Listen to this Post
Introduction: When Security Must Move at the Speed of Business
Cybersecurity has become one of the hardest balancing acts for modern enterprises. Security teams are expected to stop attackers, protect sensitive information, satisfy regulators, support employees, and respond to emerging threats, all while the rest of the business is being pushed to move faster.
Few companies illustrate that challenge better than Walmart.
The retail giant operates at extraordinary scale. Millions of employees, thousands of locations, enormous volumes of customer transactions, complex supply chains, cloud services, applications, payment systems, logistics networks, and digital platforms create an attack surface that is almost impossible to compare with that of an ordinary organization.
At that scale, cybersecurity cannot simply be a department that says "no."
It has to become part of how the company operates.
That is the central lesson behind Walmart’s approach to security operations, as described by Jason O’Dell, Walmart’s global vice president of Security Operations. His philosophy challenges one of cybersecurity’s oldest habits: using fear, uncertainty, and doubt to convince the business that security matters.
Instead, Walmart is emphasizing trust, communication, transparency, and a more constructive philosophy: “Yes, and…”
The idea is simple but powerful. When the business wants to launch a product, introduce a technology, change a process, or move quickly into a new market, security should not automatically become the department that blocks the project.
Instead, security should help find a safer way forward.
That does not mean removing controls or accepting unnecessary risk. It means understanding what the business is trying to accomplish and finding the right security architecture to support it.
And that distinction may become increasingly important as cyber threats become more automated, more sophisticated, and more deeply connected to business operations.
Walmart’s Scale Creates a Cybersecurity Problem Unlike Most Others
A Giant Attack Surface
Walmart’s enormous global footprint creates an equally enormous cybersecurity challenge.
Retailers are attractive targets because they combine valuable customer information, payment systems, employee accounts, logistics infrastructure, online services, physical locations, suppliers, and highly distributed technology environments.
An attacker does not necessarily need to compromise the most important system.
Sometimes the weakest connection is enough.
A compromised employee account can become an entry point. A vulnerable third-party service can become a bridge. A poorly protected application can expose data. A supply-chain weakness can provide attackers with access that traditional perimeter defenses were never designed to stop.
Retail Is Now Critical Infrastructure for Trust
Steve Durbin, chief executive of the Information Security Forum, describes modern retail as a frontline for consumer trust and systemic resilience.
That characterization is important.
Consumers increasingly depend on retailers for much more than buying products. Digital accounts, payments, delivery services, loyalty programs, mobile applications, online shopping, and automated logistics have transformed retail companies into technology platforms.
When those platforms fail, the consequences extend beyond inconvenience.
Customers lose confidence.
Employees lose productivity.
Suppliers experience disruption.
Executives face difficult questions.
And security teams are expected to explain what happened.
Cybercriminals See Retail as an Opportunity
The Numbers Tell a Story
The article points to
That figure represents only part of the global picture.
Behind every statistic is a different organization, attack method, business consequence, and recovery challenge.
For security leaders, this means there is no comfortable period in which the threat disappears.
The threats simply change shape.
Criminal Groups Are Not Waiting
Financially motivated cybercriminal groups have become increasingly professional.
They can specialize in initial access, credential theft, malware deployment, ransomware, data extortion, and monetization.
This creates an uncomfortable reality for large organizations: defenders are often competing against adversaries that can operate like businesses.
The difference is that attackers have no need to worry about internal governance, customer safety, or regulatory obligations.
Defenders do.
Walmart Wants Security to Become an Enabler
The Philosophy of Jason
Jason O’Dell’s approach begins with a straightforward principle: security operations should create business value while protecting trust.
That represents a major philosophical shift.
Traditional security culture often revolves around preventing things.
A business proposes something.
Security identifies risks.
Security says no.
The business becomes frustrated.
Eventually, employees begin looking for ways around security controls.
O’Dell argues that this cycle creates another form of risk.
Replacing No With Yes, And…
The alternative is not blind approval.
