Discussion about this post

User's avatar
Dan Tinsley's avatar

Proper piece this John. The Red Queen framing is spot on and the risk management vs risk reduction distinction is something ive been thinking but didnt have yourclean language for it. So cheers for that I’m nicking it.

Where I’d push back slightly is the assumption that better governance frameworks solve this. The bottleneck is that most CISOs don’t have the organisational authority or the air cover to say “we need to rip this out and it’s going to hurt for six months.” Easier to keep the dashboard green and not cause a fuss. Everyone keeps their job. Nobody asks awkward questions until the post mortem.

Too many orgs especially in that Series A to C growth phase, are spending well and still losing ground. They need someone who’ll walk in and say “half of this is treadmill, let’s talk about the half that actually moves you forward.” Your piece gives that conversation a framework. Looking forward to the next one.

No posts

Ready for more?