From “Firefighter” to CISO: building a security operation that doesn’t depend on heroes
Expensive tools don’t fix a fragile operation. Method does. Here’s what actually separates the two — and how to build it.
From “Firefighter” to CISO: building a security operation that doesn’t depend on heroes
Expensive tools don’t fix a fragile operation. Method does. Here’s what actually separates the two — and how to build it.

Pay close attention to what I’m about to tell you, because it runs against almost everything you’ve been sold.
The biggest risk to your security operation today isn’t on the outside. It isn’t this week’s ransomware strain, it isn’t the mysterious attacker, it isn’t Wednesday’s vulnerability.
The biggest risk lives inside the house: your operation depends on heroes.
And an expensive tool won’t fix that. Individual talent won’t fix that. Budget won’t fix that. Only one thing does — method.
The lesson aviation learned (and security is still learning)
Think about how flying became the safest thing humanity routinely does.
It wasn’t by hiring superhuman pilots with inhuman reflexes. It was the opposite.
Aviation got safe the moment it stopped depending on individual genius and started depending on process: mandatory checklists, standardized procedures, redundancy, and — maybe most important of all — incident investigation with no witch-hunt, focused on fixing the system instead of finding someone to blame.
Today a pilot can have a bad day, can get sick, can make a mistake. And the plane still lands safely. Because safety doesn’t live in one person’s head. It lives in the system.
Does your security operation look more like modern aviation — or like an improvised operating room where only one surgeon knows where the instruments are?
If that question stung a little, you’re exactly who I’m writing for.
Firefighter or architect?
There are two profiles in our field, and you need to know which one you are.
The firefighter spends their life putting out fires. The alert hits at 3 a.m., they fix it, everyone applauds. The next day, another fire. And another. They think they’re a hero. In reality they’re a hostage — hostage to the next problem, because they never went after the root of the smoke.
The architect builds the foundation. Nobody applauds. But the environment they designed simply doesn’t catch fire the same way twice, because every incident becomes a process, and every process becomes armor.
The question that defines your career is simple:
How much of your operation today depends on people putting out fires — and how much depends on processes that keep working when you’re on vacation, asleep, or out of the room?
The truth that will bother a lot of people in this field
I spent more than two decades building security functions globally, in contexts where a single mistake cost reputation, money, and sometimes the entire operation.
The biggest lesson isn’t in any vendor datasheet: the problem was almost never the technology.
We live in a culture that believes the answer is always in the next purchase. The next SIEM, the next EDR, the next black box with “AI” in the name. So the company stacks expensive tool on top of expensive tool — and stays exactly where it was, only now with a bigger, more out-of-control cost center.
Because a tool without method is just money on fire. It’s the Ferrari locked in the garage because nobody there knows the track.
And there’s a moment in every manager’s career when improvisation abandons you. When the “pretty PowerPoint” no longer fools the board. When you discover you’d been holding the whole thing together on adrenaline and the sheer luck of it not having gone wrong yet. That moment always comes. The only question is whether it finds you prepared — or improvising.
So let’s get to the “how.” Out of the speech, into the practice.
Building an operation that doesn’t depend on heroes isn’t luck. It’s deliberate construction. Where to start:
01 Turn every incident into an asset, not a trauma
Adopt the blameless post-mortem. When something breaks, the question isn’t “who screwed up?” — it’s “what process allowed this, and how do we close that door for good?” The knowledge living in your senior analyst’s head needs to become documentation. If they leave tomorrow, the operation can’t leave with them.
02 Move incident response out of memory and into runbooks
Clear playbooks for your most likely scenarios — phishing, compromised account, ransomware, data leak. Whoever picks up the on-call shift should be able to execute the response by reading the runbook, without “call so-and-so.” A mature operation is one where the procedure is smarter than the hero on duty.
03 Pick a framework and actually use it
NIST CSF, ISO 27001, CIS Controls — the acronym doesn’t matter; the mistake is having none. The framework is your map: it tells you where you are, where the gaps are, and where to go next. Without it you don’t have strategy, you have reaction. Map your controls, find the gaps, prioritize by risk.
04 Create cadence. Security is a routine, not an event
Vulnerability management on a defined cycle. Periodic access reviews. Backup restore tests that actually happen. Tabletop exercises to rehearse the response before the real incident. What has no cadence doesn’t exist — it becomes a “strategic plan” nobody follows.
05 Stop reporting alerts. Start reporting risk
The board doesn’t care how many alerts your SOC blocked. To them, that number is about as useful as how many liters of fuel the car burned. They want to know: which business risk did you reduce, what is it worth, and how is security enabling the company to grow with confidence? Translate everything into the language of the business — financial impact, exposure, continuity. Speak the language of alerts and you stay in the basement. Speak the language of risk and you sit at the table.
06 Build culture, not dependency
A high-performance operation has no irreplaceable genius — it has a team where the process is shared, documented, and trained. The goal isn’t for you to be indispensable. It’s for your function to run well precisely because you built something bigger than yourself.
The difference between a manager and a CISO
And here’s the point that separates the two.
Information Security is not an IT project. It’s management. It’s decision-making. It’s delivery.
The ordinary manager puts out fires and prays the next one isn’t too big. The real CISO builds the foundation that makes the fire less and less likely — and when one does break out, it gets contained by process, not by miracle.
One runs on inspiration. The other runs on method. One is a hero once. The other is reliable every single day.
Before you close this page
If you read this far and felt that good kind of discomfort — the one that signals there’s a level you haven’t reached yet — then the message landed where it was meant to.
I’m going to keep this conversation going here. In the next pieces I’ll break down, in practical terms, how to get out of “tired hero” mode: frameworks applied to reality, runbook templates, ways to report risk to the board that actually work, and how to build the kind of operation that lets you sleep at night.
→ Follow so you don’t miss it.
Because the next incident is a matter of time. The only question is this: will you be putting out the fire again — or standing outside, calm, because you built something designed not to burn?
I know which side I want to see you on. The choice is yours.
Denny Roger (@dennyroger.ciso) | SOC Builder
메타데이터
- post_id
- 275f91998cb2
- slug
- from-firefighter-to-ciso-building-a-security-operation-that-doesnt-depend-on-heroes-275f91998cb2
- url
- https://medium.com/@dennyroger/from-firefighter-to-ciso-building-a-security-operation-that-doesnt-depend-on-heroes-275f91998cb2
- canonical_url
- https://medium.com/@dennyroger/from-firefighter-to-ciso-building-a-security-operation-that-doesnt-depend-on-heroes-275f91998cb2
- author_url
- https://medium.com/@dennyroger
- status
- ok
- fetched_at
- 2026-06-27 07:40:21