Security Chief Officer knowledge
Last meeting, someone said "we're accepting that risk for now" and everyone nodded — including you. This course is for understanding everything said in that room: not how to do security, but how to follow it, question it, and decide about it.
There is nothing to read and nothing to watch. An assistant teaches you by conversation — in the car, on a walk — works out what you already know, skips it, and brings each idea back just before you would forget it. 44 ideas across the 4 sections written so far, of thirteen planned; the rest are generated as the course gets used.
Start in three steps
- 1.Create an account on this site — it is where your progress lives.
- 2. In Claude (on the web), open Settings → Connectors → Add custom connector, and give it
https://settingout.mouneyrac.com/mcp. It will send you back here to sign in once. - 3. Say"teach me the security course". That is the whole ritual.
Works in text or voice. Voice needs a paid Claude plan; the connector itself works on the free one.
What you will be able to follow
Every idea the course assesses, in the open. The conversations are where they come to life — this list is so you can decide in a minute whether the course is for you.
1The grammar of risk· 11 ideas
- Risk in a security meeting is never a mood but a sentence with parts — a threat exploits a vulnerability, with some likelihood, causing some impact — and likelihood and impact are separate axes that must never be merged, because a catastrophic-but-rare event and a modest-but-weekly one are entirely different conversations.
- "Could that happen to us?" deserves a checkable answer because threat actors come in knowable categories — criminals after money at scale, states after strategic value with patience and rare capability, hacktivists after attention, insiders already holding legitimate access — each with different capabilities and intents.
- Security never eliminates risk — the four treatments, accept, mitigate, transfer and avoid, are the only moves on the board, and the game is moving risk until what remains sits inside appetite.
- Residual risk is what is left after the controls have done their actual work — and it is the residual, never the raw starting risk, that gets measured against appetite and carried by a named owner.
- Risk appetite and tolerance — how much risk the company chooses to run in pursuit of its objectives, and how far off-target it will let things drift — are set from the top as a board-level decision (NIST CSF 2.0 makes them a Govern outcome, GV.RM-02), never a security-team preference.
- "We've accepted that risk" names a formal governance decision — an entry in the risk register with a named owner senior enough to carry it and a review date — and an acceptance nobody recorded or owns is exactly the failure the whole vocabulary exists to prevent.
- An exception to a policy, standard or control mandate is a risk acceptance in different clothes — same register entry, same named owner — plus one extra part, an expiry date, because a permanent exception is an unargued policy change, never a waiver.
- The risk register is a routing mechanism, not a museum catalogue — the CISO's job inside it is getting each residual risk delivered to an owner senior enough to accept it, and a risk parked with the security team or sitting unowned on a long list is undelivered mail, not managed risk.
- A heat-map cell is a subjective ordinal judgment — "likelihood 4, impact 5" means somebody ranked this above that, not that anything was measured — so arithmetic on the colours (multiplying the scores, averaging the cells, summing a total risk number) is meaningless, while comparing placements and arguing about them is the map's honest use.
- FAIR-style dollar quantification is a modeled estimate built from assumption-laden ranges, not a measurement — so boards act on the trend and on the comparison between options, and treating the absolute figure ("expected annual loss of $4.2M") as a fact is the misuse the method's own practitioners warn against.
- A number earns its place in the room by driving a decision someone can take — "87% patched" means nothing until it says which 13% remain, on what systems, trending which way — and a metric no decision hangs on is decoration, which is the test that later gets every technical programme funded or cut.
2The controls: a vocabulary· 10 ideas
- A security control is an answer to a specific class of breach, not a product or a checkbox — so the questions that open every control conversation are "what does this stop?" and "what catches what it misses?", because every control has a miss class and the next layer exists for exactly that reason.
- MFA asks for a second, different kind of proof at login — something you have or something you are, on top of the password — and it answers the stolen-password opener most breaches begin with, because a credential that was phished or bought in bulk no longer opens the door on its own.
- Patching is closing published holes on a clock — a vendor's fix announces the flaw to attackers as well, who race to weaponise it — so it answers exploitation of known vulnerabilities, and the speed of the clock is a funding decision the business owns, not a technical constant.
- Application control flips the endpoint's default from "run anything not known bad" to "run only approved code" — it answers the malware-execution class that filtering and signature antivirus never fully stop, because a blocklist cannot name tomorrow's malware and an allowlist does not have to.
- Hardening and macro restrictions are subtraction, not addition — turning off risky features that shipped enabled and that ordinary users never need — and they answer the malicious-document class that arrives by email, where an attachment's own embedded code does the breaking in.
- Restricting administrative privileges means the fewest people hold the keys and use them only when doing admin work — it answers the escalation class where one stolen login becomes estate-wide compromise, because an attacker's reach is exactly the reach of the account they landed on.
- EDR puts an agent on every endpoint watching behaviour rather than matching known signatures — it answers the attacker already inside, who walked past the perimeter with valid credentials or novel malware and is visible only by what they do next.
- Segmentation builds internal walls so one compromised machine cannot reach everything — it answers lateral movement, the spread phase where a single foothold becomes the whole network, by making the inside as guarded as the edge.
- Logging and telemetry are the recorded past — what systems wrote down as events happened — and they answer "we never saw it", because an attack in an unlogged corner can never be detected while it runs or investigated after it is found.
- Backups are the recovery of last resort against ransomware and destruction — but only if an attacker holding admin credentials cannot delete or encrypt them, and only if a full restore has actually been rehearsed, because modern crews hunt the backups before triggering the encryption.
