<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Thinking — Outside The Box Consulting</title>
  <subtitle>Plain-English views on security, regulation, and the widening gap between the two.</subtitle>
  <link href="https://outsidethebox.io/thinking/feed.xml" rel="self"/>
  <link href="https://outsidethebox.io/thinking.html"/>
  <updated>2026-06-15T00:00:00Z</updated>
  <id>https://outsidethebox.io/thinking.html</id>
  <author><name>Outside The Box Consulting</name></author>
  <entry>
    <title>DORA isn&#39;t your problem. Your operating model is.</title>
    <link href="https://outsidethebox.io/thinking/dora-operating-model/"/>
    <updated>2026-06-15T00:00:00Z</updated>
    <id>https://outsidethebox.io/thinking/dora-operating-model/</id>
    <summary>Firms treating DORA as a compliance-mapping exercise are building a paper fortress. It&#39;s really a test of how your firm behaves under stress, and most operating models fail that long before the ICT register does.</summary>
    <content type="html">&lt;p&gt;Walk into most DORA programmes and you&#39;ll find the same artefact: a spreadsheet with several hundred rows, one per regulatory requirement, each mapped to a policy, a control, an owner and a RAG status. Months of work. Mostly green. And almost entirely beside the point.&lt;/p&gt;
&lt;p&gt;That spreadsheet answers one question: &lt;em&gt;can we show a supervisor that a document exists for each thing the regulation mentions?&lt;/em&gt; DORA asks a different question: &lt;em&gt;when something critical breaks, does your firm keep operating?&lt;/em&gt; Those are not the same question, and the gap between them is where firms are quietly failing right now — with fully green trackers.&lt;/p&gt;
&lt;h2&gt;The 2am test&lt;/h2&gt;
&lt;p&gt;Here is the scenario the regulation is actually about. It&#39;s 2am. Your payments processor — or your cloud platform, or the SaaS product your operations team lives in — has gone down, and their status page is lying to you. Their account manager isn&#39;t answering. Your service desk is fielding calls.&lt;/p&gt;
&lt;p&gt;Now the questions that matter. Who in your firm has the authority to invoke the contingency? Not &amp;quot;who is accountable on the RACI&amp;quot; — who will actually make the call, at 2am, without convening a committee? Do they know they have that authority? Have they ever used it? What triggers the decision to fail over, and what triggers the harder one — to tell customers, to tell the regulator, to start counting the hours against your impact tolerance?&lt;/p&gt;
&lt;p&gt;If the honest answer is &amp;quot;it depends who&#39;s on call&amp;quot;, your operating model has already failed the test. No register entry fixes that. The register can be immaculate and the firm can still stand in the corridor at 2am arguing about who&#39;s allowed to spend money.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;DORA is not a documentation standard. It is a behavioural test, administered at the worst possible moment, with no opportunity to resit.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is what the regulation means by resilience, underneath the articles and the technical standards. Can the firm absorb the failure of things it depends on but doesn&#39;t control? That is an operating-model property. It lives in decision rights, escalation paths, rehearsed muscle memory and contracts you&#39;ve actually read. It does not live in a spreadsheet.&lt;/p&gt;
&lt;h2&gt;The register is a symptom, not the disease&lt;/h2&gt;
&lt;p&gt;The information register gets the attention because it&#39;s tangible and auditable, and because filling it in feels like progress. Fine — you need one, and a sloppy one will earn you awkward supervisory letters. But watch what happens when a firm treats the register as the deliverable.&lt;/p&gt;
&lt;p&gt;The register says the vendor is &amp;quot;critical&amp;quot;. Nobody has decided what the firm does in the first hour of that vendor failing. The register records an exit strategy. The exit strategy is a paragraph, written by someone who left last year, describing a migration that would in reality take nine months and has never been priced. The register lists a substitute provider. Nobody has ever run so much as a tabletop of the substitution, so nobody knows the substitute needs six weeks of onboarding and a data format you don&#39;t produce.&lt;/p&gt;
&lt;p&gt;Paper resilience. It maps beautifully. It survives contact with an auditor and dies on contact with an outage. Supervisors have started noticing the difference, and the firms getting uncomfortable follow-up questions are not the ones with gaps in their registers — they&#39;re the ones whose registers are perfect and whose people can&#39;t describe what happens next.&lt;/p&gt;
&lt;h2&gt;What good actually looks like&lt;/h2&gt;
&lt;p&gt;Good is smaller and harder than the programme plan suggests. It looks like this.&lt;/p&gt;
&lt;p&gt;For each genuinely critical third party — the handful, not the hundreds — there is a severance decision that has been &lt;em&gt;tested&lt;/em&gt;, not filed. Someone senior has sat in a room and made the call under exercise conditions: we are leaving this provider, now, and here is the sequence. The exercise found the gaps a document never would: the licence that doesn&#39;t transfer, the person who is single-handedly load-bearing, the backup that restores in twelve hours rather than two.&lt;/p&gt;
&lt;p&gt;The playbooks are written in plain English, short enough to use at 2am, and the people named in them know they&#39;re named. A playbook nobody can follow under stress is a compliance artefact wearing a hard hat.&lt;/p&gt;
&lt;p&gt;And every arrangement passes the one-sentence test we apply to everything: the person living with it can say what it&#39;s for, in one sentence, without mentioning the regulator. &amp;quot;If Provider X dies, I switch to Y, it takes four hours, and I&#39;m allowed to do it on my own authority.&amp;quot; That sentence is resilience. Forty pages of mapped controls are not.&lt;/p&gt;
&lt;p&gt;The irony is that firms which build this way find the compliance falls out of the bottom almost for free. The register describes reality instead of aspiration. The testing evidence exists because the tests actually happened. The board reporting writes itself, because there is something real to report.&lt;/p&gt;
&lt;p&gt;DORA didn&#39;t create the weakness in your operating model. It just scheduled the exam.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Fix how your firm decides under stress, and DORA becomes paperwork; fix only the paperwork, and DORA becomes prophecy.&lt;/em&gt;&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>The 40-page control document is a confession.</title>
    <link href="https://outsidethebox.io/thinking/forty-page-control-document/"/>
    <updated>2026-05-14T00:00:00Z</updated>
    <id>https://outsidethebox.io/thinking/forty-page-control-document/</id>
    <summary>Length isn&#39;t rigour. When a control takes forty pages to explain, the document isn&#39;t describing it — it&#39;s hiding the fact that nobody ever agreed what it was for.</summary>
    <content type="html">&lt;p&gt;Pick up any forty-page control standard and read it as a detective would. Not for what it says — for what it&#39;s covering up.&lt;/p&gt;
&lt;p&gt;The tell is always the same. Page 3 states the control plainly enough. Then come the exceptions. The carve-out for legacy systems that risk insisted on. The alternative process for the trading floor, negotiated after they escalated. The &amp;quot;risk-based approach&amp;quot; paragraph that means the second line and engineering never agreed on scope, so someone wrote a sentence vague enough for both to sign. Three appendices of edge cases, each one the fossil of an argument that ended in a workshop instead of a decision.&lt;/p&gt;
&lt;p&gt;That&#39;s what the forty pages are. Not rigour — sediment. Every unresolved disagreement in the organisation, laminated and given a version number. The document is long precisely because nobody with authority ever said what the control was for and made it stick. Length is the confession.&lt;/p&gt;
&lt;h2&gt;Nobody works around a control they understand&lt;/h2&gt;
&lt;p&gt;Here&#39;s why this matters beyond tidiness. Controls don&#39;t fail in audits. They fail on a Tuesday afternoon, when someone with a deadline meets a requirement they can&#39;t see the point of.&lt;/p&gt;
&lt;p&gt;A person who understands what a control protects will usually cooperate with it, even when it&#39;s inconvenient — people are not stupid, and nobody wants to be the cause of the breach. A person facing forty pages of qualified, contradictory prose doesn&#39;t get the chance to understand it. They ask a colleague, the colleague shrugs, and together they find the path of least resistance. The workaround isn&#39;t rebellion. It&#39;s the only rational response to an instruction nobody can parse.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;A control your people can&#39;t explain isn&#39;t a control. It&#39;s a queue of workarounds that haven&#39;t happened yet.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So the forty-page document doesn&#39;t just record the organisation&#39;s confusion. It manufactures more of it, daily, at the exact moments the control was supposed to work.&lt;/p&gt;
