Readout 004: The 90th Day

Why the other 89 days may determine what happens when security becomes the priority.


I tell my team something that might sound strange coming from a security leader: “Eighty-nine days out of ninety, security is not the most important thing happening in the business.”

That doesn’t mean the risks aren’t real, they are. On any given day, security teams may be thinking about workplace violence, theft, fraud, supply chain disruption, travel risk, intellectual property, crisis management or any number of threats that could have a significant impact on an organization. The rest of the business has a business to run.

Operations has product to move, sales has customers to serve, HR has a workforce to support, etc., etc…. Everyone is balancing competing demands for time, attention and resources.

A security leader who doesn’t understand that can spend a career frustrated that everyone else doesn’t see the world the way we do.

Here’s the thing: They shouldn't have to.

I have always said that we are “business leaders first, with an expertise in security.” Part of being a business leader is understanding where your function fits within the larger organization and it means recognizing that something can be incredibly important without needing to be the company's most important issue every day.

Then the 90th day comes.

When the Background Becomes the Foreground

The 90th day isn't necessarily a literal day, of course. It might be a significant theft, a workplace threat, a serious security incident, or a crisis that disrupts operations….take your pick. Sometimes nothing catastrophic happens at all, but a close call gets close enough that people suddenly begin asking different questions.

Whatever triggers it, the dynamic changes. The security team that spent the previous 89 days competing for attention suddenly has everyone’s eyes on them.

People who didn't have time for the conversation last week are asking for a meeting today and recommendations that were put aside are being considered. Leaders want to know what happened, why it happened, whether it could happen again and what can be done differently.

Security has moved from the background to the foreground and what the security leader does next matters.

Day 90 Is Not the Time to Say “I Told You So”

There can be a temptation after an incident to point backward. “We recommended this. We identified that vulnerability, and we asked for that investment. We warned all of you that this could and would happen.” Perhaps all of that is true. It also doesn’t move the organization forward.

When security suddenly has the attention of the business, there is a limited window in which meaningful change may be possible. The question isn’t whether we were right before the incident, rather it’s: “What can we do with this moment now?”

You close the gap and revisit the protection that wasn’t supported before. You bring the right people to the table, and use the incident to educate rather than assign blame. Most importantly, you make changes that will still matter when the urgency has passed.

The organization will recover. The next customer issue, deadline, or business priority will arrive, and security will no longer be the most important thing happening that day. That’s not failure. That’s business.

The Other 89 Days Matter More Than We Think

This is where I think the role of the security executive is sometimes misunderstood.

The other 89 days aren't simply the time between incidents; They're when you earn the ability to lead on Day 90.

They're when you learn the business and understand what matters to departments and the people within them actually doing the work. They're when you build relationships and establish credibility, not by making every risk sound like a crisis, but by demonstrating that you understand the difference between what is possible and what is probable.

They're also when you learn how to make the case for security in business terms.

I tell my team that we are business leaders first, with an expertise in security and that distinction matters. Our job isn't simply to identify vulnerabilities and recommend the strongest possible security solution. It's to understand the organization well enough to recommend the right solution, one that considers the risk, the operation and the realities of the business.

Sometimes that means a recommendation isn't approved or another line of business wins priority. A mature security leader has to be able to accept that without disengaging from the conversation, because the relationship you build after hearing “not now” may determine whether leadership listens when the answer needs to be “right now.”

Day 91 is Coming

Eventually, every organization has a Day 90. It may be an incident, a significant loss or a close call that exposes a vulnerability and suddenly, the theoretical becomes real. The conversations change and questions get asked. Resources suddenly become available and security has the attention of people who, quite reasonably, were focused on something else yesterday. That attention creates an opportunity, but it also creates a responsibility.

Day 90 isn't the time to prove you were right, it's the time to make the organization better.

Close the gaps you can close, and educate without assigning blame. Bring the right people into the conversation and revisit recommendations with the benefit of new information. Make improvements that will continue protecting the organization long after the urgency of the incident has faded. Day 91 is coming and when it does, the business will begin moving forward again….which is exactly what should happen.

The security leader's job isn't to keep the organization living on Day 90. It's to make sure the organization enters its next 89 days stronger than it was before.

Next
Next

Readout 003: You Can Outsource the Workforce, Not the Risk.