Power Dynamics in Security Leadership: a legato leitmotif lullaby on leading lightly and luminously

Sarai Rosenberg

BSidesSF 2026 · Day 2 · AMC Theatre 12

Overview

In her BSides SF talk, "Power Dynamics in Security Leadership: a legato leitmotif lullaby on leading lightly and luminously," Sarai Rosenberg delves into the often-overlooked yet critical role of power dynamics in shaping effective security leadership. Moving beyond traditional technical discussions, Rosenberg challenges the audience to critically examine how power is wielded, perceived, and leveraged within security organizations and across inter-team collaborations. The talk emphasizes that true leadership in security is not merely about technical expertise or hierarchical authority, but about the nuanced ability to influence, build trust, and foster genuine collaboration.

Watch on YouTube

Visual summary for Power Dynamics in Security Leadership: a legato leitmotif lullaby on leading lightly and luminously by Sarai Rosenberg
Visual summary for Power Dynamics in Security Leadership: a legato leitmotif lullaby on leading lightly and luminously by Sarai Rosenberg

Key moments

  1. 0:00 Introduction: Positions confer power, accepted as truth.
  2. 1:55 Personal motivation: Learning efficient, intentional use of power.
  3. 2:40 Ethics of power: Authoritative power is a trust withdrawal.
  4. 4:30 Trust is the lifeblood for effective security work.
  5. 6:00 Why terminology matters; defining power as influence.
  6. 6:50 Weber's three types of authority: charismatic, traditional, legal.
  7. 7:40 Historical management evolution; heavy-handed methods burn trust.
  8. 10:00 Mary Parker Follett: Distinguishing 'power over' from 'power with'.

Power Dynamics in Security Leadership: a legato leitmotif lullaby on leading lightly and luminously

Speakers: Sarai Rosenberg

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=ZFFo2yYIbIc

Overview

In her BSides SF talk, "Power Dynamics in Security Leadership: a legato leitmotif lullaby on leading lightly and luminously," Sarai Rosenberg delves into the often-overlooked yet critical role of power dynamics in shaping effective security leadership. Moving beyond traditional technical discussions, Rosenberg challenges the audience to critically examine how power is wielded, perceived, and leveraged within security organizations and across inter-team collaborations. The talk emphasizes that true leadership in security is not merely about technical expertise or hierarchical authority, but about the nuanced ability to influence, build trust, and foster genuine collaboration.

Rosenberg, drawing from her extensive experience securing some of the world's largest cloud environments and CDNs, asserts that understanding the terminology and concepts of power dynamics is essential for any security professional aiming to lead effectively. She highlights that while positions confer power, the true measure of a leader lies in their intentional and ethical application of influence. This perspective is particularly vital in an industry often characterized by directive "department of no" paradigms, which, as Rosenberg argues, are ultimately detrimental to trust and long-term security outcomes.

The talk matters because it addresses a fundamental challenge in cybersecurity: the human element of security implementation. Technical controls, no matter how robust, are only as effective as the organizational culture and leadership that supports their adoption and enforcement. By equipping security professionals with a deeper understanding of power, authority, and influence, Rosenberg provides a framework for building more resilient, collaborative, and ultimately, more secure organizations. Her insights offer a refreshing and critical lens through which to view leadership, urging a shift from authoritative mandates to empowering partnerships.

Background

▶ Watch: Introduction: Positions confer power, accepted as truth. (0:00)

The landscape of security leadership has undergone significant shifts over the decades. Historically, security teams often operated under an authoritative paradigm, frequently perceived as the "department of no." This approach, while sometimes effective in enforcing strict controls, often resulted in fractured relationships with other teams, low trust, and a reactive rather than proactive security posture. The late 20th and early 21st centuries saw a push towards a more collaborative model, emphasizing "guardrails, not gates," and integrating security into development lifecycles. However, Rosenberg observes a recent industry-wide trend, both within and outside security, reverting to a more forceful, directive authority. This cyclical pattern underscores a persistent struggle within organizations to balance control with collaboration.

Rosenberg's analysis is deeply rooted in academic foundations, drawing from psychology, sociology, and philosophy. She references the work of seminal thinkers who have shaped our understanding of power and management. Max Weber, an influential German sociologist from the late 19th and early 20th centuries, identified three primary types of authority: charismatic authority (based on personal appeal), traditional authority (derived from custom and historical precedent, like patriarchy), and rational-legal authority (stemming from formal rules and positions, such as a manager's role). Weber's era saw a shift from manual labor to knowledge work, influencing the development of Taylorism and mechanistic scientific management, characterized by hierarchical structures, strict measurements, and analytical performance evaluation.

