The “How-First” Trap in Security Programs
Originally posted on LinkedIn

One pattern I keep seeing in security programs:
We start with how to implement something before we clearly define what we should be doing and why it matters.
The conversation quickly shifts to:
• What tool do we need?
• How will our team support it?
Valid questions - but they come too early.
Early in my career, Mohit Chanana consistently challenged our team to start with the “what” and the “why” before jumping to the technical “how.”
That mindset was reinforced later during my Certified Information Security Manager (CISM) studies. Guidance from ISACA and frameworks like COBIT emphasize beginning with risk, governance, and business impact — not implementation.
The better approach:
• Define the control objective
• Evaluate the risk
• Align it to business impact and operational requirements
• Document the gap in the risk register
Only then should we decide how to solve it.
Bottom line:
Security shouldn’t start with tools.
It should start with risk and business resilience. #Cybersecurity #SecurityArchitecture #RiskManagement #ISACA #SecurityLeadership
Want help applying this in your environment?
Request a service