That Day You Said “YES” And Almost Killed Your Career?

It wasn’t an accident. You were SET UP to FAIL.

I don’t have to tell you this. You already know it. Not only that, you haven’t just felt it once. If you’re anything like the people I talk to, it can happen up to 20 times a week!

Twenty times.

Twenty times you walk into a meeting designed to do one thing and one thing only:

Place the blame for everything security…

…squarely on your shoulders.

And most of those times? That’s exactly what happens.

You walk in with the best intentions of keeping your organization safe, years of security training and hard-won experience, your checklist of controls the organization says it’s your job to make sure get included. And yet…

“We already have that.”

“The vendor provides it.”

“MFA is already the default.”

There’s always an answer. Those answers sound good. The room accepts them. The meeting moves forward.

The problem?

You’re not convinced. You know the details are vague. You know that something smells a bit half-baked.

But you also know that if you say anything…

You’re The Bad Guy—Again.

You’re “slowing things down.”

You’re “blocking progress.”

You’re “getting too detailed.”

And every time that happens, you prove them right: Security is the blocker. Security is there to get in the way. Security just slows us down.

And it means that you’re just a little less likely to get invited to the meeting next time, and the credibility you know you need for them to take you seriously took another heavy hit to the midsection.

So, you learn, right? You learn that:

You Are There So The Organization Can Say Security Was Involved.

And that means two things you face every time you’re looped into a security review meeting:

  1. If you’re not in the room, something big could slip through, and you’ll get blamed.
  2. If you are in the room, something big can still slip through, and you’ll just get blamed with more precision.

You’re not there to “make things secure.”

You’re there so blame can be clearly and neatly assigned to a named individual. And that individual is you.

As a result, you eventually – if you haven’t already – stop prioritizing “security”…

…and start prioritizing defensibility.

What other choice do you really have? I mean, if you push hard, you’re:

  • Blocking
  • Slowing things down
  • Not being realistic

And if you don’t, you know what happens. It’s not hypothetical. It’s probably a regular occurrence. You’re:

  • Asleep at the wheel
  • Rubber-stamping
  • Not adding value

Your reality doesn’t matter. The fact that there’s:

  • No time to prepare for the meeting
  • No available documentation provided ahead of time—except maybe a paragraph and a Power-Point “architecture” diagram, if you’re lucky
  • No in-depth knowledge of the systems involved—old or new
  • No – or infrequent – involvement with the team or the procurement process for the thing you’re supposed bless as “secure”
  • No true security architecture other than a list of security policies, mandatory controls and 300+ vendors you know hasn’t been updated in 6 months

That’s all “just part of the job,” and if you complain about it?

Then you’re just not being a team player, or you’re not as good as you’re supposed to be. Because, “other people” aren’t complaining.

They’re just doing their job.

And after you’ve been around this tree so many times, you start to ask yourself…

AM I CRAZY?

Are you missing something? Is there a new tool, method, framework or even a book you should read that somehow, suddenly makes this all make sense?

Because at least if it made sense…

…you’d know it wasn’t just you, your imagination or that you were somehow, despite all your experience, knowledge and expertise…

…still missing something.

But you’re not. You’re not missing anything. You’re feeling the daily, weekly and monthly pain of being part of a system that prioritizes the wrong incentives, optimizes for delivery speed…

…and uses compliance as a bargaining chip with the regulators to manage the size of the fines the organization ultimately has to pay.

That’s not you.

That’s the system you’re in.

And everything you feel…everything you experience – the stress, the friction, the frustration and the blame – is there by design.

It doesn’t mean things can’t change. But in order for that to happen, the first thing we have to do is help you…

SURVIVE THE MEETING WITHOUT OWNING EVERYTHING.

That’s the trick. That’s “Move 1” in terms of actually making security more than a blame assignment exercise.

Because the reality is that right now, that’s the best you can do. You can’t fix the meeting. You don’t have the credibility or the influence to change the process.

And the unfortunate reality is that after being put through a meat-grinder like the typical week you have…

…you probably don’t have the energy to try anyway.