&lt;h2&gt;The fix is a decision, not an edit&lt;/h2&gt;
&lt;p&gt;The tempting response is editorial: hire a technical writer, tighten the prose, get it down to twenty pages. Wrong tool. The problem was never the writing. The problem is that a decision was skipped, and the document grew to fill the space where the decision should have been.&lt;/p&gt;
&lt;p&gt;The fix is to make the decision. Ask the control&#39;s owner to complete one sentence: &lt;em&gt;this control exists so that ___&lt;/em&gt;. No sub-clauses, no &amp;quot;and also&amp;quot;, no mention of the regulator — regulations are why you must have a control, never what it&#39;s for. If the owner can&#39;t produce the sentence, you&#39;ve found the real finding, and it isn&#39;t a documentation gap. If two stakeholders produce different sentences, you&#39;ve found the argument the forty pages were burying. Have it now, with someone empowered to end it, instead of relitigating it in every review cycle.&lt;/p&gt;
&lt;p&gt;Then write down only what the sentence requires. Usually that&#39;s two or three pages: the point of the control, who does what, and what to do when it doesn&#39;t fit. The exceptions that survive are the ones the purpose justifies — the rest were never exceptions, just appeasements.&lt;/p&gt;
&lt;p&gt;We watched this play out at a mid-sized regulated firm — details blurred, pattern intact. Their access-review standard ran to thirty-eight pages and three process variants, and reviews were completed late, by bulk approval, every quarter. Managers were rubber-stamping because the document never told them what a review was &lt;em&gt;for&lt;/em&gt;. The rewrite began with one sentence: &amp;quot;this control exists so that when someone changes role, their old access dies.&amp;quot; Four pages. The variants collapsed, because once the purpose was stated, two of the three processes were visibly theatre. Completion stopped being the metric; revoked access became the metric. The reviews started catching things.&lt;/p&gt;
&lt;p&gt;Nothing about the control got weaker. It got shorter, which meant it finally got done.&lt;/p&gt;
&lt;p&gt;That&#39;s the pattern, and it generalises. Short documents are not a style preference. They are proof that somebody decided something — and a decision, unlike an appendix, is a thing people can follow at speed, under pressure, without asking permission to understand it.&lt;/p&gt;
&lt;p&gt;Next time a forty-page standard crosses your desk, don&#39;t ask who should update it. Ask what it&#39;s hiding.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The length of a control document measures the distance between your organisation and a decision it hasn&#39;t made yet.&lt;/em&gt;&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Stop showing your board heat maps.</title>
    <link href="https://outsidethebox.io/thinking/stop-showing-boards-heat-maps/"/>
    <updated>2025-12-09T00:00:00Z</updated>
    <id>https://outsidethebox.io/thinking/stop-showing-boards-heat-maps/</id>
    <summary>The red-amber-green matrix is the most successful piece of assurance theatre ever staged. What to put in the board pack instead, and why your NEDs will thank you for it.</summary>
    <content type="html">&lt;p&gt;Somewhere in your next board pack there is a five-by-five grid. Likelihood along one axis, impact along the other, a scatter of numbered dots drifting from red towards green. It will take ninety seconds of the meeting. Someone will ask about dot 7. Someone else will note that dot 12 has moved. And then the board will turn the page, having learned almost nothing, feeling almost reassured.&lt;/p&gt;
&lt;p&gt;That is the heat map&#39;s genius, and its indictment. It was never built to inform. It was built to be &lt;em&gt;finished with&lt;/em&gt;.&lt;/p&gt;
&lt;h2&gt;What the grid actually compresses away&lt;/h2&gt;
