The First Security Hire's Survival Guide
Chris Honda (Security Lead · Plotly)
BSides Seattle 2026 · Day 2 · Track 2
Overview
Chris Honda, currently the sole security person at Plotly and a veteran of BSides Seattle (fourth year attending), delivers an honest and personal talk about surviving as the first and only security hire at an organization. This is not a technical talk -- Honda states this upfront and gives the audience explicit permission to leave. Instead, it addresses the human and psychological challenges of being the person responsible for all of security at a company with no existing security program, no team, and often no clear expectations about when help is coming.

Key moments
- 0:00 Introduction: this is not a technical talk and that's okay
- 3:45 The isolation of being the first and only security person
- 5:30 Community is essential, not optional: build your personal network
- 9:45 Partnership: align security with what the business needs
- 11:45 Sitting in meetings is magical: be part of the solution
- 13:30 Say yes-if instead of no: the ISO trifecta twice in one year
- 17:30 Set team expectations in writing before you start the role
- 19:30 Two types of first: startup from scratch vs mature company with no security
The First Security Hire's Survival Guide
Speakers: Chris Honda, Security Lead, Plotly
Conference: BSides Seattle 2026
YouTube: https://www.youtube.com/watch?v=-Lo2bkwYwGg
Overview
Chris Honda, currently the sole security person at Plotly and a veteran of BSides Seattle (fourth year attending), delivers an honest and personal talk about surviving as the first and only security hire at an organization. This is not a technical talk -- Honda states this upfront and gives the audience explicit permission to leave. Instead, it addresses the human and psychological challenges of being the person responsible for all of security at a company with no existing security program, no team, and often no clear expectations about when help is coming.
Honda brings credibility through direct experience: he was the first security person at his previous company Wistic (starting as a bad software engineer who got moved to compliance, then security) and is now in his second round at Plotly, a company that has been around 12-14 years but never had a security hire. His central message is that the playbook is not the same the second time, that burnout is real and dangerous, and that community, partnership, and strategic prioritization are survival essentials rather than nice-to-haves.
The talk resonates because it acknowledges what most security talks ignore: the emotional toll of being overwhelmed, under-resourced, and responsible for everything, and the importance of taking care of yourself to remain effective.
Background
▶ Watch: Introduction: this is not a technical talk and that's okay (0:00)
Honda frames the first security hire problem as uniquely isolating. Most security professionals have worked on teams; very few have been the sole security person for an extended period. The fires keep getting bigger, the work is invisible until something goes wrong, and there is a survival period that must simply be endured before things improve.
He draws a distinction between two types of "first": being the first security person at a small, early-stage startup (like Wistic at 20-25 people, where Honda built the program from scratch including the first SOC 2 audit with no prior knowledge) versus being the first security person at a mature company that has never had dedicated security (like Plotly at 12+ years, where established employees have never worked with a security person and the culture must be built differently).
Key Findings
▶ Watch: Community is essential, not optional: build your personal network (5:30)
Community is Essential, Not Optional: Honda distinguishes between participating in communities (BSides, OWASP, ISACA, ISC2, local CISO forums like the Salt Lake CISO Forum) and building your own community. The first provides connection and validation; the second provides the personal support network of people who have been in your specific situation. Honda explicitly offers himself as a sounding board: "I want to support you and be a sounding board and when you have the hard days, I'm more than happy to hop on a call."
Partnership Means Aligning with Business Needs: Honda reframes partnership as understanding what the business actually needs, not what security thinks is important. Businesses care about making money, keeping money, and spending as little as possible. Security initiatives must be framed in business terms. His vulnerability management example: instead of saying "we need to fix these vulnerabilities," say "we'll build this out for you, and it's going to take 40% less time. Code is more secure. It gets shipped even faster. Everyone's happy."
Sitting in Meetings is Magical: Honda emphasizes that attending non-security meetings -- finance, sales, engineering -- signals that you care about being part of the solution rather than waiting to be called in when something breaks. This builds the relationships and buyin that security programs depend on.
Say No, But Frame It as "Yes, If": Instead of saying "no, this is unreasonable," Honda recommends "yes, we can do this if this is the only thing I'm working on for the rest of the calendar year" or "yes, if we can hire another two people in the next two months." This avoids triggering defensive reactions while setting realistic expectations. He draws from personal experience: completing the ISO trifecta (ISO 27001 security, privacy, and AI) twice in one year with no foundation, which he describes as "doable but will burn you out."
The Jurassic Park Rule: There will always be more to do than time allows. Ask "why" three times for every priority. If you cannot answer why you are doing something, it probably is not the most important thing.
Set Expectations Before You Start: Honda's most pointed advice is to have explicit conversations about team-building expectations before accepting the role. He started at Plotly under the assumption he would build a team -- "a conversation but nothing finalized" -- and is now having a different experience than expected. Written expectations about how long you will be the only person, what budget exists for tools, and what the hiring timeline looks like can prevent the frustration of unmet assumptions.
Technical Deep Dive
▶ Watch: Sitting in meetings is magical: be part of the solution (11:45)
The talk is intentionally non-technical. Honda self-identifies as "not the technical guy" and focuses on the human and organizational dimensions. The most technical references include completing SOC 2 audits, the ISO 27001/privacy/AI trifecta, vulnerability management programs (AppSec/ABSEC), and security awareness training. These serve as context for the prioritization and partnership discussions rather than technical deep dives.
Demo / Proof of Concept
▶ Watch: Say yes-if instead of no: the ISO trifecta twice in one year (13:30)
No demo was presented. The talk is structured as personal testimony and practical advice from direct experience.
Defensive Implications
▶ Watch: Two types of first: startup from scratch vs mature company with no security (19:30)
For anyone who is or will be the first security hire:
- Build your personal support community before you need it -- join local CISO forums, BSides communities, and make friends who have been in the role
- Frame every security initiative in business terms: how does it help make money, keep money, or reduce friction for revenue-generating teams?
- Attend non-security meetings to build relationships and demonstrate that security is part of the solution
- Replace "no" with "yes, if" to set realistic expectations without triggering defensiveness
- Apply the Jurassic Park rule: there will always be more to do than time allows; ask "why" three times to identify true priorities
- Negotiate team-building expectations in writing before accepting the role -- do not assume verbal discussions will hold
- Recognize that being the first security person at a startup vs. a mature company requires fundamentally different approaches to culture-building
- Protect yourself from burnout by setting boundaries, saying no, and recognizing that it takes longer to recover from burnout than to prevent it
Key Takeaways
- Being the first security hire is a survival situation -- acknowledge that and build accordingly
- Community is essential infrastructure, not a nice-to-have; build a personal network of people who have been in your position
- Businesses care about money -- frame security in those terms or expect no buyin
- "Yes, if" is more effective than "no" for setting boundaries and managing expectations
- The playbook is not the same the second time: different companies, maturity levels, and cultures require different approaches
- Set expectations about team growth and budget in writing before starting the role
- Burnout is a real occupational hazard; protect your time and boundaries because recovery takes longer than prevention
About the Speaker(s)
Chris Honda (who notes the proper pronunciation is "Kunda") is the security lead at Plotly, a data visualization and analytics platform that has been operating for 12-14 years. He previously built the security and compliance program at Wistic from scratch, starting as a software engineer before moving to compliance and security. He is based in Utah and is a returning BSides Seattle speaker (fourth year). Outside of work, he is a competitive dance dad and aspiring tomato farmer.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
A heartfelt personal talk about the emotional and organizational challenges of being the first security hire. Zero technical content -- no tools, no exploits, no architecture, no data. This is therapy and career advice for security practitioners, not a security research contribution. I respect the honesty but there is nothing here to evaluate technically.
Heather Calloway (CISO) — STRONG
An honest and practical survival guide for the increasingly common scenario of being the first and only security person at a company. The 'yes, if' framing, business alignment advice, and expectation-setting guidance are directly useful for security practitioners stepping into solo roles. Limited governance depth but addresses a real workforce gap.