But that doesn’t mean you have to keep accepting this as normal…accepting that you’re career is just one accidental “yes” away from being over at this particular organization…accepting that there’s nothing you can do.

Because there is.

And it doesn’t require you to champion a new process.

It doesn’t require you to adopt a new framework.

And it doesn’t require you to ask for permission to make things better.

All it takes is for you to be willing to change the way you operate in these meetings—accepting what you know you can’t change…

…and being willing to take the few, critical opportunities you have to make sure that you’re not the one walking out carrying the security burden nobody else is willing to accept is really on them.

And I can help you see and be ready to seize these moments that can completely change the trajectory of even the most high-pressure, last-minute security reviews.

I can help you do this, because I’ve been in these situations. I’ve tried the things you’ve tried, and I’ve gotten run over—exactly the same way you have.

Until I realized what I was missing—until I started seeing the meetings for what they really are…

…and better understood the motivations, expectations and pressures that existed outside the meeting…

…that were the real reasons you’re always intentionally backed into the corner and given only one obvious way out:

To accept the blame people expect you to accept so they can get on with doing the work they know they’re already struggling to deliver on time.

But what I learned is that while that’s the path you’re pushed down, it doesn’t mean you have to accept it—if you’re prepared.

If you can “read the room” and see all the hidden traps. The traps set for you—and for the entire project.

Because they’re right there in plain sight.

And being able to see them and then know exactly what to say is the only way to reliably survive the meeting.

It’s not a guarantee. Depending on the project, the team or even the day, it could still all go pear-shaped and fall apart.

But if you had something – simple rules, patterns and pat responses – that you can put in your pocket going into every meeting…

…things that would actually act like a full set of plate armor against the arrows tossed at you during the meeting…

…things that would have the best possible chance of keeping you from being misunderstood, marginalized and not having the chance to do the work required to really understand what it was you were actually being asked to approve?

It’s the best possible chance you have of consistently surviving the meeting…

…without taking ownership of things you shouldn’t…

…and without losing credibility—or your cool.

In fact, you might be surprised at how quickly things start to change—simply because you changed the way you handle yourself in these meetings.

I know, because I’ve not only experienced myself, I’ve seen countless people in the organizations I’ve worked with turn things around in exactly the same way.

But up to now, the only way for you to get access to this knowledge was by working with me directly as part of a larger transformation program. A transformation program that required management buy-in, budget allocation and willingness to take the political risk required to even try to change things at scale.

Not anymore.

Because TODAY, I’m making available for the first time ever a new program that distills the same kind of interactive coaching and mentoring experience my clients paying $50,000+ a quarter get from working with me…

…into a small, focused, self-paced and immediately actionable program I call…

Security Moves™.

Security Moves™ are designed to help you solve one recurring problem so it stays solved. This isn’t a typical training program. It’s not a framework. It’s not a method.

It’s a move.

And a move is something you can learn in 90-minutes or less and then immediately apply the very same day.

It’s designed to help you break the cycles that keep you from doing the job you not only were hired to do…

…but that you know deep down you can do—if only you got the chance.

And helping you get that chance to do the job you know you can do so you can make a difference in your organization, stop being the “blocker” or the “bad guy” and finally earn all the credibility you deserve from the people you’re breaking your back every day trying to help stay safe…

…is exactly what the first Security Move is all about. So, I’d like to officially introduce you to:

Move 1: Survive The Meeting

That’s it. That’s what we’re talking about here. Tactical advice you can learn and apply the same day that will enable you to walk into a security review and walk out without the usual blame waiting to happen…

…without being a blocker…

…without taking ownership of everything…

…and without saying “yes” to something you know you shouldn’t.

That’s the move.

And I know it sounds simple. It is. That’s the point.

But what isn’t simple is knowing how to navigate the typical security review session in a way that keeps you awake and aware enough to avoid what happens today…

…so you can change what happens to you…

…even if you can’t change what happens in the meeting.

That’s important. That’s leverage.

And it’s leverage that comes from knowing precisely what you can and can’t accomplish in a meeting like that…

…and the tools – exactly what to say and how to say it – that ensure you get the best possible outcome out of the meeting.