It is collaboration.
Instead of saying:
No, you cannot do that.
The security team can say:
“Yes, and here is how we can do it safely.”
That difference may appear cosmetic, but it can fundamentally change the relationship between security professionals and business leaders.
Security becomes a partner rather than an obstacle.
The Real Enemy Has an Unexpected Name: Friction
Security Friction Can Become a Vulnerability
O’Dell jokingly describes Walmart’s enemy using an unusually simple word:
Friction.
Friction is everything security does that slows the business down.
Sometimes that friction is justified.
Multi-factor authentication creates an additional step.
Access controls create restrictions.
Security reviews require time.
Vulnerability management can delay deployments.
Monitoring can impose operational requirements.
But every control also has an operational cost.
The Security Value Quadrant
O’Dell’s model places security value on one axis and operational friction on the other.
The ideal situation is obvious:
High security value + low operational drag.
That is where security teams should aim to operate.
High security value combined with high friction can sometimes be justified.
Low security value combined with low friction may occasionally be acceptable.
But the dangerous zone is:
Low security value + high operational drag.
That is where security controls become expensive without meaningfully reducing risk.
Why Bad Security Controls Can Increase Risk
This is one of the most important observations in the entire article.
If security controls make
They may create workarounds.
They may share credentials.
They may move sensitive information to unauthorized platforms.
They may disable protections.
They may search for unofficial tools.
Ironically, a control intended to reduce risk can therefore create new risk if it is poorly designed.
The Security Tightrope
Too Much Convenience Creates Exposure
A company cannot remove every security control simply because employees find those controls inconvenient.
Cybersecurity has to impose some restrictions.
There are situations where security genuinely needs to slow something down.
That is part of responsible risk management.
Too Much Control Creates Resistance
The opposite extreme is equally dangerous.
When security teams attempt to control everything, employees eventually become frustrated.
That frustration can turn into resistance.
The result is an organization where people perceive cybersecurity as something to defeat rather than something that protects them.
The objective is therefore not maximum control.
It is appropriate control.
Should Cybersecurity Really Be a Business Enabler?
The Skeptical Perspective
Omdia chief analyst Rik Turner offers an important counterargument.
He remains skeptical about describing cybersecurity purely as a business enabler.
And his argument deserves attention.
Sometimes security should slow the business down.
If a proposed project introduces unacceptable risk, a security team should not disguise that reality simply to appear helpful.
Security Cannot Become a Public Relations Function
A security leader who says “yes” to everything is not necessarily business-friendly.
They may simply be avoiding responsibility.
There are moments when security must say:
Stop.
There are moments when additional testing is required.
There are moments when a launch needs to be delayed.
There are moments when an architecture needs to be redesigned.
The real maturity comes from knowing which moments require friction and which do not.
Cybersecurity Leaders Need a Seat at the Strategy Table
From Technical Department to Risk Partner
Steve Durbin argues that cybersecurity leaders need to position themselves as strategic risk partners.
This is becoming increasingly important.
Executives rarely want a 50-page explanation of every technical control.
They want to understand risk.
What can happen?
How likely is it?
What would the impact be?
What are we doing about it?
Where are the remaining gaps?
What investment is necessary?
Security leaders who can answer those questions in business language become far more influential.
Understanding Risk Appetite
Every organization has a different tolerance for risk.
A retailer operating globally will have different priorities from a small software startup.
A hospital has different requirements from a manufacturing company.
A financial institution has different obligations from a media organization.
There is no universal security strategy.
The best security strategy is the one aligned with the organization’s mission, risk appetite, technology environment, and regulatory responsibilities.
Trust Is the Foundation of Innovation
Walmart’s “Know Your Business Day”
One of the most interesting examples in the article is Walmart’s “Know Your Business Day.”
The concept is straightforward.
Security leaders meet with business leaders and discuss the challenges they actually face.
That creates something technology alone cannot provide:
context.
Security professionals can understand why a particular workflow exists.
