Communication - Why Half the Job is the Conversation

I got into this work because I wanted to be left alone.

That's the honest version.

Early in my career, I loved technology for the same reason a lot of us do - it made sense to me. Computers didn't need managing, negotiating, or convincing. Bits and bytes are easy. I could take a thing apart, understand it, put it back together better than I found it, and no people problems came along for the ride.

For a while, I thought that was the whole job - do the work quietly in the background and let the results speak.

You can get away with that as an engineer. You cannot get away with it as a leader.

The day I moved into management, the math changed. A security team rarely has direct, hands-on ability to change the things it's responsible for. We don't own the endpoints, the applications, the cloud accounts, or the humans clicking the emails. Other people own those. Which means the work isn't really "go fix it." The work is getting the people who “can” fix it to want to. And if you approach that as a technologist who'd rather not deal with anyone, you generate so much friction across the business that your career doesn't last very long.

So, I did something that felt unnatural at the time: I went and learned to communicate on purpose. Not from other security people, but from professionals outside the industry who teach communication, leadership, negotiation, how to reach an agreement and then actually deliver on it. I treated it like a skill to be trained, because that's exactly what it is.

Here's what I tell my teams now, especially the brilliant ones just starting to rise into senior roles: “half of our work is communication.” You are, most of the time, just talking. Explaining risk. Explaining the cost that rides along with that risk. Explaining why we reached the conclusion we reached and then getting other people to buy into it and take ownership of it. If that sounds soft, it isn't. It's the hardest and highest-leverage part of the job.

Dictation isn't communication

I watch a lot of interactions. It's the old analyst in me. And the pattern I see most often with talented security people is this - they walk into a meeting and say, "We have to do this, and if we don't, here's the catastrophe that happens, so you need to listen to me."

That's not a conversation. That's dictation. And it goes about as well as you'd expect.

When I catch it, I pull the person aside not to scold, but to explain the thing nobody explained to them. We have to tell a story. We have to make the "why" impossible to miss. And we cannot be the only ones who own the outcome. We own security outcomes and our business partners own them, the same way we take partial ownership of the business outcomes. Ownership that only lives on one side of the table isn't ownership. It's a to-do list nobody else agreed to.

The Middle School

The clearest lesson I ever got in shared ownership had nothing to do with cybersecurity. It came from serving on my local school board.

We had a middle school that was, and I'm not exaggerating, falling in. The engineering reports were unambiguous: you can spend millions patching up this building, or you can knock it down and build a brand-new one for a lot less. Simple decision, obvious answer. And yet we could not get the city council, the people who authorized the money, to agree with us. We had the data. We had the experts. It wasn't moving.

So, I stopped trying to convince them and asked a different question, “Why don't we bring them into the room to hear exactly what we've been hearing?“

We sat the council down with the engineers for an hour and a half. That was it. By the end of that meeting, they had grabbed the flag and were running down the road with it, “We need to build a new school, it makes no sense to keep pouring money into the old one.”

A year and a half later there was a new building down the road, with new technology and a comfortable place for those kids to learn.

I didn't win that with a better argument. I won it by letting them arrive at the conclusion themselves, with the same information I had. That's shared ownership.

Communicate the real issue, put everyone in front of the same facts, and come to a common agreement, and suddenly it's not my project I'm dragging people toward. It's our mission, and they're the ones carrying the flag.

If you work with developers, none of this should be new to you. Their entire craft is stories - a beginning, chapters, a payoff. We have to do the same thing. Get everyone invested in the "why." Not "do this because I said so," but "here's why it's worth doing, can we build the plan together?" We agree on the plan. We execute the plan. When it's done, we take a breath, pat ourselves on the back, and keep moving. That loop: “Why, Agree, Execute, Acknowledge, Next”, is most of leadership.

Learn to speak business

The other half of communicating well is speaking the language of the person across from you.

Put yourself in a CFO's or CEO's chair for a minute. They're making fast decisions on maybe eighty percent of the data they wish they had, because that's how the world moves. If it's a public company, every one of those decisions has to be defensible to a board. They have a thousand things they could do this year and the capacity to do a hundred. Our job is to help them see which of those hundred things actually matter, and why, and that means bringing data, not dread.

So, I don't float vague fears. I build a case. In financial services, I can look at what the actuaries are actually paying out and know where the real threats are landing, not the theoretical million but the ten that get exploited over and over. I line those up against our risk appetite and our cyber insurance, and I bring a clear proposal: “Does it make sense to spend $250,000 to reduce $10,000 of risk?” No! So that never reaches the top of the stack. “Does it make sense to spend $250,000 to prevent a $10 million loss, when our risk appetite is only $2 million?” Now we have something. That's a conversation a CEO can follow and a CFO can defend.

What doesn't land is "we can't do AI because we can't control AI." That sentence quantifies nothing. It gates no business need. It brings no solution. And if you're not bringing solutions the business can act on, the business doesn't need you. Harsh, maybe, but true, and it's the thing I most want the technically brilliant to internalize.

The mission is shared or it's nothing

I spent the first stretch of my career believing the work would speak for itself if I just did it well enough and quietly enough. It won't. Security is a shared mission or it doesn't hold. Our job is to make the risk legible, make the "why" undeniable, and hand people enough ownership that they pick up the flag and run, because the outcomes we're protecting were never ours to carry alone.

And it turns out it's the part that matters most.

Next
Next

Identity Is the New Perimeter. We're Not Securing It Like One.