For you.

For security.

And for your entire organization.

Here’s what you’ll find inside Move 1:

A live breakdown of a typical security review meeting

One of the biggest problems with security review meetings are the stakes: the pressure is high, and you know you don’t want to make a mistake that can leave you hanging.

That means you’re normally in the meeting scrambling to figure out what’s happening.

You’re trying to frantically take notes about systems, data and connections.

And you’re building a security architecture in your head – on the fly – so that when it comes for your turn…

…you’ll be able to ask the 1-2 questions you think will matter most.

What this doesn’t do is give you the chance to really see the dynamics unfolding during the meeting. You don’t see things from the outside.

You can’t.

You’re in the middle of it—under just as much pressure as everyone else.

And that means that 9 times out of 10, you’re going to miss the things you must see if you want to survive.

They’re not about security.

They’re about people and the way they interact.

That’s why I’ve built a condensed meeting scenario we watch together as part of the program. It’s not meant to be perfect. It’s meant to show you the common, recurring situations I’ve seen in my own work and with clients…

…so I can point them out to you.

Specifically. Directly.

And in a way that “pulls back the curtain” so you can understand what’s really happening and how you can respond differently in each scenario.

You always knew things were stacked against you.

Now you’ll know exactly why. You aren’t crazy. You’re just in a crucible riding a blowtorch.

Why the questions they told you to ask not only don’t work—they often make things worse

You already know these meetings are broken. And because you still care, you want to try and fix things. You want to try and get people to listen to you. You want to show them exactly why security is important.

The problem is: you can’t fix the meeting. Inside the program, I’ll walk you through exactly why this is, and I’ll show you why you’re not the only one trapped in this charade either.

Once you see this, it allows you to stop thinking you’re doing the right thing when all you’re really often doing is making things worse. It means you’ll stop burning your credibility, and, over time, you’ll even end up building stronger relationships with the team so that they will come to you first.

Not because they have to.

Because they know you can help them deliver.

Once you see what’s really happening, meetings become easier. You can allocate your time and energy better, and, most importantly…

…you’ll learn how to safely surface the truly important areas where things will really break…

…without any drama, delays or reputational damage.

The 3 simple rules for surviving any security review

I told you that you can’t fix the meeting. Trying is the wrong move, and it will only set you up for failure. But that doesn’t mean you can’t do anything.

Inside Move 1, you’ll learn the 3 simple rules you’ll use over and over again to survive even the toughest security reviews under the tightest pressure.

And you’ll not only learn what they are, you’ll learn why they work, and you’ll see how they’re completely different than what you’ve been told you should be doing in these meetings.

Because there’s only 3 rules, they’re easy to remember. It’s not a script. It’s not a framework.

It’s just exactly what to say and how to say it.

But the best part? You only need to start with just one.

One rule.

One time.

One meeting.

That’s all it takes to change what you walk out of the meeting owning—even though you’re not stopping progress.

Once the first one works and you see the difference, you’ll want to try more. You’ll end up with more confidence in the meeting, regardless who’s there or what level they’re are, and you’ll start earning the credibility you deserve—one response at a time.

But the main thing isn’t any of that. The main benefit of using these rules successfully…

…is that you can carve out the time you need to finally do the work that needs to be done…

…all without stopping the world and getting blamed for slowing things down.

The 6 recurring trigger patterns that tell you where you’ve previously been trapped

On their own, the rules will help you. That’s the point. You can start to use them immediately right after you learn them.

But the true power in using them effectively is in recognizing exactly where the leverage is so you can get the most out of them.

That’s what the triggers give you. As a security professional, one thing we’re good at doing is learning to see patterns, and this is no different.

There’s only 6, and each one links to one of the 3 rules you can use to avoid the accountability traps that are guaranteed to be waiting for you in these review meetings.

These are the precise moments where – whether you know it or not – you’re being set up to fail, own the failures of others, or accept liability for everything that goes wrong with security.

Once you have the triggers, you’ll start to see the patterns. You’ll always know exactly which rule to use, and you’ll always know the right answer when you’re asked those innocent questions that might have previously cost you your career.

