Security leaders are often held accountable for outcomes they do not directly control.

The role exists to create coherence between decisions made elsewhere.

Security leadership is often misunderstood.

It is assumed to involve:

  • authority

  • oversight

  • control

This suggests that outcomes improve when leaders gain greater control over activities across the organisation.

They do not.

The misconception

Most security outcomes are produced by people who do not report to security.

They are shaped by:

  • engineering decisions

  • operational priorities

  • delivery pressures

  • commercial constraints

Security leadership sits alongside these influences.

It does not replace them.

Why control is the wrong model

Security leaders do not typically:

  • build systems

  • operate systems

  • own business decisions

Yet they remain accountable for their consequences.

This creates a common expectation:

If security is accountable, security must be in control.

The two are not the same.

What leadership actually does

Effective leadership aligns:

  • competing priorities

  • different time horizons

  • conflicting incentives

It creates coherence between decisions made across the organisation.

That is the work.

Why emerging technologies expose the problem

New technologies rarely create organisational weaknesses.

They expose existing ones.

AI increases the speed of decision-making and expands the number of decisions being made.

The challenge is not the technology.

It is whether those decisions remain coherent as the organisation changes.

Why this becomes visible under pressure

Under normal conditions, fragmentation is often hidden.

During:

  • incidents

  • audits

  • regulatory scrutiny

  • significant change

it becomes visible.

The question stops being:

“Who owns this?”

and becomes:

“Why did these decisions produce this outcome?”

The consequence

When alignment weakens:

  • priorities compete

  • risk is interpreted differently

  • decisions diverge

Each decision may appear reasonable in isolation.

The outcome may not.

A useful reframing

Instead of asking:

“How do we give security more control?”

Ask:

“How do we create better alignment between those making security-relevant decisions?”

Closing thought

Security leadership is rarely about directing activity.

“It is about creating coherence between decisions made elsewhere.”