When Silence Becomes a Security Vulnerability
The most important security control in the room may be the person who feels safe enough to say, “I think we missed something.”
Over two days last week, I had the privilege of supporting a Xebia security workshop led by Yianna Paris.
Yianna guided participants through social engineering, pipeline security, credential theft, vulnerable dependencies, data poisoning, prompt injection, model attacks, guardrails, and hands-on labs. Her expertise was visible not only in what she knew, but in how she taught us to think: question what a system appears to promise, follow its trust boundaries, and search for where that promise might break.
Martín Pérez Rodríguez and I joined as supporting facilitators, each contributing a shorter perspective. Martín brought additional insight from security, cloud, and DevSecOps.
I entered from a different direction.
I am not a security expert. I have, however, spent more than two decades in software engineering and engineering leadership. I have been the developer being asked to move faster. I have led teams through risk, incidents, releases, transformation, and uncertainty.
Today, my work goes deeper into the human layers beneath behavior: the convictions we defend, the values we need honored, the nervous systems we carry into rooms, and the dragons that learned long ago how to protect us.
I was not there to teach security professionals how to secure a pipeline.
I was there to notice what was happening between the people standing beside it..
The room knew how to find threats
On the first day, participants learned to identify assets, map attack paths, question trust boundaries, and consider what could be spoofed, tampered with, exposed, interrupted, or accessed without permission.
Then they reviewed one another’s work.
The assignment was not simply to listen. It was to challenge.
Yet the room became remarkably polite.
People explained their thinking. Their peers nodded. They discussed possibilities. But very few pushed into the uncomfortable questions:
💚 What assumption are you making here?
💚 How do you know that control will work?
💚 What happens if the person with access is already inside?
💚 What have you not considered?
They were learning to think like attackers, but they were still hesitant to challenge one another.
That stayed with me.
Because a team can know how to recognize a vulnerability and still be unable to speak about one.
We often imagine security failure as a gap in the code, a leaked credential, a malicious dependency, a badly configured cloud service, or an AI agent given too much authority. But there is another kind of exposure, one that rarely appears on an architecture diagram.
🔥 The engineer who notices something and doubts whether they know enough to say it.
🔥 The junior colleague who sees a weakness but does not want to embarrass the senior person who designed the system.
🔥 The security professional whose previous warnings were received as obstruction.
🔥 The employee who made a mistake and has watched what happens to people who admit mistakes here.
🔥 The person from a culture in which challenging authority is not interpreted as engagement, but as disrespect.
🔥 The team under so much delivery pressure that pausing feels more dangerous than proceeding.
These are not weaknesses a scanner can detect.
But they can leave a system wide open.
A crying baby opened the account
The second day began with a social-engineering demonstration.
A caller used urgency, confusion, emotional pressure, and the sound of a crying baby to persuade a support employee to reveal information and change access to someone else’s mobile account.
No advanced exploit was required.
The attacker understood the human being on the other end of the line: the desire to help, the discomfort of prolonging distress, and the instinct to resolve a believable emergency quickly.
The lesson seemed obvious: attackers exploit human psychology.
But I found myself thinking about what happens inside our organizations too.
Attackers exploit belonging, trust, urgency, helpfulness, fear, and authority from outside the system.
Unsafe cultures can activate those same forces from within it.
“Do not slow the release.”
“Everyone else already agreed.”
“The architect knows more than you.”
“We cannot tell the customer yet.”
“Do not bring me a problem unless you have the solution.”
“Are you sure this is serious enough to escalate?”
Nobody needs to say these sentences aloud for people to feel them. Culture teaches us what is safe through repetition: whose questions receive curiosity, whose mistakes receive compassion, whose concerns receive action, and who pays a price for making the room uncomfortable.
That is when silence becomes a security vulnerability.
What was protecting the silence?
I asked the participants to reflect on what might prevent them from raising a concern.
Their answers filled the glass:
Fear. Anxiety. Time pressure. Lack of experience. Insufficient knowledge. Delivery expectations. Too many people in the room. Inadequate support. The possibility of getting somebody else into trouble. The fear of losing belonging.
None of these answers meant that they did not care about security.
Quite the opposite.
They revealed the competing risks people carry inside themselves. There may be a technical risk in remaining silent, but there can also be an immediate social risk in speaking.
🖤 Will I look incompetent?
🖤 Will I be called difficult?
🖤 Will this damage my career?
🖤 Will the group still want me here?
🖤 Will I hurt someone I respect?
🖤 Will anything change, or will I simply make myself vulnerable?
This is where my layered personality model becomes relevant.
What we see is behavior: silence, agreement, defensiveness, anger, compliance, or challenge.
Below that behavior may sit a conviction:
Good team members do not create unnecessary conflict.
Beneath that conviction may live a value: belonging, loyalty, competence, harmony, security, or respect.
Below the value sits the rationale, the deeply personal reason this value became necessary:
If I challenge someone with more authority, I may lose their respect, damage the relationship, or no longer belong.
And beneath that, closer to the core, a dragon may be guarding something precious:
Do not let us be rejected again.