You won’t be guessing. You’ll know. And since they’re simple patterns, they’re going to work for everyone. It doesn’t matter if you’re a CISO, a security architect or a senior engineer. Anyone can do this.

But most of all, you’re not just protecting yourself, you’re protecting the project and the entire organization—from itself, even when it thinks that’s not what’s necessary.

How to lay the foundation for future change—without sticking your neck out

Once you start to use these regularly, you’re going to notice a few things. People will respond to you differently. You’re going to start to hear different things being said. You’ll hear questions being answered differently.

Different conversations entirely will surface that never had the chance before.

And once this happens, you’ve indirectly opened the door to enable future change. That doesn’t mean you’re on the hook to lead it.

It just means that now it’s possible.

And the more people on your team who can do the things you’ll be able to do once you’ve learned Move 1…

…the faster things will change outside the meeting so the nature of what happens inside will end up being completely different.

You won’t be the one suggesting sweeping changes. You’re not proposing new ways of doing things, and you didn’t even have to get permission or budget approval to do it.

All you did was learn 3 simple rules, 6 trigger patterns…

…and changed the way you handled yourself.

That’s it.

All because of one simple move that reduced blame for you and friction for the organization.

NOW IS THE TIME

Now that you know what’s possible. Now that you know that there’s a simple and straightforward way to survive even the toughest, high-pressure security review meetings…

…now is the time to act.

Depending on the day, you’ve probably already had several review meetings this week…

…and before it’s over, there’s bound to be more.

That means the only question to answer is simply this:

Do you want to walk into the next one hoping what you say doesn’t leave you personally exposed?

That’s it. That’s the question.

Because if you do nothing, that’s exactly what’s going to happen. You know this. You already experience it every time you join a call or walk into a room.

But it doesn’t have to be.

It can change in 90 minutes or less.

All you need to do is click the button below to get immediate access to Move 1, and I can promise you that if you apply what’s inside…

…you’ll walk out of your next meeting feeling different than before.

Because until you can do something so you’re not fighting for your professional survival every time you walk into a security review…

…you can’t possibly have the space, support or the bandwidth to actually make the difference you know you can make in security.

The choice is yours, and I know you’ll make the right one for you—whatever that choice may be.

Stay safe,

—
Andrew S. Townley
Archistry Chief Executive

What’s Inside Move 1: Survive The Meeting

The content of Move 1: Survive the Meeting is delivered to you as a series of short video lessons via the Archistry Learning mobile app. That means it’s always with you, wherever you go, and you’ll have quick and ready access to the rules and triggers at any time.

Module 1: The Reality of “Security Review” Meetings

In this module, you’ll discover:

  • What security reviews are supposed to deliver (and why they can’t do it)
  • How despite everyone’s best intentions, the meetings still fail
  • The “hidden truth” of what security reviews are really for

Module 2: A Typical Security Review Meeting

In this module, you’ll finally be able to see what a security review really looks like “from the outside” and without the pressure of being on the hook. You’ll see:

  • What’s really driving the agenda
  • How “good questions” are effectively ignored
  • What “security input” often becomes

Module 3: What Actually Happened

In this module, you’ll get a detailed breakdown of what you feel but can’t quite name. Specifically, you’ll learn:

  • When an “answer” actually isn’t
  • How certainty is assumed
  • What happens that allows accountability to hide

Module 4: The Only 3 Things You Can Do

Even though things are stacked against you, that doesn’t mean you don’t have options. In this module, you’ll learn the 3 rules and responses that let you:

  • Refuse to confuse assumptions with reality
  • Stop your answers from being taken out of context
  • Make real risks visible and persistent in a way that can’t be ignored

Module 5: Avoiding the Traps

In this module, you’ll discover the patterns that help you make sure you’re applying the right rule at the right time for the right reasons. In particular, you’ll find out:

  • How to detect when something sounds more true than it is
  • Exactly what you say when someone tries to fluff specifics they don’t know yet
  • What you can – and can’t do – to deal with timelines that can’t move

With those 5 modules, you have all you need – in 90 minutes or less – to survive your next security review meeting without the blame, ownership or security liability you’re used to.

