We’ve been listening to dozens of CISOs. In roundtables, peer forums, customer and prospect calls, on the record, off the record, at event floors and dinners. And the same thing keeps coming up: the security program on paper and the one running in production are rarely the same.
There’s a gap between security policy and reality.
We have researched what leading teams are actually doing to close it, and turned it into practical insights for security leaders trying to move from policy to operational reality, packaged into a whitepaper, Operationalizing Secure by Design.
Most organizations already understand Secure by Design practices, grounded in CISA’s principles of taking ownership of customer security outcomes, embracing radical transparency, and building organizational structure to support these goals, and apply them on paper.
The challenge is that shipping fast, managing legacy infrastructure, keeping decentralized teams aligned, and satisfying compliance requirements are all happening at once. And the attack surface keeps expanding regardless.
The result is a predictable failure mode: teams follow best practices on paper (such as NIST SSDF controls for threat modeling, secure coding, and periodic assessments), but attackers find the vulnerabilities that never got tested, or got deprioritized based on incomplete information.
The visibility problem is bigger than most boards realize
Boards seek assurance from CISOs and security teams. But assurance requires accurate, real-world, continuous visibility, and that’s precisely what most traditional models are failing to deliver.
Cloud adoption, API proliferation, decentralized development teams, and rapid deployment cycles have expanded the external attack surface faster than centralized governance can track. Legacy systems connect to modern infrastructure without adequate documentation, often because the original system owners have long since left the organization. Business units spin up services and tools outside formal approval processes. And annual penetration tests, by the time they’re completed, are already describing an environment that no longer exists.
The result is that most organizations are managing risk based on incomplete information. Attackers, meanwhile, are patient, targeted, and increasingly focused on application-layer weaknesses that point-in-time assessments consistently miss.
What mature programs are doing differently
The whitepaper identifies five operational shifts that distinguish leading programs from those still operating on legacy models.
Meaningful security metrics, not activity reporting. Boards and executive leadership need reporting that reflects actual risk reduction, not scan volumes or finding counts. “Total findings” is a vanity metric. “Average remediation time” is operational reality.
Mature programs track remediation speed, exploitability rates, and coverage across the attack surface, indicators that support defensible reporting and credible conversations about budget allocation. When KPIs are poorly designed, teams optimize for audits instead of reducing risk.
Continuous validation instead of periodic testing. One of the clearest trends is the growing inadequacy of annual penetration testing. Modern application environments change too quickly for point-in-time assessments to provide meaningful assurance. Replacing them with continuous, payload-based testing changes the assurance model entirely, testing internet-facing applications, APIs, authentication flows, and production attack surfaces as environments evolve.
Critically, continuous testing depends on continuous discovery: organizations cannot continuously test what they cannot continuously see.
Live asset intelligence. You cannot govern what you cannot see. Maintaining an accurate, continuously updated inventory of externally exposed assets, APIs, and services is foundational to everything else: prioritization, remediation, board reporting, and regulatory compliance. Shadow IT, unmanaged SaaS services, exposed development environments, abandoned subdomains, and unmanaged cloud services are consistently among the largest sources of untracked exposure.
This becomes especially critical during mergers and acquisitions, where live asset intelligence enables organizations to rapidly assess newly expanded attack surfaces.
Risk prioritization tied to exploitability and business impact. Risk registers often fail because they become administrative exercises rather than operational tools. A high-CVSS vulnerability in an unused legacy system isn’t the priority. A low-CVSS flaw in a payment API is.
The organizations allocating remediation effort most effectively are connecting technical risk to four factors: external exposure, verified exploitability (through payload-based testing, not signatures), business criticality, and existing compensating controls. This makes investment decisions easier to defend, both internally and to the board.
Accountability embedded across the business. Security programs that depend entirely on a centralized team do not scale. As one CSO put it: “Whenever we try to centralize stuff, we fail. Security is one of those things that traditionally end up being a gatekeeper, someone who has to say no, and then people get annoyed.”
The CISOs making the most progress are embedding accountability into role definitions, performance reviews, and security champion programs, while retaining oversight at the center. Crucially, accountability becomes self-reinforcing when findings are trusted: developers who receive high-noise alerts ignore them; developers who receive verified, exploitable findings own the fix.
Turning principles into practice: realistic timelines
The whitepaper maps these shifts to a two-horizon execution model. In the first 90 days, the focus is on immediate wins: embedding threat modeling into project workflows, establishing baseline metrics and remediation KPIs, mapping the external attack surface to reduce unidentified assets, and integrating continuous validation into release processes.
Over the multi-quarter horizon, the work shifts to organizational alignment: building cultural accountability across product teams, decentralizing governance maturity to allow process variations, aligning risk management with business metrics, and establishing shared cross-functional ownership. These changes frequently take six months or longer in complex enterprises. Failure indicators include rising remediation timelines, persistent organizational friction, and disconnects between security tooling and engineering workflows.
The strategic case for acting now
The whitepaper’s core finding is that Secure by Design is no longer a compliance initiative. It is becoming an operational discipline, and the gap between organizations that have made this shift and those still running periodic assurance models is widening. The organizations that succeed will not necessarily be the ones with the most security tooling or the largest governance frameworks. They will be the ones capable of continuously validating what is exposed, exploitable, and operationally risky across rapidly changing environments.
For CISOs navigating board expectations, budget cycles, and an expanding threat landscape, the question is no longer whether to modernize the operating model. It’s about doing it in a way that delivers measurable results, builds internal buy-in, and keeps the business moving.
The full paper covers the five operational dimensions in depth: strategy, discovery, validation, governance, and metrics, along with an overview of the implementation timelines, governance models for decentralized organizations, and the interventions that enterprise security leaders are putting into practice right now.
Download Operationalizing Secure by Design.

