> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Cybersecurity Lessons from the Semiquincentennial of Liberty
- URL: https://www.cybrsecmedia.com/cybersecurity-lessons-an-a-semiquincentennial-of-liberty/
- Published: 2026-07-06T14:40:07.000Z
- Updated: 2026-07-21T13:24:29.000Z
- Description: As the United States of America enters its second quarter millennia, the tradeoff of security and liberty is never more apropos than it is to the cybersecurity industry. (Includes infographic)
- Author: Andy Ellis
- Tags: How to CISO, CYBR.SEC.Community, blog

Security practitioners are often faced with a conundrum: do you do the "right thing"– by which we mean lock everything down – or do you "enable the business" and let everyone run rampant? The answer is neither, and we can look at 250 years of American excellence for the real answer.

Ben Franklin famously said, "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety." This quote is often misused, as people ignore the modifier *a little temporary* on *Safety*, and read this as "liberty is more important than safety."

That couldn't be farther from a plain reading of Franklin's sage advice, nor from practical advice we can use today. Franklin clearly values both Liberty and Safety in this context (or he wouldn't call people out as becoming undeserving of it); his concern is for the tradeoff of *essential* Liberties against *temporary* Safety. But how does that apply to cybersecurity?

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com) 

Cybersecurity practices can easily be viewed on two axes. On one axis, you have the cost to the business. Measured not in *dollars*, business cost is instead qualitatively measured in *impact*: how much agility have you removed from the business? The essential liberty in the context of a business is the ability to adapt and innovate, and the more that security practices impede a business's lifeblood, the more costly they are.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

On the second axis is the long-term utility of the security practices. Practices that don't produce long term risk reduction, architectural safety, or simplification are, ultimately, *temporary*, especially if they have to be continuously repeated. The goal of cybersecurity practitioners should be to minimize the *temporary* nature of a practice while also minimizing its impact on the *essential* innovation of the business.

Pivoting from passwords to a more secure authentication scheme? Permanent security, and one that, while it will have some minor impact on the business (hardcoded passwords are, sadly, the fastest way to ship!), is a good tradeoff to keep companies innovating. Cybersecurity awareness training, like most phishing simulations? They spend a lot of employee time, and don't have demonstrable long term positive gains.

Pick your tradeoffs wisely.

![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/2026/07/11c46675-33d2-44bb-b721-24f531f6e26d.png)