Last Updated on November 26, 2016 by Dave Farquhar
Explaining security is really hard, but sometimes a sports analogy helps. Here’s an appropriate sports analogy for security.
Imagine you’re playing a sport. The sport doesn’t matter. What matters is you’re playing, and so is the opponent, and you have to follow the rules while they don’t. But you still have to prevent them from scoring.
But it’s more complicated than that. Imagine there’s another game going on, either adjacent to the field or within the field. That’s the business. Whatever you do can’t interfere with that second game, and you also have to keep your cheating opponent from interfering with that second game. And your success at preventing interference with that second game is how you’re going to be judged.

David Farquhar is a computer security professional, entrepreneur, and author. He has written professionally about computers since 1991, so he was writing about retro computers when they were still new. He has been working in IT professionally since 1994 and has specialized in vulnerability management since 2013. He holds Security+ and CISSP certifications. Today he blogs five times a week, mostly about retro computers and retro gaming covering the time period from 1975 to 2000.

That is a freakishly excellent way to putting the Business of security into context.