Archistry

Survivability by Design™ since 2006

  • Home
  • About
    • Who Is Andrew?
    • C2T System™
    • The Agile Security System™
  • Contact
You are here: Home / Archistry Daily / Remember who built the spacecraft that put men on the moon?

February 21, 2020

Remember who built the spacecraft that put men on the moon?

Nope? Well, neither do I, actually. But we all remember that in 1969 the United States put the first men on the moon. The name of the company was actually two different ones: the command module was built by North American Aviation of P-51, B-25 and F-86 fame, and the lunar module was built by Grumman Aircraft, probably most famous for the F-14 Tomcat thanks to Tom Cruise and the movie Top Gun.

But nobody remembers that little detail. They remember the result.

Which brings me back to a little something called value, and the role it plays every day in the work we do as security architects.

If we don’t deliver value, very little matters. And if we DO deliver value, how we do it also rarely matters that much, as long as it works, seems reasonable and somebody doesn’t decide it either takes too long or costs too much.

The problem we have is that as humans, we’re basically selfish creatures, and we look out for No. 1 before we think about anyone or anything else.

This isn’t bad. It’s called survival.

And anyone who listens to bleeding-heart people who think being selfish is all bad needs to go back to the drawing board and think about how much good they’ll really be able to do if they aren’t able to meet their own needs before they go out and try and help anyone else.

Short version: you can’t.

That’s the main reason for the “Put on your own oxygen mask before you help anyone else with theirs” line in the safety briefings you probably ignore (like I do, since I fly so much) when you get on an airplane.

What we tend to forget is that if we have a job to do, then what matters most is the value it creates to those we’re trying to do it for.

Why?

Because they’re going to be looking out for No. 1 from their perspective just like we do from ours.

And it’s the single biggest reason why nobody cares whether we build security architecture using SABSA, TOGAF, little green men from Mars, the NIST CSF or anything else—as long as they can deliver their projects.

Truth be known – as I said recently in a whole email – they don’t actually care about security architecture at all. Nor, actually, should they.

That’s our job. But the mechanics of how we do it – the mechanism – doesn’t matter. The only thing that matters is the value that architecture delivers to someone else in terms of faster, better, cheaper solutions.

So they don’t care about SABSA, so we shouldn’t be trying to sell it to them. But that’s what we often try to do – whether it’s SABSA or something else – and it almost always falls flat.

It’s a little thing in the marketing world summarized by the late Elmer Wheeler, dubbed “The World’s Greatest Salesman” in the phrase you may have heard before:

“Sell the sizzle, not the steak.”

And that was back in 1937…

…but the advice is just as true today – and in security – as it is in marketing (just one more reason I say you’re not in the security business as an architect, you’re in sales and marketing).

The question then comes down to what “sizzle” do you sell from a security perspective—and especially as far as security architecture.

Well, the answer comes back to value—that thing people will remember that is the primary driver of your credibility and trust within the organization.

Which is why Lessons 4, 6, 8 and 9 of Module 2 of Building Effective Security Architectures talk to you about how to identify the right value for the right people…

…and the entirety of Module 1 is set up to give you the mechanics and the skills you need to do it repeatably, reliably…

…and as fast as possible.

Because if you can’t demonstrate value – and do it quickly – it doesn’t matter if you have the best methodology, framework or control library in the world.

Nobody cares.

They only care that it’s your fault their project is late and over budget.

If you want to be able to kick this particular problem to the curb – forever – then you can learn exactly what you need to do as a member of the February 24th cohort of the program. But time is running out, because now you only have 5 days left before the registration closes and I start teaching those on the inside the real critical skills a successful security architect needs.

Will you be joining us?

Stay safe,

ast
—
Andrew S. Townley
Archistry Chief Executive

Article by Andrew Townley / Archistry Daily / "Selling" Security, Agile Security, BESA, Credibility, NIST CSF, SABSA, Security Architecture, TOGAF, Trust

  • Email
  • LinkedIn
  • Twitter
  • YouTube

EMAIL NEWSLETTER

Want to get DAILY email tips on how to build a more effective security program so you can prove your security investments deliver value to the business?

You can always unsubscribe at any time, and we won't sell your data to third parties.

About Us

Archistry works with you to ensure what you want to achieve actually gets done, linking strategy, risk, governance and compliance to enable sustained exceptional performance Read More…

Testimonials

Andrew is a highly skilled and experienced information systems architect and consultant, which in my view is a rare thing. He is innovative in his thinking and merits the title of 'thought leader' in his specialist domains of knowledge—in particular the management of risk. Andrew has embraced SABSA as a framework and, in doing so, has been a significant contributor to extending the SABSA body of knowledge."

— John Sherwood, Chief SABSA Architect

"Fabulous person to work with. Very engaging and insightful. Extremely good technical knowledge with ability to relate concepts together and overcome differing opinions. Makes things work."

— Kevin Howe-Patterson, Chief Architect, Nortel - Wireless Data Services

"Andrew was able to bring clarity and great depth of knowledge to the table. His breadth of thinking and understanding of the business and technical issues along with a clear and effective communication style were of great benefit in moving the process forward towards a successful conclusion."

— Doug Reynolds, Product Manager, MobileAware

"Andrew is a fabulous consultant and presenter that you simply enjoy listening to, as he manages to develop highly sophisticated subjects in very understandable way. His experience is actually surprising and his thoughts leave you without considerable arguments for any doubts in the subjects he covers."

— Biljana Cerin, Director, Information Security and Compliance

Recent Posts

  • If you want better security, you’d better have a better security architecture
  • The ultimate security song to keep you focused on what you’re doing
  • Security heroes
  • There’s always a people problem
  • Putting your data flow diagrams out to pasture…for good

Looking for something else?

  • Home
  • About
  • Contact

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Copyright © 2006-2025 Archistry Incorporated or its affiliates

"Archistry", the stained glass window logo, "Pragmantix" and the Pragmantix™ logo, "Archistry Execution Framework (AEF)", "Archistry Execution Framework, Cybersecurity Edition (ACS)", "The Agile Security System", "The Agile Business System", "Baseline Perspectives", "Architecture Wall", "Archistry Execution Engine", "Renegade Security", "Renegade Security System", "Security Value Delivery System (SVDS)" "Collapse-to-Traction", "Collapse-to-Traction System", "Adaptive Trust & Governance Model (ATGM)", and "Adaptive Trust & Governance Model for Organizations (ATGM4O)" are trademarks of Archistry Incorporated or its affiliates.