
Every CISSP cohort has one. The student who can recite Bell-LaPadula in his sleep, name every NIST 800-53 control family without blinking, and then freezes solid the moment I ask a question that isn’t in the book: “You’re the CISO. The board just cut your budget by 30%. What do you say in the next ten seconds?”
Silence. Sometimes a nervous laugh. Once, a grown man with fifteen years in IT literally said, “Can I use a slide?” No, my friend. You cannot use a slide. In the real incident room, nobody hands you a slide.
I’ve been one of five official ISC2 CISSP instructors in Israel for years now, and I’ve stood in front of hundreds of security professionals — bank architects, SOC leads, army veterans, a few genuinely brilliant people who could design you a Zero Trust architecture on a napkin. And here is the uncomfortable thing I’ve learned, cohort after cohort: security almost never fails because someone didn’t know the domain. It fails at the seam between domains — and between the domain and the human being who has to act on it under pressure, at 2 a.m., with the CFO calling.
The Exam Is Not the Enemy
Let me be fair to the exam. CISSP’s eight domains — from Security and Risk Management to Software Development Security — are a genuinely good map of the territory. I don’t teach it because it’s a hoop; I teach it because it forces structure onto chaos, the same way a BIA forces structure onto a company that thinks “we’ll figure it out during the incident.”
But a map is not the terrain. I’ve watched candidates ace practice exams at 92% and then, three months later, sit across from me in a real engagement unable to explain to a client’s CEO why an unpatched VPN appliance is a business risk and not just a “medium severity finding” on page 47 of a PDF nobody will open.
That gap — between knowing the control and being able to translate it into money, reputation, and consequence — is where I’ve seen almost every real breach actually begin.
The Domain That Isn’t on the Syllabus
There is no official “Domain 9: Human Improvisation Under Pressure.” There should be. In twenty years — MAMRAM, Nation-E, Comsec, BDO — I have never once seen an incident where the root cause was “we didn’t own the right product.” I have seen dozens where the control existed, on paper, beautifully, and collapsed the moment a real person had to operate it under stress.
A bank I assessed had a textbook-perfect PAM deployment — vaulted credentials, session recording, the works. CISSP Domain 5, gold star. Then during a live incident, an admin needed emergency access at 3 a.m., the vault’s approval workflow required a manager who was asleep, and someone — under pressure, trying to be helpful — shared a local admin password over WhatsApp “just this once.” That’s not a technology failure. That’s a process that never rehearsed its own exception.
Another client had a SIEM most vendors would kill for, tuned, correlated, feeding a 24/7 SOC. But analysts were measured on mean-time-to-close-ticket, not accuracy. So a genuine lateral-movement alert got closed in ninety seconds because ninety seconds looked great on the dashboard. The KPI was the incentive. The incentive shaped the behavior. The behavior became the breach.

Following Is a Skill, Not a Default
Outside the office I teach and dance sensual bachata — leading as an invitation, following as an active, trained art, not passive drift. I bring the same lens to security teams, because most breach post-mortems I’ve run describe organizations where “leading” (the policy, the CISO’s directive) was clear, but “following” (the operational team actually executing it under real conditions) was never trained as its own discipline.
You don’t hand someone a control document and assume they’ll execute it gracefully during an actual fire. You rehearse the exception. You rehearse the moment the manager is asleep, the vendor is screaming, the CFO is on the line asking why the website is down. In dance, an untrained follower freezes or overcorrects the instant the lead does something unexpected. In security, an untrained team does exactly the same thing — and the incident report calls it “human error,” when really it’s “we never practiced the hard part.”
Where the Real Money Gets Lost
Here is the number that should worry every board: in the majority of the enterprise risk assessments I’ve run at BDO — banks, industrials, public-sector clients across Israel and Europe — the technical control existed. The finding was almost always about ownership, escalation, or translation: nobody knew who was accountable when the alert fired at an inconvenient hour, or the control was designed by someone who never had to explain its absence to a room full of people holding the company’s P&L.
That’s the F1-brakes conversation again, in a different outfit. Brakes don’t exist so you drive slowly. They exist so you can go fast and still make the corner. A control that nobody can operate under real pressure isn’t a brake — it’s a decoration bolted onto the chassis for the inspection.

What I Now Teach Differently
These days, when I run the CISSP course — or the CAIO course, where the stakes of translation are arguably higher because the board barely understands what an AI agent even is — I spend deliberately more time on the seam than on the domain. I ask candidates to defend a control decision to a hostile board, not just describe it. I run tabletop exercises where the “correct” textbook answer is deliberately unavailable — the approving manager is asleep, the budget got cut, the vendor is unreachable — because that is the exam that actually gets administered, by reality, without a syllabus.
Practical Takeaways
- Certify translation, not just recitation. In every tabletop or awareness session, force the technical lead to explain the risk in money and reputation terms to a non-technical “board,” live, without slides.
- Rehearse the exception, not the happy path. Your PAM, your escalation flow, your BIA — all of them need a drill where the approving manager is unreachable. That’s when you find the WhatsApp password.
- Audit your incentives, not just your controls. If your SOC is measured on speed of closure rather than accuracy of triage, you’ve built the ninety-second blind spot yourself.
- Treat “following” as a trained skill. Operational teams need deliberate practice executing policy under pressure — not a document handed down and assumed absorbed.
Back in the Lecture Hall
That student who froze on the budget-cut question came back to the same seat six months later, in a different cohort, auditing the module again. This time I asked him the same question. He didn’t reach for a slide. He looked at me and said: “I’d tell the board what we stop being able to detect for the next ninety days, and what that’s worth if it happens once.” That’s it. That’s the whole exam, right there — not the domain, the translation. He passed CISSP a month later. But he’d already passed the exam that matters.
If this resonated, I’d genuinely like to hear your own version of “the domain that isn’t on the syllabus” — come find me and connect on LinkedIn: https://www.linkedin.com/in/omri-sagron-cissp-24508331/
I write From the CISO’s Diary from 20 years across BDO, ThriveDX, the IDF and my own ventures. Let’s connect: Omri Sagron on LinkedIn.