Controls Are Means, Not Ends

I ran a half marathon Sunday. I finished first in my age group. This despite a decidedly unconventional training routine.

For much of my adult life, I’ve been a fairly consistent amateur runner. I’ve never been exceptionally fast, but PRs from years past include a sub-22-minute 5K, a half marathon below 1:40, and a couple of marathons below four hours. I believe my marathon PR was 3:47 at Las Vegas in 2010, but I’m going on memory.

Over the years, I’ve learned how to train. I’ve done the 10-week mileage programs. I’ve logged hundreds of miles preparing for a single event. That’s the proven method. That’s the way you’re supposed to do it.

We say that a lot in information security, don’t we?

For this half marathon, I logged a total of about 17 miles of training runs over 10 or so weeks. Not 17 miles per week. Seventeen miles total. That includes a July 4th 5K event, a couple of fun trail runs, and a seven-mile “wake up” trail run about a week before the race.

Yet I didn’t just survive the half marathon and finish. I won my age group with a respectable time, at least for this 59-year-old male, of 2:18.

How?

I do a lot of cycling, both indoors on Zwift and outdoors mountain biking. My resting heart rate is in the 40s, and my VO2 max remains strong for my age. Those activities have built and maintained an aerobic system capable of handling much more than cycling. Years of running experience, some limited running-specific conditioning, and knowing how to pace myself took care of other parts of the equation.

In other words, I didn’t follow the conventional control. But I still addressed the underlying risks.

Back to information security.

I occasionally see discussions about “compensating controls” in a disparaging sense. One LinkedIn thread I saw recently slammed the very idea of compensating controls, arguing that we shouldn’t need them if the primary control is designed properly.

I think that misses the point.

We should not put the controls first. We should concern ourselves first with the risks we’re trying to mitigate.

Too often, “compensating control” becomes a compliance term rather than a risk-management concept. We start with a prescribed control, discover that we can’t or don’t want to implement it exactly as prescribed, and then ask what “compensating control” we can put in its place.

But why are we starting with the control? Start with the risk.

Back to running. What were my risks? I might have a crappy time. I might not finish. I could hurt myself. I could really hurt myself.

None of those risks inherently says that I must follow a conventional running mileage program to mitigate them. Through experience and conditioning, I’ve found another way to address much of the risk. In fact, I would argue that my approach may be better for me because it reduces the pounding on my knees while maintaining a strong aerobic base.

That doesn’t mean cycling magically replaces every benefit of running. It doesn’t. Just as in information security, one control doesn’t necessarily address every dimension of a risk. My aerobic conditioning addressed one component. Running experience, limited running-specific training, pacing, and knowing my own capabilities addressed others.

The objective wasn’t to comply with a running standard.

The objective was to manage the risks well enough to achieve the desired outcome.

Seventeen miles of running wasn’t the standard way to prepare for a half marathon. But the standard wasn’t my objective. Managing the risks was.

So perhaps we should stop spending so much time debating “primary” versus “compensating” controls. Better yet, stop making controls the starting point for information security. Identify the risks. Understand the outcomes you’re trying to prevent. Then identify the combination of controls that mitigates those risks effectively and provides the resilience the organization needs.

Controls are means, not ends.

That’s how we build high performance, whether we’re talking about running a half marathon or building an information security program.

Photo: The author crossing the finish line at the 2026 Fall Creek Falls Half Marathon. Todd Temple Photography

Warning Signs

An extension to situational awareness is to recognize warning signs when that awareness makes you aware of potential danger. How we react to those warning signs can have profound effects on our life, whether it be with our writing, our relationships or even with our health.frequency-309372_1280

About a year and a half ago I developed a dull pain in my left upper chest, right below the collarbone. I thought that at first I had possibly slept on it wrong, but after a month I realized this was something else. Still, I’d go days when I wouldn’t feel the dull pain, only to have it return a week or more later.

This went on for a couple of months before I decided to investigate the issue (first mistake: if concerned about health, get it checked immediately). My primary care physician diagnosed it as a “trigger point” and suggested I do a door frame stretching exercise. That really didn’t help much, both the diagnosis and the exercise. I needed to know what it was, or at least what it wasn’t.

Google searching brought up a couple of potentially serious causes. I could have bone cancer or a cardiac issue. A trip to the clinic ruled out bone cancer, though the X-ray showed some arthritis in my neck (I’m 51 so that’s to be expected). The EKG, on the other hand, informed the clinic physician of a serious heart issue and that I needed to go to the ER immediately.

I felt fine, had no history of hear issues, and considered myself to be in decent health, and so I explained that to her and asked her to provide more details. She showed me the EKG printout, circling one peak or valley, stating it wasn’t normal. Again, I felt fine, and asked for verification that the leads had been inserted in the correct sensors (I’ve that happened before, resulting in alarming readings). She verified and also pointed out my heart rate was too low – 42 beats per minute.

At that point I was pretty much sure her diagnosis was incorrect. I’m a runner so it’s not uncommon for my resting heart rate to be in the low 40s or even upper 30s. I protested and managed partial success. I didn’t need to go to the ER but I had to see a cardiologist the next day.

The cardiologist took one look at my EKG and asked me why I was there. I shrugged my shoulder and replied because the clinic told me to come. A few more questions followed with an apology for wasting my time and that I was perfectly healthy, more healthy than the majority of the 51 year males he’s seen.

Eventually working with a chiropractor produced the results I desired, a reduction of the annoying pain, but I would have been fine living with it if I had to. I did not ignore the warning signs and addressed them head on instead of ignoring and hoping the issue would go away.

What do we do when we see warning signs in our spiritual lives? Today I pray, but before I probably did a lot of things that were counterproductive. As a Christian author, I hope that the words I type somehow help others find their spiritual weaknesses and help to find a path out of the darkness.

Leaving Darkness is available at https://www.amazon.com/Leaving-Darkness-Greg-Schaffer/dp/1973644118/

Image by Clker-Free-Vector-Images from Pixabay