<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Working Security. Not washing it. on Roman Jasins</title><link>https://romanjasins.com/working-security/</link><description>Recent content in Working Security. Not washing it. on Roman Jasins</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Wed, 29 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://romanjasins.com/working-security/index.xml" rel="self" type="application/rss+xml"/><item><title>People First</title><link>https://romanjasins.com/working-security/10-people-first/</link><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/10-people-first/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Design alone isn&amp;rsquo;t enough. The best method in the world fails if the people inside it don&amp;rsquo;t adopt it. Adoption isn&amp;rsquo;t about training or motivation. It&amp;rsquo;s about making the work meaningful and intuitive.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You&amp;rsquo;ve built the connected model. Established the cadence. Right-sized the programme for your actual risks. And on paper, it all works beautifully.&lt;/p&gt;
&lt;p&gt;Then you assign the first access review to someone in operations, and they ignore it for two weeks.&lt;/p&gt;</description></item><item><title>Proving It</title><link>https://romanjasins.com/working-security/11-proving-it/</link><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/11-proving-it/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The ultimate test isn&amp;rsquo;t passing an audit. It&amp;rsquo;s answering &amp;ldquo;are we secure enough?&amp;rdquo; at any moment, with reasonable confidence.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Your board asks: &amp;ldquo;Are we secure?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;You know the answer is complicated. You know that &amp;ldquo;secure&amp;rdquo; isn&amp;rsquo;t a binary state, that risk is contextual, that compliance isn&amp;rsquo;t the same as security, and that the programme has strengths in some areas and gaps in others. You know all of this, and you have about 10 minutes of the board&amp;rsquo;s attention.&lt;/p&gt;</description></item><item><title>The Compound Effect</title><link>https://romanjasins.com/working-security/12-the-compound-effect/</link><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/12-the-compound-effect/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Working Security&amp;rsquo;s real payoff isn&amp;rsquo;t in month one. It&amp;rsquo;s in year two, and beyond. When the programme starts giving back more than you put in.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="the-worst-quarter-and-the-best-quarter"&gt;The worst quarter and the best quarter&lt;/h2&gt;
&lt;p&gt;The worst quarter is the first one. You&amp;rsquo;ve done the honest inventory. You&amp;rsquo;ve picked your most painful area and connected it. You&amp;rsquo;ve run one cycle. The results were promising — the access review was clearer, the evidence was better, the person who did it actually understood the task. But the rest of the programme is still running the old way. You&amp;rsquo;re maintaining two systems. The connected model is incomplete. The cadence is established in one area but not yet in others. You&amp;rsquo;re spending more total effort than before, because transition work sits on top of operational work.&lt;/p&gt;</description></item><item><title>Everything Connects</title><link>https://romanjasins.com/working-security/06-everything-connects/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/06-everything-connects/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Security parts don&amp;rsquo;t exist in isolation. When you build a programme that understands the connections between them, the impossible becomes manageable.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It&amp;rsquo;s 9:15 on a Tuesday morning and you&amp;rsquo;ve just seen the news. One of your cloud providers has disclosed a data breach. Customer data may have been exposed. Details are still emerging, but the news mentions &amp;ldquo;unauthorised access to customer account metadata.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Your CEO wants to know if you&amp;rsquo;re affected. Your biggest client&amp;rsquo;s security team has sent an email asking for a statement. Your DPO wants to know if this triggers a GDPR notification obligation.&lt;/p&gt;</description></item><item><title>Make the Work Disappear</title><link>https://romanjasins.com/working-security/07-make-the-work-disappear/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/07-make-the-work-disappear/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The goal isn&amp;rsquo;t to do more security work. It&amp;rsquo;s to make the necessary work efficient, well-timed, and distributed enough that it barely registers.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;October. You know what&amp;rsquo;s coming.&lt;/p&gt;
&lt;p&gt;The ISO surveillance audit is in six weeks. The management review is overdue. Half the access reviews that should have happened quarterly happened once, in February. The risk register hasn&amp;rsquo;t been touched since the last audit. Three policies are out of date — one references a system you decommissioned in March. Evidence folders are a mess of screenshots with names like &lt;code&gt;final_v3_ACTUAL.png&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>Start Where You Are</title><link>https://romanjasins.com/working-security/09-start-where-you-are/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/09-start-where-you-are/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;You don&amp;rsquo;t need to burn it all down. You need to be honest about what you have, connect what&amp;rsquo;s worth keeping, and let go of what was always fiction.