This rigid approach evolved through the 20th century, with modern management increasingly incorporating human relations, coaching, career growth, autonomy, and motivation, particularly with the rise of knowledge workers. The digital age further emphasized adaptability, teamwork, and human well-being. However, Rosenberg notes that despite these advancements, the allure of "heavy-handed and directive methods" persists as an appealing shortcut, especially under urgent pressures or in hostile job markets. She cautions that such methods ultimately erode trust and worker motivation, highlighting the critical need for a more nuanced approach.

A pivotal figure in Rosenberg's discussion is Mary Parker Follett, a contemporary of Weber and now recognized as the "mother of modern management." Follett's work, which gained prominence later in the 20th century, distinguished between power over and power with. Power over represents a directive form, where one person dictates actions to another (e.g., a manager assigning work). In contrast, power with leverages empowerment and collaboration to influence actions (e.g., a manager coaching a report). This distinction forms a cornerstone of Rosenberg's argument for more effective security leadership.

Further enriching this foundation is Hannah Arendt's definition of power as a collaborative concept, emphasizing the human ability "not just to act, but to act in concert." Arendt, writing after fleeing the Holocaust, posits that power resides collectively within a group, emerging from collaboration rather than being held solely by an individual leader. This perspective challenges the conventional view of a leader as the sole wielder of power. Rosenberg also touches upon the insights of clinical psychologist Rollo May, who built on Arendt's ideas, linking violence and anger to feelings of powerlessness and repressed rage. Together, these academic frameworks provide a comprehensive lens through which Rosenberg analyzes the intricate, often invisible, forces at play in organizational dynamics and their profound impact on security outcomes.

Key Findings

▶ Watch: Ethics of power: Authoritative power is a trust withdrawal. (2:40)

Rosenberg's talk distills several critical findings regarding power dynamics in security leadership, challenging conventional wisdom and offering a more effective path forward:

  1. Power is the Ability to Influence, Not Just Authority: A core finding is that power extends far beyond formal titles, positions, or the ability to issue directives. Rosenberg defines power simply as the ability to influence. This broad definition encompasses various forms, including charismatic authority, the formal rational-legal authority of a manager, and the informal influence cultivated through relationships. Understanding this distinction is crucial, as many forms of power are wielded intentionally, while others exist inherently due to social situations (e.g., racial, ethical, gendered power dynamics) regardless of individual intent.
  1. Authoritative Power is a Trust Withdrawal: Every instance of using authoritative power (power over) constitutes a trust withdrawal. While the impact can be small if applied thoughtfully and transparently, it always depletes the organizational trust account. Trust, Rosenberg emphasizes, is the "lifeblood" of effective work, built slowly and lost quickly. She argues that the shift back towards forceful, directive authority in the industry is detrimental to this vital asset. The goal of leadership should be to be trustworthy, rather than merely demanding trust.
  1. The Superiority of "Power With" over "Power Over" for Sustained Influence: Drawing from Mary Parker Follett, Rosenberg advocates for leveraging power with—an empowering, collaborative approach—over power over—a directive one. While acknowledging that "power over" has its necessary, albeit rare, applications (e.g., critical incident response like Log4j), she stresses that it should be avoided unless truly necessary. Power with, exemplified by coaching and fostering shared goals, builds long-term influence and engagement.
  1. Power is Socially Situated: Beyond formal and informal types, power is deeply embedded in social contexts. Rosenberg highlights that power is socially situated across racial, ethical, gendered, and class lines, and within marginalized bodies. This means the impact of power dynamics is never equal among targets, and a leader's actions or a team's reactions are always influenced by these underlying social structures. The analogy of "the bear and the fish do not come to the table as equals" powerfully illustrates this inherent imbalance.
  1. Influence Without Authority is the Bread and Butter of Security Leadership: Given that security professionals often need to drive change across teams they don't directly manage, influence without authority becomes paramount. Rosenberg outlines a four-step recipe: 1) Establish rapport (charismatic authority), 2) Emphasize shared goals (collective power), 3) Provide security risk context (using Follett's concept of integration of perspectives), and 4) Describe mitigation options (empowering choice, not dictating). This approach shifts from telling people what to do to enabling them to make informed decisions that align with security objectives.
  1. Zero Upset is Not a Target: Rosenberg challenges the notion that effective leadership means avoiding all conflict or anger. She states, "Zero is not a target" when it comes to upset people, anger, or disagreements. Instead, she argues that disagreements and discussions are healthy relationship-building exercises. Anger and "violence" (in Arendt's and May's sense, as expressions of impotence or repressed rage) often stem from powerlessness or feeling unheard. Leading with curiosity and seeking to understand these underlying fears can de-escalate conflict into collaboration, whereas tranquility can sometimes be a warning sign of unaddressed issues.

