# The CISO's Craft: Watchmaker or Gardener?

DevFeed: [The CISO's Craft: Watchmaker or Gardener?](<https://devfeed.tech/articles/the-ciso-s-craft-watchmaker-or-gardener-39499.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/the-ciso-s-craft-watchmaker-or-gardener>)

Author: Phil Venables

Published: 2026-01-24T16:39:53Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [craft](<https://devfeed.tech/tags/craft.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [precision](<https://devfeed.tech/tags/precision.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article considers whether security leaders should operate more like precise watchmakers, adaptive gardeners, or both when leading organizational transformations. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

## Source excerpt

Some time ago I saw a comment about the distinction between acting like a "watchmaker" or a "gardener" when undertaking organization transformations. I misplaced the original reference so, unfortunately, I can't credit appropriately. But, I've been thinking a lot about what this would mean in the context of security leadership. Specifically, should the CISO be a watchmaker or a gardener, or both? The Watchmaker CISO: Precision and Control Imagine a master watchmaker, meticulously crafting...