Notes in the margin¶
The ways security programmes fail tend to rhyme, and few of them are technical. A finding lands as blame, so the report gets softened. No one in the room has the authority to act on it. A threat model describes the network as it was assumed to be eighteen months ago, and the same class of incident arrives on a quarterly cycle. None of that is a tooling gap.
Gerald Weinberg spent decades watching software teams work under pressure. Virginia Satir spent hers on how people communicate when they feel threatened. The adult Montessori framing turns both into a way of designing places where people actually learn. Read together, they change what gets looked at, what gets asked, and what counts as a finding.
- Other ways of looking
- Limits and uses of these foundations
- Problem-solving leadership in security
- Change in security organisations
- Security system effectiveness
- Organisational development for security
- Learning at one’s own pace, in one’s own direction
- The prepared environment
- Self-directed learning
- Hands-on materials and exercises
- Facilitation over instruction
- Reflection and feedback loops
- Learning culture
- Rotation programmes
- Gamified scenarios
- CTFs as learning environments
- Defensive skills for attackers
- Book review: The discovery of the child
- Book review: The secret of childhood
- Book review: From childhood to adolescence
- Book review: To educate the human potential
Last updated: 1 July 2026