Back to Insights

Hiring a Head of Security Doesn't Solve the Translation Problem

Six months in: a 40-page roadmap, three new vendor contracts, a budget request. And no way to evaluate any of it.

Hiring a head of security is the right move. It doesn't solve the translation problem.

Six months in, you have a 40-page roadmap, three new vendor contracts, and a budget request. Your head of security is competent. The recommendations are probably sound.

But you have no way to evaluate any of it. Every question gets answered with more technical detail. Every pushback requires expertise you don't have. You are fully dependent on someone you hired to be independent.

That is not a failure of trust. It is a structural problem.

The structure is this. Most functions produce something you can check without being expert in it. Revenue is a number. A product either gets used or it does not. Security mostly produces non-events. A quiet year is equally consistent with good spending and with luck. The signal that would let you check is the one that is missing. The only judgement available is the judgement of the person proposing the work.

Trust is the right stance toward a good hire, and it is not a decision procedure. You can trust someone completely and still owe the company a reason for the number. One that survives being repeated to a board without them in the room.

What you need is not expertise

You do not have to become a security expert to evaluate a security proposal. You have to be able to compare it to something. What is normal at this size. What this usually costs. What a company like yours tends to do first. That is a benchmark problem rather than a technical one. It is also the part a roadmap rarely contains.

  • Which part of this is required, and which part is your judgement.
  • If the budget were half, what would you keep, and what does dropping the rest cost us.
  • What did you consider and rule out, and why.

None of those require you to understand the technology. All three are hard to answer with more detail, which is what makes them useful.

Your head of security gains more from this than you do. Right now the best they can get is deference. Deference is not a decision. It leaves them carrying a budget nobody else has actively agreed is right. An approval that survived a real question is worth more than one that did not.


The Security Diagnosis is not a check on your hire. It is how you show up to that conversation as an informed decision-maker. It gives you the questions to ask, the benchmarks to use, and a clear picture of what is appropriate for your stage.

So when your head of security comes to you with a budget request, you can evaluate it yourself.

Related: The Security Diagnosis

Fixed scope. The questions to ask, and the benchmarks to judge the answers.

The Security Diagnosis

Also relevant: The Leadership

Fractional CPO or CTO. We own the function and leave it running.

The Leadership

Read next