There is one sentence I hear from information security leaders more than almost any other:
“I don’t have time to do what I need to do.”
The problem usually isn’t motivation, discipline, or effort. Security leaders already work hard. The deeper problem is that their ability to handle difficult work attracts more difficult work.
Questions, approvals, exceptions, vendor reviews, audit requests, incidents, meetings, unfinished decisions, and executive concerns all flow toward the person who has demonstrated that they can carry them. Eventually, being able to handle almost anything becomes the reason the leader has time to think about almost nothing.
I wrote The Security Leader’s Operating System to help change that.

Security Leaders Don’t Need Another Productivity Trick
Most productivity systems concentrate on organizing work after it has already been accepted.
This field guide starts earlier.
Before deciding where a task belongs, it asks whether that work should exist in its current form at all. It applies the EDSAM mental model:
- Eliminate work that does not need to happen.
- Delegate outcomes that do not require the leader’s authority or judgment.
- Simplify work until it produces the smallest useful result.
- Automate the predictable parts of the work that remains.
- Maintain only what must remain under the leader’s direct care.
The objective is not to help security leaders process an endlessly growing queue more quickly. It is to redesign the system so that less work requires the leader in the first place.