The Unheld Ground

4.3
(97)

Why the job isn’t finished when the fix goes in

Estimated reading time: 6 minutes

Key Takeaways

  • The job isn’t finished when the fix goes in; ongoing vigilance is crucial to truly secure improvements.
  • Organizations often focus on deployment while neglecting the need for a sustainment plan to hold ground.
  • John’s three questions should guide post-fix evaluations: Is it actually working? What is it breaking elsewhere? Are we genuinely better?
  • Cybersecurity demands continuous monitoring due to active adversaries, but this lesson applies to all domains where change occurs.
  • Holding ground requires planning, designated responsibility, and scheduled reviews to ensure lasting effectiveness.

The Story

Yesterday afternoon, over two cups of coffee that both went cold before we finished them, I sat across from John. Twenty-five years in the Marines, the last stretch of that career spent entirely inside cybersecurity. He’s retired now, and when he said the word “retired,” his shoulders actually dropped, like something physical had been set down. Not tired-relieved. Survivor-relieved.

“Especially now,” he said, “with AI in the mix and half the world’s governments treating cyber like a standing front. I’m glad I’m out of it.”

What stayed with me wasn’t the relief. It was something he mentioned almost as an aside — said with the flatness of a line he’s repeated so many times it no longer sounds, to him, like a revelation. He told me that across two decades of network defense, the leadership he answered to kept making the same mistake, in different uniforms and different companies. They treated a security improvement as a finish line. Patch deployed. Firewall rule written. Training delivered. Box checked. Meeting adjourned.

“The job isn’t finished when the fix goes in,” he said. “That’s when the real work starts. Is it actually holding? Is it slower now, more brittle — did we just move the vulnerability somewhere we can’t see it? Or did we just buy ourselves a feeling?”

I’ve heard versions of this from operators in a dozen fields, but never with quite that precision. John wasn’t only describing a cybersecurity problem. He was describing a pattern I now think of as the unheld ground — the habit of treating the taking of a position as the end of the campaign, when the position was never secure until someone stayed to hold it.

1. Taking the Hill

In military terms, taking a hill and holding a hill are two different operations, planned and resourced separately. Taking it is the dramatic part — the part with a clear objective, a visible outcome, a moment everyone can point to and call done. Holding it is unglamorous, ongoing, and easy to under-resource, because nothing about it produces a single satisfying instant of completion.

Most organizations only plan for the first operation. A security improvement, a new process, a restructured team — the project plan ends at deployment, because deployment is what shows up on the roadmap slide. But the actual objective was never “install the patch.” It was “reduce the risk,” and risk is a condition, not an event. You cannot finish a condition. You can only maintain it, or lose it.

2. The Debrief Nobody Schedules

Launches get calendar invites. Follow-ups rarely do. I’ve sat through dozens of kickoffs for transformation initiatives with a clear go-live date, a champagne-adjacent Slack message, and a project closed in the tracker — and almost never a meeting booked for thirty, sixty, or ninety days out to ask the only question that actually mattered: did it hold?

“A completed project and a sustained result are not the same deliverable, even though we file them under the same name.”

Michel Paquin

That single missing meeting is often the entire gap between an organization that improves and one that just keeps announcing improvements.

3. Three Questions That Belong After Every Fix

John’s framing, stripped of its cybersecurity vocabulary, generalizes to almost any change a leader can make. After the rollout, after the reorg, after the new tool goes live, three questions deserve a standing place on the calendar:

Is it actually working — by the measure that mattered before we started, not a new one we’re relieved to have available now?

What is it breaking elsewhere — a slower process, a workaround people have quietly adopted, a dependency we didn’t know we had?

Are we actually better, or do we just feel better — has the underlying exposure gone down, or has the anxiety about it simply gone quiet?

None of these questions can be answered on launch day. They require distance, and they require someone whose job it is to come back and ask.

4. An Adversary That Doesn’t Concede

Cybersecurity has a feature most corporate change doesn’t: an adversary who is actively, intelligently trying to undo your fix the moment you deploy it. That gives John’s world an urgency that’s hard to argue with — stop watching, and someone is already testing the gap.

But it would be a mistake to file this away as a cybersecurity-only lesson. Markets adapt. Competitors respond. Regulations shift. Employees find the path of least resistance around a new control within weeks, not because they’re defiant but because that’s what humans do with friction. Nothing you improve stays improved by default, even without a hostile actor on the other side of it. The ground doesn’t hold itself in any domain — it only feels that way in the domains where the pressure testing it is invisible.

5. The False Peace

The most dangerous outcome of a security fix isn’t failure. It’s silence that gets mistaken for success. John described watching teams relax after a deployment simply because the alerts went quiet — not because the underlying exposure had actually closed, but because nobody was looking closely enough anymore to trigger one.

“Silence after a change is not evidence it worked. It’s just the absence of evidence, dressed up to look like one.”

Michel Paquin

This is the unheld ground at its most costly: not the visible failure that gets escalated and fixed, but the quiet failure nobody is checking for, sitting underneath a genuine, well-earned sense of relief.

6. Holding Ground as a Discipline

Holding ground is not a mindset; it’s a design choice made before the fix ever ships. Three habits make it real rather than aspirational:

Build the sustainment plan into the original proposal, with its own owner and its own budget line, so it isn’t left to whoever happens to remember three months later.

Name a specific person responsible for holding, distinct from whoever was responsible for taking. The skills, incentives, and attention span required to deploy a change are not the same ones required to watch it.

Put a review date on the calendar before the launch date, not after. If the follow-up meeting doesn’t exist until someone thinks to schedule it, it will keep losing to whatever is loudest that week.

7. When This Doesn’t Apply

Not every fix needs indefinite vigilance. A one-time compliance filing, a physical repair with no ongoing state, a decision that resolves cleanly and stays resolved — these don’t need a sustainment plan, and building one anyway just spends attention you’ll need elsewhere. The judgment call is whether the thing you changed sits in a system that keeps moving after you’ve touched it. If it does, hold it. If it genuinely doesn’t, let it be finished, and don’t manufacture monitoring theater where none is needed.

8. What to Do This Week

Pick one initiative your organization closed out in the last ninety days — the one everyone still refers to in the past tense, as done. Put thirty minutes on the calendar this week and ask John’s three questions about it, out loud, with the people who built it. You may confirm it held. You may not. Either way, you’ll know something you currently only assume.

How useful was this post?

Click on a star to rate it!

Average rating 4.3 / 5. Vote count: 97

No votes so far! Be the first to rate this post.

As you found this post useful…

Follow me on social media!

I'm sorry that this post was not useful for you!

Let me improve this post!

Tell me how we can improve this post?

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *