When I introduced the Cybersecurity Compass some years ago, it was a different world. It was a different ocean, without AI.
The water still moved back then, but slowly enough that a crew could watch it change one stretch at a time. I built the compass for that motion, because even a slow ocean needed direction more than it needed a map. What I did not know yet was how much faster this same ocean was about to get.
A map shows terrain. A compass shows direction. Neither claims to know what lies over the horizon. That distinction is why the compass still holds today. What changed is the horizon itself, and how fast it now arrives.
We still draw maps of the attack surface anyway. We chart the assets, the endpoints, the cloud workloads, the identities, and call the result a strategy. A map is a picture of what already exists. It says nothing about where the water moves next, and on this ocean nothing holds still long enough for a map to matter anymore.
The compass: https://cybersecuritycompass.github.io/
What Cyber Risk Actually Is Before It Becomes a Metaphor
Before the ocean metaphor goes any further, it is worth being precise about what a ship out there is actually navigating. Cyber risk is not a mood or a hunch. It exists only where three things overlap: a threat capable of doing harm, a vulnerability that threat could use, and a consequence significant enough to matter. Remove any one of the three and there is no cyber risk yet, only a piece of one.
The threat itself does not have to choose to cause harm. A storm can be a threat. So can a setting nobody meant to leave open, or a system that fails on its own without anyone attacking it at all. Cyber risk needs the overlap. It does not need an adversary standing behind it.
This is why cyber risk is dynamic, shared, and continuous, and why each of those three words carries weight rather than decoration. Dynamic, because the overlap shifts the moment a new exploit appears or a control gets switched off. Shared, because it flows through suppliers, partners, and software no single ship fully owns. Continuous, because it does not pause between the assessments scheduled to look for it. An ocean is not decoration laid on top of this definition. It is the only honest way to describe something that behaves exactly like this.
The Ocean We Keep Charting Like a Coastline
The attack surface is not a coastline, fixed and known once it is surveyed. It behaves like open ocean. It expands with every new cloud service, every new AI capability adopted before anyone reviews it, every third party connection signed into a contract, every line of code shipped faster than security can look at it. An ocean does not hold still long enough to be charted once and defended forever.
That ocean produces storms without much warning. Adversary techniques do not evolve on a schedule we can plan around. They form the way weather systems form, unevenly, hard to predict, capable of striking a stretch of water that looked reinforced last year and is exposed this year. Nobody sailing that ocean has a chart guaranteeing safe passage. The organizations that treat their risk assessment like a chart, finished once and referred back to for the next twelve months, are navigating water that has already changed shape since the day they drew it.
The Ocean Itself Is Accelerating
This was the ocean the compass was first built for. New water arrived slowly enough that a crew could review each stretch as it appeared. A service went live, someone looked at it, the chart got updated, the ship sailed on. Growth and attention moved at roughly the same pace.
That stopped being true. New water now appears between one watch and the next, faster than any crew built for a trickle can review a flood. And it is not only the amount of water that changed. The rate at which new water appears is itself climbing. Each new agent creates the conditions for more agents. Each integration opens a door to more integrations. Growth used to be something a crew could plan a season around. Now it feeds itself, and the gap between what exists and what has actually been seen does not grow at a steady pace. It compounds. By the time one stretch of ocean has been reviewed, the water beyond it has already moved further than it moved during the entire time it took to look.
This is the difference between speed and acceleration, and the difference matters. Speed is how fast new water appears. Acceleration is whether that speed is itself increasing, and that is the real signature of this era. A defense built around a fixed review cadence was built for a world where the growth curve stayed flat. It rarely does anymore.
Storms Do Not Send a Forecast
A breach behaves like a storm in more ways than the metaphor usually gets credit for. A storm does not ask permission to form, and it rarely forms exactly where the last one did. It gathers strength in whichever stretch of water is least prepared for it, which is precisely why the stretch reinforced after last year’s storm is not the one that matters this year. Treating a breach as a single event, contained and closed once the incident report is filed, misses what a sailor already knows. The water that produced one storm is still capable of producing the next one an hour later, and the next crew that sails through it inherits whatever was learned, or wasn’t, from the last passage.
This is where uncertainty stops being a problem to solve and becomes the environment itself. No captain gets a forecast with certainty attached. They get patterns, pressure readings, and a sky that tells them something is changing, and they act on that before the full picture arrives. Cyber risk works the same way. Waiting for certainty before deciding is not caution. It is a decision to let the storm choose the timing instead of the crew.
