Organizations are tearing apart their workflows and rebuilding them with AI-assisted tooling, which means the shelf life of a security architecture is now measured in months rather than years. John Linford of The Open Group makes the case that open standards are not the bureaucratic drag people assume, but the only thing capable of telling a security team why a tool exists before someone buys it.
⬥EPISODE NOTES⬥
Something structural is shifting in how security work gets done. When anyone on a team can stand up a working tool in an afternoon, the constraint stops being capability and starts being coherence. John Linford, Security Portfolio Director at The Open Group, spends his time on exactly that problem, running the Security Forum, the Open Trusted Technology Forum, and the Assured Dependability Work Group, where practitioners from organizations of wildly different sizes argue their way toward standards that are supposed to survive contact with reality.
His framing of the tool question is blunt and worth stealing. When a team says it can build the thing, the first response is to ask what decision the thing informs. A dashboard showing numbers nobody was looking at before is not a security improvement, it is a new source of numbers. Standards, in this reading, are not compliance artifacts to be shown to an auditor. They are the thing that tells an organization which part of the problem a tool is supposed to solve, and how it fits alongside everything else already in place. The corollary matters just as much: when the tools themselves conform to a standard, vendors compete on the value they actually deliver rather than on the cost of switching away from them.
Linford takes the same argument up a level to architecture. Security architecture only works when it sits inside a broader enterprise and IT architecture rather than beside it, and that requires a CISO with genuine authority and a seat at the executive table. Where that authority is thin, The Open Group's Security Forum has leaned on the idea of security champions, people embedded across teams who do not need deep security skills but do need to know when to pull a specialist into the room. Getting that right moves the security conversation into the design phase, which is the only place it is cheap.
The scaling question gets an honest answer. The Open Group operates on one vote per member organization, which means a three-person shop carries the same weight in a final standard as Microsoft or RTX. That structure forces the standards to be implementable by organizations that have no security architect at all, and it shows up in deliberate choices like defining roles rather than job titles, because in a small company one person wears eight of them.
Then there is zero trust, which Linford describes with a line that circulates as a running joke inside the Security Forum: it is just what cybersecurity should have been from the beginning. The Zero Trust Commandments trace directly back to the Jericho Forum's deperimeterization work from the 1990s, and they fit on a single page on purpose. Secure assets according to their value and the damage their compromise would cause, and the spending priorities sort themselves out. The alternative, as he puts it, is announcing you will implement all five hundred-odd controls in NIST 800-53 and wishing yourself luck.
His closing point is the one most likely to sting. Security practitioners are fluent in security and frequently illiterate in business. Telling a board that twenty controls are required for conformance with the EU Cyber Resilience Act invites one question about cost. Telling them the same work opens a market and removes a year of analysis before expansion is a different conversation entirely, about the same twenty controls.
⬥GUEST⬥
John Linford, Security Portfolio Director at The Open Group | On LinkedIn: https://www.linkedin.com/in/johndouglaslinford/
⬥HOST⬥
Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/
⬥RESOURCES⬥
The Open Group | https://www.opengroup.org/
The Open Group Security Forum | https://www.opengroup.org/forum/security-forum-0
Zero Trust Commandments | https://pubs.opengroup.org/security/zero-trust-commandments/
Zero Trust Architecture at The Open Group | https://www.opengroup.org/forum/security/Zerotrust
The TOGAF Standard, 10th Edition | https://www.opengroup.org/togaf
Open Trusted Technology Forum | https://www.opengroup.org/forum/trusted-technology-forum
The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/
⬥ADDITIONAL INFORMATION⬥
🎧 More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast
📺 Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq
📰 Subscribe to The Future of Cybersecurity Newsletter | https://itspm.ag/future-of-cybersecurity
✉️ Connect with Sean Martin | https://www.seanmartin.com/
⬥KEYWORDS⬥
john linford, the open group, sean martin, zero trust, security standards, enterprise architecture, togaf, security governance, ciso leadership, security architecture, open standards, security culture, supply chain security, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast