THE SECURITY BRUTALIST

Security Team Manager: From Program Optics to Survivability

Under Security Brutalism, you stop managing for appearances and start managing for survivability. The job is building a small, sharp team that can detect, decide, and recover quickly when something goes wrong, not producing a slide deck full of initiatives that signals effort without ever generating it.

You staff for operators, not coordinators. Look for people who can own a problem end to end and understand the systems they protect well enough to act with discipline under pressure. Give them a clear mission, the four laws the team runs on, and baselines that don't bend across the organization. Nobody should be guessing what's required once a decision has to happen fast.

Keep the team lean on purpose. Growing headcount to match every request spreads focus thin and adds coordination overhead right when speed is what you need most. Cut theater controls. Remove busywork. Kill reporting that looks good but doesn't tie back to risk reduction or faster incident handling. What survives is work that actually helps the team live through a real attack.

Governance runs on clear authority and consistent enforcement, not a growing pile of committees. Draw sharp lines around who owns which decisions and which standards are truly mandatory. Track every exception, give it a deadline, and close it out rather than letting it become permanent by default. Protect the team's time too, because drilling, refining runbooks, and staying on top of inventory, patching, and access control only happens when that time isn't already gone to meetings.

With executives, talk about the actual terrain. What you have, where it's weak, what's being done to harden it, how fast you can see trouble, and how well you can recover from it. Over time, the program looks less ornate and more like a simple, heavy structure that everyone understands and trusts. It won't win any design awards. It holds when the bad day finally comes.