Skip to main content
AdvisoryBy Jason LeeJuly 22, 202611 min read

What It Takes to Build a Cyber Program in 2026 and Beyond

Every security leader can describe a busy program. Far fewer can describe a managed one. Episode three of The Blind Spot is about the difference, and the guest has spent enough time on both sides of the boardroom door to be blunt about it.

Brian Herr is the founder of Startup Starting Blocks and a security and industry advisor who runs and advises cybersecurity programs across a portfolio of companies. In some he presents to the board. In others he sits on the board as the advisor asking the questions. He is also, as Jason puts it in the intro, a friend and a mentor going back years.

The five levers that actually move a board

Brian's starting point is that boards have stopped wanting the brass tacks. Cybersecurity has become a question of how the company does business securely and compliantly, and what needs to reach the board are the things that touch five levers:

  • How are you protecting and helping grow existing money and contracts
  • How are you protecting new revenue and sales
  • How are you protecting people and community, which is where data privacy lives
  • How are you protecting the company's operations, scale, and efficiency
  • How are you handling regulatory and contractual risk

Those levers show up in every board meeting. Programs that get funded are the ones that report against them. Which lever sits at the top is entirely situational: in healthcare, people and community lead because it is life safety. In SaaS, protecting existing money, new money, and availability trade places depending on the day. In regulated and defense work, contracts and regulatory obligations rise to the top, because getting blackballed can end the company outright.

Start with the business, not the stack

When Brian takes on a new program, he does not open the tooling inventory. He interviews the technology leader, the CFO, and the CEO separately, and asks each what the most important processes and services are.

The answers, he notes, do not always line up. That gap is the first finding. From there he walks each leader through what catastrophic looks like, then high, medium, and merely annoying, sometimes in dollars and sometimes just in what impact feels like.

Then comes the exercise that reframes everything: an incident response and recovery workshop run as if the whole place is gone. How do we build it back? The map that comes out of it is a dependency tree of business processes, not technology, with protection, detection, response, and recovery examined at each node.

"When I frame the program, it starts with what does the business care about."

Two slides, and the receipts go in the appendix

Jason asks the question he has now put to multiple guests: how many slides for the board? Brian's answer matches what the show keeps hearing. Two to three.

Overall program status. What is in flight, with month to date or year to date reporting. Then something practical: what is performing, where the money is going, what percentage is allocated where, and which risk areas it is funding. The security operations dashboard, the time to response and time to remediation numbers, what Brian calls the cool kid receipts, go in the appendix for the one person who always asks.

"They don't care about bits, bytes, wires. None of that matters."

What they do want is an overall risk score showing where the program is against where it should be, a worst case to best case impact spread, and that spread set against insurance coverage. Because everyone in that room is, in Brian's framing, a money manager. The inevitable question is how do we reduce this, and the answer is either work already underway or work seeking funding. At that point it becomes a clean decision: take the risk, or spend the money.

"They want to know that someone understands the business, knows how to protect the business, and has already gone through the entire plan of how to detect, respond, and ultimately recover. That confidence is what they want in a program. The rest is fluff."

Not sure your program would survive that workshop?

Z Cyber maps your critical business processes to real protection, detection, response, and recovery, then reports it in language the board can act on.

Talk to an Advisor →

The insurance conversation nobody has early enough

Brian is direct about what he finds when he arrives: every company he goes into ends up needing its insurance redone. It is never right.

The better carriers now run serious questionnaires and price against how well the program is actually run, which rewards the work. The trap is on the other side of an incident, because getting coverage back after a breach is a different, harder, and more expensive process. There are also categories buyers assume fall under cyber that sit under an entirely different part of the policy.

His approach is to bring the business context first. He already knows from the leadership interviews what catastrophic looks like and what the real risk tolerance is, so the coverage conversation starts from reality instead of from a template. As he frames it, running a program means understanding the profit and loss statement and the insurance, not just the controls.

Cheap security has to be designed

Asked for the single tool that gives the best return, Brian does not pick a category leader. He picks data collection and telemetry.

On waste, his diagnosis is sharper than the usual shelfware complaint. When he inventories an existing shop, he typically finds tools being used at roughly ten percent of their capability, with forty to sixty percent overlap against another tool, and then another, plus the integrations and people to hold it all together.

"Cybersecurity doesn't have to be expensive. But if it's not going to be expensive, it has to be well thought out."

The design principle is integration over pedigree. Plan the stack so the platform, detection, managed response, the incident response team, forensics, recovery, and insurance all work together and have worked together before. Buying the top-rated product in every single domain is how programs get expensive quickly without getting safer. In one engagement, rebuilding along those lines saved almost fifty percent of spend, materially increased coverage, and dropped time to response to minutes. The freed budget went to the places nobody had funded yet: security around AI agents and SaaS tools, and governance for enterprise and customer-facing applications.

There is a companion insight for anyone trying to get something funded. Security pushing a purchase alone carries a stigma. The same purchase backed by compliance, IT operations, and security together tends to find budget, because it becomes spend once, use many.

"When you speak money, you speak the love language of the board and the CFO."

