This article was originally published in the ASIS Kenya Newsletter – THE TRAILBLAZER, December 2025 / January 2026, Vol. 1, No. 10, and has been adapted and expanded for web publication to further develop its strategic and security leadership perspective.
Security and resilience in the global 2026 landscape
In the global security landscape of 2026, the industry is obsessed with the concept of “Zero Trust.” We design architectures based on the assumption that nothing — and no one — should be trusted by default. While this is a necessary technical standard in our digitalized world, it carries a significant cultural risk. When we treat our workforce solely as potential threats, we erode the very fabric of organizational resilience.
As security leaders operating in a hyperconnected global economy, we need a counterbalance. I believe the answer lies in exporting a distinctly African philosophy to the international stage: Ubuntu.
“I am because we are”: the foundation of culture
Ubuntu translates roughly as “I am because we are.” In a security context, this means that individual security is inseparably linked to collective security. When we embed this mindset into our organizations, security ceases to be a set of rules imposed by a department and becomes a shared communal value.
This strategy aligns directly with the concept of #DoSecurity, which I have previously advocated. It is not enough for a security manager to write policies; the entire organization must understand that acting in accordance with security procedures is the only way to ensure business continuity. Some time ago, while leading a Data Center security team in Latin America, it became clear that only when team members fully understood their roles in security operations and business continuity did they truly assume responsibility for achieving a strong and secure environment. When employees embrace Ubuntu, they do not bypass protocols because they understand that a breach for one is a breach for all.
Trust, but Verify: the mechanism of resilience
Culture alone, however, is not a strategy. To achieve a truly protected and resilient organization, we must combine the empathy of Ubuntu with the discipline of the Cold War–era doctrine: “Trust, but Verify.”
These two concepts are not opposites; they are allies.
Trust (Ubuntu): risk ownership and empowerment
We trust our people to take ownership of risk. We empower them to act as the first line of defense and to align their objectives with the organization’s strategy. We build a culture where reporting a mistake is safe, not punished.
Verify (ESRM): discipline, control, and sustainability
We validate that trust through rigorous Enterprise Security Risk Management (ESRM) methodologies and controls embedded in our mitigation strategy. We do not verify because we distrust our community; we verify because we value its survival.
As described in the Security 360 approach, this verification is achieved through continuous monitoring and risk assessment. We must identify both the risk and the risk owner, ensuring that our “trust” is supported by data and real-time feedback loops.
The global imperative for 2026
For professionals seeking to lead on the global stage, the lesson is clear: do not practice security in isolation. We must stop extinguishing fires without a methodology.
Instead, we must present the world with a sophisticated hybrid model. One that first understands business strategy, builds a culture of Ubuntu to foster loyalty and engagement, and applies “Trust, but Verify” mechanisms to ensure our defenses hold.
In doing so, we move beyond being simple “gatekeepers.” We become architects of a resilient ecosystem, where culture and control coexist in perfect harmony.



