Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ColumnsCybersecurityCyber Tactics ColumnLogical SecuritySecurity & Business Resilience

Cyber Tactics

Don’t Ignore the Most Important System You Manage

Be sure to maintain the most critical piece of infrastructure: the human running it.

By Pam Nigro, Contributing Writer
Cyber Tactics
Image: Quardia / iStock / Getty Images Plus via Getty Images.
July 30, 2026

I was at an ISACA conference recently and had the chance to hear Shola Richards speak. If you haven’t heard him, his energy is incredible, but what really stuck with me wasn’t just the motivation — it was the way he framed resilience. He challenged us to take the very lessons we use in our cybersecurity strategy — the logic, the frameworks, and the defenses we build for a living — and apply them to our own lives.

In our world, we don’t build systems under the delusion that they’ll never be attacked. We know better. Instead, we build resilient systems: architecture that can take a hit, recover quickly, and come out stronger on the other side.

So why don’t we do that for ourselves? We’re so busy defending the network that we forget to maintain the most critical piece of infrastructure in the enterprise: the human running it. It’s time to move past generic “avoid burnout” advice and start looking at our own playbooks.

 

The Human CIA Triad

We live by the CIA triad at work, but Shola’s take on applying it to our personal lives was a total “aha” moment for me.

  • Confidentiality: This is fundamentally about access control. In cyber, we don’t give admin rights to everyone. In life, we shouldn’t give “emotional admin rights” to every person or notification that demands our attention. Not everyone deserves root access to your time and energy.
  • Integrity: Does your public leadership match your private reality? If you’re telling your team to “log off and recharge” while you’re sending emails at 2 a.m., you’re a corrupted system. That disconnect creates a kind of internal friction that drains your battery faster than anything else.
  • Availability: We all know 100% uptime is a myth for machines, so why do we expect it from ourselves? True availability isn't about being “on” 24/7; it’s about being fully present when it matters. To do that, you have to schedule planned maintenance windows — meaning you must be deliberately “offline” sometimes to prevent an unscheduled crash.

“In our world, we don’t build systems under the delusion that they’ll never be attacked. We know better. Instead, we build resilient systems: architecture that can take a hit, recover quickly, and come out stronger on the other side.”

 

Being the Buffalo

Shola shared a story about storms that I haven't been able to stop thinking about. When a storm rolls in, cows run away from it. But because they aren’t very fast, the storm eventually catches them. They end up running with the storm — staying trapped in the rain and wind way longer than they had to.

Buffalo, on the other hand, wait for the storm and then charge directly into it. By running toward the trouble, they get through it faster and come out the other side sooner.

In our industry, the “storm” is usually that awkward conversation with a stakeholder, a critical project that’s going off the rails, or a major mistake we need to own up to. Every day we avoid it, we’re being the cow. Resilience is about being the buffalo — facing the hard stuff head-on so we can get back to clear skies.

 

Defense-in-Depth (The Power of Empathy)

We know that a single firewall isn't enough. We need layers. In our personal lives, those layers of Defense-in-Depth are built through empathy.

It starts with how we treat our users — not as “security risks,” but as people. It moves to our teams, where we need to start noticing the person before the alert. When someone misses a deadline, the first question shouldn’t be “Where is the report?” It should be “Are you okay?”

But the hardest layer is empathy for ourselves. We’re great at patching servers, but we’re terrible at patching our own lives. We need to trust our own need for rest with the same logic we use to trust a system’s need for a reboot. It’s not a weakness; it’s a maintenance requirement.

 

A Quick Personal Audit

Just like we perform regular security assessments, I’ve started asking myself three questions at the end of every month:

  • What’s my biggest “unpatched vulnerability” — that one tough conversation or decision I’m avoiding? (Time to be the buffalo).
  • Which part of my personal CIA triad is failing right now?
  • Am I giving myself the same grace I’d give a colleague who was struggling?

 

The Bottom Line

The reality of our jobs is that the threats aren’t going away. With AI accelerating the threat landscape, the pace isn’t going to slow down. But we already have the tools to handle it — we just have to stop ignoring the most important “system” we manage.

You’re already resilient. You’ve survived every “worst-day-ever” the job has thrown at you so far. The goal now is to be intentional about it: building that resilience before the next incident occurs, not while you’re standing in the middle of a triage.

Start small. Set one boundary this week. Have that one hard conversation. Choose one thing to “patch.” Then next week, do it again.

Resilience isn't built in grand gestures. It's built in the daily, disciplined choices to protect your CIA triad, face your storms and back your team.

The storms are coming.

Will you be the cow, or the buffalo?

KEYWORDS: business continuity planning digital security security culture software testing security tools

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Nigro headshot

Pam Nigro is the Vice President of Security and Security Officer at Medecision. She also is an ISACA Board Director and was the 2022-23 ISACA Board Chair. Image courtesy of Nigro

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Office employees working

    Insider risk: Don't ignore the community context

    See More
  • Internet lists

    Absolutely the most important list you will ever read!

    See More
  • ‘Communication! Communication! Communication!’: The Most Important Key to Success in Business Leadership

    See More

Related Products

See More Products
  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

  • The Database Hacker's Handboo

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing