Sit in enough security team meetings and you'll hear the same lament from most managers: "I can't get this done because I don't have the authority. If leadership would just mandate it, this would move." It's an understandable complaint. It's also the wrong diagnosis, and a career spent waiting for it to be fixed is a career spent waiting.
Here's the uncomfortable arithmetic of running security: almost nothing the function needs to accomplish can be accomplished alone, and almost nobody it needs is obligated to prioritize it.
Security needs finance to fund tools they didn't ask for. It needs HR to change onboarding processes they've run the same way for years. It needs department heads to treat access reviews as something other than busywork, employees to abandon workarounds that genuinely make their jobs easier, and executives to care about risks that haven't materialized yet.
No mandate covers all of that. And the instinctive response, to want more authority, misreads what's actually happening, in two ways worth examining closely.
Two Observations That Break the Authority Theory
First: watch who actually gets things done in your organization. It's rarely the person with the strongest mandate. It's the person other teams answer quickly and say yes to, and that standing was built through a hundred small negotiations, not granted by an org chart. Meanwhile, people with real positional authority get slow-rolled and worked around daily. Authority without relationships is remarkably easy for an organization to ignore.
Second: look at how actual diplomats operate. A diplomat has zero authority over the other side of the table. They cannot order another country to do anything. Yet skilled diplomats get their way, consistently, on matters far more contested than a security rollout, through preparation, patience, calm, and knowing the other party's interests better than the other party has articulated them.
The absence of authority isn't a security leader's handicap. It's the job description. Security influences departments it doesn't control; that's how the role is built, and it's permanent.
The leaders who accept that early outperform the ones who spend years waiting for a mandate. And here's the part that stings: even when the mandate arrives, it doesn't work the way they imagined.
Why Mandates Fail Even When You Win Them
Every security leader who has fought for and won a mandate has watched some version of this play out:
- Forced compliance is minimal compliance. The mandatory reviews get completed, in the sense that every box gets checked. Whether any box gets read is a different question. A mandate buys the letter of the requirement and none of its purpose.
- Enforcement spends capital you'll need next quarter. Every escalation, every "per policy, this is required" email, draws down trust with a team security will inevitably need again. Security deals with every department repeatedly, forever. Negotiation compounds goodwill; enforcement compounds resentment.
- Workarounds move faster than enforcement. No one has ever blocked a tool faster than employees can route around the block, and every workaround creates exactly the ungoverned access the block was meant to prevent.
- The math never works. A security team of five cannot police an organization of a thousand. The function only works if most people cooperate voluntarily, which means the actual job is generating voluntary cooperation.
So if the mandate isn't the missing piece, what is? Knowing the terrain: what every team you depend on is actually optimizing for, and where your requests collide with it.
The Map: What Each Team Actually Optimizes For
Nearly every conflict security has with another team traces back to a request threatening something that team is measured on, usually without anyone realizing it. This map is the diagnosis:

Two things about this map matter more than its rows.
None of these teams is wrong. Finance controlling spend is finance doing its job. A department head protecting velocity is doing theirs. What security experiences as obstruction is usually each function correctly pursuing what it exists to pursue, and once that lands, most of the frustration converts into useful information.
Most security requests are phrased in security's language, not the listener's. "We need this for our security posture" means everything inside the security team and nothing to finance. Every collision on this map is really a translation failure, and translation is a learnable craft.
The Diagnosis, Summed Up
The complaint was never really about authority. Three findings replace it:
- Authority, even when granted, compels only the minimum. The mandate produces checked boxes and quiet workarounds, not outcomes.
- The people who get things done run on influence, built through repeated fair dealing, not positional power.
- The friction security experiences is terrain, not obstruction: every team correctly pursuing its own metrics, colliding with requests phrased in the wrong language.
Which raises the real question: if the answer is working this terrain like a diplomat, what does that craft actually look like, move by move? That's its own piece: every security leader is a diplomat, and here's the toolkit.
Frequently Asked Questions
Wouldn't all of this be unnecessary if leadership just gave security real authority?
The evidence says no. Teams with genuine mandates still get slow-rolled daily, because authority compels the minimum and influence earns the rest. Even a strong mandate needs relationship work to produce more than checkbox compliance. The leaders who get both use the authority rarely and the influence constantly, which is the ratio that actually works.
Isn't this just office politics with a nicer name?
There's a real difference. Politics in the cynical sense means advancing at others' expense. What this diagnosis points toward means understanding other teams' legitimate interests well enough to find genuinely shared outcomes: finance really does benefit from spend visibility, HR really does benefit from faster onboarding. Nothing here requires anyone to lose for security to win.
What about when another team's interests genuinely conflict with a security requirement?
That's the small minority of cases where escalation is appropriate, and it's exactly where a track record of accommodation pays off. Escalation after visible attempts to work with a team gets taken seriously in a way default escalation never does. The rare, reluctant escalation is credible precisely because it's rare.
Is the fix here about personality, or is it learnable?
Learnable, and that's the point of naming it as diplomacy rather than charisma. Mapping what teams optimize for, translating requests into their terms, and building standing through repeated fair dealing are methods, not traits. The companion piece linked above covers them move by move.















