KELCHIN
Practice / Community

The security conversations we should have more often

Alex Kelchin · Edited English version · Russian original ↗

The most useful part of CISO Forum Club 2026 happened between the talks.

I met people at the stands who knew their products and could explain why they had made particular choices. Later, I tried to leave and ended up talking for another three hours. We compared how our security work was organised, what had failed and what had actually helped.

Those conversations were the reason the day was worthwhile.

Share what happens before the incident

We have plenty of incident retrospectives. I see much less public discussion of the everyday practices intended to prevent those incidents: how a team works, which controls it chose, what it tried and abandoned, and why a particular arrangement holds up in practice.

That leaves people learning the same lessons independently. A CISO can spend months working through something a colleague at another organisation has already dealt with.

The details make these conversations useful. What was the constraint? Who had to operate the control? Where did it get in the way? What changed after the first attempt?

Make room for the unfinished answer

Meetups, small groups and technical discussions give us space to compare those details. They do not have to produce a polished success story. “We tried this, it failed here, and this is what we changed” is often the part another team can use.

I would like more of that exchange between events too. Otherwise, we keep paying for the same mistakes one team at a time.