All because you now can see the traps, apply the rules, and change the way you respond under pressure.

However, to make absolutely sure you’re never lost, I’ve also included a special bonus:

BONUS: Quick-Reference Rule Cards

For each of the 3 core rules, I’ve created a special “rule card” that you’ll always have with you – right in your phone – so you’re never at a loss for how to respond in a security review meeting. Each card reminds you:

  • The name of the rule
  • What you’ll hear when the rule applies
  • What you can say
  • Exactly what the rule helps you do

Armed with these, you’ll have exactly what you need to survive your next security review immediately after you finish the program.

Now’s not the time to wait. Now’s the time to take action.

WILL IT REALLY WORK FOR ME?

I understand that you might still have questions. You’re living the reality of being set up to fail every time you walk in a security review. You’ve already tried many different things, and…none of them moved the needle.

It’s perfectly normal to wonder if everything I’ve said above is really going to be the right thing to help you survive your next security review, so I want to share with you some answers to the questions people ask me when I tell them about the program.

Will this actually work in my environment?

I know what you’re thinking: but my organization is different. We’re a highly regulated environment. We don’t have any leverage. We can’t change the process.

And we’re stuck with the meetings the way they are.

There’s nothing I can do to change them.

You’re right. There isn’t anything you can do to change the way the meetings work without changing something in the larger organization first.

If you could do that, you already would’ve.

But the thing is, every organization faces the same pressures. It doesn’t matter the industry, the nature of what they sell.

Timelines are everything.

Security is an afterthought.

The tools might be different. The reporting structures may change. The budget allocations might be more or less.

And the politics?

Always some degree of dysfunctional.

We’re humans. There’s no other way, really.

That means that the underlying dynamics of the meetings are going to be the same, but the reality is, you always have control of one thing:

How you choose to respond.

With the 3 rules and knowing the 6 triggers, what you now have are options for responding differently than you do today without them.

And once you respond differently…

…there’s no way the people in the meeting can respond the way they did before.

That’s why this works.

You don’t try to control the meeting. You don’t try to tell people what to do.

You just change what you choose to do.

And that’s all it takes to enable a different outcome.

What if I do everything exactly right—and it backfires?

It’s true that the Move gives you specific things to say and tells you when to use them. What it doesn’t tell you is exactly how the other person is going to respond.

The truth is: you’ll never know exactly how someone is going to respond to what you say.

Maybe they’re having a bad day. Maybe something happened to them that doubled – or tripled – the normal pressure they’re under going into one of these meetings.

You can’t control them.

You can only control you. And the thing you have to remember is that these rules and responses aren’t given to you cold.

They’re given to you with context. They’re given to you with guidance. And the most important guidance included with the rules…

…is about how you deliver them.

This is the biggest risk you face in whether or not what you say – rule or otherwise – backfires.

The most basic aspect of human psychology is that we mirror the behavior of others. If someone is aggressive to us, we naturally respond accordingly.

That’s the key.

It’s like the old saying goes: “It’s not exactly what you say, it’s how you say it.”

I can’t guarantee everything is going to go smoothly. These meeting are high-stress, high-pressure environments in many cases.

But I can give you guidance based on everything I’ve learned about dealing with high-stress situations over my entire 30-year career…

…and that’s exactly what I’ve done as part of this program.

The objective isn’t “winning.” The objective is surviving without giving anything important away.

And the best way to do this is exactly to follow the delivery advice I give you in Module 4. That’s really all you need.

And if it still all goes pear-shaped?

You don’t change your delivery. You don’t change the way you respond.

You stay inside what you’ve learned, and don’t let yourself get sucked into an escalation nobody wants.

It might be hard in the moment.

But even if it backfires, you’ll still be ready with what you’ve learned—even if you don’t yet fully believe you are until it happens, and you prove it works to yourself.

But I already ask good questions. Why do I need to do anything different?

I’m sure you do. You’re asking the questions you’ve been taught to ask about the things you’ve been told are important.

