Official Routledge listing now live

Rebuilding Cybersecurity

How to Restore Trust, Leadership, and Real Protection in a Broken System

Forthcoming from CRC Press / Routledge, Cheri Hotman's book examines the uncomfortable gap between the cybersecurity programs organizations can prove they have and the protection those programs actually provide.

Author · Cheri Hotman Cybersecurity + Cyber GRC Leadership Publication · January 14, 2027
CRC Press / Routledge
Rebuilding Cybersecurity
How to Restore Trust, Leadership, and Real Protection in a Broken System
Cheri Hotman

The question underneath the book

Your audit passed.
Your dashboard is green.
Are you actually secure?

Cybersecurity has become remarkably good at proving that work was done.

We have frameworks. Certifications. Dashboards. Questionnaires. Tools. Audits. More tools. More audits. And an endless parade of green check marks telling executives everything is under control.

Meanwhile, organizations keep getting breached.

Rebuilding Cybersecurity challenges executives, board members, CISOs, and cybersecurity practitioners to confront the gap between the security programs we have built and the protection we actually provide.

Then it asks what it would take to rebuild the system around what actually matters.

How did we get here?

The problem is bigger than another framework or better tool.

Drawing on decades of experience owning these problems from inside organizations and then working across hundreds more, Cheri examines the forces that quietly pulled cybersecurity away from its purpose.

01

Fragmented ownership

Responsibility gets distributed so widely that accountability can disappear.

02

Fear and pressure

Teams optimize for proving they are compliant instead of improving protection.

03

Misaligned incentives

Activity, evidence, certifications, and dashboards can become proxies for actual outcomes.

04

Checkbox culture

Passing the test becomes the destination instead of one form of proof along the way.

Cybersecurity was never supposed to become a system for producing green check marks. It was supposed to help protect what matters.
Security + compliance Compliance and security were never supposed to be opponents.

We have been told that compliance and security are two different things. They are not. They were always intended to work together.

But somewhere along the way, organizations stopped using compliance to help build protection and started using it primarily to prove that they passed.

Customers are not really asking whether an audit was completed. Boards should not care only whether the dashboard is green. People who entrust an organization with their information are trusting it to protect what matters.

The audit matters. The framework matters. The evidence matters. They are foundations and proof, not the finish line.

The Cybersecurity Rebuild Model

Rebuild the program around its purpose.

The Cybersecurity Rebuild Model is introduced in the book as a way to uncover where security programs have drifted from their purpose and begin rebuilding them around accountability, priorities, trust, and real protection.

Real protection at the center
01 · Purpose

What are we protecting?

Understand where the security program has drifted from the protection it was intended to provide.

02 · Accountability

Who owns the outcome?

Restore meaningful accountability where fragmented ownership has weakened the program.

03 · Priorities

What actually matters most?

Focus people, money, technology, and time around meaningful risk and real protection instead of another green check mark.

Who the book is for

For the people accountable when cybersecurity has to work.

The book is written for people responsible for protecting organizations, overseeing risk, building the program, proving it works, or trying to keep all of those things connected.

01

Executives

Business leaders accountable for cybersecurity risk and organizational outcomes.

02

Boards

Directors responsible for oversight, governance, accountability, and trust.

03

CISOs

Security leaders responsible for building effective programs with finite resources.

04

Cyber GRC practitioners

People translating frameworks, evidence, risk, technology, and policy into operating programs.

05

Risk + assurance leaders

Professionals working across governance, compliance, assurance, and business risk.

06

Anyone asking the harder question

People unwilling to assume that passing the audit automatically means the organization is secure.

Cheri Hotman, author of Rebuilding Cybersecurity and Managing Partner of Hotman Group

About the author

Cheri Hotman

CPA MBA CCISO CISSP Managing Partner · Hotman Group

Cheri did not learn cybersecurity and Cyber GRC only by studying frameworks or implementing them for other people. She has owned the responsibility from inside organizations.

In one year alone, she faced as many as 42 audits and regulatory examinations.

She knows what it feels like to have too much to do, too few resources, another requirement coming through the door, and the same question being asked for what feels like the thousandth time.

That experience, followed by years working across hundreds of organizations, gave her a perspective a person operating inside one environment cannot reasonably be expected to have. She has seen what works, what creates noise, what survives contact with reality, and what repeatedly fails.

Cheri is also the creator and host of The Art of Cybersecurity , where she explores the judgment, creativity, leadership, and people side of solving difficult cybersecurity problems.

The philosophy in practice.

The connection to Hotman Group

The book and the work come from the same place.

Rebuilding Cybersecurity examines the leadership, governance, accountability, incentive, and system-design problems that can cause cybersecurity programs to drift from their purpose.

Hotman Group works with organizations facing many of those same problems in practice.

That means helping organizations understand actual risk, restore accountability, prioritize what matters, build or fix cybersecurity and Cyber GRC programs, make technology work, meet requirements, and keep improving over time.

The point is the same in both places: frameworks, audits, compliance, and technology matter, but they exist to support the larger objective of protecting the business.

Meet Hotman Group

Publication details

Rebuilding Cybersecurity: How to Restore Trust, Leadership, and Real Protection in a Broken System

Author Cheri Hotman
Publisher CRC Press / Routledge, Taylor & Francis Group
Subject Cybersecurity + Cyber GRC Leadership
Publication date January 14, 2027
Edition 1st Edition
Paperback ISBN 9781041379911
Length 208 pages
Illustrations 10 black-and-white illustrations

Better cybersecurity is possible. But we have to be willing to rebuild what is not working.

Rebuilding Cybersecurity will be published by CRC Press / Routledge on January 14, 2027. The work of rebuilding cybersecurity is already happening.