The Room that mattered
Your security advisor might be doing excellent work. You might never see the results of it.
A pattern that I see more often that I'd like
A founder hires a vCISO or security consultant. The CTO becomes the internal counterpart — the person who approves, implements, and advances the security agenda. It's a natural arrangement. The CTO speaks the language, understands the technical context, and can engage.
What nobody notices is that the CTO has also become a filter.
Every insight the advisor produces gets translated before it reaches the CEO or the board. Risk assessments become status updates. The connection between security posture and business outcomes — revenue protection, enterprise deals, regulatory clearance — gets simplified somewhere between the advisor's report and the room that actually makes decisions.
The advisor thinks the work is landing. The CTO thinks they're helping. The CEO is making decisions without the full picture.
Nobody is doing anything wrong. That's what makes it hard to see.
I know this pattern because I was on the wrong side of it once
One of my early clients replaced me. Not because my work was wrong — the findings were sound, the framework was right, the controls I recommended were appropriate. They replaced me because my work never reached the person who needed to hear it.
The CTO was my counterpart. Capable, engaged, genuinely committed to doing the right thing. He was also, without either of us realising it, translating everything I produced before it reached the CEO.
I was solving the room that the CTO gave me. Not the room that mattered.
I noticed something on the occasions when the CTO wasn't available. Those conversations with the CEO felt different. Not easier exactly, but more direct. There was no translation layer. I had to explain things in terms he already cared about, and when I did, something landed differently.
I just didn't understand what I was observing until it was too late.
The firm that replaced me could speak that language fluently. They'd learned what I hadn't yet: that the counterpart and the decision-maker are not always the same person. And when the CTO is acting as a buffer — even a well-meaning one — your best security work never reaches the person whose conviction you actually need.
What this means if you're a founder or CEO
If you've hired a security advisor and your board still doesn't seem to get it — if security feels like a cost center rather than a business decision — the problem might not be the quality of the work. It might be where the conversation is happening.
Ask yourself: when did you last sit in a security conversation directly? Not a status update. Not a summary from your CTO. The actual conversation about what your exposure is, what it costs you, and what you're doing about it.
If the honest answer is never, you might be the CEO in my story. And your security advisor might be doing work you'll never fully benefit from.
The counterpart and the decision-maker are not always the same person. The best security programs I've seen are the ones where the CEO knows enough to ask hard questions — not because they've become technical, but because someone made security legible in the language they already think in.
That's the room that matters. Make sure you're in it.
If this resonates, I'm happy to talk through what it looks like in practice. No deck, no pitch — just a conversation: paolo@bare-consult.nl
