowledgment of mistakes enhances credibility, whereas concealment increases risk. The most resilient governments are not those without flaws, but those capable of adapting transparently before their constituents.

From Awareness to Action

Identifying vulnerabilities constitutes only part of the challenge; addressing them effectively demands both discipline and restraint.

In cybersecurity, this approach entails prioritizing remediation over self-congratulation, thorough preparation prior to disclosure, and critical evaluation before taking action.

In policy contexts, this requires deliberate prioritization, engaging only in actions where the anticipated outcomes justify the associated costs.
Misapplied strength can become a source of vulnerability, whereas a thorough understanding of weaknesses can provide strategic foresight.

The Next Step: The Flow of Force

Sun Tzu ends this chapter with motion: the strong shifting to the weak, the weak transforming to the strong.

He implies that awareness must evolve into timing. The wise general aligns his force with the moment, not against it. And that, “All men can see the tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved.”

This concept serves as a transition to the subsequent lesson, which focuses on the dynamics of energy in motion and the strategic management of power with balance and rhythm.

We’ve learned where to stand. Next, we’ll learn how to move. As Master Tzu concludes Chapter VI:

Military tactics are like unto water; for water in its natural course runs away from high places and hastens downwards. Water shapes its course according to the nature of the ground over which it flows; the soldier works out his victory in relation to the foe whom he is facing. Therefore, just as water retains no constant shape, so in warfare there are no constant conditions.

Leading us directly back to this lesson’s seemingly simple principle: “So in war, the way is to avoid what is strong and to strike at what is weak.”