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You&amp;rsquo;ve read the first eight chapters. Hopefully I managed to articulate how security programmes become performances. You understand why connections matter, why the cadence works, why proportionality is the missing conversation. And you&amp;rsquo;re sitting in front of your own programme — the one with the stale risk register, the policies nobody remembers exist, the evidence folder with screenshots from 2019, and the spreadsheet that only one person understands — and you&amp;rsquo;re thinking: where do I start?&lt;/p&gt;</description></item><item><title>The Right Amount</title><link>https://romanjasins.com/working-security/08-the-right-amount/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/08-the-right-amount/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&amp;ldquo;How much security is enough?&amp;rdquo; is the question every business asks and no framework answers. It&amp;rsquo;s answerable — but only if you can see what you&amp;rsquo;re actually getting for what you&amp;rsquo;re spending.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It might go something like this. A CTO at a 35-person Series A B2B SaaS gets asked by a prospective enterprise customer whether they have ISO 27001 certification. They don&amp;rsquo;t. The deal is worth €400K annually. So the CTO does what any sensible person would do: panics quietly and calls a consultant.&lt;/p&gt;</description></item><item><title>Reality Check</title><link>https://romanjasins.com/working-security/05-reality-check/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/05-reality-check/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Start from what&amp;rsquo;s real, and you will be protecting the business. Start from the framework, and you will be protecting a picture of the business that fits the frame.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You are in a kickoff meeting for an ISO 27001 implementation — a mid-size software company, about 80 people, with an experienced consultancy guiding the certification.&lt;/p&gt;
&lt;p&gt;The consultant opens with: &amp;ldquo;Let&amp;rsquo;s start by going through the Annex A controls and identifying which ones apply to your organisation.&amp;rdquo;&lt;/p&gt;</description></item><item><title>The Blame Game</title><link>https://romanjasins.com/working-security/03-the-blame-game/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/03-the-blame-game/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;When security fails, we blame people. But individual failure is almost always a structural failure wearing a name badge.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It often goes like this. A mid-size company — about 200 people, with a software product — has a security incident. Not catastrophic, but real. An employee has reused a password across a personal account and a company system. The personal account gets breached. The attacker uses the same password to access the company&amp;rsquo;s environment. From there they pivot to a shared drive with company data. Nothing is taken, locked, or altered, as far as anyone can tell — but it&amp;rsquo;s close enough to hurt, and you can never be sure.&lt;/p&gt;</description></item><item><title>The Standards Trap</title><link>https://romanjasins.com/working-security/04-the-standards-trap/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/04-the-standards-trap/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Standards were designed to help. In practice, they&amp;rsquo;ve become the problem — creating duplicate work, conflicting language, and an industry that profits from the complexity rather than reducing it.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You manage access to your production environment. You do it well. There&amp;rsquo;s a working process: joiners get access approved by their manager and provisioned by IT, movers get their access reviewed when they change roles, leavers get deprovisioned on their last day. The whole thing is reviewed quarterly. Evidence is collected — who approved what and when, with what justification. The control works.&lt;/p&gt;</description></item><item><title>The Overwhelm</title><link>https://romanjasins.com/working-security/02-the-overwhelm/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/02-the-overwhelm/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;People do the minimum because they&amp;rsquo;re overwhelmed, not because they&amp;rsquo;re lazy — and the problem is structural, not personal.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here&amp;rsquo;s a job description. You&amp;rsquo;ll recognise it:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Security &amp;amp; Compliance Lead. Responsible for maintaining the organisation&amp;rsquo;s security programme, including risk management, policy development, access control, vulnerability management, incident response, vendor assessment, business continuity planning, security awareness training, audit preparation, regulatory compliance, and liaising with authorities. Reports to the CTO. Must be familiar with ISO 27001, SOC 2, GDPR, NIS2, and relevant industry frameworks. Experience with cloud security, application security, and network security preferred.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>The Performance</title><link>https://romanjasins.com/working-security/01-the-performance/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://romanjasins.com/working-security/01-the-performance/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Most security programmes perform to produce a certificate, not to protect the business. Everyone involved knows it.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You passed your security audit. Congratulations. The ISO 27001 certificate is on the wall. The sales team is already using it in proposals, and the LinkedIn post got 200 likes.&lt;/p&gt;
&lt;p&gt;Let me ask you something. If a critical vendor went down tomorrow — the one that hosts your customer database, or the one that notifies users about transactions — how quickly could you identify which of your services are affected — not just the obvious ones? Which customers would be impacted? What contractual notification obligations kick in?&lt;/p&gt;</description></item></channel></rss>