First Principles of Cybersecurity: Essays on Leadership, Trust, and Organizational Maturity – Part II

First Principles of Cybersecurity Essays on Leadership, Trust, and Organizational Maturity -- MattShannonSecurityPro.com

Leadership Is a Security Control

The Environment Leaders Create Determines the Level of Security Their Organizations Achieve

Ask ten security professionals to name the most important security controls in a modern organization, and the answers will sound familiar. Multi-factor authentication. Endpoint detection and response. Network segmentation. Encryption. Vulnerability management. Security awareness training.

None of those answers is wrong. Each represents a critical layer in a mature security program.

Yet they all share a common characteristic: they are downstream of another control that receives far less attention but influences every one of them..

Leadership.

This may seem like an unusual assertion. Leadership does not appear on a network diagram. It cannot be licensed, deployed, or patched. It generates no alerts and produces no dashboard filled with metrics. Yet every meaningful security decision within an organization is ultimately shaped by leadership. Before a firewall is purchased, before a policy is written, before an employee completes awareness training, someone has already decided that security matters—or that it does not.

That decision is leadership in action.

Every Organization Is Perfectly Designed to Produce Its Security Culture

There is a saying often attributed to systems theorist W. Edwards Deming: “Every system is perfectly designed to get the results it gets.” Whether or not those were his exact words, the principle remains instructive.

Security culture is no exception.

Organizations rarely arrive at their security posture by accident. Rather, it emerges from thousands of decisions made over time. These are decisions about priorities, incentives, resources, accountability, and acceptable risk. Employees learn what truly matters not by reading policies, but by observing leadership.

If executives insist on secure practices even when they create inconvenience, employees notice.

If managers routinely ask teams to “just make it work” regardless of established procedures, employees notice that, too. Culture is not built through declarations. It is built through repetition.

Leadership determines what is repeated.

According to the 2024 Verizon Data Breach Investigations Report, over 80% of breaches involved a human element, highlighting that culture, behavior, and leadership are as critical as any technical control.

The Strongest Policies Cannot Overcome Weak Priorities.

Many organizations invest considerable effort in writing comprehensive security policies. These documents establish expectations, define responsibilities, and provide consistency across the enterprise. They are necessary.

They are also insufficient. A policy reflects what an organization says it values. Leadership reveals what it actually values.

Consider two organizations with identical password policies.

In the first, executives follow the same authentication requirements as everyone else, allocate time for security training, and treat security concerns as legitimate business discussions. In the second, executives routinely request exceptions, postpone security projects in favor of short-term operational gains, and regard cybersecurity as primarily the IT department’s responsibility.

On paper, the organizations appear identical. In practice, they are fundamentally different.

Policies establish direction and leadership establish credibility.

Employees are remarkably adept at distinguishing between the two.

Leadership Defines Acceptable Risk

One of the most misunderstood aspects of cybersecurity is the belief that the objective is to eliminate risk. It’s not. Every organization accepts risk. The question is whether those decisions are deliberate or accidental.

Leadership determines where that line is drawn. When a board approves funding for identity modernization rather than postponing the investment for another year, it is making a security decision.

When a superintendent supports temporary operational disruption to remediate a critical vulnerability rather than accepting unnecessary exposure, that is a security decision.

When an executive asks not only, “What will this cost?” but also, “What risk does this reduce?” security has become part of organizational decision-making rather than an afterthought.

Security professionals identify and communicate risk. Leadership determines which risks are acceptable.

These responsibilities are distinct, but inseparable.

Trust Is a Preventive Control

Technical controls prevent malicious activity, and leadership often prevents organizational failure.

Employees who trust their leaders report mistakes sooner. They ask questions before making assumptions. They admit uncertainty before uncertainty becomes an incident.

Conversely, organizations that punish honest mistakes often create an environment where employees hide them. The initial phishing email is rarely what causes the greatest damage.

Silence does.

Trust is therefore more than an abstract leadership quality. It is a practical security control that shortens response times, improves communication, and encourages the reporting behaviors upon which effective incident response depends.

Organizations frequently invest millions of dollars in detection technologies while overlooking one of the simplest ways to improve detection: creating an environment where people feel safe speaking up.

Technology Scales Capability. Leadership Scales Behavior.

Technology can authenticate identities, encrypt data, detect anomalies, and automate countless security functions. It can’t establish priorities, create accountability, model integrity, or build trust. Only leadership can accomplish those things.

This is why organizations with modest security budgets, but disciplined leadership often outperform organizations possessing sophisticated technologies but inconsistent governance. The difference is not the tools themselves. It is the environment in which those tools operate.

Technology amplifies capability and leadership amplifies behavior. Given enough time, behavior almost always proves to be the more influential force.

Actionable Steps for Leaders

  • Model security behaviors consistently at every level of the organization.
  • Integrate risk discussions into executive decision-making, not just technical reviews.
  • Foster a culture of psychological safety so employees feel comfortable reporting mistakes and asking questions.
  • Align security policies with actual business practices—avoid policies that are routinely bypassed.
  • Invest in both technology and leadership development to scale capability and culture in tandem.

Final Thoughts: Leadership as the First Control

It is tempting to think of cybersecurity as something managed by the security department. Firewalls belong to network engineers. Endpoint protection belongs to security analysts. Policies belong to governance teams.

Leadership belongs in every decision.

Every decision about priorities, every allocation of resources, every conversation about acceptable risk, and every example set by those entrusted to lead either strengthens or weakens the organization’s security posture.

For that reason, leadership should not be viewed merely as support for cybersecurity.

It should be recognized for what it is.

The first security control.

Key Takeaways:

  • The downstream effects of leadership shape every aspect of an organization’s security posture.
  • While policies and technology matter, leadership determines how they are valued, implemented, and, more importantly, enforced.
  • Trust and culture are practical security controls that improve incident response and reduce risk.
  • Consistent, visible prioritization of security by leaders is more influential than any single technical investment.
  • Security is ultimately a human endeavor, and its success is determined by the actions and environment set by those who lead.
  • This perspective is echoed by leading frameworks, NIST CSF and ISO 27001, which position governance and leadership at the foundation of resilient security programs.

The technologies organizations deploy may change. The threats they face certainly will. But the principle remains constant: every security program ultimately reflects the leadership that built it.

Leadership, then, is not merely support for security; it’s the foundation.

First Principles of Cybersecurity: Essays on Leadership, Trust, and Organizational Maturity – Part I

The Hidden Cost of Convenience in Cybersecurity

Why Intelligent People Circumvent Security,
and What Mature Organizations Do About It

Walk into almost any classroom in the country at the beginning of a new school year, and you’ll witness controlled chaos.

Teachers are preparing lesson plans, organizing classrooms, responding to parents, configuring technology, attending meetings, and welcoming a new group of students, all before the first bell ever rings. The pace is relentless, and every minute matters.

Now imagine walking past a cart of student Chromebooks and noticing something unexpected.

A small adhesive label with a student’s name, username, and password affixed directly to the device.

At first glance, it’s easy to criticize the practice. After all, writing credentials on the very device they’re intended to protect undermines one of the most fundamental principles of information security.

But if that’s where the conversation ends, we’ve learned very little. The more interesting question isn’t why someone ignored security.

The better question is: Why did this feel like the best solution in the first place?

That distinction matters because mature cybersecurity is not built by identifying mistakes. It is built through understanding the conditions that make those mistakes seem reasonable.

Intelligent People Rarely Choose Insecurity

One of the most persistent misconceptions in cybersecurity is the belief that policy violations emanate primarily from ignorance, carelessness, or indifference.

In reality, most people are trying to do exactly what they’ve been hired to do. Teachers are trying to teach. Nurses are trying to care for patients. Engineers are trying to deliver systems. Executives are trying to lead organizations. Their objective is not to violate policy.

Their objective is to accomplish meaningful work. When security introduces unnecessary friction into that work, people naturally begin searching for ways to reduce it. Not because they oppose security. Because they are optimizing for progress. The sticky note wasn’t malicious. It was an optimization.

Unfortunately, it optimized the wrong variable.

The Path of Least Resistance

Human beings are remarkably consistent. When presented with multiple ways to accomplish the same objective, we tend to choose the one that requires the least effort. Behavioral psychologists have studied this phenomenon for decades. Economists describe it through concepts like bounded rationality and mental effort. Engineers simply recognize it as good design.

Cybersecurity often forgets it entirely.

Organizations frequently assume that if policies are written clearly enough, people will simply follow them. Experience suggests otherwise. People generally follow the path that requires the fewest decisions, the least interruption, and the least additional effort. That’s not laziness, it’s human nature.

Every unnecessary step added to a security process becomes another opportunity for someone to find a shortcut. And shortcuts have a way of becoming habits.

The Difference Between Immature and Mature Security Programs

Immature organizations respond to incidents by writing another policy. Mature organizations ask a different question.

Why did this make sense to someone?

That question shifts the conversation from blame to design. Consider the classroom example.

Should passwords remain private? Absolutely.

Should credentials ever be attached directly to a device? Of course not. But stopping there ignores the larger lesson. Why did an experienced educator, someone strongly dedicated to their students, conclude that this was the most practical solution?

Perhaps student onboarding was cumbersome. Perhaps the process required frequent password retrieval.

Perhaps the system created more friction than necessary during one of the busiest weeks of the year. Those possibilities deserve just as much attention as the policy itself. Because good security doesn’t merely tell people what not to do. It makes the secure choice the wise choice.