Technical Deep Dive

▶ Watch: Why terminology matters; defining power as influence. (6:00)

While not "technical" in the traditional sense of code or vulnerabilities, Rosenberg's talk offers a profound technical deep dive into the mechanics of human influence and organizational power, presenting a structured framework for security professionals to analyze and apply these concepts. This involves understanding the theoretical underpinnings of power, the evolution of management philosophies, and practical strategies for influencing security outcomes.

At the core of Rosenberg's framework is the explicit definition of power as the ability to influence. This is a critical distinction from mere authority, which she describes as a form of force. She elaborates on Weber's three types of authority:

  • Charismatic Authority: Influence derived from an individual's personality, charm, or perceived special qualities. In a security context, this could be a security engineer who builds rapport and respect through their expertise and communication style.
  • Traditional Authority: Power based on established customs, traditions, or historical precedent. While less directly applicable in modern tech, its echoes can be seen in long-standing organizational hierarchies or unwritten rules.
  • Rational-Legal Authority: Authority vested in a formal position or office, governed by rules and laws. This is the manager's ability to hire or fire, or an incident commander's delegated power during a crisis. Rosenberg notes this hangs like the "sword of Damocles" over reports.

Rosenberg then traces the evolution of management thought, showing how these power dynamics have been conceptualized and applied. The late 19th century saw Taylorism and mechanistic scientific management, characterized by strict hierarchies, analytical performance metrics, and a "boss knows best" mentality. This heavy-handed approach, while efficient for industrial automation, proved less effective for the burgeoning class of knowledge workers. The 20th century saw the rise of human relations approaches, incorporating coaching, career growth, autonomy, and motivation, leading to the more adaptable, human-centric management styles prevalent today, especially in the digital age. Despite this evolution, the temptation to revert to directive, "heavy-handed" methods remains, particularly in high-pressure security scenarios.

A central conceptual tool introduced is Mary Parker Follett's distinction between power over and power with.

  • Power Over: A directive, unilateral form of power where one person dictates actions to another. Examples include a manager assigning tasks or a parent yelling "Stop!" to a child running into the street. Rosenberg advises using this only when "truly necessary," such as in critical incident response (e.g., Log4j vulnerability remediation).
  • Power With: A collaborative, empowering form of power that leverages shared goals and mutual influence. This involves coaching, providing feedback, and supporting growth. This approach builds trust and long-term engagement.

Rosenberg further integrates Hannah Arendt's concept of collective power, where power is not an individual attribute but emerges from people acting "in concert." A leader, in this view, doesn't hold power themselves but facilitates the collective power of the group. This is particularly relevant in security, where outcomes often depend on cross-functional collaboration. She also highlights that power is socially situated, meaning it interacts with and is influenced by broader societal dynamics like race, gender, and class. This adds layers of complexity, as the impact of power dynamics is rarely uniform.

The practical application of these theories culminates in Rosenberg's "basic recipe for influencing security goals without authority," a four-step methodology:

  1. Establish Rapport: Leverage charismatic authority to build trust and connection with stakeholders. This is the foundation for any successful influence attempt.
  2. Emphasize Shared Goals: Frame security initiatives in terms of common objectives that benefit all parties, tapping into collective power. Instead of "you must do this," it becomes "how can we achieve X together?"
  3. Provide Security Risk Context (Integration): This step utilizes Follett's concept of integration, where distinct perspectives are combined to make a decision. Security professionals should articulate the "outcomes of a hypothetical attacker scenario," explaining threats and consequences without dictating solutions. This integrates the security perspective with the operational realities of other teams.
  4. Describe Mitigation Options: Instead of prescribing a single solution, offer a range of potential mitigating security controls within the attack chain. This empowers stakeholders by giving them choices, allowing them to participate in the decision-making process and choose the path that best fits their context, while still achieving security goals. This collaborative approach leverages "power with."

