Archistry

Survivability by Design™ since 2006

  • Home
  • About
    • Who Is Andrew?
    • C2T System™
    • The Agile Security System™
  • Contact
You are here: Home / Archistry Daily / How to make your own security luck

March 18, 2019

How to make your own security luck

In response to a previous email, a reader raised the challenges of actually practicing proper security architecture in organizations where the title says “Enterprise Security Architect” and yet they expect you to “roll up your sleeves” and do everything from incident RCA to security strategy to organizing the company piss up.

And he’s right: it is a challenge.

It is possible, however.

You just need to understand what it takes.

Imagine you’re at a security conference (or any other place where security architects might be found), and eventually, you’ll see a huddle of people standing around lamenting about the state of security where they work.

They all have a story about how everyone – from the CEO to the janitor – “just doesn’t get it” and how they’re tired of beating their heads against the wall trying to change that.

And sometimes…but unfortunately not every time…there’s a lone voice that talks about how things work in their company.

They have things like “stakeholder engagement” and “risk appetite”…

And they talk about “business alignment” like it’s a real thing rather than just a pipe-dream invented by some analyst firm so they can milk their customers for money.

After a while, “the rest” eventually decide that lone voice is either delusional or “just lucky”, because, either way, it’s just too far away from their own reality to be possible.

That getting that “lucky” would be like winning the lottery—a one-in-a-million chance.

And for them, they’re probably right. Because they don’t understand what “luck” really is.

But you, dear reader, aren’t like them at all…because I’m going to let you in on a little secret.

And that secret is: luck is like leprechauns—it doesn’t exist.

At least, not in the way most people think.

Remember back to a few days ago when I talked about the Law of the 7 P’s. The one that says: Proper Previous Planning Prevents Piss Poor Performance.

Yeah. That one.

“Luck” is simply a word people who fail to plan use when they watch someone who lives by the Law of the 7 P’s act to take advantage of an opportunity they see right in front of their nose (And, mind you, I’m talking about this in a good way, not an exploitative and manipulative bastard kind of way).

It’s “luck” because to them, they just don’t see how that situation could’ve been anticipated. And that makes sense, because they’re just not playing the same game we need to play.

So what does “security luck” look like and how do we make our own?

Well, the first thing we have to do is understand what we’re really trying to do in our job.

Our job – as an architect, an engineer, and ESPECIALLY as a security leader – is to enable the business to operate safely, effectively and with as little disruption as possible.

Back to what we said yesterday, that means we have to understand what it is we’re trying to support, what kinds of wolves might be living in the woods and exactly what Little Red Riding Hood might need to do to make sure she gets to Grandma’s house before she’s short a relative.

And if we understand that, we’ll be able to say the right things, make the right connections and share the right insights so that we build our credibility and earn the trust of our business colleagues and the executive leadership team.

And when we have that credibility, we can make sure we’re doing the right things, at the right time and in the right way so we can both think strategically and act tactically in ways that guarantee we’re building an effective security program.

Some might call it “luck.”

But we know it’s more than that. It’s Proper Previous Planning in action.

So when you find yourself a bit down on your “luck” and you want some help getting your mojo back:

  1. Go to this URL: https://archistry.com/go/LuckFactory
  2. Scroll to the bottom
  3. And click the big, yellow button.

I’ll be waiting for you with your little green hat, your little green vest and your lifetime leprechaun membership card.

ast
—
Andrew S. Townley
Archistry Chief Executive

P.S. Don’t wait too long. We’re getting closer and closer to the deadline when this round of the program will close, and I wouldn’t want you to miss it.

Article by Andrew Townley / Archistry Daily / Business Alignment, Law of the 7 P's, Luck, Security Architecture

  • Email
  • LinkedIn
  • Twitter
  • YouTube

EMAIL NEWSLETTER

Want to get DAILY email tips on how to build a more effective security program so you can prove your security investments deliver value to the business?

You can always unsubscribe at any time, and we won't sell your data to third parties.

About Us

Archistry works with you to ensure what you want to achieve actually gets done, linking strategy, risk, governance and compliance to enable sustained exceptional performance Read More…

Testimonials

Andrew is a highly skilled and experienced information systems architect and consultant, which in my view is a rare thing. He is innovative in his thinking and merits the title of 'thought leader' in his specialist domains of knowledge—in particular the management of risk. Andrew has embraced SABSA as a framework and, in doing so, has been a significant contributor to extending the SABSA body of knowledge."

— John Sherwood, Chief SABSA Architect

"Fabulous person to work with. Very engaging and insightful. Extremely good technical knowledge with ability to relate concepts together and overcome differing opinions. Makes things work."

— Kevin Howe-Patterson, Chief Architect, Nortel - Wireless Data Services

"Andrew was able to bring clarity and great depth of knowledge to the table. His breadth of thinking and understanding of the business and technical issues along with a clear and effective communication style were of great benefit in moving the process forward towards a successful conclusion."

— Doug Reynolds, Product Manager, MobileAware

"Andrew is a fabulous consultant and presenter that you simply enjoy listening to, as he manages to develop highly sophisticated subjects in very understandable way. His experience is actually surprising and his thoughts leave you without considerable arguments for any doubts in the subjects he covers."

— Biljana Cerin, Director, Information Security and Compliance

Recent Posts

  • If you want better security, you’d better have a better security architecture
  • The ultimate security song to keep you focused on what you’re doing
  • Security heroes
  • There’s always a people problem
  • Putting your data flow diagrams out to pasture…for good

Looking for something else?

  • Home
  • About
  • Contact

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Copyright © 2006-2025 Archistry Incorporated or its affiliates

"Archistry", the stained glass window logo, "Pragmantix" and the Pragmantix™ logo, "Archistry Execution Framework (AEF)", "Archistry Execution Framework, Cybersecurity Edition (ACS)", "The Agile Security System", "The Agile Business System", "Baseline Perspectives", "Architecture Wall", "Archistry Execution Engine", "Renegade Security", "Renegade Security System", "Security Value Delivery System (SVDS)" "Collapse-to-Traction", "Collapse-to-Traction System", "Adaptive Trust & Governance Model (ATGM)", and "Adaptive Trust & Governance Model for Organizations (ATGM4O)" are trademarks of Archistry Incorporated or its affiliates.