Business leaders can understand why a particular security control is necessary.
Both sides become more empathetic.
Innovation Moves at the Speed of Trust
O’Dell references Stephen R. Covey’s well-known principle that innovation happens at the speed of trust.
The concept fits cybersecurity remarkably well.
If business leaders trust security, they involve security earlier.
If security trusts business leaders, security teams can focus on helping rather than policing.
If employees trust security, they are more likely to report suspicious activity.
If executives trust security leadership, they are more willing to fund long-term resilience.
Trust therefore becomes a security control in its own right.
Transparency Is More Powerful Than Fear
Abandoning FUD
Fear, uncertainty, and doubt have historically been powerful tools for security professionals.
Show executives a terrifying attack scenario.
Explain the consequences.
Request funding.
Sometimes it works.
But it is not sustainable.
Eventually, executives become numb to endless warnings.
Every month brings another catastrophic headline.
Every year produces another unprecedented threat.
Fear loses its effectiveness.
Honest Risk Conversations Work Better
A mature security organization can say:
We have this control.
We do not have that control.
Here is the gap.
“Here is what we are doing about it.”
Here is the expected timeline.
“Here is what could happen if we do nothing.”
That conversation is much more valuable than simply saying:
Everything is dangerous.
The One-Page Executive Security Brief
Turning Complexity Into Clarity
O’Dell describes another practical technique: creating an executive-friendly one-page summary when a major cybersecurity story appears in the news.
The purpose is not to overwhelm executives.
It is to answer the obvious question:
Are we okay?
Preparation Beats Panic
When a new vulnerability or attack makes headlines, executives may immediately ask whether the company is exposed.
A prepared security team should already have an answer.
The one-page document can show:
What the threat is.
Which controls address it.
Whether those controls are already deployed.
What protections are planned.
Where gaps remain.
What additional action is required.
This approach transforms breaking news from a panic event into an already-managed risk discussion.
Color-Coded Security Planning
Making Risk Visible
The article describes a color-coded system for mapping threats against defensive controls.
The idea is simple.
Different colors communicate whether a security control already exists, whether a mitigation is planned, whether additional work is underway, or whether a gap remains.
This makes a complex threat landscape easier for executives to understand.
Security Leaders Should Never Hide Gaps
Perhaps the strongest lesson is the importance of admitting weaknesses.
No serious organization has perfect security.
Pretending otherwise is dangerous.
A security leader who says “we have no gap” when one clearly exists may create more risk than the vulnerability itself.
Transparency allows leadership to make informed decisions.
Deep Analysis: Building a Low-Friction Security Operations Model
Start With Security Telemetry
A modern security operation needs visibility before it can optimize anything.
Useful telemetry can include identity events, endpoint activity, cloud logs, network activity, application events, and authentication records.
A basic Linux investigation might begin with:
journalctl --since "1 hour ago"
This allows analysts to inspect recent system activity and establish an initial timeline.
Search for Authentication Anomalies
Identity remains one of the most important areas of enterprise defense.
For Linux environments:
grep -Ei "failed|invalid|authentication failure" /var/log/auth.log
This can help identify repeated authentication failures that deserve investigation.
The exact log location varies by operating system and distribution.
Inspect Active Network Connections
Unexpected network connections can sometimes reveal compromised processes or unusual activity.
A basic diagnostic command is:
ss -tulpn
Security teams can use the output to identify listening services and investigate unexpected processes.
Monitor Running Processes
A simple process review can provide useful context:
ps aux --sort=-%cpu | head
High CPU consumption does not automatically indicate compromise, but unusual processes should be investigated in context.
Check for Unexpected Persistence
Persistence mechanisms deserve particular attention during incident response.
On Linux, defenders can review scheduled tasks with:
crontab -l
And system-wide scheduled tasks can be reviewed through:
ls -la /etc/cron.
The objective is defensive investigation, not blindly deleting suspicious entries.
