Radical Results: A Security Org's Version of Radical Candor
Evan Johnson
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
Security teams are notoriously hard to evaluate — there are no quarterly numbers to hit, no obvious product ships, and success is often defined by things that don't happen. Evan Johnson, co-founder and CEO of RunReveal and former first security engineer at Cloudflare and Segment, proposes a two-axis framework adapted from the book Radical Candor: plotting security initiatives on a Cartesian plane of "vibes" (collaboration and cultural fit) versus "effectiveness" (actual risk reduction), then using those historical data points to understand how the team is perceived and where it can improve. ---

Key moments
- 3:59 Radical Candor quadrant system adapted as foundation for security team framework
- 10:00 New framework: vibes (collaboration) and effectiveness as security team axes
- 18:00 Interactive tool released at ejcx.dev/radicalresults for team self-assessment
- 20:00 WebAuthn rollout case study: 6-month project should have taken 1 week
- 22:00 CEO call under active attack forced immediate rollout proving speed beats caution
- 24:00 Linux MDM case study: focus group approach damaged dev relationships unnecessarily
- 25:59 Conclusion: optimize for more dots on plot over perfect individual execution
Radical Results: A Security Org's Version of Radical Candor
Speaker: Evan Johnson
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch on YouTube
Reading time: ~6 minutes
TL;DR
Security teams are notoriously hard to evaluate — there are no quarterly numbers to hit, no obvious product ships, and success is often defined by things that don't happen. Evan Johnson, co-founder and CEO of RunReveal and former first security engineer at Cloudflare and Segment, proposes a two-axis framework adapted from the book Radical Candor: plotting security initiatives on a Cartesian plane of "vibes" (collaboration and cultural fit) versus "effectiveness" (actual risk reduction), then using those historical data points to understand how the team is perceived and where it can improve.
Introduction
The management literature on giving and receiving honest feedback rarely accounts for security teams specifically. Radical Candor, Kim Scott's widely-read guide to direct communication in management relationships, is a book that roughly half the audience at this BSidesSF talk had read — but it was written for individual manager-employee dynamics, not for evaluating how a security organization as a whole is perceived across an entire company.
Evan Johnson, who has served as the first security engineer at Cloudflare and at Segment and now leads RunReveal, a company focused on security logging, came to BSidesSF 2025 with a framework he has been refining through his own experience as a security leader. His thesis: measuring a security team's effectiveness is genuinely difficult, and the standard frameworks do not transfer cleanly to security. But the quadrant concept from Radical Candor — when applied at the team level rather than the individual level — gives security leaders a useful tool for diagnosing how their work is landing at the company.
The Radical Candor Foundation
▶ Watch: Radical Candor recap (04:00)
Kim Scott's original framework places individual conversations on a two-axis quadrant. The vertical axis is "care personally" — genuine concern for the other person. The horizontal axis is "challenge directly" — the ability to give real feedback even when it is uncomfortable. The ideal is the top-right quadrant: Radical Candor, where both care and directness are present. The acceptable fallback is "Obnoxious Aggression" (bottom-right): sometimes you are blunt without much personal warmth, but at least you were honest. The dangerous quadrants are "Ruinous Empathy" (top-left: you care but can't deliver the message) and "Manipulative Insincerity" (bottom-left: neither honesty nor care).
Johnson illustrated these quadrants with two anecdotes from the book. In the first, Sheryl Sandberg tells Scott she sounds unintelligent when she says "um" constantly and needs coaching — dipping into obnoxious aggression to get the message across after gentler hints failed. In the second, "Bob" underperforms for an entire year while Scott, caring personally but avoiding directness, never gives him the feedback he needed. When she fires him, Bob asks why she never said anything — a textbook example of ruinous empathy resulting in a worse outcome for both parties.
Why Security Teams Are Different
▶ Watch: The measurement problem in security (12:01)
Johnson was candid about three uncomfortable truths that make security team evaluation genuinely hard:
Security outcomes are not directly attributable. A team can do everything right and still suffer a major breach. A team can do everything wrong and never appear on the front page of a newspaper. The correlation between security work and security outcomes is real, but imperfect — which means the team is not "solely responsible" for whether the org succeeds or fails security-wise.
Context matters more than playbooks. The biggest mistake a security leader can make, Johnson argued, is arriving at a new company and repeating what worked at the last one. A bank's security team looks completely different from a startup's, and neither model is wrong — they are calibrated to different organizational contexts, risk tolerances, and company cultures.
Most security work is not measurable. A sales team has a quarterly number. An engineering team is either shipping or not. A finance team has books that close. Security teams often operate without comparable metrics, which makes it easy for their work to be undervalued or misunderstood.
These constraints led Johnson to his core question: if you cannot measure security outcomes directly, how do you evaluate whether a security team is doing well at the company level?
