Working Security. Not washing it.
Most security programmes are performances. They exist to produce a certificate. And everyone involved knows it.
Nobody in that room is stupid or lazy. The scramble before the audit, the evidence written retroactively, the risks nobody looks at for ten months — that’s the system designed for passing audits. I call it washing security: the appearance of the thing with not enough substance.
This book is about the alternative. A programme that starts from what your business does and builds the security it needs, then tells you all year round what works and what doesn’t — not just once a year whether you passed an audit.
It won’t tell you which risk methodology, incident triage, or tooling to use — it’s agnostic on all of that. Its subject is the thing that usually gets overlooked: how to keep security work moving in the right direction.
It’s for anyone who wants to build working security, or has a hard time falling asleep at night.
All chapters are here, free. I’m still editing toward the final version — when it’s done, the whole book will be available to download, and on paper for those who prefer it.
Why and how this book was written.
Part I — Washing Security
Part II — Working Security
Part III — Making It Stick
The method the book argues for is open source — guides for planning, scoping, and delegating security work, free to use and improve: github.com/working-security/method.
Why and how this book was written
I believe there is always a better way to do things. Which means mine isn’t the best. Someone must have a better one, and I hope they can teach me. I’m simply sharing here what I’ve learned so far.
The arguments in this book are mine. They come from my own experience, observations, opinions, and from what people generously taught me along the way. I use AI for research, editing, and preparing the book for publishing. I try to verify claims before I make them. I stand behind what this book describes, and I am open to being proven wrong.