---
title: "Build a Cybersecurity Team With the Secure Methodology"
description: "A practical, seven-step framework for building a cybersecurity team from scratch that actually works with the rest of the business."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Build a Cybersecurity Team With the Secure Methodology",
      "description": "A practical, seven-step framework for building a cybersecurity team from scratch that actually works with the rest of the business.",
      "image": "https://christianespinosa.com/__l5e/assets-v1/c4116db4-cda4-462d-a153-5d5a514ca27d/how-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology-card.png",
      "datePublished": "2022-07-12T00:00:00+00:00",
      "dateModified": "2026-06-26T00:00:00+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/how-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How long does it take to build a cybersecurity team from scratch using this framework?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Twelve to eighteen months to get to a steady-state operating model with five to seven people. Faster if you inherit infrastructure and slower if you also have to build identity, logging, and endpoint from zero. Anyone promising six months is selling something."
          }
        },
        {
          "@type": "Question",
          "name": "What if I only have budget for one hire?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Hire the leader who can do the hands-on work themselves for the first year. Then build the business case for the next two roles using the charter and the early wins. One excellent first hire is worth three mediocre ones."
          }
        },
        {
          "@type": "Question",
          "name": "Do I need to outsource any of this to a managed service?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Twenty-four-seven monitoring is often the right thing to outsource early because it is hard to staff and easy to get wrong. Strategy, charter, governance, and culture cannot be outsourced. If a vendor offers to outsource those, that is a red flag."
          }
        },
        {
          "@type": "Question",
          "name": "How does the Secure Methodology compare to NIST CSF or ISO 27001?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "They are complementary. NIST and ISO tell you what to do. The Secure Methodology tells you how to build a team that can actually execute against them. Most failed programs have a binder full of frameworks and a team that cannot run them."
          }
        },
        {
          "@type": "Question",
          "name": "What is the biggest mistake new security leaders make?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Trying to fix everything at once. The methodology forces sequencing. Awareness before fixing. Mindset before hiring. Communication before tools. Skip the sequence and the team thrashes."
          }
        },
        {
          "@type": "Question",
          "name": "Where can I learn more about the Secure Methodology in depth?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The full framework, with case studies, lives in The Smartest Person in the Room. The companion workbook walks a leader through applying each step to their own team."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Secure Methodology](/blog/category/secure-methodology)

# How to Build a Cybersecurity Team From Scratch Using the Secure Methodology

July 12, 2022 4 min read 885 words 

Most cybersecurity teams are not built. They accrete. A few engineers, a tool, an incident, a hire, another tool, another hire. By year three nobody can explain what the team is actually accountable for. The Secure Methodology is what I do instead

![](/__l5e/assets-v1/e019998b-44d6-47eb-9a0f-f03a319ae1e2/44d483ac3e0a.jpg)

Published

July 12, 2022

Read time

4 min

In this essay

1.  [01 Start with a charter, not a hire ](#start-with-a-charter-not-a-hire)
2.  [02 The seven steps, in the order they need to happen ](#the-seven-steps-in-the-order-they-need-to-happen)
3.  [03 Hiring the first five ](#hiring-the-first-five)
4.  [04 What good looks like at month twelve ](#what-good-looks-like-at-month-twelve)

Jump to

1.  [01 Start with a charter, not a hire ](#start-with-a-charter-not-a-hire)
2.  [02 The seven steps, in the order they need to happen ](#the-seven-steps-in-the-order-they-need-to-happen)
3.  [03 Hiring the first five ](#hiring-the-first-five)
4.  [04 What good looks like at month twelve ](#what-good-looks-like-at-month-twelve)

The takeaways

1.  01 
    
    A new cybersecurity team needs a charter before it needs headcount: what risks it owns, what decisions it makes, what it escalates.
    
    What to do next Name one person on your team where team is the bottleneck, and coach them on it this quarter.
    
2.  02 
    
    Hire for judgment and communication first; technical depth is teachable, taste is not.
    
    What to do next Run a 15-minute conversation with your team about hire at the next stand-up, and listen more than you talk.
    
3.  03 
    
    Awareness, mindset, acknowledgment, communication, monkey first, reinforcement, and improvement are the seven steps. Skipping any of them creates the dysfunction you see in mature teams.
    
    What to do next Run a 15-minute conversation with your team about awareness at the next stand-up, and listen more than you talk.
    
4.  04 
    
    The team's job is not to be the smartest. It is to make the rest of the company safer without slowing it down.
    
    What to do next Run a 15-minute conversation with your team about team at the next stand-up, and listen more than you talk.
    
5.  05 
    
    Operating cadence beats org chart. Weekly judgment, monthly metrics, quarterly retros.
    
    What to do next Run a 15-minute conversation with your team about operating at the next stand-up, and listen more than you talk.
    

Almost every cybersecurity team I have walked into has the same origin story. Something bad happened, or almost happened, and the company hired a person. That person bought a tool. They hired two more people. Those people bought three more tools. A few years later there is a team, a stack, a queue, and absolutely no shared understanding of what the team is actually for.

The Secure Methodology is the operating model I wish I had been handed the first time I built a security team from scratch. Seven steps, in order, that produce a team the business actually wants to work with instead of route around.

## Start with a charter, not a hire

Before the first req opens, I write down three things. What risks does this team own. What decisions does this team make without asking. What does this team escalate, and to whom. Two pages, signed by the executive who will defend the budget.