Use Hashes to Validate Files
When investigating a suspicious file, defenders can calculate a cryptographic hash:
sha256sum suspicious_file
The resulting hash can then be compared against trusted internal records or reputable threat-intelligence sources.
Automate the Boring Work
Automation is essential for reducing operational friction.
Security teams should automate repetitive activities such as:
Alert enrichment.
Asset identification.
Threat-intelligence lookups.
Ticket creation.
Evidence collection.
Vulnerability prioritization.
Compliance reporting.
Routine executive dashboards.
The objective is not to automate security away.
It is to give security professionals more time for decisions that actually require human judgment.
Measure Security by Outcomes
Counting alerts is not enough.
A security operations center should consider measurements such as:
Mean time to detect.
Mean time to respond.
Mean time to contain.
Coverage of critical assets.
Percentage of high-risk vulnerabilities remediated.
Identity protection coverage.
Number of recurring incidents.
Business disruption caused by security controls.
That final metric is particularly relevant to
Security should measure not only how much protection it provides, but also how much operational friction it creates.
The Goal Is Not Zero Risk
Zero risk does not exist.
Attempting to achieve it can become extraordinarily expensive and may still fail.
The real objective is resilience.
A resilient organization assumes that some attacks will succeed.
It prepares for detection.
It limits blast radius.
It protects critical systems.
It maintains recovery capabilities.
It learns from incidents.
And it continuously improves.
What Undercode Say:
- Security Should Be Measured by Business Impact
Cybersecurity teams have spent years measuring themselves through technical metrics.
But executives ultimately care about business outcomes.
The strongest security program is not necessarily the one with the most tools.
It is the one that reduces meaningful risk without unnecessarily damaging productivity.
2. Friction Is an Underestimated Security Metric
Security teams rarely talk about friction.
They should.
Every additional authentication step, approval process, security review, application restriction, and technical requirement creates operational cost.
That cost should be measured.
- Employees Are Part of the Security Architecture
A technically perfect control that employees constantly bypass is not a perfect control.
Human behavior must be considered when security architecture is designed.
4. Trust Can Reduce Security Risk
When employees trust security teams, they are more likely to report suspicious behavior.
When developers trust security engineers, they involve them earlier.
When executives trust the CISO organization, security investment becomes easier to justify.
Trust has measurable security consequences.
- “Yes, And…” Is Better Than Blind “Yes”
The Walmart philosophy should not be interpreted as security approving everything.
It means security should search for solutions.
A request can be accepted while its implementation is redesigned to reduce risk.
- Security Must Still Have the Courage to Say No
There is a danger in overcorrecting.
Security leaders should not become business cheerleaders.
If a proposal creates unacceptable exposure, the answer must remain no.
The difference is that the refusal should be accompanied by a safer alternative whenever possible.
7. Executive Communication Is a Security Skill
Technical expertise alone is no longer enough.
Security leaders must explain risk clearly to executives.
The ability to turn thousands of technical signals into one meaningful business decision is a major leadership capability.
- One-Page Reporting Can Be More Powerful Than Huge Reports
Executives need clarity.
A concise document showing threat, exposure, controls, gaps, and next steps can be more useful than dozens of pages of technical information.
9. Transparency Creates Better Decisions
Admitting a security gap does not automatically demonstrate failure.
Sometimes it demonstrates maturity.
Executives cannot manage risks they do not know exist.
10. Threat Intelligence Should Lead to Action
Security teams should not simply collect threat reports.
They should connect intelligence to actual controls.
If an emerging attack technique cannot be mapped to an existing defense, that should become a roadmap item.
11. Retail Security Is Becoming More Complex
Retail now combines physical infrastructure with cloud computing, mobile applications, digital payments, logistics technology, identity systems, APIs, and artificial intelligence.
The traditional network perimeter is no longer enough.
12. Third Parties Matter
A company’s security posture is increasingly influenced by suppliers, software vendors, contractors, cloud providers, and partners.
