The recruiter’s dilemma
A puzzled recruiter recently asked me how highly experienced, deeply technical, and perfectly matched candidates were getting summarily rejected for security roles. Reaching out to contacts inside the organisation confirmed my suspicions. The inexplicable behaviour he was observing has a precise name: defensive hiring.
Defensive hiring occurs when an insecure manager intentionally recruits under-qualified or passive candidates to eliminate the threat of being outshined or replaced. While this phenomenon exists across all industries, it is dangerously acute in cybersecurity. Why? Because cyber is ceasing to be a technical discipline. It has become a political one.
Political domains select for loyalty, not capability. Fearing exposure, managers are increasingly rejecting top-tier talent in favour of “safe” hires. They are selecting for malleability over mastery, actively blocking candidates who possess the technical authority to wield influence or expose foundational gaps. Steve Jobs famously warned the dynamic triggers the “Bozo Explosion”. A fatal cycle where B-players hire C-players out of fear, sparking a self-reinforcing race to Z.
This dynamic is part of a broader organisational pathology Steve Jobs would have named cyberoptics. The tendency for cyber investment, hiring, and decision-making to be driven by optics, political theatre, and reputational signalling rather than measurable risk-mitigation outcomes. Cyberoptics explains why organisations over-invest in visible controls, under-invest in capability, and reward loyalty over competence. It is the structural fuel that accelerates defensive hiring and the Bozo Explosion.
Why cyber is uniquely vulnerable
The cyber industry is uniquely prone to this behaviour. It didn’t grow organically, it exploded. When crypto-fuelled extortion turned cybercrime into a highly profitable global enterprise, the demand for “cyber expertise” went mainstream overnight. What was once a deeply technical niche in critical infrastructure, finance, and government suddenly became a mass-market career path.
This boom gave rise to the “title-based expert.” A new generation of practitioners inherited the cyber expert moniker without ever earning their technical stripes. Today, many occupy senior leadership roles, hiding behind a façade of frameworks and policy documentation to mask the expertise they simply do not possess.
Combine this extreme information asymmetry with a high-stakes blame culture, and the instinct to hire for loyalty over competency is amplified. Insecure managers require subordinates they can easily control or use as scapegoats.
Protecting the scapegoat strategy
Cyber is a high-blame industry. When a breach happens, the board wants a head on a platter. A malleable, less-competent subordinate will panic and take the fall. A seasoned, multi-domain master, however, will have a meticulously documented paper trail proving they warned leadership about the exact vulnerability six months ago. Insecure managers hire people they can fire; they aggressively avoid people who can implicate them.
The multi-domain master
The true threat to an insecure manager is not a purely technical operator. The threat is true cross-domain cyber expertise. When a seasoned practitioner possesses cross-disciplinary fluency, seamlessly bridging governance and risk, enterprise architecture, and gritty operational reality, they become a massive political liability to a one-dimensional leader.
Dismantling the silos
Insecure leaders survive by compartmentalising security. They keep GRC, Architecture, and Security Operations in distinct silos because it makes the narrative easier to control. A multi-domain master instantly breaks those walls down:
- The GRC threat: they can look at a risk register and instantly identify which controls are purely “paper security” and which actually prevent lateral movement. They cannot be placated by a green status report.
- The Architecture threat: they understand how to map enterprise frameworks directly to business strategy, mathematically proving when a bloated vendor solution fails to integrate with the specific infrastructure.
- The Operations threat: they know exactly when a SOC is drowning in alert fatigue due to fundamentally flawed architectural design, and they know exactly where to point the finger.
The loss of information monopoly
A leader who only understands governance relies on being the exclusive translator between technical teams and the business. When a practitioner enters the room who holds advanced architectural knowledge, understands offensive security mechanics, and possesses the business acumen to explain enterprise risk to a board, the insecure leader loses their utility. The practitioner doesn’t just see the whole chessboard; they can explain the strategy to the executives better than the manager can.
The “unmanageable” problem
From a political standpoint, a multi-domain expert is incredibly difficult to manipulate. If a manager tells an IT team, “Security requires we block this integration,” a pure analyst might accept it. A multi-domain practitioner will challenge the premise, design a compensating control, and securely enable the integration anyway. They solve the exact problems that insecure managers use to justify their bloated headcount.
