Working Security. Not washing it.
Most security programmes are performances. They exist to produce a certificate, not to protect the business. And everyone involved knows it.
Nobody in that room is stupid or lazy. The scramble before the audit, the evidence written retroactively, the risks nobody looks at for ten months — that’s the system designed for passing audits. I call it washing security: the appearance of the thing with not enough substance.
This book is about the alternative. A programme that starts from what your business actually does, and tells you all year round whether you’re protected — not once a year whether you passed.
It’s for anyone who wants to build working security, or who has a hard time falling asleep at night.
All twelve chapters are here, free. I’m still editing toward the final version — when it’s done, the whole book will be available to download, and on paper for those who prefer it.
Why and how this book is written.
Part I — Washing Security
Part II — Working Security
Part III — Making It Stick
Why and how this book was written
I do genuinely believe there is always a better way to do things. That doesn’t mean mine is the best — the opposite: there will always be a better one. When we stay open-minded like that, keep sharing our experiences, and learn from the feedback we get, we move things forward — and we help each other live better lives.
The arguments in this book are mine, in the sense that they come from my own experience, observations, and opinions, and from what people generously taught me along the way. I use AI for research, editing, and preparing the book for publishing. I try to verify every claim before I make it. I stand behind these words, and I am open to being proven wrong.