Principles for a High-Performing Security Team
Originally written in 2021
Security is a team sport. Technology is important, but people, judgment, and trust determine whether a team succeeds when systems fail, attackers adapt, or incidents unfold.
1. Build Competence First
Everyone should strive to master their craft. Learn the fundamentals thoroughly before chasing the newest technology or trend.
Experience alone is not enough. Security changes constantly and learning should never stop. Senior engineers should continue learning just as deliberately as junior engineers.
Be known for doing the basics exceptionally well.
2. Care About the Team
Strong security teams are built on trust.
Help teammates succeed. Share knowledge freely. Review work with the goal of making people better, not proving yourself right. During incidents, support each other instead of assigning blame.
People perform better when they know the team has their back.
3. Have Conviction
Be clear about your principles and stand behind them.
If you believe a design introduces unnecessary risk, explain why. If an incident reveals a weakness, acknowledge it openly. If you commit to fixing something, follow through. Consistency builds credibility.
4. Give People Room to Act
Leadership should define objectives, priorities, and constraints. Teams closest to the problem should decide how to solve it.
Security engineers, incident responders, and architects often have the best understanding of what is happening in real time. Give them the authority to make decisions while maintaining clear communication. Trust people to use their expertise.
5. Practice Before It Matters
Incidents are poor places to discover missing documentation, unclear ownership, or broken processes.
Run tabletop exercises, test recovery, practice investigations, and validate detections. Simulate realistic attacks.
Training builds confidence and exposes weaknesses while the cost of failure is still low.
6. Write Down How You Operate
Document the principles that guide the team.
Define engineering standards, architectural expectations, incident response procedures, and decision-making guidelines. Keep them practical, concise, and easy to understand.
Good documentation creates consistency without creating bureaucracy.
7. Reward Initiative
People should be encouraged to identify problems, improve processes, automate repetitive work, and challenge assumptions.
Thoughtful action should be recognized, even when every outcome is not perfect. Waiting for permission should not become the default.
A team that learns quickly will outperform one that simply follows instructions.
8. Expect Change
Attackers evolve, technology changes, and business priorities shift.
Plans will require adjustment and designs will need revision. The controls that worked yesterday may become ineffective tomorrow.
Adaptability is a professional skill, not an exception.
9. Value Different Perspectives
Some of the best ideas come from people who ask uncomfortable questions or challenge established thinking.
Encourage respectful disagreement. Invite different technical viewpoints and listen to people with different backgrounds and levels of experience.
Healthy debate leads to better decisions than easy agreement.
Final Thought
The goal is to build a team that understands the mission, thinks independently, learns continuously, supports one another, and consistently makes sound decisions under pressure.