Much of today’s information security spending and effort is focused on detecting and responding to incidents, but what if we could be more proactive, and influence the broader organization to be more secure by design thereby reducing the cost and complexity of reactive security while delivering better overall assurance?