Security leaders are often held accountable for outcomes they do not directly control.
The role exists to create coherence between decisions made elsewhere.
Security leadership is often misunderstood.
It is assumed to involve:
authority
oversight
control
This suggests that outcomes improve when leaders gain greater control over activities across the organisation.
They do not.
The misconception
Most security outcomes are produced by people who do not report to security.
They are shaped by:
engineering decisions
operational priorities
delivery pressures
commercial constraints
Security leadership sits alongside these influences.
It does not replace them.
Why control is the wrong model
Security leaders do not typically:
build systems
operate systems
own business decisions
Yet they remain accountable for their consequences.
This creates a common expectation:
If security is accountable, security must be in control.
The two are not the same.
What leadership actually does
Effective leadership aligns:
competing priorities
different time horizons
conflicting incentives
It creates coherence between decisions made across the organisation.
That is the work.
Why emerging technologies expose the problem
New technologies rarely create organisational weaknesses.
They expose existing ones.
AI increases the speed of decision-making and expands the number of decisions being made.
The challenge is not the technology.
It is whether those decisions remain coherent as the organisation changes.
Why this becomes visible under pressure
Under normal conditions, fragmentation is often hidden.
During:
incidents
audits
regulatory scrutiny
significant change
it becomes visible.
The question stops being:
“Who owns this?”
and becomes:
“Why did these decisions produce this outcome?”
The consequence
When alignment weakens:
priorities compete
risk is interpreted differently
decisions diverge
Each decision may appear reasonable in isolation.
The outcome may not.
A useful reframing
Instead of asking:
“How do we give security more control?”
Ask:
“How do we create better alignment between those making security-relevant decisions?”
Closing thought
Security leadership is rarely about directing activity.
“It is about creating coherence between decisions made elsewhere.”