The problem is that in most cases, those aren’t the right questions for the meeting you’re in—even though that’s what everyone expects you to ask.

How many times have you gotten the perfect answer in the meeting…

…and then later found out that the reality behind that answer was totally different?

And because it was different…

…you ended up owning a problem you thought wouldn’t happen…

…and under a deadline you didn’t know about until the notice hit your inbox?

I said this earlier, but it’s worth repeating: you aren’t set up to ensure delivery is “secure” in a typical security review meeting.

You’re set up to approve what’s already been decided.

And when faced with that situation, the reality is that you’re set up to fail. There’s no other outcome. You’re put in a no-win situation, with insufficient information to understand the implications of a decision you’re asked to make in a heartbeat.

Have the questions you ask today solved that problem?

Have the questions you ask today reliably meant that you didn’t get blamed for things someone else did or didn’t do?

Have the questions you ask today helped you build the credibility and trust with the delivery team that you’ve worked hard to deserve?

Maybe they have.

But if they haven’t, then it’s not because you’re not asking good questions. It’s because you’re trying to be part of a different meeting than the one you’re in.

Move 1 is about recognizing and surviving the meeting you’re in…

…so you can finally get the chance to make the difference you know you can make in security.

How can this really work? It seems too simple.

I get it. Only 3 rules, 6 trigger patterns, exactly what to say—and a bold claim that this will somehow miraculously allow you to survive meetings that either effectively go nowhere or end up ripping you to shreds.

How can something that seems so simple really deliver what I say?

Because, in a security review meeting, you naturally think the job is to validate security.

The reality is that in a 10, 30 or even 60 minute meeting – coming in cold, not knowing what’s been done for the weeks before the meeting and without any time to really digest anything you hear – you don’t have time for anything that’s NOT simple.

Imagine: if I gave you a 32-point checklist of the motivations, possible responses and potential project and security risks that might appear in a meeting…

…you’d never use it.

You couldn’t.

You’re already overloaded just trying to keep up with figuring out what everyone else already knows that you don’t.

The only hope you have is something that doesn’t require you to think. It must be simple, otherwise not only won’t it work…

…you won’t remember to use it—or even worse…

…you’ll be afraid to try because there’s too much that might go wrong.

That’s not what a Security Move is about. It’s about building survival reflexes under pressure you can count on automatically.

All you have to do is be willing to invest 90 minutes or less of your time and try one rule in one meeting to start building those reflexes from scratch.

That’s all it takes.

And yes, it’s simple.

That’s the whole point.

I have 20+ meetings a week already. My schedule’s already full. I don’t have time for this.

You’re right. You already don’t have enough time. You’re already overloaded.

So, let me ask you something:

How does walking into another meeting exactly the same way you walked into the last one change that dynamic?

How does it not make it worse?

Because, for every meeting you attend where you walk in with a security control checklist and you walk out owning everything to do with security “working”…

…you’re also walking out with a future calendar full of problems you’ll need to solve. Problems you knew were there – everyone knew were there – but yet everyone assumed wouldn’t materialize.

What happens to your schedule then?

Learning a Security Move isn’t a major investment. That’s the whole point. They’re something you can immediately use in 90 minutes or less—in the very next meeting you have.

This isn’t a book you have to read and think about.

It’s not a week’s worth of lectures you need to digest, organize, internalize and then try to figure out how to apply.

It’s tactical clarity and practical tooling you can instantly understand and unleash.

Even if you only ever use one rule, consistently, every time…

…then you still have the chance of carving out time you otherwise wouldn’t have…

…so you can finally do some of the work you know you need to do but never can.

Everyone has the same amount of hours available to them in a day. The only thing different is how they choose to spend them.

With Move 1 in your back pocket, you have options you didn’t have before.

And those options literally can change everything.

As long as you decide to let them.

NOTE: there are no refunds for the program, and there are no guarantees of any kind that you will personally achieve any of the results mentioned from other past program participants or from prior customers or clients referenced in the program. Your completion of the linked order form and successful payment is your agreement to these terms.

Should you have any questions or issues in completing this purchase, please contact customer service at custserv@archistry.com.