3Who owns what: governance and accountability· 12 ideas
- Directors oversee and management executes — a board probes whether a process exists, is resourced and has been independently verified, never how the control is configured — so "how do we know?" is the board doing its job, and a management answer full of implementation detail has misread the question.
- Cyber resilience is part of every Australian director's due-diligence obligation — the Federal Court's ASIC v RI Advice decision (2022) established that failing to manage cybersecurity risk can breach a company's statutory obligations, and ASIC treats it as within directors' duty of care — so "could our directors be personally liable?" is a live question in any Australian boardroom, not APRA-sector exotica.
- Govern is the one NIST CSF function leadership performs rather than delegates — setting appetite, assigning roles, owning policy are decisions only executives can make — while the CISO executes the other five (Identify, Protect, Detect, Respond, Recover) inside the boundaries leadership set.
- The CISO's mandate is to make the business own its own risks — surfacing them and routing them to owners senior enough to accept or fund them — never to absorb them all; where the CISO reports (CIO, CEO, board) is conference chatter, because what turns on it in the room is whether that mandate holds.
- Every risk and every control has a named business owner — a person, not a team — so "that's a first-line responsibility" is a routing statement pointing at the operator who owns that risk daily, not security brushing off work.
- "Three lines of defense" says who may mark security homework — operators own their risks daily (first line), security/risk/compliance sets guardrails and oversees (second), internal audit independently verifies and answers to the audit committee, not management (third) — so "that's a first-line responsibility" is a routing decision, not a brush-off.
- Internal audit reports to the audit committee of the board, not to management — going around the CISO is the design, not distrust — and the CISO's own second-line function gets audited too, so "who checks the checkers?" has a structural answer rather than a hopeful one.
- The policy stack is a gradient of force — policies state management's intent, standards make specific requirements mandatory, procedures say how, guidelines merely advise — and a policy is a management decision that binds only as far as leadership is willing to enforce it.
- Non-discretionary requirements outrank discretionary ones — "the insurer or the regulator requires it" is the strongest currency in the room because it converts a security ask into a condition of doing business, where the only remaining question is how, not whether.
- An incident is scored on two independent ladders — an engineering SEV level measuring operational impact, and a business-legal classification measuring data, duties and disclosure — so a SEV1 outage can carry zero regulatory duty while a quiet SEV3 exposure triggers notifications, and most cross-talk in an incident room is the two ladders confused.
- "Do we have to tell anyone?" is a legal question answered from facts and clocks — what data, whose, when you knew — not a communications preference, which is why lawyers sit in incident rooms and the honest early answer is "counsel is assessing", never a reflexive "no".
- In Australia's APRA-regulated sector — banks, insurers, superannuation — Prudential Standard CPS 234 names the board itself as ultimately accountable for the entity's information security, so for those companies "the board is accountable" is not governance rhetoric but the written words of the standard.
6Identity: the modern perimeter· 11 ideas
- Most breaches now begin with a valid login — credentials stolen, phished or bought — rather than a software exploit, which makes identity the modern perimeter and the domain's standing questions who has access, whether it is still needed, and how strong the proof is that it is really them.
- Authentication proves who you are and authorization decides what you may do — two separate gates that fail differently — so a session can be genuinely you and still wrongly powerful, and letting one word stand for both is the classic confusion of any access conversation.
- SSO trades many weak doors for one strong one — a single well-defended identity provider replaces dozens of password forms — which makes the IdP the highest-value target in the company and the list of applications still outside SSO the real risk register of the identity programme.
- "We have MFA" is several different claims wearing one name — SMS codes, app codes and push approvals can all be phished or fatigued in real time, while FIDO2 passkeys bind the credential to the site and cannot be relayed — so the decision on the table is which tier is mandated for which population, not whether MFA exists.
- MFA protects the login, not the session — after authentication the browser holds a session token that infostealer malware can copy and an attacker can replay, walking in without ever seeing a password prompt — so "which factor, and was it the login or the session that was stolen?" is the post-breach question that sorts two failure modes needing different fixes.
- Non-human identities — service accounts, API keys, OAuth grants, machine credentials — outnumber the human accounts several times over and sit outside the machinery built for people, with no MFA, no offboarding when their owner leaves and often no known owner at all, which makes them the unmanaged majority of the identity estate.
- Least privilege — every account holding only what the job currently needs — is kept true or lost through the joiner-mover-leaver lifecycle, because movers accumulate access nobody removes and leavers leave orphaned accounts behind, which is why stale access and orphaned accounts are the findings every identity audit opens with.
- PAM and just-in-time access are measured by blast radius — how much damage one stolen credential can do — and their target is standing privilege, because admin rights that exist only while a task needs them mean the credential an attacker steals at two in the morning opens nothing.
- Zero trust is an architecture, not a product — NIST 800-207's model in which no network location is trusted and every request is evaluated on identity, device health and context — assembled over years from identity, device and segmentation work, never installed in a quarter.
- The zero-trust decision questions are "which pillar is weakest?" and "what legacy thing does this let us retire?" — progress is set by the weakest of the identity, device, network, application and data pillars and paid back by what gets switched off — never "which single product should we buy?".
- An access review campaign establishes that named reviewers attested to listed entitlements on a date — evidence an auditor will accept — while quietly assuming the list was complete, the reviewers understood what each entitlement grants, and approve-all fatigue did not do the deciding, which is exactly where its assurance leaks.
Sections five to thirteen — frameworks, assurance, cloud and data, software and vendors, detection, incidents, the Australian regime, AI, and money — are designed and will be generated as the first sections get real use.