&lt;p&gt;Consider what has to be true for a dot to land on the chart. Someone judged the likelihood of, say, &amp;quot;a material cyber event&amp;quot; — a guess about an adversary&#39;s intentions, dressed as a number. Someone judged the impact — another guess, averaging away the difference between a bad week and an extinction event. The two guesses were multiplied, a piece of arithmetic with no defensible meaning, and the product was mapped to a colour chosen mainly for how it would land in the meeting. Amber, usually. Amber is the colour of not having the argument.&lt;/p&gt;
&lt;p&gt;Every decision-relevant fact died in that compression. Which service would actually stop. Whether the exposure is growing or shrinking. What we&#39;re doing about it, what that costs, and whether it&#39;s working. How confident anyone is in any of this. A heat map is what remains of a risk conversation after everything a board could act on has been boiled off.&lt;/p&gt;
&lt;p&gt;And it fails in both directions at once. It&#39;s too abstract to support a decision, and just concrete-looking enough to create the feeling that oversight has occurred. The NEDs can&#39;t interrogate it — there&#39;s nothing load-bearing to press on. Dot 9 moved from red to amber because a workshop re-scored it. Nothing in the world changed. The chart improved anyway.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The heat map&#39;s real function is to end the conversation — and the conversation is the only thing the board was there to provide.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Regulators have noticed. The supervisory question is no longer &amp;quot;does the board see cyber risk information?&amp;quot; It&#39;s &amp;quot;can the board evidence that it &lt;em&gt;challenged&lt;/em&gt; anything?&amp;quot; A page of unchallengeable colours is not just unhelpful now. It&#39;s a liability with a page number.&lt;/p&gt;
&lt;h2&gt;Give them something to judge&lt;/h2&gt;
&lt;p&gt;The board&#39;s job is not to absorb assurance. It&#39;s judgement: weighing what the executive proposes, pressing where the answers wobble, choosing between costly options under uncertainty. So give them material that judgement can grip. In practice that&#39;s a handful of plain-English questions, answered honestly, a page or two at most.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;What would hurt us most?&lt;/em&gt; Not a risk category — a scenario, in words. &amp;quot;Our claims platform is down for four days and we can&#39;t pay customers.&amp;quot; Name the two or three that would genuinely wound the firm, and say plainly how exposed we are to each, in the terms the board already thinks in: days of outage, customers affected, money.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Are we getting better or worse?&lt;/em&gt; A trend, not a temperature. Time to detect, time to recover, what the last real incident and the last exercise actually showed. Better or worse than a year ago — and if the honest answer is &amp;quot;worse, because the estate grew faster than the controls&amp;quot;, say that. Boards forgive bad news. They shouldn&#39;t forgive discovering it late.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;What did we decide last quarter, and did it work?&lt;/em&gt; This is the question almost no board pack answers, and it&#39;s the one that turns reporting into governance. We approved £800k for privileged access; here&#39;s what changed and what didn&#39;t. We accepted the risk on the legacy platform; here&#39;s what that acceptance has cost us since. Decisions that are never revisited aren&#39;t decisions — they&#39;re gestures.&lt;/p&gt;
&lt;p&gt;Notice what these three have in common: each one can be wrong. A named scenario can be challenged as the wrong scenario. A trend can be disputed. A decision review can reveal that the money bought nothing. That&#39;s the point. Judgement needs a surface with grip, and grip means falsifiable claims in plain English — not a grid that is compatible with every possible state of the world.&lt;/p&gt;
&lt;p&gt;Your NEDs will thank you, and not out of politeness. The good ones know the ninety-second heat-map ritual is theatre; they&#39;ve sat through it at every firm on their portfolio, and they know exactly what it&#39;s for. Handing them three answerable questions is handing them their actual job back.&lt;/p&gt;
&lt;p&gt;The heat map asks the board to admire your risks. The alternative asks them to govern.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;If the board can&#39;t be wrong about what you&#39;ve shown them, you haven&#39;t shown them anything.&lt;/em&gt;&lt;/p&gt;
</content>
  </entry>
</feed>
