The exception that quietly became the policy
Every organisation has a policy and every organisation breaks it, which is neither scandalous nor avoidable. Systems predate rules, acquisitions arrive with their own arrangements, and a business occasionally needs to do something the standard forbids in order to make money. The exception process exists for this, and it is the most neglected mechanism in the entire field.
Neglected because it is dull, and consequential because it is where the real security posture is decided. A policy describes what an organisation intends. The exception register describes what it actually does. In most places that register is a spreadsheet, incomplete, with entries that have no expiry, no compensating measure, and an owner who left two years ago. Those entries are not deviations from the security programme; collectively they are the security programme.
A functioning version has four properties and none of them require software. Every exception expires, with a date, and the default on expiry is that it stops rather than renews. Every exception names a person senior enough to be uncomfortable signing it. Every exception states what is being done instead, even if that is nothing, because writing "nothing" is itself informative. And the whole register is reviewed by somebody outside the function that requested them.
The same neglect shows up in the one rehearsal that matters. An incident is a governance event before it is a technical one: counsel arrives, an insurer must be notified, a regulator's clock starts running in every jurisdiction where customers live, and somebody has to speak publicly within hours while the forensic picture is still incomplete. Organisations that have practised this discover the awkward questions in a conference room — who authorises paying an extortionist, who signs the customer letter, whether the chief executive or the general counsel fronts the announcement — and organisations that have not discover them at two in the morning with a journalist already holding the story.
A rehearsal worth the afternoon has a specific shape. No slides, a scenario nobody in the room helped write, the communications and legal people present rather than represented, and one deliberate complication introduced halfway through: the backups are encrypted too, or the person with the authority is on a flight. What it produces is not a plan. It is a list of decisions nobody had realised were unassigned, which is the same output as the exception register arrived at from a different direction.
Get that working and a surprising amount of the rest becomes easier. Board reporting acquires content that is genuinely about the future. Prioritisation stops being an argument about severity scores and becomes a queue ordered by what the organisation has already admitted it is uncomfortable with. And the person carrying the personal exposure discussed above has, for the first time, a record showing which decisions were theirs and which were somebody else's.