SYSTEM SECURE

The most underrated cybersecurity decision of 2026 is not a procurement decision, a hiring decision, or an architecture decision. It is the decision to write down what you are not going to do this year and to defend the list against the entirely reasonable people who will, throughout the year, ask you to do those things anyway. This Sunday letter is about that list, why it matters more than its glamorous counterparts, and how to start writing it on Monday morning.

According to Gartner’s 2025 CISO research, the most consistent predictor of security program effectiveness is not budget or headcount. It is the discipline of program scope, expressed as what the program is not doing, not just what it is doing. The 2025 IBM CISO survey reinforces what every effective CISO already knows: the no list is what protects the yes list from becoming impossible to deliver.

Why the No List Has Become the Most Underrated CISO Tool

Every reasonable request that comes to a CISO over the course of the year is reasonable in isolation and unsustainable in aggregate. A new compliance framework, a new business unit, a new platform request, a new regulatory expectation, a new audit finding. Each is reasonable on its own. The CISOs who fail this year are not the ones who say yes to the wrong thing. They are the ones who say yes to everything reasonable and have nothing left to give the things that matter.

The no list is the discipline that prevents that failure mode. The list is not a set of refusals. It is a set of deferrals, with explicit reasoning, that the CISO and the executive team have agreed on at the start of the year. The list protects the work the CISO has committed to delivering, and it protects the team from the slow accumulation of well-intentioned obligations.

“The CISOs whose programs deliver in 2026 share one habit. They have a no list, the executive team has reviewed it, and the CISO defends it without apology when reasonable requests arrive in the middle of the year.”

Sunday letter reader, iSECTECH Sunday letter notes

What the No List Actually Contains

A useful no list contains 5 to 10 specific items, each with a one-sentence reason. The frameworks the program is not adopting this year. The regions the program is not expanding into yet. The platforms the program is not piloting. The compliance overlays the program is not pursuing. The internal initiatives the program is not sponsoring. The list should be readable in three minutes. It should be reviewed quarterly. It should be updated only with executive concurrence, not unilaterally by the CISO or unilaterally by any requesting business unit.

The boardroom version of the list is a single slide once a year. The board does not need every item. They need the discipline of knowing that the list exists, that it is defended, and that the CISO understands the program’s constraints clearly enough to commit to specific yeses with confidence. The slide is one of the most powerful tools in the CISO’s board engagement toolkit.

Three Habits Every CISO Should Build This Quarter

First, draft the no list this week, even if it is imperfect. The discipline of writing it begins the moment the writing begins. Second, share it with the executive team within the month, framed not as refusals but as scope discipline that protects committed work. Third, review the list quarterly with the executive team, allowing items to move from the no list to the yes list with explicit reasoning when conditions change. The combination of those three habits over a year produces the program scope discipline that durable security programs are built on.

“The CISOs I trust most are the ones who can tell me, in 30 seconds, what they are not doing this year and why. The ones who cannot answer that question are the ones whose programs will be overrun by reasonable requests before the year ends.”

Phil Venables, former Google Cloud CISO and Goldman Sachs CISO

Where the No List Belongs in the Operating Rhythm

The no list belongs in the executive team’s annual planning ritual, alongside the yes list. It belongs in the CISO’s quarterly business review, alongside the program metrics. It belongs in the conversations the CISO has with peer executives when they bring reasonable requests forward. The list is not a defensive document. It is an enabling document, and it works best when it is treated as a normal feature of how the program operates.

This Sunday letter sits inside a longer sequence on executive discipline. See the earlier letters on CEO phishing report Sunday letter, CHRO and CISO Sunday letter, and cybersecurity as practice not project. The connecting thread is unchanged. Discipline is what produces durable security programs, and discipline is built in the calendar.

Read one CISO post-mortem this week from a program that did not deliver what it committed to deliver. Pay attention to the structure of obligations the program accumulated through the year. The pattern that recurs is almost always the same: each individual addition was reasonable, and the aggregate of reasonable additions overwhelmed the program’s capacity to deliver on its original commitments.

Open a blank document on Monday morning and write down 5 to 10 things your program will not do this year. Do not edit. Do not justify. Just write. Then put the document aside for 48 hours, return to it, and refine. By Friday you will have a defensible no list. By the end of the month you will have an executive-aligned no list. By the end of the quarter you will have a program scope discipline you did not previously have.

iSECTECH works with CISOs and executive teams on building program scope discipline that protects the work the program has actually committed to deliver. If your year is already feeling like an aggregate of reasonable requests, talk to us. We will help you draft the list, align it with the executive team, and defend it through the year.

A Note on Cultural Reception

The no list is occasionally received poorly the first time it appears. Executives unfamiliar with the discipline may initially read it as resistance rather than as scope clarity. The mature pattern is to frame the list as a commitment device: the CISO is committing publicly to deliver the yes list, and the no list is what makes the commitment defensible. Framed that way, the list builds executive trust rather than eroding it, because trust is built by people who deliver what they committed to deliver and lost by people who quietly miss commitments they accumulated under pressure.

“The CISO who can say no with reasons builds more executive trust than the CISO who says yes to everything and quietly misses commitments. Trust is the slowest currency to earn and the easiest to lose by overcommitting.”

iSECTECH Sunday letter review summary

One operational nuance worth raising is governance cadence. The teams that mature fastest on CISO no list run a 90-minute review every quarter that includes engineering, security, and one executive sponsor who reports the findings into the next board meeting without translation. That single meeting, repeated four times a year, has more impact on program maturity than any tooling decision an organization will make in the same period.

Another observation from the field: most enterprise programs that fail on CISO no list fail at the handoff between teams and not at the technical decision itself. A documented handoff template, with explicit acceptance criteria and a 48-hour clarification window, eliminates more program-level risk than any architectural diagram on its own.

A note on metrics: pick three numbers, publish them internally every quarter, and refuse to report on the fourth until those three are trending in the right direction. The discipline of reporting on three numbers concentrates the conversation. Mature CISO no list programs in 2026 share that discipline almost without exception.

A final observation: the gap between the best and average CISO no list programs in 2026 is not a tooling gap. It is a discipline gap, closed one quarterly review at a time. Programs that age well are programs that show up.

A Quiet Closing Note

If you write down a no list this week and share it with one trusted executive peer by Friday, the most underrated cybersecurity decision of your 2026 will be made. Everything else in the program follows from the clarity of that list. The decision is not glamorous. The discipline is the entire point.

One last observation worth carrying into Monday morning: the no list is not a finite document. It evolves through the year as conditions change and as the executive team and the CISO learn which deferrals turned out to be the right calls and which need to be revisited sooner. The list is a conversation rather than a statute, and the conversation is what produces the program-scope discipline that quietly distinguishes effective CISOs from busy ones in 2026.