The AI accelerant
That paranoia is about to get a whole lot worse. AI is dismantling cybersecurity theatre by rapidly commoditising the surface-level governance and administrative tasks that title-based experts rely on to justify their existence. Roles that came into existence purely for optics, politics, or organisational theatre will become impossible to justify when AI can replicate their output instantly.
Facing obsolescence, insecure managers will experience threat rigidity and lean even harder into the one thing AI cannot replicate: political loyalty. Operating under the mistaken belief that AI will somehow compensate for a malleable team’s lack of foundational capability, they will accelerate their efforts to isolate the highly capable multi-domain master.
And their fear is justified. A seasoned practitioner combining deep cross-domain knowledge, strategic vision, and emotional intelligence, when augmented with AI is what a steam-powered loom engineer was to terrified 19th-century textile workers.
How defensive hiring rots the business
This isn’t just an HR problem; it is an operational and financial crisis actively destroying capital. Insecure leaders lack the technical depth to evaluate architecture, so they buy vendor promises instead. Because they cannot design an effective, context-aware strategy, they attempt to purchase one off the shelf. This leads to a massive misallocation of capital - spending millions on redundant tools, overlapping dashboards, and complex platforms that inevitably become shelfware. They mask this incompetence by relying on a bloated security stack that generates noise and the illusion of coverage, rather than a lean architecture that actively reduces risk.
The budget preservation play
Cybersecurity functions often command massive, sometimes unscrutinised budgets. A non-technical manager justifies their value by pointing to the millions spent on a sprawling vendor stack (“Look at all these dashboards; we are secure”). A multi-domain expert is dangerous because they advocate for simplification. They might point out that the business doesn’t need a $2 million platform, but rather a few well-configured native controls and a Python script. To the enterprise, this is a massive win. To the insecure manager, this threatens to shrink their budget, their headcount, and consequently, their perceived political power.
Operational paralysis and IT friction
Worse still, this dynamic creates severe organisational friction, paralysing the business. The greater the manager’s insecurity, the greater their compulsion to engage in turf wars and build toxic fiefdoms, driven by the delusion that cyber owns both the risk and the controls. They own neither. The business owns the risk, and IT owns the controls. Ego-driven, low-capability cyber teams consistently alienate IT administrators, guaranteeing that security initiatives are quietly ignored or actively sabotaged.
Lacking the technical skill to securely enable complex new technologies, these malleable teams default to their only available defence mechanism: blocking them. The cyber function devolves into the “Department of No,” throttling innovation, such as AI adoption, dragging down overall business growth.
How political gatekeeping works
When a manager wants to consciously reject a superior candidate without alerting HR or the executive team, they rarely do it on technical grounds. They use the system against itself:
- Weaponising “culture fit”: this is the most common execution method. A highly capable candidate who asks penetrating questions about the existing architecture during an interview is easily dismissed to HR as “combative,” “lacking soft skills,” or “not a good culture fit.”
- The certification shield: managers will intentionally write job descriptions requiring highly specific compliance certifications knowing that elite, hands-on-keyboard operators rarely waste time maintaining them. This provides a “legitimate” HR filter to quietly eliminate A-players.
- The vendor-specific trap: managers will intentionally disqualify a candidate for lacking hands-on experience with one specific platform or framework demanding CrowdStrike, for example, or TOGAF over SABSA, or NIST over ISO27001. This tactic deliberately ignores the reality that true architectural principles transcend individual products, and the anatomy of a lateral movement attack doesn’t change because of a logo.
This gatekeeping serves a dual purpose. It doesn’t just keep the multi-domain master out of the building; it actively protects the manager’s foundational reliance on vendor promises. If a leader lacks the depth to architect a lean, context-aware strategy, they survive by purchasing expensive, off-the-shelf platforms and treating the vendor’s marketing material as their security architecture. Bringing in a master of a competing platform, or worse, a master of the underlying architectural principles, introduces someone who will immediately spot the redundant tools and overlapping dashboards. By demanding extreme vendor specificity, the manager ensures they only hire technicians trained to pull the levers of the current toolset, rather than experts who will question why the machine was built that way in the first place.
5 signs of the Bozo Explosion
How does a non-technical CEO or CFO spot this rot? Here are the five leading indicators to determine whether the bozo dynamic has taken root within your security organisation:
1. The cemetery of potential
Do not just look at who the security manager hired; audit who they rejected. If you pull the CVs of the last ten rejected candidates and find a graveyard of deep technical mastery, proven track records, and capability that vastly outstrips the hiring manager, defensive hiring is actively occurring. The manager is filtering for malleability, not capability.
