September 20, 2026
What’s Stopping You? Starting Before You Feel Ready
I recently spent five days in Sydney attending SANS LDR514: Cybersecurity Strategic Planning, Policy, and Leadership.
By Paul Adrian Peña
6 min read
I expected to come home thinking about cybersecurity strategy and leadership.
I didn't expect to come home thinking about a cyborg corgi, my beginnings as a software developer, and a question from my instructor that I haven't been able to stop thinking about:
"What's stopping you?"
But perhaps I should start at the beginning.
Five days thinking about leadership
I attended LDR514 because I wanted to become a better security leader.
Over five days, we explored strategic planning, creating a vision and mission for a security team, stakeholder management, developing and inspiring people, and communicating security priorities across an organisation.
There was a lot to take away.
But what stayed with me wasn't a particular framework or methodology.
It was thinking about the kind of leader I want to become.
I've spent years working in information security, particularly in governance, risk and compliance. I've managed people and security programmes, worked through audits and risks, and collaborated with technical teams and senior stakeholders.
But being good at security doesn't automatically make someone a good security leader.
Leadership requires something else.
One concept that particularly resonated with me was servant leadership.
For me, servant leadership means recognising that my role isn't to have all the answers. It is to create an environment where my people can succeed — removing obstacles, developing their capabilities, giving them opportunities and helping them become better at what they do.
The course made me reflect on how I lead today and how I want to develop as a leader.
It also made me realise that sometimes we are already applying leadership principles without consciously putting a name to them.
Which brings me to a corgi.
Apparently, cybersecurity leaders are marketers too
During a discussion about stakeholder management, our instructor, Melissa Bischoping, said something that immediately caught my attention:
Security leaders need to be good at marketing too.
Marketing?
It isn't necessarily the first skill that comes to mind when you think about cybersecurity leadership.
But I immediately thought about something I'd done with my own security team.
Like many security teams, we had an image problem.
Security can easily become known as the serious team.
The team that asks difficult questions.
The team that introduces controls.
The team that finds something wrong with what you've built.
Or, perhaps worst of all:
The team that says "no".
That wasn't the relationship I wanted us to have with the organisation.
Our job wasn't to stop people from doing things.
Our job was to help the business develop secure products and provide secure services to our customers.
So I tried something different.
I created a mascot.
A cyborg corgi.
His name was Cycorgi.
A lot of people in our organisation love pets, so a corgi was immediately relatable. But this wasn't an ordinary corgi. Cycorgi had futuristic armour, cybernetic technology and a distinctly cybersecurity personality.
I started putting him into our presentations.
Then into more presentations.
Eventually, people began recognising him.
And something interesting happened.
People liked Cycorgi.
Security communications became a little more approachable. Presentations became a little more engaging. People started associating our team with something other than policies, controls, audits and the word "no".
Cycorgi gradually became part of our team's identity.
The funny thing is that I never thought of this as marketing.
There was no grand branding strategy behind it.
I simply wanted to improve our relationship with the people we worked with.
Listening to Melissa explain that security leaders also need to understand marketing made something click.
Cycorgi had been a marketing decision. I just hadn't realised it at the time.
We weren't marketing a product.
We were changing how people perceived and engaged with security.
And that matters.
We can have excellent policies, frameworks and controls, but if people avoid engaging with the security team, we've created another problem.
Security depends on influence.
And influence depends on relationships.
Sometimes leadership means changing those relationships.
I thought that was the end of my lesson about branding.
It wasn't.
Then Melissa turned the question towards me
On the final day of the course, I spoke with Melissa about becoming more involved with SANS.
I told her I was interested in helping as a teaching assistant and, perhaps one day, becoming an instructor myself.
Teaching has increasingly interested me because I've reached a point in my career where I don't just want to continue learning. I want to share some of what I've learned with others.
Melissa explained that having examples of speaking engagements, presentations or videos could help demonstrate my ability to communicate and teach.
