skip to content

Your security backlog is all audit checkboxes while incidents come from elsewhere — how do you rebalance?

level: principalimportance: should knowfreq 38%

answer

  1. two portfolios, funded differently
  2. obligations are a cost to minimise
  3. the backlog follows the reported number
  4. objectives, not implementations, are mandated
  5. auditor early, parallel run, then retire

basics

~20 s

Split the work into two funded portfolios: obligations, satisfied and evidenced as cheaply as possible, and risk reduction, funded by measured exposure. Then change what gets reported, because one pass-rate number always pulls the backlog toward checkboxes.

solid answer

~50 s

First accept that the obligations are not optional — the certificate and the customer contracts behind them are revenue, so 'stop doing compliance work' is not a proposal. Split the portfolio explicitly: obligation work is a fixed cost you drive down by automating evidence, and risk-reduction work is funded against measured exposure. Then fix the reporting, because whatever single number leadership sees is what the backlog optimises for; pass rate alone rewards adding easy controls. Add a second axis with variance, such as time from leaver event to access revoked. The real leverage is upstream, at the point where a framework objective becomes an internal control: most frameworks state an objective, not an implementation, so you can re-implement it as a check on the thing that matters — with the auditor consulted early, not presented with a fait accompli. And pick your fights: a cheap green control that nobody is harmed by is not worth the quarter it would cost to argue away.

go deeper

for a junior

Understand that some security work exists because a contract or certificate requires it, and that it cannot simply be dropped in favour of work you find more useful.

for a middle

Be able to explain why automating a control's evidence is the cheapest way to shrink the obligation portfolio, and why that is different from removing the control.

for a senior

Show how to run a replacement control in parallel for a reporting period so the transition never shows a coverage gap, with the auditor consulted before anything is retired.

for a principal

Own the incentive design: name the second reported axis, defend the split between obligation cost and risk-reduction investment, and be explicit about which fights you decline.

## The situation, stated honestly The backlog is full of items whose only justification is a framework row. The incidents of the last year came from somewhere else. Both facts are real, and the naive conclusion — do less compliance work — is wrong, because the certificate is attached to contracts and the contracts are attached to revenue. The problem is not that obligation work exists; it is that obligation work and risk-reduction work are competing for the same engineers out of the same queue, judged by the same metric, and the metric favours the checkbox. ## Separate the portfolios and fund them differently Make the split explicit and visible: **Obligations.** Work that exists because a framework, a regulator or a customer contract requires it. Success is 'satisfied and evidenced'. It is a **cost to minimise**, not a risk to reduce, and the way to minimise it is to automate the check and the evidence so that satisfying it next quarter costs nearly nothing. Every hour spent automating a control's evidence is an hour permanently removed from this portfolio. **Risk reduction.** Work justified by measured exposure — incident and near-miss patterns, leading indicators, threat coverage. Success is a metric moving. The overlap is the good part: a control that is both obligatory and effective. Aim to grow that overlap by re-implementing obligations as effective checks rather than by adding separate work in both columns. ## Change the number, or the backlog will not change The backlog optimises for whatever is reported. A single pass-rate figure rewards adding many easy controls and punishes replacing one weak control with one strong one that starts red. So publish a second axis alongside it. Useful candidates: - A small set of exposure indicators with real variance: 95th-percentile time from leaver event to access revoked, proportion of privileged accounts with a phishing-resistant factor, count of production services outside the standard identity path. - Control-to-incident coverage: of the last N incidents, how many had a control whose failure would have caught it. - Evidence cost: engineer-hours per control per quarter, which makes automation visibly pay for itself. And say plainly what pass rate is: a measure of **obligation satisfaction**, not of security. Leadership reading 98 percent as assurance is the most expensive form of satisfied-but-ineffective in the organisation, because it drains urgency from the work that is not on the report. ## The leverage is at the interpretation layer Between a framework objective and an internal control there is a translation step, usually done once, years ago, by someone copying a common implementation. That translation is where the checkbox was born and where it can be rewritten. Most frameworks state an **objective** — authenticate users appropriately, restrict access to what is required — and leave the implementation to you. So the same objective that produced a 90-day rotation control can be re-implemented as phishing-resistant factors plus compromised-credential monitoring plus deprovisioning driven by the HR leaver event, and still satisfy the objective. Do this with the auditor in the room **early**. An auditor asked in advance whether a proposed implementation satisfies an objective will usually engage with it; an auditor shown a retired control at fieldwork will raise a finding. Bring the mapping, the check and the evidence format together — how the new control will be sampled matters as much as what it does. ## Sequencing, so nothing goes red on the way Run the replacement in parallel for at least one reporting period, keeping the old control alive. You get a clean transition with both evidence sets, a real measurement of the new control's red rate before anything depends on it, and no window where the report shows a gap. Retire the old control at a period boundary, in writing, with the mapping updated. ## Choose the fights Not every checkbox is worth attacking. Three tests for whether to spend the political capital: 1. **Does it consume real engineering time each quarter?** If so, automate the evidence first and reassess; the cheapest win is usually cost, not deletion. 2. **Does it cause harm?** Some controls actively degrade security — mandatory rotation producing predictable mutations is the canonical case — or train people to treat the security function as an obstacle. Those are worth the fight. 3. **Does it give false assurance?** A control that leadership believes covers a risk it does not cover is worse than no control at all, because it suppresses the funding request that would fix the risk. A cheap, automated, harmless checkbox that nobody thinks about fails all three. Leave it green and spend the quarter elsewhere. Knowing which battles not to fight is most of what separates a lead who changes the programme from one who is known for complaining about compliance.

  • Leadership reads the 98 percent pass rate as 'we are secure'. How do you correct that without sounding defeatist?
    Do not argue with the number; add one beside it. Report pass rate as obligation satisfaction, and publish two or three exposure indicators with variance next to it, with their trend. Then show the control-to-incident mapping for the last year. The message is that one number is going well and the other is where the investment is needed, which is a funding conversation rather than a complaint.
  • The compliance owner is measured on pass rate. How do you keep them on side?
    Never propose anything that makes their number worse without a swap. Automate evidence for the controls they carry, which reduces their cost and raises reliability; run replacements in parallel so coverage never dips; and get their name on the re-mapping when the auditor accepts it. If you can also get their metric widened to include evidence cost and coverage, the incentive stops fighting you.
  • How do you decide which checkbox controls to leave alone?
    Leave anything cheap, automated and harmless. Spend capital only where a control consumes recurring engineering time, actively degrades behaviour, or gives leadership assurance it has not earned. Automating a control's evidence is nearly always cheaper than arguing it away, and it converts the control into a fixed cost of near zero, which is the outcome you wanted anyway.

saying these in an interview costs you the question

  • Proposes dropping compliance work as if the certificate were optional
  • Treats pass rate as a measure of security posture
  • Retires a control before the auditor has seen the replacement
  • Fights every checkbox instead of choosing the harmful ones
  • Adds a new metric with no variance and no owner

context