The rush to AI is the rush to the cloud again

Brian and Jason both remember the scramble to the cloud, when everything went up fast, got expensive faster, and nobody could say quite where anything lived. Brian sees the same pattern in the rush to AI, including the fantasy that it replaces people rather than augmenting them.

His useful move is to split the word. AI at the enterprise and customer service application layer, where language models meet customers, is a different problem with different controls than augmentation and automation at the user and data layer, where engineers and marketing teams are automating their own work. Treating them as one initiative is how governance fails.

He is also seeing security teams inherit AI governance, partly because they already do cost and use governance well, and partly because, as the IT teams tell him, security is used to being the unpopular one.

The entry level is disappearing

The part of the conversation most worth sending to someone early in their career: the low-level tasks people used to learn on are being automated, which means new practitioners are expected to arrive closer to tier two.

Brian's advice splits cleanly. Use college for the business courses, because that is what lets you run a program later. Get the hands-on skills from the community, through open source labs, inexpensive real-world training, and volunteering. He describes talking with someone who had no formal experience but ran security and networking for their church, walking them through the specifics, and concluding they had passed the gate.

Then the part that matters more than another certificate:

"We're not different. We're just farther in our career than you. And we're more than happy to share how we got here. But you have to have enough gumption to ask."

A warm referral from someone who has actually talked to you cuts through automated filtering in a way an application never will. And with teams shrinking and getting more efficient, adaptability and genuine human communication are becoming the differentiators, precisely because so much of the noise is now machine generated.

"Your program success is about the people. The tech changes. The company changes."

Burnout, and being a little wrong in the right direction

On keeping a team sharp while the threats and the tooling move overnight, Brian offers no golden answer, which is the honest one. He has watched people burn out despite his best efforts, and burned out himself.

What he does prescribe is practical: sometimes a leader has to force real time off and plan around it, because there is nothing worse than someone taking leave they badly needed and returning to a worse pile than they left. The diagnostic he and Jason both use is a calendar check. Ask when someone last took a day off, and if the answer is that they cannot because something will break without them, the problem is not the vacation. It is the single point of failure, and the fix is cross-training.

He also flags a newer failure mode: leaders comparing human output to a machine that does not sleep, and mistaking that gap for underperformance.

"Be a little wrong in the right direction and course correct along the way."

For a profession trained on getting it perfect the first time, every time, that permission is the difference between a team that learns and a team that quietly burns down.

The one question

The Blind Spot closes every episode the same way: what is the one thing you wish the other side of the conversation understood? Brian aims his answer at everyone outside the profession.

"At the core, cybersecurity people, we're all about protecting people. That's why we put the passion into it that we do. At the end of the day, we know we are protecting people."

Listen to the full episode

The full conversation runs about 39 minutes and is worth the time for anyone building, inheriting, or defending a security program right now. Watch or listen here:

Brian Herr is the founder of Startup Starting Blocks Inc. and a security and industry advisor working across a portfolio of companies, from program design and board reporting to cyber insurance and stack consolidation. New episodes of The Blind Spot are released every two weeks. If you are rebuilding a program and want it to hold up in front of a board, talk to a Z Cyber advisor.

Frequently Asked Questions

What does a well-run cybersecurity program look like in 2026?

A well-run program is organized around what the business is trying to do, not around the tool stack. It reports against five levers that show up in every board meeting: protecting existing revenue and contracts, protecting new revenue and sales, protecting people and community, protecting operations and efficiency, and handling regulatory and contractual risk. It also spends real attention on detection, response, and recovery rather than treating protection as the whole job, because nothing is perfect and boards want to know what happens when something fails.

How should a CISO report cybersecurity to the board?

Two to three slides. The first covers overall program status, the second covers what is in flight with month to date or year to date reporting, and the third is practical: what is performing, where the money is going, and which risk areas it is funding. Technical dashboards such as time to response and time to remediation belong in an appendix for the one person who asks. Boards are money managers, so pair the reporting with a best case to worst case impact range and what it would cost to reduce it, which turns the conversation into a decision they can actually make.

How can a company reduce cybersecurity tool spend without losing coverage?

Start with an inventory of what is already owned. Most organizations use roughly ten percent of a given tool and carry forty to sixty percent overlap with another tool they also pay for. Rebuilding the stack around tools that natively integrate, so that the platform, detection, managed response, incident response, forensics, recovery, and insurance all work together, can cut spend substantially while improving coverage. In one case described on the episode, that approach saved almost fifty percent of spend and dropped time to response to minutes.

How do you start a cybersecurity career now that AI is doing entry-level work?

The low-level tasks people used to learn on are increasingly automated, so new practitioners need to arrive closer to a tier two skill level. The practical path is to take business courses for the long game, get genuine hands-on experience through community training, open source labs, and volunteer work, and then build real relationships. A referral from someone who has talked to you and seen your work cuts through automated resume filtering in a way that another certificate does not.

Who is Brian Herr?

Brian Herr is the founder of Startup Starting Blocks Inc. and a security and industry advisor who runs and advises cybersecurity programs across a portfolio of companies. He presents to boards in some organizations and sits as a board advisor in others, and his work spans program design, board reporting, cyber insurance, and rebuilding tool stacks around integration. He is the guest on episode three of The Blind Spot, Z Cyber's podcast.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.