Five Years of Building Red Sentry; Five Ways I’ve Changed My Perspective.

Five Years of Building Red Sentry; Five Ways I’ve Changed My Perspective.

Valentina Flores

CEO


Early on in my career, I had some pretty strong opinions about cybersecurity. 

And I thought I was right, because  they felt like simple logical truths. 

Ah, youth. 

The longer I work in cybersecurity, the less absolute I get, and I love that. 

Five years building a company, thousands of penetration tests, a growing team, and approximately 525,600 conversations about risk later, I still believe in many of the same fundamentals. But I understand them very differently.

So for 5 years, here are 5 things I’ve changed my perspective about: 

#1: I’ve stopped saying “humans are the biggest vulnerability.” 

Is it true? Yes. But is it helpful for any real conversation around cyber? Not really. 

Employees are the largest threat in cybersecurity the same way drivers are the largest threat on the road. Of course they’re involved in most incidents—they’re the ones using the system.

People click phishing links. They reuse passwords. They approve MFA prompts they definitely did not initiate. They share information they shouldn't. They prop open doors.

And when security controls get annoying enough, humans become extremely creative engineers.

From an attacker's perspective, sometimes exploiting a person is much easier than exploiting technology, and I still believe that.

What I've changed my mind about is what we do with that information.

People don't make decisions in a vacuum.

They're answering an email between meetings. They're trying to hit a deadline. They're helping a customer. They're following a process nobody properly explained. 

They're using the workaround their coworker showed them because the “secure” process requires six approvals, three systems, and possibly a blood sacrifice.

Sometimes an insecure decision is actually a perfectly rational decision inside the environment we've created.

If employees repeatedly work around a security control, we can keep sending them back to training.

Or—and hear me out—we could ask why everyone hates the security control.

Those lead to very different solutions.

Humans aren't something we can engineer out of cybersecurity. Humans are the environment we're securing.

The better question isn't, “How do we stop people from making mistakes?”

It's “How do we make the secure choice the one that actually makes sense?”

#2: I’ve stopped focusing on technical reports so much. 

I realize this is a slightly dangerous sentence for the CEO of a penetration testing company to write.

Obviously, cybersecurity is technical.

But there are hundreds of scanners and reports giving technical problems. You don’t need me for that. 

How I can really help you is turning that into business logic, prioritization, urgency, perspective…. A vulnerability can look terrifying on paper and mean relatively little in a specific environment. Something else can look boring until you realize what it connects to.

I've learned so many lessons about security programs in general.

  • More tools don't automatically mean more security.

  • More alerts don't automatically mean more visibility.

  • More policies don't automatically mean better behavior.

  • And more findings definitely don't automatically mean a better pentest.

Sometimes more just means…more. More dashboards nobody checks. More alerts everyone ignores. More systems nobody is completely sure who owns.

As a CEO, I've developed a much greater appreciation for simple questions:

  • Who owns this?

  • What are we protecting?

  • What happens if it breaks?

  • What should we fix first?

  • Can anyone explain why we bought this tool?

The goal isn't to build the most impressive-looking security program. It's to build one that actually works for the business it's protecting.

#3: There is no finish line, and my competitive side has to accept that. 

I love finishing things.

Pentest: done. 

Audit: passed.

Certification: achieved.

Vulnerability: remediated.

Check. Check. Check.

Unfortunately, cybersecurity has absolutely no respect for my love of checkboxes.

The company you secured yesterday isn't the company you're securing today.

Someone gets hired. Someone leaves. A vendor gets connected. An application gets deployed. A developer changes something. Someone introduces a new AI tool because apparently we all agreed we're doing that now. The environment moves constantly.

Early on, I found that frustrating. You could do everything right and still never be “done.”

Now I think that's the point. Security maturity isn't reaching some magical state where nothing bad can happen. It's building an organization that knows what to do when things inevitably change.

I love being agile way more than being stable. 

You cannot promise a company that nothing bad will ever happen. Anyone who does should make you a little nervous. But you can build a company that's really hard to knock down.

That's resilience.

And increasingly, I think that's one of the best measures of a mature security program.

#4: The Sky Is Not Always Falling.

Cybersecurity has a fear problem. And I get it. Our entire industry is built around thinking about all the horrible things that could happen.

Attackers! Ransomware! Data breaches! Nation-states! Your printer is probably plotting against you!

Early in building Red Sentry, I thought part of my job was making sure people understood all of that risk.

Here's what an attacker could do. Here's how bad this could become. Here's the worst-case scenario. Here's why you need to act RIGHT NOW.

And sometimes, yes. You do need to act right now. But not every time.

Over the years, I've learned there's a huge difference between communicating risk and creating fear.

Fear gets attention.

Understanding risk creates better decisions.

If everything is critical, nothing is critical.

If every vulnerability is an emergency, eventually people stop listening.

And if cybersecurity professionals constantly tell business leaders the sky is falling, we can't really be shocked when they eventually stop looking up.

Personally, I don't want someone buying security because we scared them enough.

I want them buying security because they understand what they're protecting, where they're exposed, what matters most, and why the investment makes sense.

Most CEOs already know cybercrime is scary. They got the memo.

What they need is someone who can tell them which of the 900 scary things actually deserve their attention.

Sometimes the most valuable thing a cybersecurity leader brings into the room isn't urgency.

It's perspective.

#5: Security Isn't the Mission.

This might be the biggest shift in how I think as a CEO.

Cybersecurity people care deeply about cybersecurity. Shocking, I know.

But for most businesses, cybersecurity isn't the mission. The mission is:

  • Treating patients.

  • Building software.

  • Moving money.

  • Serving customers.

  • Selling something.

  • Making something.

  • Whatever that organization exists to do.

Our job is to help them keep doing it.

Security controls that nobody follows aren't particularly useful.

Policies employees don't understand aren't particularly useful.

A 150-page pentest report that nobody knows how to prioritize isn't particularly useful.

And a security program that makes doing everyone's actual job nearly impossible is eventually going to create some spectacular workarounds.

The strongest security programs don't exist separately from the business. Instead, they understand the business.

  • Where is the company going?

  • How do people actually work?

  • What matters most?

  • What would genuinely hurt us?

  • Where can we accept risk?

  • Where absolutely can't we?

  • What are we protecting—and why?

That requires cybersecurity leaders to understand a lot more than technology. And we hate that.

Tech is easy! What’s harder? 

People. Operations. Revenue. Customers. Priorities. Tradeoffs. Risk.

And sometimes knowing when to say:

“Technically, I don't love this. But for the business, it makes sense.”

That's not weak security. That's mature security.

Conclusion

Five years ago, I thought experience would give me more answers. Instead, it gave me better questions, fewer absolutes, and a much better sense of what actually matters. Growth doesn’t always mean becoming more certain—it means gaining enough perspective to know when to sound the alarm, when to challenge the conventional wisdom, and when to say, “This really isn’t that deep.” 

Now that I know more about cybersecurity than I ever have, I know less about cybersecurity than I ever have. And that’s the point!

Ready to find out what's actually vulnerable?

Get your pentest scoped and priced, no guesswork on cost.

Ready to find out what's actually vulnerable?

Get your pentest scoped and priced, no guesswork on cost.

Ready to find out what's actually vulnerable?

Get your pentest scoped and priced, no guesswork on cost.