A good decision made under this kind of uncertainty is not judged by whether the storm arrives. It is judged by whether the crew was ready to meet it if it did. A captain who reinforces the hull and then never meets the storm that week did not waste the effort. The absence of damage is not proof the decision was unnecessary. It is often the clearest sign the decision was right.
Not Every Danger in This Ocean Is Weather
Storms explain the ocean’s unpredictability, but they do not explain all of it. Some of what a ship meets out there is not weather at all. It is a fleet that chose this water on purpose, studied the routes other ships took, and is still studying the one this ship just sailed.
This is where the metaphor has to stop being kind. A storm has no memory and no intention. It does not learn from the ship that survived it last year. The fleet does. Every time a raid is repelled, the raiders do not treat it as a defeat. They treat it as information about which stretch of hull held and which did not, and they come back with that information, not with the same approach that just failed. A defense that only prepares for the storm that already happened is preparing for an opponent who has already moved on to studying the next one.
The asymmetry lives here too. A crew has to defend the entire hull, every plank, all the time. A raider only has to find one seam, once. That is not a fair fight, and no amount of investment makes it fair. What investment changes is how quickly a breach in the hull is seen, how well it is contained, and how fast the ship keeps sailing afterward. The crew must be right continuously. The fleet only has to be right once.
Not Every Raider Flies Its Own Flag
Not every ship on this ocean that means harm looks like a raider. Some fly the colors of a friendly vessel, send the right signal at the right distance, and are welcomed alongside before anyone checks whether the flag matches the hull underneath it. This is not weather, and it is not a raid in the old sense. It is a ship built to be believed.
The danger here is not that the signal is unconvincing. It is that it is convincing enough, fluent in every mark a friendly vessel is supposed to show, with nothing real behind it. A crew that grants passage because the flag looks right has confused the appearance of legitimacy with legitimacy itself. The fix is not sharper eyes. It is refusing to grant passage on the strength of a flag alone, and checking the hull anyway, every time, no matter how convincing the colors look from a distance.
The Danger That Comes Aboard Through the Hatch
Not every danger reaches this ship from outside the hull. Some of it is already below deck, and nobody signed it aboard.
There are three kinds of hands on any ship now, and only one of them is the crew a captain hired, trained, and knows by name. The second kind climbed aboard through a hatch nobody was watching, an integration wired in over a weekend, a tool given more reach than anyone meant to grant it, present and working and appearing on no manifest at all. It is not hostile. It is simply ungoverned, and ungoverned authority on a ship is a wreck waiting for the right wave. The third kind never boards at all, and does not need a flag of any color to do its work. It reaches the ship only as a signal from beyond the horizon, a message the crew’s own hands read and trust and act on, without the raider ever needing to set foot on deck.
A ship defended only against the first kind is defended against one hand in three. The question that matters is no longer only who is aboard. It is how much any hand, hired or not, can set in motion before someone else has to say yes.
Some of the Ocean Is Covered in Fog
None of this, the raider, the false flag, the hand that came aboard uninvited, would matter as much if the ocean were fully lit. It is not. Parts of it sit under fog, water that belongs to the ship, that the ship can reach, that carries real danger, and that nobody aboard has actually seen yet.
Fog does not avoid the deep water. A hazard can sit entirely inside it, the most dangerous stretch of the whole voyage hidden behind the one place nobody thought to look. A crew cannot rate what it has not found, and it cannot defend what it has not rated. This is why the danger that sinks a ship is rarely the storm on the horizon everyone already braced for. It is the one nobody logged, sitting exactly where the fog was thickest, discovered only when something finally ran into it.
Why a Compass and Not a Better Map
None of it, the raiders, the false flags, the hatch, the fog, gets any less dangerous by drawing a better map of it. A more detailed map is still a map, a picture of what already exists, and every danger just catalogued proves that what’s underneath keeps moving. What actually helps is a different question, asked again and again as the water changes under the hull: not where is the danger, but which direction reduces exposure right now.
Climate change makes the point plainly enough on its own. It has made storms harder to predict, more intense, less bound to the season anyone expected them in. Meteorologists work harder than ever to read patterns that keep shifting under them. But north is still north. A compass still points to the same pole it always has, and needs only the smallest correction for a drift that takes centuries to matter. Nobody has proposed retiring the compass because the storms got worse. If anything, it matters more exactly when the weather stops behaving the way it used to, because it is the one reading that never depended on the storm holding still long enough to be forecast.
