What a decade of defense-grade security taught me about small-business risk
When people hear I spent a decade doing security in defense, they assume it means locked down, zero risk, everything by the book. Nothing moves until it’s signed off. That’s the picture.
It isn’t what I learned, and it isn’t what I brought with me.
The discipline was never about eliminating risk. It was about knowing which risks were safe to take quickly, and which ones would get someone hurt. Then being honest in advance about which was which. That distinction is the most useful thing I can hand a small business owner, because it’s the same question you’re already answering every week, usually without a method for it.
Here are the principles that actually transferred, and the honest translation of each, because they don’t survive the trip intact. A small firm can’t simply copy the military version, and pretending otherwise would be the least useful thing I could do.
Perfection is the enemy of completion
Through my entire time in command, I kept a phrase written on the whiteboard in my office. The original wording was blunter than a company blog will take, but the polite translation is exact:
Perfection is the enemy of completion.
We had to try things, fail fast, and pivot hard to make the mission. A plan that was still being perfected while the window closed wasn’t a plan, it was a hobby. I’ve since heard a cleaner version of the same idea: feedback, not failure. Same instinct, you learn by finishing something and letting reality mark your homework.
This is the principle I’d most want a small business to have. It is also the one that’s most dangerous to hand over without a caveat. Because here’s the tension I keep running into with small firms in security:
The paralyzing part of the cyber relation is the draw to fail fast, but the fear that too big a failure could spell the end of your business.
That fear is not irrational. It’s the correct instinct, and most advice ignores it. “Move fast and break things” is a fine motto when the things that break are cheap. It is terrible security advice on its own, and the missing step is the one nobody mentions.
Sort your failures by whether you can survive them
Here is the part I’ll state once, plainly, and then move on.
In special operations, the failures we could afford to make fast were the ones that wouldn’t get anybody killed. Everything else, we de-risked first, methodically, before we moved at all.
That is not recklessness. It is the opposite of recklessness, and it’s the step people skip when they quote “fail-fast” at you. Fail-fast only works after you’ve done the deliberate work to know which failures are survivable. The speed is earned by the sorting. Take away the sorting and you don’t have a bias for action, you have a gamble.
Your version isn’t life and limb. But it is livelihood, and the sorting question is identical: is this a bad week, or is this a closed business?
A misconfigured internal tool that annoys your staff for an afternoon is a bad week. Shipping a feature that turns out to be wrong is a bad week. Trying a new supplier and hating them is a bad week. Fail fast on all of it — try, learn, pivot, and don’t spend three months in committee first.
Losing the customer that is 40% of your revenue because you couldn’t answer their security questionnaire honestly is not a bad week. A breach that torches the trust you spent nine years building is not a bad week. Data loss you cannot recover from because nobody ever tested the backup is not a bad week. Those are the ones you de-risk first, every single time, before you go fast anywhere near them.
Most small firms I meet have this exactly inverted. They move cautiously and slowly on the reversible things (the new tool, the new process, the thing they could simply undo on Friday), and then they move fast and loose on the irreversible ones. Usually for one of two reasons: the irreversible ones are boring and it’s easier not to look, or the “new shiny” feels like something they can’t live without.
Sorting risk by recoverability, before you decide how fast to move, is the whole game. It’s also free.
Audacity, backed by competence
A friend of mine put it well when we were talking about what small firms actually need:
Audacity. Small businesses need to take risks to get ahead/move forward. Be audacious when the time comes.
He’s right, and his comment reminded me of a former commander of mine. (I’ll leave the name out, old habits.) His standard was that he wanted audacious logisticians: people confident enough in their skills not to freeze when the moment came, but not so cocky or arrogant that the “warfighter” lost respect for them.
That phrase has stuck with me for years, because the two halves hold each other up. Audacity without competence is just noise, and everyone downstream can smell it. Competence without audacity is a team that has all the skill in the world and missed the moment to use it.
The small-business version: take the smart risk when the moment comes, but earn the right to first, by being good at the thing. “Be bold” is empty advice on its own. Bold and good is how a small team wins work it has no business winning.
Not everything is a five-alarm fire
Three habits I still run on, and all three translate directly.
The first is a triage rule I’ve never dropped:
If it’s not life, limb, or eyesight I’m not screaming.
The security equivalent is refusing to treat every alert as a crisis. Most things are not the emergency they feel like at the moment they land. If you run full-volume at every one of them, your team stops being able to tell the difference between the alert that matters and the ninety that don’t. That’s precisely when the real one walks past you. Triage by actual impact. Keep your voice down. Save the adrenaline for the thing that deserves it.
The second is a question I ask before proceeding, in that order:
Is this legal, is this ethical, is this moral?
It isn’t complicated and it isn’t meant to be. It’s the quiet standard underneath the work, and it has stopped me doing a few things that were technically available to me.
The third I take from Pete Blaber’s The Mission, the Men, and Me: when in doubt, develop the situation. That’s his line, not mine, but it’s the best description I know of the right posture when you don’t yet understand what’s happening. When you don’t know enough, you don’t freeze and you don’t thrash. You go and get more information, and you let the picture resolve before you commit. In an incident, that discipline is worth more than any tool you can buy. The temptation is always to do something immediately, and the first something is usually wrong.
Why I brought this to small firms
I got into cyber because it scratched the same itch. The cyber kill chain and a penetration test have the shape of a military operation: you study the target, you find the way in, you execute, you adapt when it doesn’t go to plan. I loved executing, and this looked like the next version of it.
But the reason I brought it here, to small businesses rather than large ones, is simpler and I’ll say it straight:
Small teams are capable of great and amazing things with the right training and attitude. The lack of bureaucracy and ability to iterate quickly often makes their output seem greater than larger companies by comparison of input.
That’s been true of every good small team I’ve ever been on. The output-to-input ratio is absurd when the standard is high and nobody is waiting for permission. A fifteen-person firm can turn a decision around in a day that would take a large organisation a quarter; if the discipline is there. They can be safer than the big company too, not despite being small but because of it.
That’s the whole argument for taking defense-grade discipline and bringing it down to a firm that could never afford a security department. Not the paperwork. Not the theater. The judgment is knowing which is which: what can kill the business versus what only bruises it. De-risk the first, move fast on the rest.
If that’s the standard you want and you’re not sure where your own line between bruise and kill actually sits, that’s a conversation worth having and if you’d rather know who you’d be talking to first, that’s what the about page is for. Some of the discipline lives in the unglamorous stuff, like being able to answer a customer’s security questionnaire truthfully rather than hopefully.
References & further reading
Sources cited in this post:
- Pete Blaber, The Mission, the Men, and Me (Berkley, 2010) — the source of “when in doubt, develop the situation” — https://www.penguinrandomhouse.com/books/301958/the-mission-the-men-and-me-by-pete-blaber/
Related reading on this site: