INFORMATION SECURITY LEADER

Haddin Meier

HAY-din MY-er

Like Hayden. Last name rhymes with fire.

Leading security.
Building resilience.

I lead security strategy, develop teams, and turn complex risks into clear decisions. My approach combines executive perspective with hands-on technical experience.

GUIDING PRINCIPLES

The principles that guide how I make decisions, lead teams, and approach complex challenges.

  • Strategy & governance

    Explore my principles: Strategy & governance

    Strategy is the discipline of leaving good things undone.

    There will always be more worthwhile work than capacity. A strategy must explain what deserves attention, what can wait, and what we will deliberately decline. Priorities become credible when they change how we allocate people, time, and money.

    Governance should make judgment travel.

    Good governance lets people make sound decisions without needing the same senior person in every room. It makes intent, authority, and boundaries clear. If every routine decision still travels upward, we have more work to do.

    Every metric needs a counterquestion.

    When a number improves, ask what might have become worse, disappeared from view, or been redefined. Measures help us investigate reality. They become dangerous when improving the measure becomes sufficient proof of progress.

    A decision should carry its conditions for reconsideration.

    Explain what you believe, what you are uncertain about, and what evidence would change your mind. This makes it easier to adapt without turning every change of direction into a contest over who was right.

  • Security & technology

    Explore my principles: Security & technology

    The safe path should require the least invention.

    People should have a clear, practical way to do their work securely. Repeated workarounds are a reason to examine the approved process. Build useful defaults and supported paths, then reserve additional friction for decisions whose consequences justify it.

    Complexity spends attention before it spends money.

    Every tool, integration, and exception creates something people must understand, maintain, and eventually recover. Evaluate technology by the operational burden it creates throughout its life. A capability has limited value if we cannot operate it reliably.

    A control earns confidence by surviving a test.

    A policy, purchased tool, or green dashboard is a claim about protection. Test whether the protection works under relevant conditions. Confidence should reflect demonstrated coverage, known limitations, and evidence recent enough to matter.

    Security should preserve the freedom to act.

    Protect the organization’s ability to serve customers, change direction, and recover from mistakes. Evaluate security investments against those capabilities. Make the risks we accept as explicit as the risks we reduce.

  • People & resilience

    Explore my principles: People & resilience

    Make bad news cheap to deliver.

    People watch what happens to the person who raises a problem. Receive unwelcome information with curiosity, especially when it challenges your own decision. Keep standards high while making early disclosure safer than silence.

    Delegate judgment with the work.

    Responsibility needs the authority, context, and resources to act. Explain the outcome, the constraints, and when to escalate. Develop people’s ability to decide, then give them room to exercise it.

    Heroics shouldn't be necessary.

    Enable people to rise to a challenge, but make those moments rare. Celebrate carefully: rewarding heroics can encourage dependence on them. Hold leaders accountable for results and for creating conditions that make routine rescue unnecessary.

    A lesson is learned when future work changes.

    An incident review should leave something different behind: a stronger control, a clearer decision, a tested recovery step, or a better design. Assign ownership and verify the change. Understanding a failure is only part of preventing its return.