If you cannot answer those questions, the first hire will spend their first year trying to answer them while also being on call. They will burn out and leave, and you will repeat the cycle.

## The seven steps, in the order they need to happen

**1\. Awareness.** The team and the business both need to see the current state honestly. Asset inventory, identity hygiene, incident history, regulatory posture. No fixing yet. Just look. Most programs skip this because it is uncomfortable.

**2\. Mindset.** Security is a service function. It exists to enable the business to take smart risk, not to block all risk. If the team's mindset is gatekeeper, every interaction with engineering or product is going to be a fight. Reset this before you hire.

**3\. Acknowledgment.** People do what they are recognized for. If the only time security speaks to engineering is to file a critical finding, engineering will avoid security. Build the habit of acknowledging good security behavior loudly and publicly. It is the cheapest culture lever you have.

**4\. Communication.** This is the skill that separates a tolerable security team from a great one. Analysts who can write a clear incident summary in plain English, engineers who can explain a risk trade-off to a product manager in two sentences, leaders who can present to a board without jargon. Hire for this. Train for it.

**5\. Monkey first.** Borrowed from a Google X principle. Do the hard thing first. If the program depends on solving identity, solve identity. Do not start with the easy wins because the easy wins do not change your risk profile, and you will run out of political capital before you get to the thing that matters.

**6\. Reinforcement.** Whatever behavior you want, you have to reinforce it on a cadence. Weekly stand-ups that surface judgment calls. Monthly metrics that the team actually owns. Quarterly retros where mistakes are discussed without blame. The cadence is the program.

**7\. Improvement.** Build in time for the team to get better. Not just training budget on a spreadsheet. Actual hours on the calendar, protected from the queue, where engineers go deeper, learn a new tool, run a tabletop, write a postmortem. A team that never improves stops being a team and becomes a ticket factory.

## Hiring the first five

The order matters more than the titles. My usual sequence for a team being built from zero:

1.  A leader who can communicate with the business and is willing to do hands-on work for the first year.
2.  A generalist engineer who can build the foundations of identity, logging, and endpoint.
3.  A second engineer who complements the first in skills and temperament.
4.  A program or GRC person to own policy, audit, and the boring but load-bearing work.
5.  A detection and response person, once there is enough infrastructure to detect and respond on.

Notice what is not on this list early. A SOC. A red team. A threat intel function. Those come later, once the foundation exists. Build them too early and they have nothing to defend or attack against.

## What good looks like at month twelve

The team has a charter the rest of the company can quote back at them. There is a published process for how a product team requests a security review and how long it takes. There is at least one tabletop on the books per quarter. The board has seen a metric dashboard they actually understand. And nobody on the team has worked a sixty-hour week in the last month.

If any of those is missing, go back to the step in the methodology you skipped. It is always one of the seven.

This is the framework that runs through everything in [The Smartest Person in the Room](/books/the-smartest-person-in-the-room), and it is the same model the consulting team at [Blue Goat Cyber](https://bluegoatcyber.com) uses with medical device manufacturers when they need a security function stood up under FDA scrutiny. The order is the same. The discipline is the same. The deliverable is a team that makes the company safer without slowing it down.

> “You are not building a SOC. You are building the muscle the whole company uses to make safer decisions. The technology is the easy part.”

Frequently asked

### How long does it take to build a cybersecurity team from scratch using this framework?

### What if I only have budget for one hire?

### Do I need to outsource any of this to a managed service?

### How does the Secure Methodology compare to NIST CSF or ISO 27001?

### What is the biggest mistake new security leaders make?

### Where can I learn more about the Secure Methodology in depth?

[](/blog/how-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fhow-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology&text=How%20to%20Build%20a%20Cybersecurity%20Team%20From%20Scratch%20Using%20the%20Secure%20Methodology) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fhow-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fhow-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology) [Email](mailto:?subject=How%20to%20Build%20a%20Cybersecurity%20Team%20From%20Scratch%20Using%20the%20Secure%20Methodology&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fhow-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.

Keep reading

-   [
    
    ### Why People Still Beat Technology in Cybersecurity
    
    The reason this methodology exists. Tools without team design do not move the outcome.
    
    Read essay → ](/blog/the-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people)
-   [
    
    ### Will AI Help or Hurt Cybersecurity?
    
    AI changes the workload of the team you are building, but not the design principles.
    
    Read essay → ](/blog/will-ai-and-machine-learning-help-or-hurt-cybersecurity)
-   [
    
    ### Why Technical People Struggle With People Skills
    
    The single biggest predictor of whether a security team succeeds or fails.
    
    Read essay → ](/blog/why-do-technical-people-struggle-with-people-skills-and-how-can-companies-fix-it)

[← Previous essay 

Cybersecurity Isn’t Black and White: Why Cyber Leaders and Their Teams Must Embrace the Gray - Christian Espinosa

](/blog/cybersecurity-isnt-black-and-white-why-cyber-leaders-and-their-teams-must-embrace-the-gray)

Related, The Secure Methodology

### Turn technical experts into great communicators

The Secure Methodology™ is Christian's 7-step framework for building cybersecurity teams that actually collaborate. Read the book or bring the program to your organization.

[Explore the Secure Methodology](/programs/secure-methodology)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)