Cybersecurity is the same shape of problem, and AI is its climate change. It did not just add more storms. It shifted the baseline a crew used to read the water by, the same way a warmer planet shifted what a normal season even means. What did not change is what a compass reads. Direction still means the same thing it always did, which way reduces exposure right now. The instrument was never built to forecast the storm. It was built to keep a ship oriented no matter which one arrives, and that job gets more important, not less, the less predictable the storms become.
A compass earns its usefulness through a strange property. The needle never settles and calls itself finished. If it did, it would stop being a compass and become a fixed marker, as useless as a map the moment the coastline shifts. The needle keeps moving because the ship keeps moving, before the breach, during it, after it, and then before the next one, on and on with no final heading where the work stops. That is the part most cybersecurity programs get wrong. They treat prevention, detection, and recovery as three boxes to check in sequence, instead of one ring that never stops turning.
Three Directions, One Ring
Cyber risk management is the proactive and predictive direction, reading the water ahead before the storm forms. Detection and response is the reactive and defensive direction, holding the line while the storm is directly overhead. Cyber resilience is the direction of recovery and improvement, learning the storm well enough to sail differently the next time one forms. None of the three is a phase you complete and file away. They are one ring, turning continuously, each stage feeding the next before the last one is even finished.
I built the Cybersecurity Compass around this because for years the industry has treated cybersecurity as a straight line: prevent, then detect, then recover, in that order, each stage closed out before the next begins. It is a comforting story. It is also not how an ocean behaves. The water does not wait for the previous storm’s cleanup to finish before generating the next one, and neither should our defense.
One Ring for the Clock, One Ring for the Compass
A single ring could have carried everything, the timing and the domain and its character all in one band. It does not, because a ring asked to answer two different questions at once ends up answering neither clearly.
The outer ring is a clock. It answers one question only, where the ship stands relative to the breach, before it, during it, or after it. A clock does not tell a crew what to do. It tells them when they are. That distinction matters more than it looks, because most cybersecurity programs mistake a snapshot of their exposure for knowing the time. A heat map is a photograph of the water taken once, colored and filed, and it stays exactly that color long after the water underneath it has changed. A clock does not work that way. It keeps ticking whether anyone is looking or not, and it is the only honest way to answer what hour it actually is on this ocean right now.
The ring just inside it is the compass itself, and it answers a different question entirely. Not when, but which discipline governs this hour and what it looks like in practice, proactive and predictive, reactive and defensive, or recover and improve. The hour and the direction move together, always, because the timing and the discipline change at the same moment. But they stay two rings rather than one, because a captain reads them as two separate questions even when both answers arrive together.
At the center of both rings sits the one thing that does not turn at all. People, process, and technology hold the same position no matter what hour the clock reads or which direction the compass names, because none of the three belongs to only one hour. The hands that read the instruments before a breach are the same hands that read them during and after one. The process that governs a decision does not get replaced at midnight. The technology that carries out the action does not swap itself out when the clock ticks forward. This is why the three sit at the center instead of out on either ring. They are not bound to one hour. They are the fixed point both rings are drawn around.
And they hold that position interlocking rather than side by side, each one cut to fit exactly where the other two stop. A ship missing one of the three does not simply have a gap. It has a hole shaped like the piece that is missing, and the other two, however well built, cannot close over it on their own.
Strategy Is Choosing Which Water to Defend
A ship cannot reinforce every plank equally and still move anywhere. Strategy is the set of choices that decides where the hull gets reinforced first, and that choice has to be made on purpose, not left to whichever alarm rang loudest last week. Cybersecurity strategy is an integrative set of choices that positions the ship on the stretch of ocean it has chosen to sail, in a way that sustains its cyber resilience over time. Choices, not activity. Position, not coverage. Sustained, not achieved once and filed away.
This is uncomfortable, because it means accepting that not every stretch of hull gets equal attention, and that some water gets left less reinforced on purpose. That is not negligence. Trying to defend everything equally is how a crew ends up defending nothing well. Strategy is the discipline of saying plainly which water matters most to this particular ship, and living with that choice long enough to find out whether it was the right one.
Governance Is Who Holds the Wheel
Strategy chooses the heading. Governance decides who is allowed to turn the wheel, how fast word of a change in the water reaches them, and who answers for the choice afterward. Governance is not a policy filed once a year. It is the structure that keeps strategy connected to whoever is actually accountable for the ship, established, communicated, and checked continuously rather than reviewed once at the end of a voyage.
