What Good Looks Like: Building a Meaning-Centric Security Organisation
What Good Looks Like: Building a Meaning-Centric Security Organisation
By Julian Brownlow Davies | Meaning In the Signal, Week 11 | 7 July 2026
I have spent this series making a diagnosis. The constraint in modern security has moved from detection to comprehension; the industry has largely failed to notice the shift and continues to invest against the old bottleneck; and the consequences of that mismatch show up everywhere, from the compliance dashboard that obscures more than it reveals to the SOC analyst quietly acquiring the empirical evidence that their judgement does not change outcomes. Diagnosis is the easier half of the work. A series that spends ten essays describing a problem owes its readers, in the eleventh, some account of what the alternative looks like, and this is my attempt to pay that debt.
I want to be careful about the form this takes, because the genre of the security maturity model is well populated and mostly useless. A meaning-centric organisation is not a destination reached by climbing a five-stage ladder, and I have no interest in adding another framework of that kind to a field already drowning in them. What I can offer is more specific and, I hope, more useful: a set of deliberate inversions. In each of the dimensions that matter - how you measure, who you hire, how work flows, what you automate, and what your culture rewards - the meaning-centric organisation does something close to the opposite of what the industry currently optimises for. The inversions are where the argument becomes practical.
Measure the Throughput of Meaning, Not the Throughput of Alerts
Everything begins with measurement, because measurement is what an organisation actually optimises for regardless of what its strategy documents claim. The dominant metrics in security operations - mean time to detect, mean time to respond, alerts triaged, tickets closed, coverage percentages - are all measures of throughput, and they all measure the throughput of the wrong thing. They measure the rate at which signal moves through the system. What matters is the rate at which the organisation develops a reasoned, contextualised understanding of what that signal means for this environment.
The objection to measuring meaning is immediate and fair: it does not fit on a dashboard. Comprehension is harder to quantify than latency, and a board would rather see a number trending in the right direction than a nuanced account of whether the organisation is getting better at understanding its own risk. I accept the difficulty. I do not accept it as a reason to keep measuring the wrong thing, because the absence of a clean metric is not the same as the absence of the thing being measured, and optimising for a convenient proxy is how organisations end up efficient at everything except the outcome they exist to produce.
The proxies for meaning are imperfect, and they are still better than what most organisations track. How often does an escalation change what the organisation does, rather than entering a backlog to be reviewed at some future window? What proportion of the security team’s time is spent on investigation - the reasoning-intensive work of understanding what a finding means - versus processing, the rule-following work of moving it through a workflow? When a finding turns out to matter, how long had the organisation been sitting on the information required to understand that it mattered? None of these is a single clean number. All of them point at comprehension rather than volume, and an organisation that watches them will make different decisions than one watching mean time to respond.
Incentives: Reward the Meaningful Finding, Not the Closed Ticket
The previous essay argued that the great advantage of the crowdsourced model is an incentive structure that behaves like a market pricing meaning - the novel, high-impact finding is worth more, and confers more standing, than the commodity one, so effort flows toward what matters without anyone directing it. The uncomfortable observation for anyone building a security organisation is that most internal incentive structures point the other way. They price activity. The analyst who closes the most tickets, triages the most alerts, and keeps the mean-time metrics moving is the one the system rewards, and the analyst who spends two days understanding a single finding that turns out to matter is, by the same metrics, underperforming.
An organisation gets the behaviour it rewards, not the behaviour its strategy documents describe, and if the reward structure prices volume then no amount of talk about comprehension will produce it. The inversion is to align the internal incentive gradient with meaning rather than throughput: to recognise, promote, and pay for the investigation that reframed the organisation’s understanding of its own risk, not merely the queue that was cleared. This is harder than it sounds, precisely because the meaningful contribution is more difficult to count than the closed ticket, but the difficulty of measuring it is not a licence to reward the thing that is easy to count instead.
The intrinsic side matters as much as the extrinsic one. The crowd harnesses curiosity as well as competition, and the same is true inside the walls. The deepest and most durable motivator for a security analyst is the restored belief that their judgement changes outcomes, which is why the feedback loop I turn to below is not only a process mechanism but a motivational one. An organisation that pays well while systematically teaching its people that their investigative work is irrelevant has not solved the motivation problem; it has papered over it, and the best people will leave for somewhere their judgement is seen to matter.
People: Hire for Investigation, Not for Operation
The second inversion concerns who you bring in and how you develop them. The industry hires, overwhelmingly, for tool proficiency - certifications, familiarity with particular platforms, the ability to operate the stack - and it develops people by training them on more tools. This produces technicians who are skilled at running the machinery and progressively less practised at the thing the machinery was supposed to support, which is investigative reasoning about what is happening in the environment.
A meaning-centric organisation hires and develops for the opposite quality. It looks for the investigative instinct - the curiosity that asks what this finding means, what an adversary would do with it, and what one would need to understand about this environment to answer that question well - and it treats tool proficiency as the easily-acquired part, because it is. This is not a romantic preference for generalists over specialists. It is a recognition that the scarce and valuable capability is contextual reasoning, and that contextual reasoning is built through investigation, mentorship, and accumulated environmental knowledge rather than through another platform certification. The value of cognitive diversity does not stop at the organisation’s boundary. A security team homogenised into uniform playbook-runners has discarded internally the very diversity of perspective that makes an external crowd valuable, and a meaning-centric organisation guards its internal cognitive diversity - of background, of instinct, of the way different people break different assumptions - as deliberately as it would seek variance from outside.
