Episode Details

Back to Episodes

When Everyone Can Build Their Own Tools, What Holds Security Together? | A Redefining CyberSecurity Podcast Conversation with John Linford, Security Portfolio Director of The Open Group

Episode 619 Published 6 hours ago
Description

EPISODE NOTES

Something structural is shifting in how security work gets done. When anyone on a team can stand up a working tool in an afternoon, the constraint stops being capability and starts being coherence. John Linford, Security Portfolio Director at The Open Group, spends his time on exactly that problem, running the Security Forum, the Open Trusted Technology Forum, and the Assured Dependability Work Group, where practitioners from organizations of wildly different sizes argue their way toward standards that are supposed to survive contact with reality.

His framing of the tool question is blunt and worth stealing. When a team says it can build the thing, the first response is to ask what decision the thing informs. A dashboard showing numbers nobody was looking at before is not a security improvement, it is a new source of numbers. Standards, in this reading, are not compliance artifacts to be shown to an auditor. They are the thing that tells an organization which part of the problem a tool is supposed to solve, and how it fits alongside everything else already in place. The corollary matters just as much: when the tools themselves conform to a standard, vendors compete on the value they actually deliver rather than on the cost of switching away from them.

Linford takes the same argument up a level to architecture. Security architecture only works when it sits inside a broader enterprise and IT architecture rather than beside it, and that requires a CISO with genuine authority and a seat at the executive table. Where that authority is thin, The Open Group's Security Forum has leaned on the idea of security champions, people embedded across teams who do not need deep security skills but do need to know when to pull a specialist into the room. Getting that right moves the security conversation into the design phase, which is the only place it is cheap.

The scaling question gets an honest answer. The Open Group operates on one vote per member organization, which means a three-person shop carries the same weight in a final standard as Microsoft or RTX. That structure forces the standards to be implementable by organizations that have no security architect at all, and it shows up in deliberate choices like defining roles rather than job titles, because in a small company one person wears eight of them.

Then there is zero trust, which Linford describes with a line that circulates as a running joke inside the Security Forum: it is just what cybersecurity should have been from the beginning. The Zero Trust Commandments trace directly back to the Jericho Forum's deperimeterization work from the 1990s, and they fit on a single page on purpose. Secure assets according to their value and the damage their compromise would cause, and the spending priorities sort themselves out. The alternative, as he puts it, is announcing you will implement all five hundred-odd controls in NIST 800-53 and wishing yourself luck.

His closing point is the one most likely to sting. Security practitioners are fluent in security and frequently illiterate in business. Telling a board that twenty controls are required for conformance with the EU Cyber Resilience Act invites one question about cost. Telling them the same work opens a market and removes a year of analysis before expansion is a different conversation entirely, about the same twenty controls.

GUEST

John Linford, Security Portfolio Director at The Open Group | On LinkedIn: https://www.linkedin.com/in/johndouglaslinford/

HOST

Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Po

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us