This matters more than most crews want to admit, because every layer of command placed between a sighting and a decision is a layer the danger does not have to cross. A raider answers to no board and no reporting line. A well governed ship does not remove its own chain of command to match that speed, and should not try. It builds the shortest chain that still carries real accountability, so that word of danger reaches whoever holds the wheel in one move rather than five. The wheel has to turn fast. It also has to turn in the hands of someone who will answer for the turn. Governance is what makes both true at once.
There is a sharper question underneath all of this, and the hatch already raised it. It is not only who is allowed to turn the wheel. It is how much any hand aboard, hired or not, can set in motion on its own before someone else has to approve it. Minimizing what any hand can reach is no longer enough by itself. What matters just as much is minimizing what it can start without asking. A hand that can only read the charts is a different danger than a hand that can also change the ship’s heading unsupervised, and governance that only asks what a hand can access, without asking what it can set in motion alone, is answering half the question.
Speed Versus Precision
Whoever holds the wheel still has to decide under uncertainty. Every reading a compass gives is taken before the full picture arrives, and every heading chosen from it is a decision made on incomplete information. This is the tension a captain lives with on every passage. Wait for more information and the storm gets closer. Decide too fast on too little and the ship turns the wrong way. Neither extreme is the answer. The question a compass forces is not whether to decide with certainty, because certainty never arrives in time to matter. The question is how much precision a decision needs before speed becomes more valuable than accuracy.
This is the same tension that separates organizations that manage cyber risk from organizations that only document it. Waiting for a complete picture of exposure before acting produces a report, not a decision, and the water has already moved by the time the report is finished. A compass does not ask for a perfect bearing. It asks for the best available direction, taken now, correctable the moment new information arrives. That is not a lower standard than precision. It is what precision actually looks like when the environment refuses to hold still long enough to be measured twice.
A compass reading is not a single number either. It is a bearing with a margin, corrected again the next time it is read. A crew that demanded one exact figure for how much danger lay ahead would be asking the instrument to lie to them, since the honest answer was never a point. It was always a range, and the range itself was the useful part.
The Three That Actually Move the Ship
The center holds because these three actually do the work. People read the instruments and make the call. Process turns that call into repeatable action instead of a one time decision made under pressure. Technology carries the action out at the speed the water now demands, because a correct decision made too slowly is still a loss.
Strengthen only one of the three at any stage and the compass still spins without settling. A brilliant analyst without a repeatable process is a single point of failure wearing a job title. A mature process running on technology that cannot keep pace with the threat is a beautifully documented delay. Technology without people who understand what it is telling them is just noise with a dashboard. All three have to be tuned together, at every stage of the ring, for the needle to hold true.
There is a reason people cannot simply be replaced by faster instruments, even now. A compass reading is intelligence. It tells the crew what the water is doing. But intelligence alone has always moved a step behind an ocean that does not wait to be understood. What closes that gap is instinct, the hand that feels the swell change under the hull before any gauge confirms it, and turns the wheel a moment before the numbers would have told it to. Instinct is not a faster version of reading the instruments. It is what the crew has that the instruments do not, and it is the one part of the three that speed alone can never manufacture.
Resilience Is an Outcome, Not an Installation
Most organizations still talk about cyber resilience as something you buy, install, and then have. A certification, a maturity level, a project with a start date and an end date after which the box gets checked. That framing is comforting, and it is wrong. Cyber resilience is not a capability. It is an outcome, the result of managing cyber risk continuously rather than reviewing it once a year and calling the review a state of security.
A ship is not resilient because someone installed a resilience feature before it left port. It is resilient because the crew keeps reading the compass, keeps adjusting the sails, and keeps learning something from every storm and every raid it survives. Resilience shows up only in the doing, never in the having. An organization that stops turning the ring the day after a good audit is not resilient. It is lucky, and luck runs out exactly when a storm, a fleet, a false flag, or an unwatched hatch decides to test it.
This is also why chasing a posture free of cyber risk is the wrong goal, not just an unreachable one. A ship that measures itself against zero cyber risk will always feel behind, because the ocean keeps producing new water to worry about. A ship that measures itself against how well it is navigating right now, with the information it has, is playing a different game, one that can actually be won every single day instead of never.
Where the Ring Becomes an Operation
A compass reading taken once a year cannot keep a ship oriented through a storm that forms in an afternoon. This is the exact gap that led me to build the Cyber Risk Operations Center (CROC). The Cybersecurity Compass gives the direction. The CROC is what makes that direction operational, turning cyber risk management from an annual exercise into a continuous practice that runs at the same speed as the ocean it is watching. A compass without an operating center to act on its reading is direction with nowhere to go. An operating center without a compass is speed with no orientation. Neither one alone is enough.