The environmental knowledge is the part most organisations neglect entirely. An analyst who knows which assets carry disproportionate strategic value, who understands the threat actor profiles most relevant to this sector, and who holds a working model of the most plausible attack paths through this specific environment can make a faster and more reliable triage decision than one reasoning from generic feeds and a configuration database. That knowledge does not come from security training. It comes from the business being willing to share what it knows about its own crown jewels, and from an organisational commitment to developing the tacit, hard-to-codify understanding that separates a researcher from a ticket-processor. Very few security training programmes develop it, because it is expensive and slow and does not produce a certificate.
Process: The Feedback Loop Is Infrastructure
The third inversion is the one I consider most important and see implemented least. In most security organisations the feedback loop - the mechanism that tells an analyst whether their judgement was correct and why - is an afterthought, if it exists at all. An escalation is raised, it disappears into a remediation process, and the analyst rarely learns whether the finding they judged significant turned out to matter, what the remediation achieved, or whether the adversary progressed or was contained. The loop that should close never does, and its absence is the direct mechanism by which talented people learn that their judgement is irrelevant.
A meaning-centric organisation treats the feedback loop as first-class infrastructure, resourced and designed with the same seriousness as the detection pipeline. When an analyst escalates a finding, the organisation ensures that the outcome flows back to them - was this significant, what did we do, what happened - because that returning signal is what allows judgement to improve and what prevents the empirical accumulation of helplessness. This is not a tooling problem, or not primarily one. It is a design choice about which loops the organisation considers worth closing, and the organisations that close it are the ones whose best analysts stay engaged over years rather than disengaging or leaving.
The same essay’s worth of thinking applies to triage itself. Triage anchored to a genuine understanding of the environment - what the crown jewels are, which attack paths lead to them, which threat actors are relevant - produces meaning. Triage anchored to a generic severity score produces a queue. The process inversion is to organise the flow of work around the paths that matter to this organisation rather than around the volume of findings the tools happen to generate, so that the scarce resource of human attention is spent where comprehension has the highest return.
Technology: Deploy AI to Augment Comprehension, and Deploy It Last
The fourth inversion is about what you automate and where in the process you apply it. The industry’s instinct is to apply automation and increasingly AI at the front of the pipeline, to detect faster and generate more signal, which accelerates production of exactly the input the organisation already cannot fully comprehend. I have argued that this is deploying the most powerful tools we have against the constraint that is not binding, and that the effect is to enrich the flood rather than to help anyone make sense of it.
The meaning-centric organisation inverts the placement. It applies automation to the parts of the work that are genuinely rule-following and reserves human judgement for the parts that require contextual reasoning, rather than the common inversion in which automation absorbs the interesting investigative work and leaves the humans processing what the playbook could not classify. It treats AI as a comprehension aid - something that helps a human understand a finding faster, that surfaces the context required to judge it, that prioritises by likely meaning rather than by generic severity - and it positions that capability as the last step before human judgement rather than the first step that generates more to judge. The validation and prioritisation layer, the part that decides what deserves a human’s scarce attention, is where the technology earns its place, and it earns it by increasing the throughput of meaning rather than the throughput of alerts.
Culture: Make the Escalation Decision Safe
The final inversion is cultural, and it underwrites all the others, because measurement, hiring, process, and technology all fail if the culture punishes the behaviour they are meant to produce. In many security organisations the escalation decision carries an asymmetric personal cost. Escalating an uncertain finding invites friction from engineering, challenge from leadership, and the implication that the analyst should have known it was noise, while the cost of failing to escalate is diffuse, deferred, and rarely attributed. Rational people respond to that asymmetry by calibrating their escalation threshold to the level at which raising a concern is personally safe rather than the level at which the risk warrants it, and they do so unconsciously, and their leadership would be genuinely troubled to learn it was happening.
The cultural inversion is to make the escalation of a well-reasoned uncertain finding an act that is recognised as good security instinct rather than treated as a failure of filtering. This is a leadership posture more than a policy: it is the difference between an organisation in which investigation is valued and one in which only closure is rewarded, between a culture that treats a thoughtful wrong call as the cost of a team that thinks and one that treats it as a mark against the individual. Psychological safety has become a slightly worn phrase, but the specific version of it that matters here is concrete. It is whether an analyst believes that bringing forward an uncertain judgement, and being wrong, is survivable. Where they believe it is not, they stop bringing forward uncertain judgements, and the organisation loses precisely the signal its most capable people are best placed to provide.
The Reset
I have called this series an argument about meaning, and I want to close it honestly, which means conceding that everything I have described here is harder than what it replaces. Volume is easy to measure, tools are easy to buy, and throughput is easy to report. Comprehension is none of those things. A meaning-centric organisation asks more of its leaders, invests in capabilities that do not produce clean metrics, and accepts a kind of difficulty that the detection-centric model allows everyone to avoid. I would not pretend otherwise, and I have spent enough time in enough organisations to know that the gap between describing this and building it is wide.
But the difficulty is not a reason to keep optimising the wrong constraint, and the industry’s continued investment against a bottleneck it crossed years ago is not made wise by the fact that the alternative is hard. The organisations that will matter in the next decade of security are the ones that recognise the shift, measure the thing that actually predicts whether they will catch what matters, and build the human capability to extract meaning from a signal environment that no longer yields it automatically. The signal is abundant and getting more so. Meaning is scarce and getting scarcer. The whole of this series has been an argument that the scarcity, not the abundance, is where the work now lies - and the organisation that internalises that is the one that will still be standing when the noise finally overwhelms everyone who mistook it for the point.
You have read a series arguing that comprehension, not detection, is the constraint that now defines security. The only question that matters is the one you can answer without me: in your own organisation, is a single pound, a single hire, or a single hour of attention currently being redirected from finding more toward understanding what you have already found - and if not, what exactly are you waiting for?