The Radical Results Framework
▶ Watch: The two-axis framework (14:01)
Johnson adapted the Radical Candor quadrant for security teams by replacing the individual interpersonal axes with two team-level dimensions:
Vibes (X-axis, horizontal) — Johnson named this axis "vibes" deliberately, noting that it is really about collaboration and cultural fit. How well does the security team work with the rest of the company? Do they say yes or no in a way that matches the company's communication norms? He gave a concrete example: a CISO friend of his had built a highly capable security team, but in a company culture where other teams "laid down the law" with direct mandates, his security team was too deferential — getting "shoved around." The vibes of the team, despite individual technical excellence, were miscalibrated for the cultural environment. The "shift left" movement, Johnson argued, partially emerged as a survival mechanism for security teams that learned to avoid friction by embedding into engineering processes rather than standing apart from them.
Effectiveness (Y-axis, vertical) — The axis that should be self-evident but requires specificity: the team's ability to actually manage risk. Johnson's view is that effectiveness requires more than advice and consultation — security teams have to own projects, manage risks to completion, and avoid being "clipboard-holding" observers. "You have to get in the action," he said. Teams that partner closely with engineering and own specific deliverables demonstrate effectiveness more visibly than teams that flag risks and wait.
▶ Watch: Real-life examples on the quadrant (20:03)
Johnson plotted two real past projects on this framework:
WebAuthn rollout (high effectiveness, vibes misread). His team rolled out WebAuthn — hardware-backed phishing-resistant authentication, YubiKeys for everyone — but took six months to complete a deployment that could have happened in a week. The mistake was a staged, cautious rollout calibrated for a company culture that valued thoroughness, at a company whose actual culture prized speed above almost everything else. The project succeeded technically, but the pace was misaligned. The CEO eventually called midway through an active attack and said "turn it on now." That call was the signal, Johnson said, that the team had been miscalibrated from the start. On the quadrant, he revised his initial self-assessment downward on the vibes axis — the security team had not read the cultural environment accurately enough.
Compliance-driven distribution list enforcement (vibes suffered for thoroughness). A second project involved deploying controls around email distribution lists as a compliance obligation. Rather than gathering stakeholder input once and then moving quickly, the team ran an extended focus group that dragged on, damaged relationships with other parts of the company, and produced an outcome that was no more effective than a faster approach would have been. Johnson's lesson: when a mandate is compliance-driven, use the compliance obligation itself as cover — "we have to do this, sorry, here's a sticker if you find a bug" — rather than creating the impression that the outcome is negotiable.
More Dots Is Better
▶ Watch: Optimizing for more dots on the board (18:02)
One of Johnson's most practical pieces of advice: optimize for volume of completed projects rather than perfection on each individual one. He called this "more dots on the board." A security team that ships many small, visible wins — across a range of partners in the company — accumulates both the data points needed to self-evaluate and the goodwill that makes future collaboration easier. Good vibes from today's project pay dividends when the next security initiative needs buy-in. In contexts where correctness and thoroughness are non-negotiable (highly regulated financial institutions, for example), the calculus changes — but for most tech-adjacent security teams, shipping faster and learning from feedback is almost universally better than waiting for perfection.
Notable Quotes
"The biggest mistake you can commit as a security engineer or a security leader is you show up to a company and you just repeat what you've seen that works before." — ▶ 12:01
"You have to be not a clipboard-holding security team. You have to get in the action. You have to own and manage certain risks and projects that you wanna see completed." — ▶ 16:01
"The CEO called six months into this project and said, 'Turn it on now. I'm tired of waiting.' That should have been the red flag immediately that we should have done this way faster." — ▶ 22:03
Key Takeaways
- Security team performance is best evaluated on two dimensions: how collaborative the team is culturally (vibes) and how effective it is at reducing actual risk (effectiveness). Neither axis alone is sufficient.
- Cultural fit is not a soft concern. A technically excellent team calibrated for the wrong organizational culture will underperform and lose influence. Understanding the company's communication norms — whether they reward directness or collaboration — is a prerequisite for effective security leadership.
- Plot past projects on the framework. Johnson's tool is retrospective: rate your own major initiatives over the past year on both axes, notice the patterns, and identify where the team is systematically miscalibrated.
- Speed is usually underrated in security. The WebAuthn example shows that a six-month rollout of a one-week change can be technically successful and culturally wrong at the same time. Unless the organizational culture genuinely values thoroughness over speed, bias toward moving faster.
- Good vibes compound. Every project completed with positive collaboration builds social capital that makes the next security initiative easier to land. The case for investing in relationships is not just cultural — it is strategic.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Johnson's 'Radical Results' vibes-vs-effectiveness quadrant is a genuinely useful diagnostic for security leaders who've built technically excellent teams that still fail to land organizational influence. The WebAuthn rollout story is an honest self-critique that most security leaders would never give on stage. But this is management consulting content in a security conference slot — interesting, not technical.
Heather Calloway (CISO) — WEAK
Johnson's radical results framework — plotting security initiatives on vibes versus effectiveness axes — gives security leaders a retrospective tool for diagnosing where their team is miscalibrated. The WebAuthn rollout case study is honest and instructive. The framework's scope is organizational effectiveness, not security impact.