Do not let us become unsafe.
Do not let them discover that we are not enough.
The dragon is not trying to compromise the system. It is trying to protect the person.
But what protects one person socially can expose an entire organization technically.
“Speak up” is not a safety strategy
We tell people to speak up as though courage were a switch they could flip.
But people do not enter difficult conversations as disembodied, rational minds. They bring history, culture, hierarchy, identity, previous consequences, and a living nervous system into the room.
When belonging, safety, or dignity feels threatened, we have less access to the spacious, curious thinking needed for a complex conversation. Some of us fight. Some retreat. Some freeze. Some comply so quickly that we only discover our real answer later, when we are alone and angry with ourselves for saying nothing.
I know that feeling.
I have been the director of engineering and still felt afraid to tell the CEO that I would not do what they asked.
Seniority does not remove our nervous systems. A title does not silence our dragons. Power may change the consequences, but it does not make us immune to fear, judgment, or the longing to remain part of the pack.
So psychological safety cannot mean placing the full burden on the person with less power and applauding them when they manage to be brave.
The receiver has work to do too.
❤️🔥 How do leaders respond when someone questions their decision?
❤️🔥 What happens when an engineer admits that a key was exposed?
❤️🔥 Does the security team arrive as a partner or as the department of no?
When somebody says, “I do not understand,” do we become curious or make them regret revealing it?
The answers teach the organization whether truth is welcome.
Security depends on how quickly truth can travel
During the technical sessions, we explored the many places where vulnerabilities can enter a system: data, code, dependencies, build artifacts, deployment configuration, runtime behavior, credentials, AI models, agent instructions, retrieval sources, monitoring, and feedback loops.
Every stage needs technical controls.
It also contains human decisions.
🔥 What do we trust?
🔥 What must we verify?
🔥 Which risk can we accept?
🔥 Who owns the response?
🔥 What evidence is enough?
🔥 Who is allowed to stop the pipeline?
🔥 And what happens to them if they do?
Later, while teaching about credentials and incidents, Yianna referred back to my session. She emphasized that when a secret is exposed, blaming the individual misses the larger question: what in the system allowed that mistake to happen so easily? Was the secure route unclear, inaccessible, or so cumbersome that people learned to work around it? Had they seen others punished for admitting similar mistakes?
That connection mattered to me.
My contribution had not been a soft-skills break from the real security training.
It was part of the security training.
Technical controls and human conditions are not competing concerns. They protect different parts of the same living system.
A courageous security conversation
Feeling safe does not mean every conversation will feel comfortable. Security work often requires us to carry messages people do not want to hear.
But we can learn to bring those messages without attacking the dignity, competence, or autonomy of the people receiving them.
A courageous conversation begins by finding the shared ground:
We both want this release to succeed without creating avoidable harm.
Then describe what you observe without pretending you know another person’s intentions:
I see that this credential does not expire and is shared across several services.
Name the risk or the impact as you understand it:
I am concerned that if it is exposed, we may not be able to identify who used it or limit the damage quickly.
Invite another perspective:
What am I missing? Is there another control already in place?
Name what you need:
I need us to understand and record the risk before we proceed.
Then build the response together:
Can we agree on an owner, a temporary control, and a date for replacing it?
This is not about decorating a warning with nicer words. It is about keeping enough safety in the conversation for multiple perspectives to remain available.
We do not need identical convictions. We do not need to agree about every interpretation of the past. But we do need a way forward that honors what matters to the people involved and protects the shared outcome.
That is the difference between compromise and consensus.
Compromise too often asks everyone to abandon something important.
Consensus asks: What solution can we build together in which the essential needs in this room are still honored?
The most important control may already be in the room
I left those two days with enormous respect for the technical depth Martín and Yianna brought into the room. They helped participants see attack surfaces most people would never notice. They made invisible technical risks tangible, practical, and alive.
And together, we exposed something larger.
A secure organization is not one in which nobody makes mistakes.
It is one in which people can reveal mistakes before they become disasters.
It is not one in which everybody agrees.
It is one in which assumptions can be challenged without threatening someone’s place in the group.
It is not one in which fear disappears.
It is one in which fear does not have to make the decision.
The most important security control in the room may not be a scanner, policy, model, or guardrail.
🐉 It may be the person who notices the weak signal.
🐉 The colleague who is not fully certain.
🐉 The junior engineer whose perspective does not match the architecture diagram.
🐉 The security professional tired of being treated as an obstacle.
🐉 The person whose dragon is whispering, Stay quiet. It is safer that way.
Leadership begins in the moment we make it possible for that person to speak and show them, through our response, that telling the truth did not cost them their belonging.
Because sometimes the sentence standing between a hidden weakness and a preventable incident is simply:
“I think we may have missed something.”
In Leadership Landing (https://www.theleadershiplanding.com/), this is the territory we explore: not only what leaders do, but what lives beneath the doing. We learn to recognize the convictions, values, protective dragons, and nervous-system responses shaping the room, so that courage does not depend on becoming fearless, and people can bring forward the truths an organization most needs to hear.




Comments