I ran a half marathon Sunday. I finished first in my age group. This despite a decidedly unconventional training routine.
For much of my adult life, I’ve been a fairly consistent amateur runner. I’ve never been exceptionally fast, but PRs from years past include a sub-22-minute 5K, a half marathon below 1:40, and a couple of marathons below four hours. I believe my marathon PR was 3:47 at Las Vegas in 2010, but I’m going on memory.
Over the years, I’ve learned how to train. I’ve done the 10-week mileage programs. I’ve logged hundreds of miles preparing for a single event. That’s the proven method. That’s the way you’re supposed to do it.
We say that a lot in information security, don’t we?
For this half marathon, I logged a total of about 17 miles of training runs over 10 or so weeks. Not 17 miles per week. Seventeen miles total. That includes a July 4th 5K event, a couple of fun trail runs, and a seven-mile “wake up” trail run about a week before the race.
Yet I didn’t just survive the half marathon and finish. I won my age group with a respectable time, at least for this 59-year-old male, of 2:18.
How?
I do a lot of cycling, both indoors on Zwift and outdoors mountain biking. My resting heart rate is in the 40s, and my VO2 max remains strong for my age. Those activities have built and maintained an aerobic system capable of handling much more than cycling. Years of running experience, some limited running-specific conditioning, and knowing how to pace myself took care of other parts of the equation.
In other words, I didn’t follow the conventional control. But I still addressed the underlying risks.
Back to information security.
I occasionally see discussions about “compensating controls” in a disparaging sense. One LinkedIn thread I saw recently slammed the very idea of compensating controls, arguing that we shouldn’t need them if the primary control is designed properly.
I think that misses the point.
We should not put the controls first. We should concern ourselves first with the risks we’re trying to mitigate.
Too often, “compensating control” becomes a compliance term rather than a risk-management concept. We start with a prescribed control, discover that we can’t or don’t want to implement it exactly as prescribed, and then ask what “compensating control” we can put in its place.
But why are we starting with the control? Start with the risk.
Back to running. What were my risks? I might have a crappy time. I might not finish. I could hurt myself. I could really hurt myself.
None of those risks inherently says that I must follow a conventional running mileage program to mitigate them. Through experience and conditioning, I’ve found another way to address much of the risk. In fact, I would argue that my approach may be better for me because it reduces the pounding on my knees while maintaining a strong aerobic base.
That doesn’t mean cycling magically replaces every benefit of running. It doesn’t. Just as in information security, one control doesn’t necessarily address every dimension of a risk. My aerobic conditioning addressed one component. Running experience, limited running-specific training, pacing, and knowing my own capabilities addressed others.
The objective wasn’t to comply with a running standard.
The objective was to manage the risks well enough to achieve the desired outcome.
Seventeen miles of running wasn’t the standard way to prepare for a half marathon. But the standard wasn’t my objective. Managing the risks was.
So perhaps we should stop spending so much time debating “primary” versus “compensating” controls. Better yet, stop making controls the starting point for information security. Identify the risks. Understand the outcomes you’re trying to prevent. Then identify the combination of controls that mitigates those risks effectively and provides the resilience the organization needs.
Controls are means, not ends.
That’s how we build high performance, whether we’re talking about running a half marathon or building an information security program.
Photo: The author crossing the finish line at the 2026 Fall Creek Falls Half Marathon. Todd Temple Photography
who say enthusiastically, without reservation, that it was one of the best decisions they have ever made. In fact, I have yet to meet a former drinker who regrets quitting. The change in clarity in life, the enhanced perception of purpose, the shift in focus of priorities and use of discretionary time and money all are unparalleled.
Unlike my functional alcoholic acquaintance of 20 plus years ago, that doesn’t have to be the end game though. Sometimes a health condition caused or worsened by alcohol consumption shakes one back to reality; that’s what happened to me. As 