Security Culture Is a Design Problem

Culture is often described as shared values or shared beliefs. In cybersecurity, culture is better measured using shared behaviors. Those behaviors are influenced less by slogans than by systems.

When secure behavior is intuitive, people adopt it naturally. When secure behavior consistently slows people down, even well-intentioned professionals begin inventing workarounds.

The problem isn’t that people prefer convenience. The problem is when convenience and security are placed in opposition to one another. Strong organizations refuse to accept that tradeoff.

Instead, they ask: “How can we design systems where the secure path is also the easiest path?”

That question signifies a profound shift in thinking. Rather than expecting people to overcome human nature, mature organizations design with human nature in mind.

Leadership Beyond Technology: Setting Security Culture by Example

This principle extends far beyond passwords. In practice, organizations sometimes hard-code credentials because rotating them seems cumbersome. Employees reuse passwords because managing dozens of unique ones is impractical without support. Executives may bypass established processes they perceive as slow, sometimes even advocating for policies they themselves neglect. These behaviors highlight how security actions, good or bad, are shaped by leadership priorities and organizational culture.

Frameworks like Zero Trust (ZT) and NIST’s Cybersecurity Framework (CSF) both emphasize the importance of aligning policies and controls with real-world workflows. For example, Zero Trust encourages the principle of ‘never trust, always verify’, but it also emphasizes minimizing user friction by making secure access seamless. Similarly, NIST CSF calls for continuous improvement and adaptation to actual business context, including user experience, as a critical part of protecting information.

A 2024 Verizon Data Breach Investigations Report found that over 80% of breaches involved a human element, whether through error, misuse, or social engineering. This underscores the need to design security with people, not just technology, in mind.

Consider the widely publicized 2023 MGM Resorts breach: attackers gained access not through a technical exploit, but by manipulating an employee via social engineering. The aftermath highlighted both the human cost of poor security design and the value of resilient, well-communicated processes. Mature organizations study such incidents to inform better system and workflow design, not just to enforce stricter rules.

None of these behaviors are unique to education. They are remarkably consistent across industries. Whether it’s healthcare, finance, manufacturing, government, or cloud engineering, it’s the same.

Technology changes, human behavior does not. This is why effective cybersecurity leaders spend as much time understanding organizational behavior, workflow design, and communication as they do learning about technology. Firewalls protect networks, encryption protects data, identity platforms protect access, and leadership shapes behavior.

And behavior, modeled first by leadership, ultimately determines whether those technologies succeed.

Designing for Reality

There is an old saying in engineering: “Don’t design for perfect conditions. Design for the conditions that are the reality.”

Cybersecurity deserves the same mindset. People work under the pressure of deadlines. And many humans are easily distracted.

They make mistakes. They focus on competing responsibilities. Expecting otherwise isn’t leadership. It’s wishful thinking. The strongest security programs acknowledge these realities and build systems that accommodate them.

Not by lowering standards. By lowering unnecessary friction. Good security accounts for human behavior. Great security aligns human behavior with enterprise intent. That is where security culture begins.

Actionable Steps for Leaders:

  • Review critical workflows for unnecessary security friction; streamline processes where possible. Invest in user-friendly identity and access management platforms that support secure, seamless authentication (e.g., password managers, SSO).
  • Regularly communicate the ‘why’ behind security policies and invite feedback from end users.
  • Model secure behaviors at the leadership level; visible adherence by executives sets cultural expectations.
  • Align technology investments with both security best practices (ZT, NIST) and the realities of day-to-day business operations.

Final Thoughts: Designing for Humans

Key Takeaways:

  • Security workarounds are rarely due to ignorance; they’re often rational responses to unnecessary friction.
  • Mature organizations design security systems that align with natural human behaviors and incentives.
  • Leadership sets the tone—when executives model secure, user-friendly practices, security culture flourishes.
  • Frameworks like Zero Trust and NIST CSF emphasize the importance of user experience and continuous improvement.
  • The most resilient organizations prioritize systems that help people succeed, not just avoid failure.

The sticky note attached to the Chromebook was never really about the sticky note. It’s an example that every decision in a security environment reflects a larger system of incentives, constraints, priorities, and, mostly, habits.

More often than not, systems fail because they ask ordinary people to behave in extraordinary ways. Technology rarely fails first. People rarely fail first. The most resilient organizations understand this. They don’t build security around an idealized version of human behavior. They build it around reality.

Because in the end, cybersecurity isn’t simply about protecting systems. It is the discipline of building systems that help people succeed. And perhaps that is the deeper lesson.

Convenience isn’t the enemy of security. Poor design is.

Or, said another way, Strong security cultures are not built by asking people to overcome human nature. They are built by knowing human nature well enough to design systems that coordinate convenience with security.