This deep dive reveals that effective security leadership is an intricate dance of understanding various power forms, consciously choosing between directive and empowering approaches, and strategically integrating diverse perspectives to achieve shared security outcomes. It's a "technical" skill in human systems engineering.

Demo / Proof of Concept

▶ Watch: Weber's three types of authority: charismatic, traditional, legal. (6:50)

While Sarai Rosenberg's talk did not feature a live technical demonstration or a software-based proof of concept in the traditional cybersecurity sense, she provided a compelling real-world scenario that served as a practical illustration of her theoretical framework. This "proof of concept" was a narrative demonstration of how applying nuanced power dynamics can transform a contentious security initiative into a collaborative success.

Rosenberg recounted an incident where her security team aimed to implement an audit feature for customer data access. The goal was to log "who accessed customer data, when, and for what reason." Initially, the customer support team reacted with anger and defensiveness, fearing judgment, workflow disruption, and additional clicks or text entries. This reaction, Rosenberg explained, stemmed from their feeling of powerlessness and historical treatment, a prime example of Rollo May's observation about violence arising from repressed anger and fear.

Instead of asserting "power over" and mandating the feature, Rosenberg's team applied the principles of "power with" and integration. They stepped back to understand the customer support team's fears: "What are you afraid of?" By leading with curiosity, they uncovered concerns about being judged, workflow interruption, and added cognitive load.

The collaborative solution involved leveraging existing technical mechanisms – specifically, using the HTTP referrer. This allowed the system to transparently capture:

  • Who accessed the data (the support agent).
  • When they accessed it.
  • Why (by linking the referrer to the customer ticket the agent was working on).
  • What they were doing (helping that specific customer).

Crucially, this solution required no change to the customer support team's workflow; it provided evidence that they were doing their job without extra effort or clicks. This transformed the feature from a perceived imposition into a transparent mechanism that validated their work and provided necessary security oversight. The outcome was a successful implementation where "everyone was happy," demonstrating the power of understanding underlying fears, fostering collaboration, and designing solutions that respect existing workflows and empower users, rather than dictate to them.

Defensive Implications

▶ Watch: Mary Parker Follett: Distinguishing 'power over' from 'power with'. (10:00)

The defensive implications of Sarai Rosenberg's talk are not about patching vulnerabilities or deploying firewalls, but about building **resilient, trustworthy, and effective security *organizations***. The principles she outlines provide a blueprint for security leaders and practitioners to "defend" against common pitfalls that erode trust, hinder collaboration, and ultimately weaken an organization's overall security posture.

  1. Defend Against Trust Erosion: The most critical defensive implication is to recognize that every use of authoritative power is a trust withdrawal. Security teams must consciously minimize their reliance on directive "power over" and instead cultivate "power with." This means shifting from mandates to enablement, from dictating to coaching. In situations requiring immediate authority (e.g., critical incident response), transparency about the necessity and intended outcomes can help mitigate the trust withdrawal. Proactively building trust through consistent, collaborative engagement is the primary defense against future resistance.
  1. Cultivate Influence Without Authority: Security professionals often operate without direct managerial authority over the teams they need to secure. Therefore, mastering influence without authority is a crucial defensive skill. By establishing rapport, emphasizing shared goals, providing clear risk context (using hypothetical attacker scenarios), and offering multiple mitigation options, security teams can guide stakeholders towards secure choices rather than forcing them. This approach defends against the perception of security as an impediment and fosters a sense of shared responsibility.
  1. Proactive Conflict De-escalation and Understanding: The talk highlights that anger and resistance often stem from feelings of powerlessness or unaddressed fears. A defensive strategy involves leading with curiosity and actively seeking to understand the root causes of resistance. Instead of reacting defensively to pushback against a security initiative, ask: "What are you afraid of? What are your concerns?" This approach, exemplified by the customer data audit scenario, allows security teams to de-escalate potential conflicts into collaborative problem-solving, thereby defending against unproductive disagreements and fostering better solutions.
  1. Recognize and Address Socially Situated Power Dynamics: Security leaders must be acutely aware that power is socially situated. This means recognizing how factors like race, gender, class, and other marginalized identities can influence how power is perceived, wielded, and experienced within the organization. A "defensive" posture here involves actively working to mitigate the unequal impacts of power dynamics, ensuring that security initiatives do not inadvertently disadvantage or disempower certain groups. This requires self-awareness, empathy, and a commitment to equitable leadership.
  1. Embrace Disagreement as a Healthy Signal: Reject the notion that "zero upset" is a target. Instead, view disagreements and discussions as healthy relationship-building exercises. A lack of dissent can sometimes signal tranquility as a warning sign—that people don't feel safe to voice concerns. Defensively, security leaders should actively encourage questioning and open dialogue, creating an environment where concerns can be raised and addressed collaboratively, rather than festering into resentment or passive non-compliance.
  1. Strategic Use of Authority in Incident Response: While generally advocating for "power with," Rosenberg acknowledges the necessity of directive "power over" in specific contexts, particularly during security incident response. An incident commander must be directive, delegating tasks decisively. However, even here, awareness of power dynamics is crucial. The concept of executive swoop, where an executive's presence disrupts the incident commander's authority, serves as a defensive lesson: leaders with higher formal power should be mindful of their impact and, ideally, empower the incident commander to maintain clear lines of authority during a crisis.

