Operational perspectives on cybersecurity, risk governance, and security leadership — written from 22 years in the field, not from a vendor brief.