It's that time of year when you get to defend your program.
You show how your practitioners improved the fabric of capabilities, and you do it without pointing out the flaws or the weakness you knew it had. We speak in risk reduction. Maturity, not gaps. That's the genre, everybody in the room understands the genre, and there is nothing dishonest about any of it.
The part worth talking about happened before that. I spent all week defending my program in my head, before the questions started.
That week matters more than the meeting does. I can make better questions than anyone else, because I know my program. Give me an hour with it and I will build the question that lands on the thing I already know is soft.
Nobody else can. The questions that come back to you grow out of a framework or last quarter's incident, which is why they keep landing in the places where you already have an answer ready.
Most of us treat preparation as rehearsal, assembling the narrative and running the delivery until it lands clean. Preparation is the hard truth exercise, and it's the only audit your program gets where the auditor already knows where the soft spots are.
The exercise runs in a different language than the meeting does. There you speak risk reduction and maturity. The exercise has to speak gaps, out loud, to yourself, or the meeting turns into the place where you learn about them.
Here are the three I built this week. How strong is your program defined, in writing, to show completeness? Does every part of the fabric have a clearly assigned owner, and are those owners aware of their ownership? Can you describe, in clear methods, the maturity of each part, and when looked at in totality, do those parts complete the fabric needed to address the risks?
Watch where your answers go. If the answer is a product name, you have not answered. A tool sitting in the environment with a default policy and nobody behind it covers exactly nothing, and the coverage map still counts it green anyway, year after year.
The answer that holds names a person, the signal that reaches them, and what they do next. Not by describing the tools, by showing how practitioners operate against risk. That version invites a follow-up question, and a follow-up is the only real evidence you were believed.
One more thing, and it is the part I did not expect. Writing it down gets you partway. Saying it out loud finds the rest, and the distance between those two is much larger than it has any right to be. Your ear notices what your eye forgives.
So, here's the MondayMove
Say your entire program out loud, start to finish, with nobody in the room. Begin at a risk you carry, talk your way through to the practitioner who acts on it, and mark every sentence your voice will not finish.
It will show you the places your program is weak before somebody else finds it for you.
Discussion