Scaling Security

The 7 Pillars of Elite Cybersecurity Programs

Published by IT Revolution
Distributed by Simon & Schuster

LIST PRICE $34.00

PRICE MAY VARY BY RETAILER

Get 20% off with code SPOOKY plus free shipping on orders of $40 or more. Discount on physical products only. Terms apply.

Buy from Other Retailers

About the Book

The difference between a good security program and a great one isn't better tools—it's the operating model that makes security scale.

Every security leader has felt it: the gap between knowing what good looks like and being able to deliver it at scale. Your team is skilled. Your frameworks are sound. And yet the organization keeps outpacing your defenses—more complexity, more dependencies, more surface area, more risk—while the same structural problems recur quarter after quarter. The issue isn't your expertise. It's that most security programs are still built on artisanal craftsmanship in a world that demands industrial-grade execution. Adversaries are not waiting. They are industrializing too.

Scaling Security offers a way forward. Phil Venables has spent decades at the center of the hardest security problems in the world—as CISO at Goldman Sachs for seventeen years, as the first CISO of Google Cloud, and as an advisor to boards, central banks, and the White House. He has seen what separates elite security programs from merely competent ones, and it is not better tools or bigger budgets. It is seven pillars that transform security leadership from reactive expertise into organizational leverage: setting leading indicators of performance, modernizing for inherent defensibility, prioritizing the high-impact 20 percent, amplifying people through structure and AI, architecting for resilience, running security like a business, and weaponizing speed as strategy.

This is not a technical manual. It is a leadership operating system for CISOs and senior security executives who need to move their programs from bespoke to scalable—from dependent on individual artisans to driven by organization-wide systems that hold even under pressure.

The leaders building the security programs of the next decade are building them right now.

About the Author

Phil Venables is recognized as one of the most experienced security executives in the world. He was appointed as the first Chief Information Security Officer of Google Cloud, where risk, security, compliance, and privacy were overseen across one of the largest technology platforms on earth. Prior to that, nearly two decades were spent at Goldman Sachs — first as the firm's inaugural CISO, a role held for seventeen years, and subsequently as Chief Operational Risk Officer, operating partner in the private equity business, and Board Director of Goldman Sachs Bank. In 2024, he was inducted into the Chief Security Officer Hall of Fame. He is currently engaged as a Partner at Ballistic Ventures and Senior Advisor at Warburg Pincus.

At the highest levels of security policy, Venables has been called upon to advise governments and institutions around the world. From 2021 to 2025, he was appointed to the President's Council of Advisors on Science and Technology at the White House, where initiatives spanning cyber resilience and artificial intelligence were advanced. He is seated on the Information Security and Privacy Advisory Board of NIST, the Security and Technology Advisory Board of MITRE, and is counted among the membership of the Council on Foreign Relations. Degrees in Computer Science, Formal Methods, and Cryptography were earned at the University of York and The Queen's College, Oxford, and he is credentialed as a Chartered Fellow of both the British Computer Society and the Institute of Information Security. Phil Venables lives in Hoboken, New Jersey.

 

Product Details

  • Publisher: IT Revolution (February 23, 2027)
  • Length: 400 pages
  • ISBN13: 9781966280354

Browse Related Books

Raves and Reviews

If cybersecurity were purely a technical problem, we would have solved it decades ago. At its heart, security has always been about incentives and leadership—and few understand that better than Phil Venables. Scaling Security is a masterclass in organizational economics, revealing how lowering the unit cost of control creates a lasting defensive advantage. This is urgent and essential reading for leaders in the era of AI-powered attacks.

 

– Nicole Perlroth, New York Times bestselling author, This Is How They Tell Me the World Ends

Many cybersecurity books try to tell you what good looks like. This one tells you how to actually get there inside a real organization with competing priorities, a finite budget, and executives who need to be convinced. It is a management operating system for security leaders, and I'd hand it to every rising CISO and every board member who oversees one.

– Rob Joyce, Former Cybersecurity Director, NSA

We don't lose because we can't secure systems. We lose because we can't do it at scale. No one is better qualified than Phil Venables to tell us how.

– Dmitri Alperovitch, Chairman, Silverado Policy Accelerator, bestselling author ofWorld on the Brink

Phil brings thirty years of frontline experience in writing this timely book. Scaling Security provides a blueprint for building inherently defensible architectures that are capable of withstanding sophisticated adversaries. This is vital reading for anyone tasked with defending systems at scale.

 

– Anne Neuberger, Deputy National Security Advisor, 2021-2025

Scaling Security further shifts how we think about cybersecurity from reactive firefighting to systemic engineering. Every policymaker or practitioner needs this on their shelf.

– Bill Dally, Chief Scientist, Nvidia

I've been a fan of Phil's insightful and pragmatic writing for years. Scaling Security brings together what makes his work so valuable: deep experience, clear thinking, and advice you can actually use. This is essential reading for security leaders who want to move beyond heroics and build programs that last.

 

– Assaf Keren, CISO, Meta

Drawing on decades of leadership experience, Phil provides a practical roadmap for turning security into a lasting organizational capability. This book is essential reading for security professionals, business leaders, and board members who want to build more resilient and successful organizations.

– Tim McKnight, CISO, Merck

I have had a front row seat to Phil Venables' impact on cybersecurity since my Foundstone days back in the early 2000s. I have always considered his insights the gold standard. Phil has been one of the architects of modern enterprise security, and now he has published a masterclass for all of us.

– Kevin Mandia, CEO, Armadin

Phil Venables is the gold standard for CISOs—having designed, driven, and delivered security at four of the world’s largest and most targeted companies. In this book, he shares the lessons behind that success, introduces his seven pillars for creating and sustaining an elite security program, and offers invaluable counsel on how to build security in—not bolt it on. As someone who has personally benefited from Phil’s expertise and counsel, I can say without hesitation: This is a book that leaders and practitioners alike need to read. It’s that good.

– Gen. Paul M Nakasone (Ret.), Former Director of NSA and Commander, Cyber Command

The more you depend on something, the more you have at risk were it to fail. As such, your risk management paradigm must be this: resilience for the things that matter. There is no other option. Building out an inherently defensible environment to ‘industrial strength’ is not a cliche here because that is what Scaling Security gives you the game plan to do.

– Dan Geer

Resources and Downloads

High Resolution Images

BACK TO TOP