That conversation led us back to branding.
Except this time, we weren't talking about a security team's brand.
We were talking about mine.
Then she asked:
"What's stopping you?"
That was harder to answer.
Because this time I couldn't hide behind a framework, strategy or cyborg corgi.
The answer was me.
I wasn't sure anyone would listen
I had doubts.
I didn't know where to start.
I didn't know whether I could speak well enough to attract people's attention.
Would anyone actually be interested in what I had to say?
Could I communicate my ideas clearly enough that they would make sense to someone else?
What if I put something out there and nobody cared?
There were plenty of reasons I could give myself for waiting.
Then I realised something.
I've been here before.
I used to avoid the security people
Before working in information security, I was a software developer.
And I have a confession.
The security people were sometimes the people I wanted to avoid.
They were the people who might look at what we were building and point out the vulnerabilities we'd just introduced.
You'd submit a pull request feeling pretty good about your work, and someone from security might come along and explain all the creative ways it could be abused.
Then, somehow, I ended up becoming one of them.
When I decided to move into information security, I wasn't ready either.
I didn't have years of cybersecurity experience.
I didn't have an impressive collection of security certifications.
I hadn't completed specialised security training.
There were people in the industry who knew vastly more than I did.
I could have looked at all of that and decided:
Maybe I'll start when I'm ready.
But I wanted to work in security.
So I started.
I learned.
I made mistakes.
I asked questions.
I worked with people who knew far more than I did.
And I kept learning.
Eventually, information security stopped being the field I was trying to enter.
It became my career.
The pattern suddenly looked familiar
Sitting in Sydney years later, I realised I was doing the same thing again.
When I wanted to enter cybersecurity, I thought I needed more knowledge and experience before I could belong.
Now I wanted to write, speak and perhaps eventually teach, and I was telling myself I needed more confidence and experience before I could begin.
Different goal.
Same hesitation.
And Melissa had reduced the whole problem to four words:
What's stopping you?
Perhaps the answer wasn't a lack of knowledge.
Perhaps it wasn't my speaking ability.
Perhaps it wasn't that I didn't have anything useful to say.
Perhaps I was simply waiting to feel ready.
And experience should have taught me something by now:
Feeling ready and being ready aren't necessarily the same thing.
Nobody starts with their tenth presentation
There will always be another certification I could earn.
Another course I could complete.
Another year of experience I could accumulate.
Another presentation I could practise.
Another article I could rewrite before showing anyone.
If I wait until I feel completely ready, there will always be another reason to wait.
But there has to be a first article.
There has to be a first presentation.
There has to be a first video.
There has to be a first time standing in front of an audience wondering whether what you're about to say will connect with anyone.
Nobody starts with their tenth presentation.
They start with their first.
So this is mine
This article is part of that start.
I want to share what I've learned — and what I'm still learning — about cybersecurity governance, risk, compliance, security leadership and AI governance.
But I also want to talk about the parts of a cybersecurity career that don't fit neatly inside standards and frameworks.
Leadership.
Communication.
Mistakes.
Career transitions.
Developing people.
Building relationships.
And apparently, occasionally using a cyborg corgi to make cybersecurity more approachable.
I'd eventually like to teach more formally.
Maybe that journey will take me towards becoming a SANS instructor.
Maybe it will lead somewhere I haven't considered yet.
For now, I'm less concerned about where it ends.
I'm more interested in starting.
Because somewhere out there may be another software developer looking at cybersecurity the way I once did.
Maybe they don't have the certifications.
Maybe they don't have formal security training.
Maybe everyone else seems to know more than they do.
Maybe they're wondering whether they belong.
I can't tell them exactly where their journey will lead.
But I can tell them what worked for me.
I started.
Then I kept learning.
And years later, standing at another starting line, perhaps it's time I took my own advice.
So, thank you, Melissa, for asking the uncomfortable question.
I think I finally have my answer.
Nothing.
And this is me starting.