By internalizing these defensive implications, security professionals can transform their approach from one of enforcement to one of empowerment, building stronger relationships, fostering a more secure culture, and ultimately achieving more robust security outcomes for their organizations.

Key Takeaways

  • Power is Influence: Power is fundamentally the ability to influence others, extending beyond formal authority or position. Effective security leadership requires understanding and leveraging diverse forms of influence, including charismatic, traditional, and rational-legal authority.
  • Trust is Paramount: Every use of directive "power over" is a trust withdrawal. Trust is the "lifeblood" of collaboration, built slowly and lost quickly. Security leaders should prioritize being trustworthy and cultivating "power with" to foster strong, lasting relationships.
  • Influence Without Authority is Essential: For security professionals, who often need to drive change across teams they don't manage, mastering influence without authority is critical. This involves establishing rapport, emphasizing shared goals, providing clear risk context, and offering mitigation options, rather than dictating solutions.
  • Embrace Collaboration Over Command: While directive authority has its rare, necessary uses (e.g., critical incident response like Log4j), "power with" (empowering, coaching, collaborating) is generally more effective for sustained security outcomes. It integrates perspectives and builds collective power.
  • Understand Socially Situated Power: Power dynamics are not neutral; they are deeply influenced by social factors like race, gender, and class. Security leaders must be aware of these inherent imbalances and their impact on how power is perceived and experienced within the organization.
  • "Zero Upset" is Not the Goal: Healthy relationships involve disagreements and discussions. Actively engaging with and understanding the root causes of anger or resistance, which often stem from powerlessness, can transform conflict into collaboration. Tranquility can sometimes be a warning sign of unaddressed issues.

About the Speaker(s)

Sarai Rosenberg is an experienced security leader with a distinguished career in securing large-scale, complex environments. She has been responsible for securing one of the largest cloud environments in the world, as well as one of the largest Content Delivery Networks (CDNs) globally. Beyond her significant technical contributions, Sarai has dedicated several years to researching and writing about power dynamics and management, driven by her personal interests in power, management, and communication. Her unique perspective is informed not only by academic study in psychology, sociology, and philosophy but also by her lived experiences, which have compelled her to be highly efficient and intentional in her use of power. This background has shaped her into a highly effective leader who champions nuanced, collaborative approaches to security leadership.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Rosenberg is a credible speaker with real operational background, and the core framework — power-over vs. power-with, trust as a depleting resource, influence without authority — is genuinely useful for security leaders who've never been forced to think systematically about this. The customer-audit HTTP-referrer story is a clean, honest proof of concept. But the talk is fundamentally a well-curated lit review (Weber, Follett, Arendt, May) dressed in security clothing, and the academic scaffolding is heavier than the original contribution warrants.

Heather Calloway (CISO) — SOLID

Rosenberg is clearly a thoughtful practitioner, and the core argument — that directive authority erodes trust and that influence without formal power is the real skill in security leadership — is sound and underserved at most security conferences. But the talk stays at the level of framework introduction rather than institutional diagnosis, and it never reaches the accountability or governance layer where these dynamics actually break down at scale.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026