Security teams must therefore evaluate ecosystem risk rather than focusing exclusively on internal infrastructure.
13. Identity Deserves Special Attention
Compromised credentials remain one of the most attractive routes into large organizations.
Strong authentication, least privilege, session monitoring, and identity analytics should remain central components of enterprise defense.
14. Security Architecture Should Anticipate Failure
Assuming that every defense will work perfectly is dangerous.
Modern architecture should assume that credentials can be stolen, endpoints can be compromised, and vulnerabilities can be exploited.
The question becomes: what happens next?
15. Blast-Radius Reduction Is Critical
Segmentation, least privilege, application isolation, and strong identity controls can prevent one compromised system from becoming an enterprise-wide disaster.
16. Automation Should Reduce Alert Fatigue
Security analysts cannot investigate every alert manually.
Automation should prioritize the signals that actually matter.
Better prioritization can improve both security and employee experience.
17. Artificial Intelligence Will Increase the Pressure
AI is likely to accelerate both attack and defense.
Attackers can automate reconnaissance and social engineering.
Defenders can automate analysis, detection, and response.
This makes efficient security operations even more important.
18. Human Judgment Will Remain Necessary
Automation cannot completely replace security leadership.
Risk decisions often require business context, ethics, legal judgment, and knowledge of organizational priorities.
19. Security Culture Starts With Leadership
Employees notice how executives treat cybersecurity.
If leadership treats security as a nuisance, employees often follow.
If leadership treats it as part of responsible business operations, the culture changes.
20. Security Should Be Involved Earlier
The cheapest security vulnerability is often the one that never gets introduced.
Security teams should participate during architecture and design rather than waiting until deployment.
- DevSecOps Is Part of the Same Philosophy
Security cannot remain a final checkpoint.
Automated testing, secure development practices, dependency monitoring, and continuous assessment can integrate security without creating unnecessary delays.
22. Risk Appetite Must Be Explicit
Organizations should know what risks they are willing to accept.
Without a defined risk appetite, every security decision becomes an argument.
23. Security Roadmaps Need Business Context
A security roadmap should not simply list technologies.
It should explain what business risk each investment addresses.
24. Security Budgets Need Evidence
Executives are more likely to support security investment when leaders can explain the relationship between spending and risk reduction.
25. Incident Response Builds Institutional Memory
Every incident should produce lessons.
If the same failure occurs repeatedly, the organization has not truly learned from the first incident.
26. Communication During Incidents Matters
Technical recovery is only one part of incident response.
Customers, employees, executives, regulators, suppliers, and partners may all require different information.
- Security Teams Should Learn From Each Other
O’Dell’s emphasis on conversations with industry peers is valuable.
No organization experiences every threat.
Sharing lessons can accelerate defensive maturity.
28. There Is No Universal SOC Blueprint
A security operations center designed for a global retailer will look different from one designed for a small software company.
Scale, technology, risk, regulation, and business model all matter.
29. Security Leaders Must Understand Operations
A security team that does not understand how the business actually works will struggle to build effective controls.
Security begins with understanding.
30. Empathy Is a Technical Advantage
Understanding why employees behave a certain way can reveal weaknesses that technical analysis alone misses.
31. Convenience Is Not the Enemy
Convenience becomes dangerous only when it removes meaningful security protections.
Good design can sometimes produce both convenience and security.
32. Friction Should Be Deliberate
Every security obstacle should have a reason.
If nobody can explain why a control exists, it deserves review.
33. Security Controls Should Evolve
Threats change.
Business processes change.
Technology changes.
Security controls must therefore be continuously evaluated rather than treated as permanent.
34. Resilience Is More Realistic Than Prevention
No organization can guarantee prevention.
Organizations can, however, become harder to compromise and faster to recover.
35. Security Is Ultimately About Trust
Customers trust retailers with their information.
Employees trust organizations with their identities.
Executives trust security teams to protect the company.
Protecting that trust is the real purpose of cybersecurity.