Inside that operating center sits a second instrument, one that does not just point a direction but scores every single request against it, continuously, the moment it is made. Every hand that wants to act, every course a passenger or a piece of cargo requests, passes in front of this gauge before it is granted, and the gauge answers in proportion to the danger of that specific request, not by a rule written into the ship’s log months ago. This second gauge is what lets the compass’s direction actually reach a decision fast enough to matter.
Cyber risk does not stay inside one hull for long. It moves through suppliers, partners, and every connection a ship trusts enough to let aboard, which is the shared half of the definition most ships forget the moment they leave port. A ring that only turns within our own walls is watching half the ocean.
None of this was built to predict every storm, name every fleet before it arrives, or clear every hand that comes aboard in advance. It was built so that whatever danger comes, weather, raiders, false colors, or a hatch left unwatched, the ship is still oriented when it arrives, and still turning the ring afterward instead of standing still, congratulating itself on having survived.
It is offered as one attempt among many, in the hope it is useful to others navigating the same water.
References
Castro, J. (2024). Safely Sailing the Digital Ocean with the Cybersecurity Compass. ResearchGate. https://www.researchgate.net/publication/387410177 DOI:10.13140/RG.2.2.20696.00003
Castro, J. (2024). From Reactive to Proactive: The Critical Need for a Cyber Risk Operations Center (CROC). ResearchGate. https://www.researchgate.net/publication/388194441 DOI:10.13140/RG.2.2.27408.93445/1
Castro, J. (2024). Decoding Cyber Risk: A Visual Representation. ResearchGate. https://www.researchgate.net/publication/388386953 DOI:10.13140/RG.2.2.33733.15849/1
Castro, J. (2025). What Is Strategy in Cybersecurity? Rethinking the Way We Lead, Protect and Adapt. ResearchGate. https://www.researchgate.net/publication/393674625 DOI:10.13140/RG.2.2.16703.42409
Castro, J. (2025). What Is Governance in Cybersecurity? ResearchGate. https://www.researchgate.net/publication/393065290 DOI:10.13140/RG.2.2.30988.63360
Castro, J. (2025). Umbrellas, Storms, and Cyber Risk: Why Threat Management Is Not Risk Management. ResearchGate. https://www.researchgate.net/publication/396695719 DOI:10.13140/RG.2.2.24818.98240
Castro, J. (2026). Cyber Resilience Is Not a Capability. It Is an Outcome. ResearchGate. https://www.researchgate.net/publication/404823009 DOI:10.13140/RG.2.2.18528.85766
Castro, J. (2026). Cybersecurity: The Infinite Chess Game. ResearchGate. https://www.researchgate.net/doi/10.13140/RG.2.2.33672.58886 DOI:10.13140/RG.2.2.33672.58886
Castro, J. (2026). Current Cybersecurity Operating Models Do Not Operate at the Speed and Acceleration of the Attack Surface in the AI Age. ResearchGate. https://www.researchgate.net/publication/408208523 DOI:10.13140/RG.2.2.12744.07687
Castro, J. (2026). The CISO Reporting Structure Is the Starting Point of Cyber Resilience Failure. ResearchGate. https://www.researchgate.net/publication/408316374 DOI:10.13140/RG.2.2.14467.67362
Castro, J. (2026). Rethinking Zero Trust for the Agentic AI Era. ResearchGate. https://www.researchgate.net/publication/406634241 DOI:10.13140/RG.2.2.17165.29924
Castro, J. (2025). Artificial Intelligence (AI) vs Artificial Instinct (Ai), The Distinction Cybersecurity Can’t Afford to Ignore. ResearchGate. https://www.researchgate.net/publication/397834714 DOI:10.13140/RG.2.2.31096.30725
Castro, J. (2026). Synthetic Trust: The New Risk Layer in the Age of AI. ResearchGate. https://www.researchgate.net/publication/401824509 DOI:10.13140/RG.2.2.34107.27688
Castro, J. (2025). Cybersecurity and the Unknown Unknowns: Why the Greatest Cyber Risks Are Off the Map. ResearchGate. https://www.researchgate.net/doi/10.13140/RG.2.2.10409.66406 DOI:10.13140/RG.2.2.10409.66406
Castro, J. (2025). Beyond the Gridlock: Why Cyber Risk’s Nature Exposes Heat Maps’ Fatal Flaws. ResearchGate. https://www.researchgate.net/publication/391776569 DOI:10.13140/RG.2.2.21325.76000


