How to Restore Trust, Leadership, and Real Protection in a Broken System
Forthcoming from CRC Press / Routledge, Cheri Hotman's book examines the uncomfortable gap between the cybersecurity programs organizations can prove they have and the protection those programs actually provide.
The question underneath the book
Cybersecurity has become remarkably good at proving that work was done.
We have frameworks. Certifications. Dashboards. Questionnaires. Tools. Audits. More tools. More audits. And an endless parade of green check marks telling executives everything is under control.
Meanwhile, organizations keep getting breached.
Rebuilding Cybersecurity challenges executives, board members, CISOs, and cybersecurity practitioners to confront the gap between the security programs we have built and the protection we actually provide.
Then it asks what it would take to rebuild the system around what actually matters.
How did we get here?
Drawing on decades of experience owning these problems from inside organizations and then working across hundreds more, Cheri examines the forces that quietly pulled cybersecurity away from its purpose.
Responsibility gets distributed so widely that accountability can disappear.
Teams optimize for proving they are compliant instead of improving protection.
Activity, evidence, certifications, and dashboards can become proxies for actual outcomes.
Passing the test becomes the destination instead of one form of proof along the way.
We have been told that compliance and security are two different things. They are not. They were always intended to work together.
But somewhere along the way, organizations stopped using compliance to help build protection and started using it primarily to prove that they passed.
Customers are not really asking whether an audit was completed. Boards should not care only whether the dashboard is green. People who entrust an organization with their information are trusting it to protect what matters.
The audit matters. The framework matters. The evidence matters. They are foundations and proof, not the finish line.
The Cybersecurity Rebuild Model
The Cybersecurity Rebuild Model is introduced in the book as a way to uncover where security programs have drifted from their purpose and begin rebuilding them around accountability, priorities, trust, and real protection.
Understand where the security program has drifted from the protection it was intended to provide.
Restore meaningful accountability where fragmented ownership has weakened the program.
Focus people, money, technology, and time around meaningful risk and real protection instead of another green check mark.
Who the book is for
The book is written for people responsible for protecting organizations, overseeing risk, building the program, proving it works, or trying to keep all of those things connected.
Business leaders accountable for cybersecurity risk and organizational outcomes.
Directors responsible for oversight, governance, accountability, and trust.
Security leaders responsible for building effective programs with finite resources.
People translating frameworks, evidence, risk, technology, and policy into operating programs.
Professionals working across governance, compliance, assurance, and business risk.
People unwilling to assume that passing the audit automatically means the organization is secure.
About the author
Cheri did not learn cybersecurity and Cyber GRC only by studying frameworks or implementing them for other people. She has owned the responsibility from inside organizations.
She knows what it feels like to have too much to do, too few resources, another requirement coming through the door, and the same question being asked for what feels like the thousandth time.
That experience, followed by years working across hundreds of organizations, gave her a perspective a person operating inside one environment cannot reasonably be expected to have. She has seen what works, what creates noise, what survives contact with reality, and what repeatedly fails.
Cheri is also the creator and host of The Art of Cybersecurity → , where she explores the judgment, creativity, leadership, and people side of solving difficult cybersecurity problems.
The connection to Hotman Group
Rebuilding Cybersecurity examines the leadership, governance, accountability, incentive, and system-design problems that can cause cybersecurity programs to drift from their purpose.
Hotman Group works with organizations facing many of those same problems in practice.
That means helping organizations understand actual risk, restore accountability, prioritize what matters, build or fix cybersecurity and Cyber GRC programs, make technology work, meet requirements, and keep improving over time.
The point is the same in both places: frameworks, audits, compliance, and technology matter, but they exist to support the larger objective of protecting the business.
Publication details
Rebuilding Cybersecurity will be published by CRC Press / Routledge on January 14, 2027. The work of rebuilding cybersecurity is already happening.
Ask HG