36.
The philosophy applies to technology companies, banks, manufacturers, healthcare organizations, governments, and virtually any large enterprise.
Every organization struggles with the same fundamental question:
How much security is enough without preventing the business from functioning?
- The Best Security Team Is Not the Loudest
A mature security organization does not need to constantly announce danger.
Its success becomes visible through predictable operations, fast response, strong resilience, and informed decision-making.
38. Transparency Should Become a Habit
Transparency cannot appear only during crises.
Organizations should regularly communicate their security posture, priorities, limitations, and roadmap.
39. Trust Must Be Earned
Security teams cannot demand trust.
They earn it by being accurate, consistent, transparent, responsive, and willing to understand business realities.
40. The Future Belongs to Collaborative Security
The future of enterprise cybersecurity will not be defined simply by stronger firewalls or more detection rules.
It will be defined by organizations capable of combining technology, people, business strategy, automation, resilience, and trust.
That is the deeper lesson behind
✅ Walmart’s Security Strategy Focuses on Reducing Operational Friction
The article accurately presents Jason O’Dell’s emphasis on reducing unnecessary security friction while maintaining meaningful protection. The goal is not to eliminate security controls, but to make them more useful and business-aligned.
✅ Trust and Transparency Are Central Themes
The discussion correctly emphasizes trust, direct communication, transparency, and collaboration between security and business leadership. These principles are presented as fundamental components of Walmart’s security-operations philosophy.
✅ Retail Has a Broad and Complex Attack Surface
The
❌ “Security as an Enabler” Does Not Mean Security Should Always Say Yes
This interpretation would be misleading. The article itself includes skepticism from Rik Turner and recognizes that security sometimes must slow business operations. A mature security organization needs both collaboration and the ability to reject unacceptable risk.
✅ There Is No One-Size-Fits-All Security Operations Model
The article correctly highlights that security operations differ according to organizational size, business model, technology, culture, and risk profile. Walmart’s approach should therefore be viewed as a useful model, not a universal blueprint.
Prediction
(+1) Security Teams Will Become More Embedded in Business Strategy
As cyber risk increasingly affects revenue, reputation, operations, and customer trust, security leaders will increasingly participate in strategic planning rather than appearing only when something goes wrong.
(+1) Low-Friction Security Will Become a Competitive Advantage
Organizations that can provide strong protection without unnecessarily slowing employees and developers will have an operational advantage over companies burdened by inefficient security processes.
(+1) Executive Security Reporting Will Become Simpler
Security leaders will increasingly rely on concise dashboards and risk summaries that explain exposure, controls, gaps, business impact, and priorities rather than overwhelming executives with technical data.
(+1) Identity and Access Security Will Become Even More Important
As cloud services, remote work, automation, and AI agents expand, identity will remain one of the most important control points in enterprise security.
(+1) AI Will Accelerate Security Automation
Security operations will increasingly use AI to correlate alerts, summarize incidents, identify unusual behavior, enrich investigations, and automate repetitive defensive tasks.
(-1) Organizations That Treat Security as a Roadblock Will Face Greater Risk
Companies that create excessive operational friction may encourage employees to bypass controls. Over time, this can turn poor security usability into an actual security vulnerability.
(-1) Fear-Based Security Communication Will Lose Its Effectiveness
Constantly using catastrophic scenarios to obtain attention or funding is unlikely to remain effective with executives who are already exposed to an endless stream of cybersecurity warnings.
(+1) Trust Will Become a Measurable Security Asset
The strongest organizations will increasingly recognize that employee cooperation, executive confidence, transparent reporting, and cross-functional collaboration are not merely cultural advantages. They directly influence how effectively security controls work.
(+1) The Future of Security Operations Will Be Built Around Resilience
The ultimate objective will shift further away from the unrealistic promise of preventing every attack and toward building organizations that can detect compromise quickly, contain damage, recover operations, and learn from every incident.
▶️ Related Video (82% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