2. The cartel dynamic
It is standard practice for a new leader to bring over a trusted lieutenant. It is a massive red flag when they attempt to transplant their entire former team. This is not about accelerating delivery; it is about building a political fortress. Hiring exclusively from a pool of former colleagues ensures the manager is surrounded by established loyalty, insulating them from the threat of independent, highly competent outsiders.
3. The copy-paste strategy
Real security architecture is anchored in the unique operational reality of the business. The threat model for a corporate law firm looks fundamentally different from a highly decentralised retail supply chain. If the cyber strategy relies on generic heuristics, compliance checklists, and boilerplate frameworks rather than a tailored methodology, the leadership lacks the technical depth to translate business context into technical controls.
4. The Watermelon program
These are security programs that are green on the outside (status reports, compliance dashboards, paper audits) but deep red on the inside. To test for a watermelon program, executives must bypass the dashboard and commission a deep technical configuration assessment. If there is a massive disconnect between the documented controls and the actual technical reality, the department is optimising for optics, not outcomes.
5. Sanctioned shadow IT
Insecure managers protect themselves by expanding their footprint. This manifests as a bloated organisational chart filled with superficial roles that cannot be directly mapped to specific risk mitigation. The most dangerous symptom of this bloat is sanctioned shadow IT, when security teams begin building and running their own isolated infrastructure to avoid integrating with general IT. It is a structural symptom of a leader prioritising absolute control over enterprise alignment.
The brutal reality of cyber leadership
To simply label these managers as insecure ignores the brutal reality of the position. Cyber leadership is uniquely punishing. In most corporate disciplines, management is about optimising a static process. Cyber is entirely different. It is driven by an active, intelligent adversary.
You cannot govern what you do not fundamentally understand. The role requires a rigorous command of theoretical risk management, applied adversarial thinking, and deep IT infrastructure. True cybersecurity leadership rests on navigating three unyielding realities:
- The adversarial prerequisite: you cannot design a resilient defence if you lack an offensive mindset. If a leader doesn’t intuitively understand how a system actually breaks, or how an adversary chains seemingly minor vulnerabilities into a systemic breach, their concept of “risk” is nothing more than a theoretical fantasy drawn from a compliance matrix.
- The multi-domain burden: cyber leadership is ruthless because it demands cross-disciplinary fluency. A true leader must understand enterprise architecture to build the solution, offensive security to test it, and business strategy to secure the capital to fund it.
- The comprehension void: when a leader lacks this multi-domain mastery, a terrifying dynamic emerges. A practitioner comes to them to explain a complex lateral movement path. The leader literally lacks the technical vocabulary to parse the severity of the threat or challenge the logic. In that moment of complete opacity, the leader feels entirely out of control. Paranoia is the inevitable byproduct of this comprehension void.
The antidote is true capability
The antidote to defensive hiring is an operating model aggressively focused on outcomes over optics. The organisations that will survive and thrive in this environment are those willing to clear out the theatre and rebuild their security functions around absolute, undeniable capability.
The catalyst
The role of the multi-domain master has never been more pivotal. When you hire this calibre of talent, operators who possess true multi-domain mastery and adversarial fluency, AI ceases to be a disruptive threat. Instead, it becomes a massive force multiplier.
The competitive edge
Organisations that secure this tier of elite talent can fully leverage AI to strip away operational drag. Empowered by capable architecture, they can securely speed up complex technology adoption, permanently dismantle the “Department of No,” and transform cybersecurity from a bloated cost centre into a distinct, high-speed competitive advantage.
The final warning
The primary adversary the security team is fighting isn’t a hacker in Eastern Europe. It is their own leadership’s ego.
The bottom line: if your cyber leadership is hiring for loyalty to protect themselves from exposure, you are paying a massive premium for human friction. You are actively funding the paralysis of your own enterprise. Stop selecting for malleability.
Key Takeaway
When cyber leaders hire for loyalty over capability, the business funds its own paralysis. Five signs tell a board whether the rot has set in.
It is time to end the Bozo Explosion, clear out the theatre, and build an architecture grounded in reality. Because the quiet truth of the industry is this: in many organisations, the primary adversary the security team is fighting isn’t a hacker in Eastern Europe, it is their own leadership’s ego.