My security education started on the offensive side. CEH taught me to think like someone trying to get in; CHFI taught me to think like someone reconstructing what happened after they did. Both are valuable, and both left me with a slightly dangerous confidence — the feeling that if I could think like an attacker, I understood security. Then I sat CISA, and the auditor's chair turned that confidence on its head.

Because the auditor doesn't ask "is this secure?" The auditor asks "can you prove it's secure, to someone who has no reason to take your word for it?" Those are very different questions, and the gap between them is where most real-world security quietly fails. I've come to think the audit mindset is the most underrated thing in the whole discipline — and in a 2026 threat landscape that's meaner than the one I trained in, it's the mindset that actually holds up.

1. Poacher to gamekeeper

The offensive mindset is seductive because it's concrete. You find a hole, you demonstrate it, you feel clever. But it has a blind spot: it optimises for the exciting failure, the clever exploit, the thing that makes a good war story. Most breaches aren't clever. They're a disabled log, an expired certificate nobody renewed, an offboarded employee whose access lingered for months, a backup that was never tested. Boring, systemic, and invisible to someone only looking for the exciting way in.

CISA retrained my attention onto exactly that boring, systemic layer. The auditor's question — show me the evidence this control operated, every time, over the period — surfaces the rot that attacker-thinking skips right over. I stopped asking only "how would I break in?" and started also asking "if I had to prove to a hostile reviewer that this environment is controlled, where would I fall apart?" That second question found far more real problems than the first ever did.

2. Evidence, not assurances

The phrase I took from CISA and never let go of is "evidence, not assurances." In IT we run on assurances — "yes, we patch," "of course we review access," "backups are handled." An auditor accepts none of it. Show the patch report. Show the access review with dates and sign-off. Show the successful restore. If it isn't evidenced, as far as the audit is concerned it didn't happen, and — this is the part that changed me — as far as reality is concerned it probably didn't either.

Running my own estates, I started holding myself to that standard before anyone external could. Not "we have a process" but "here is the artefact that proves the process ran." It's more work, and it's the difference between believing you're in control and actually being in control. The belief is comfortable. The evidence is true.

An assurance is a story you tell yourself. Evidence is what survives contact with someone who doesn't trust you. Run your estate for the second one.

3. The controls that survive both the audit and the attacker

Here's what I find reassuring: the controls an auditor cares about and the controls that actually stop a 2026 attacker are, overwhelmingly, the same controls. Ransomware this year runs on multi-extortion — encrypt the data, steal a copy, threaten to leak it — and the thing that defeats it isn't magic, it's immutable, tested backups plus tight identity, exactly what an auditor asks you to evidence. Attackers increasingly get in through stolen identity rather than clever exploits, and the defence is MFA, conditional access and prompt de-provisioning — again, straight off the audit checklist.

That convergence is the whole argument for the audit mindset. You are not choosing between "satisfying the auditor" and "stopping the attacker." Done honestly, they're the same program of work. The organisations that treat audit as a box-ticking distraction from real security have misunderstood both.

4. The front door hasn't moved — but the lock-picks got better

If there's one place the threat landscape has genuinely shifted since I trained, it's the quality of the attempt at the front door. Email is still where most incidents begin, but business email compromise now costs organisations billions a year, and the messages themselves have levelled up. AI writes them now — clean grammar, correct local idiom, your company's tone, tailored to the recipient's role. The tells we taught users to spot are gone. Voice phishing has climbed to become one of the top initial-access methods, because a convincing phone call sidesteps every email filter you own.

The auditor's response to this is unglamorous and correct: don't rely on humans being perfect. Evidence the technical controls that don't depend on someone spotting a fake — domain authentication so your brand can't be spoofed, filtering that catches what it can, MFA so a stolen password isn't game over, and a verification step for anything that moves money or changes payment details, no matter how legitimate the request sounds. You can't audit "our staff are vigilant." You can audit whether the controls that survive a vigilant-staff failure are actually in place.

5. Risk you accept versus risk you ignore

CRISC added the last piece, and it's a distinction most technical people get wrong: there's a world of difference between a risk you've accepted and a risk you've ignored. An accepted risk has a name, an owner, a documented decision that someone with the authority to make it looked at the exposure and chose to live with it. An ignored risk is just a landmine nobody's admitted is there. The two can look identical on a quiet day. They look very different the morning after an incident, when the question becomes "did anyone decide this was acceptable, or did we just never look?"

So I run a real risk register — not the audit-theatre kind that gets updated once a year, but a living record of the exposures I know about, who owns each, and what we've decided to do. It means that when something does go wrong, I can show it was a considered decision rather than negligence. That's not just good governance; in a regulated environment it's the difference between a defensible position and an indefensible one.

6. Run it like the audit is tomorrow

The habit all of this collapses into is simple to state and hard to live: run your estate as though a competent, sceptical auditor is arriving tomorrow morning. Not in a panic — as a standing posture. Could you produce the evidence, today, that your controls are operating? If yes, you're almost certainly also in decent shape against the actual threats, because the controls overlap so heavily. If the honest answer is "I'd have to scramble," that scramble is the exact gap an attacker is looking for.

Coming from the offensive side, I resisted this for years — it felt like paperwork getting in the way of real security. I had it backwards. The auditor's discipline is real security; it's just security that has to prove itself rather than merely feel confident. If you're trying to move an estate from "we think we're fine" to "we can show we're fine," I'm happy to talk it through.