Security leaders are often trapped in endless assessments and opinion-giving without driving actual change. Staying busy with spreadsheets, dashboards, and emails doesn't move the organization forward.

Here's how we can break out of the "Chief Opinion Officer" mode: https://zeltser.com/chief-opinion-officer-to-action-taker

#CISO #cybersecurity #leadership #infosec

From Chief Opinion Officer to Action-Taker

Security leaders who only assess risks and express concerns operate as Chief Opinion Officers rather than change agents. Delivering outcomes requires agreeing with colleagues on what's real, deciding where to focus, and taking action without striving for perfection.

Lenny Zeltser

@lennyzeltser Great article! The last point on "progress, not perfection" really hit home as I've seen things die on that vine too many times.

FYI - I think there's an unintentional formatting issue when you bring up the vuln mgmt hamster wheel, it looks like there's supposed to be a link there.

@dylanam Thanks for letting me know about that formatting issue. I think I fixed it now.
@lennyzeltser No worries, looks fixed on my end!