A closer look at a cartoon drawn for one chapter — and why the job it describes doesn’t get easier as the program matures.

I had a cartoon drawn a while back: a security leader standing at the center of a room, with every stakeholder pulling from a different direction. It was meant as a small illustration for one chapter. It ended up being one of the most accurate summaries of the job I’ve produced.

Look at what’s being asked

Look at what’s actually being asked of the person in the middle. Secure. Compliant. Fast. Cloud-native. Privacy-respecting. AI-ready. Due Tuesday.

The board wants a clear view of cyber risk. The regulator wants evidence, on a stopwatch. The auditor wants assurance. Engineering wants speed. The CEO wants confidence. Finance is standing over the budget with a pair of scissors. And now AI has joined the meeting too, with its own list of demands nobody fully agreed to yet.

None of these people are wrong to want what they want. That’s what makes the job hard — every request is legitimate, and almost none of them are compatible with each other on the timeline everyone has in mind.

Not panic. Sequencing.

The instinct to picture in that moment isn’t panic. It’s sequencing. Which of these demands actually has a hard deadline this week versus one that only feels urgent because it was asked out loud most recently. Which stakeholder needs a real answer versus a credible plan and a date. Which risk, if left alone another quarter, quietly becomes the incident that makes every other conversation irrelevant.

That’s the actual skill underneath “security leadership” — not knowing every control in every framework, though that matters too, but being the one person in the room who can hold six competing, valid demands at once and decide, calmly, what gets attention today.

Why this doesn’t get easier

It’s tempting to think this gets easier as a program matures — more headcount, more tooling, more maturity, fewer fires. Some of that is true. But the number of legitimate stakeholders pulling on a security leader has only grown over the last decade, not shrunk. Regulators multiplied. Customers started asking their own security questions directly. AI arrived with its own governance demands stacked on top of everything that was already there.

The job was never going to get quieter. The skill worth building is deciding well when everyone in the room wants something different — preferably by Tuesday.


Vikas Khandelwal is the Founder & Principal Consultant at Secalyx Technologies and author of the upcoming From Risk to Trust series for CISOs and cybersecurity leaders.

Leave a Reply

Your email address will not be published. Required fields are marked *