Controls Are Means, Not Ends

I ran a half marathon Sunday. I finished first in my age group. This despite a decidedly unconventional training routine.

For much of my adult life, I’ve been a fairly consistent amateur runner. I’ve never been exceptionally fast, but PRs from years past include a sub-22-minute 5K, a half marathon below 1:40, and a couple of marathons below four hours. I believe my marathon PR was 3:47 at Las Vegas in 2010, but I’m going on memory.

Over the years, I’ve learned how to train. I’ve done the 10-week mileage programs. I’ve logged hundreds of miles preparing for a single event. That’s the proven method. That’s the way you’re supposed to do it.

We say that a lot in information security, don’t we?

For this half marathon, I logged a total of about 17 miles of training runs over 10 or so weeks. Not 17 miles per week. Seventeen miles total. That includes a July 4th 5K event, a couple of fun trail runs, and a seven-mile “wake up” trail run about a week before the race.

Yet I didn’t just survive the half marathon and finish. I won my age group with a respectable time, at least for this 59-year-old male, of 2:18.

How?

I do a lot of cycling, both indoors on Zwift and outdoors mountain biking. My resting heart rate is in the 40s, and my VO2 max remains strong for my age. Those activities have built and maintained an aerobic system capable of handling much more than cycling. Years of running experience, some limited running-specific conditioning, and knowing how to pace myself took care of other parts of the equation.

In other words, I didn’t follow the conventional control. But I still addressed the underlying risks.

Back to information security.

I occasionally see discussions about “compensating controls” in a disparaging sense. One LinkedIn thread I saw recently slammed the very idea of compensating controls, arguing that we shouldn’t need them if the primary control is designed properly.

I think that misses the point.

We should not put the controls first. We should concern ourselves first with the risks we’re trying to mitigate.

Too often, “compensating control” becomes a compliance term rather than a risk-management concept. We start with a prescribed control, discover that we can’t or don’t want to implement it exactly as prescribed, and then ask what “compensating control” we can put in its place.

But why are we starting with the control? Start with the risk.

Back to running. What were my risks? I might have a crappy time. I might not finish. I could hurt myself. I could really hurt myself.

None of those risks inherently says that I must follow a conventional running mileage program to mitigate them. Through experience and conditioning, I’ve found another way to address much of the risk. In fact, I would argue that my approach may be better for me because it reduces the pounding on my knees while maintaining a strong aerobic base.

That doesn’t mean cycling magically replaces every benefit of running. It doesn’t. Just as in information security, one control doesn’t necessarily address every dimension of a risk. My aerobic conditioning addressed one component. Running experience, limited running-specific training, pacing, and knowing my own capabilities addressed others.

The objective wasn’t to comply with a running standard.

The objective was to manage the risks well enough to achieve the desired outcome.

Seventeen miles of running wasn’t the standard way to prepare for a half marathon. But the standard wasn’t my objective. Managing the risks was.

So perhaps we should stop spending so much time debating “primary” versus “compensating” controls. Better yet, stop making controls the starting point for information security. Identify the risks. Understand the outcomes you’re trying to prevent. Then identify the combination of controls that mitigates those risks effectively and provides the resilience the organization needs.

Controls are means, not ends.

That’s how we build high performance, whether we’re talking about running a half marathon or building an information security program.

Photo: The author crossing the finish line at the 2026 Fall Creek Falls Half Marathon. Todd Temple Photography

When Not Writing is Writing

I have not put any effort into my WIP today, nor do I plan to. But that’s not to say that I haven’t been writing. No, by my estimation, I have laid down about 2500 words today. In fact, I’ve spent the better part of the day writing and editing and formatting, just not Christian fiction.

A backstory is in order (yes, I know, never in chapter one, or in the blog case, paragraph one I suppose – this is paragraph two, so I’m good). A little less than two years ago, I left the corporate word to start my own information security executive consulting company, vCISO Services, LLC. We provide executive information security consulting – part-time Chief Information Security Officer services.

I love what I do, which is servingCover2 small and midsized businesses with access to quality, experienced CISO talent. Business has been solid, and we have clients nationwide. I enjoy helping businesses, plus it is a calling – check this video for my short testimony from 2017 explaining that.

However, running a business is more than working for clients. Another aspect is working to find clients to work for. Yes, that dreaded marketing aspect that is a difficult part of being an indie writer exists in all businesses. Thus, at times I have to turn off the client side and focus on marketing. Today was that type of day.

I finished the first edition of a small guide to information security for small and midsized businesses, drawing on my two years as a consultant. What I tried to do was explain the issues that most books or websites don’t address – pragmatic advice for those who need it. At about 6500 words, it’s not a long read, but it’s enough for a giveaway in return for a newsletter list sign up.

This is where my fiction writing experience helps. I’m currently running a BookFunnel promo for my first novel to build my writing email list. This will serve the same purpose for my company list (substantially larger than my author list at the moment but growth is always good). I would not have opened a BookFunnel account if it weren’t for my fiction marketing needs. Nor would I have known about Calibre if I didn’t have a need to convert my first novel to ebook.

So – no WIP writing but much writing activity. Still sounds like a productive day.