Not careless ones. Not negligent ones. Organizations that had done the work and had nothing written down to show for it.
I spent a long stretch of my career working on how boards oversee cybersecurity — the SEC's disclosure expectations, the Delaware duty-of-oversight cases, the machinery of what directors are supposed to know and when they're supposed to know it.
Somewhere in there I started asking a question that seemed simple.
Almost nobody could answer it.
Not because they were hiding anything. They'd genuinely made the decision. Someone remembered the meeting. The security tool was purchased, the vendor was hired, the risk was discussed. But the record of the decision — who decided, on what date, based on what information, with what reasoning — didn't exist anywhere a regulator or a board could find it.
Organizations get into trouble after an incident less often because they lacked a control, and more often because they cannot demonstrate that leadership was engaged in the decisions around that control.
A firewall doesn't defend you in a deposition. A dashboard shows what's true today; it can't tell anyone what was true eighteen months ago on the day something mattered. And when the questions finally come — from a regulator, an insurer, a board, opposing counsel — they are almost never did you have security?
They are: what did you decide, when did you decide it, and what did you know at the time?
That's not a slogan I made up to sound clever. It's the plainest description I've found of how these situations actually resolve.
The more of this work I did, the more I ran into a specific and consistent surprise.
Organizations that had never once thought of themselves as financial institutions were sitting squarely inside a federal rule written for financial institutions. Not because of what they sell. Because of what they do.
A business can send every credit application to an outside lender, never hold a note, never call itself anything but a dealership or a shop or a practice — and still be inside the definition, because arranging financing is a financial activity.
Nobody had told them. Not their attorney, not their IT provider, not their insurer. It isn't secret information; it's just not information that travels.
That's the gap I decided to work in. Not selling security to people who already know they need it — explaining an obligation to people who don't yet know it exists, and then showing them what proof of it actually looks like.
I educate organizations that collect and protect consumers' financial information on how to document cybersecurity decisions before, during, and after a material cybersecurity incident.
I also serve as a designated Qualified Individual under 16 CFR §314.4(a) — the person the FTC Safeguards Rule requires an organization to name as responsible for overseeing its information security program.
I don't sell monitoring, scanning, remediation, or software. I'm not an IT provider and I'm not trying to become one.
I build the record. What was decided, by whom, on what date, based on what — organized so it can be produced when someone asks.
The people implementing controls shouldn't be the only ones documenting whether leadership oversaw them. That's a different job.
There's a version of this business built on fear — lead with penalty figures, imply catastrophe, sell relief. It works on some people, and I've decided not to do it.
Partly because I find it distasteful. Mostly because it produces bad outcomes: an organization that buys out of fear buys the wrong things, in the wrong order, and never understands why it owns them.
So I'll tell you what you're exempt from before I tell you what you owe. I'll tell you when something doesn't apply to you, even when saying so ends the conversation. And I'd rather you understand the reasoning well enough to challenge me than accept a conclusion because I sounded confident.
An organization that understands why a requirement exists will maintain it after I'm gone. One that was frightened into it won't.
Twenty questions, about six minutes. No sales call attached to it, and you'll know more when you finish than when you started.
Check where you stand Have a direct question? Get on my calendar
A.V. Señero is Founder and Governance Evidence Translator™ of FID Governance LLC, the Sacramento firm behind PaperTrailProof™. He serves as a designated Qualified Individual under 16 CFR §314.4(a) and educates organizations that collect consumers' financial information on FTC Safeguards Rule accountability, WISP governance, and the evidence required to show an information security program is actually operating.
Leadership is the disciplined allocation of attention toward reducing uncertainty through evidence.