> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Patriots Training Camp Gets Right About Cybersecurity
- URL: https://www.cybrsecmedia.com/what-patriots-training-camp-gets-right-about-cybersecurity/
- Published: 2026-08-20T09:41:53.000Z
- Updated: 2026-08-20T09:53:23.000Z
- Description: Patriots training camp offers cybersecurity leaders a lesson in making security everyone’s job: embed protection into the work people already do instead of telling employees not to screw up.
- Author: Andy Ellis
- Tags: Foorball and Cybersecurity, CYBR.Signal, Article

***This article is based on the latest episode of CYBR.Signal, which you can catch here:***

[Everything is Everyone’s ResponsibilityCISO Andy Ellis argues security shouldn’t be everyone’s job, it should be built into everyday work and aligned directly with clear business goals![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-040f0151-3cce-4f28-80b8-9533825890d4.jpg)CYBR.SEC.Media, and CYBR.SEC.Media![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/CYBR.Signal_Ep-23-1-ec2c01b2-e0ab-4976-a98d-6a38049fda82.png)](https://www.cybrsecmedia.com/everything-is-everyones-responsibility/)

I’m at Patriots training camp, which is one of my favorite places to be.

And naturally, while everyone else is thinking about Drake Maye, the offensive line and whether the Patriots are going to have a good season, I’m thinking about cybersecurity.

![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/2026/08/a3d0d601-ec13-488d-9075-5b31ed34c93d.webp)

Occupational hazard. More specifically, I’m thinking about one of the industry's favorite clichés: Security is everyone's responsibility.

We say it constantly. And sitting here watching training camp, I'm starting to think we've been saying it wrong. Because when cybersecurity people say "security is everyone's responsibility," what we often mean is:

Everybody else has a responsibility not to screw up.

Don't click that.

Don't open this.

Don't send that.

Don't let the bad guy in.

Congratulations, Susan in Accounting. In addition to doing the job we hired you to do, you're now apparently a human intrusion-prevention system.

That's not a particularly useful definition of shared responsibility.

But look around Patriots training camp and you can see a much better version of it happening everywhere.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## The security team that isn't a security team

There are people standing around the field whose job includes making sure nobody rushes it.

Security! Except they're also hospitality staff.

Ask them a question and they'll help you. They'll point you in the right direction. They're part of making sure you have a good day at training camp.

There's an announcer keeping the crowd entertained and informed. He's also telling us the security rules.

There are PR people working with the media. Their job is to facilitate coverage of the Patriots. But they're also making sure reporters follow the rules around recording. And the credentialed media themselves have responsibilities about material that shouldn't have been recorded in the first place.

PR is doing security. Media is doing security. Hospitality is doing security. But here's the important part: They're not stopping their real jobs to "do security."

Security is embedded in their real jobs. And that's where I think cybersecurity has gotten this backward.

## Maybe everything is everyone's responsibility

Maybe it isn't that security is everyone's responsibility.

Maybe **everything is everyone's responsibility.**

The hospitality people here aren't security professionals who occasionally answer a fan's question. They're hospitality professionals whose job naturally includes protecting the environment.

The PR team isn't moonlighting as the security department. Protecting information is part of successfully doing PR.

That distinction sounds small. It isn't.

Because cybersecurity teams spend an enormous amount of energy trying to turn everyone else into amateur cybersecurity professionals.

Maybe we should spend more time figuring out how cybersecurity naturally fits into what those people are already responsible for.

And maybe we should start by figuring out what business we're actually in.

## The Patriots aren't just in the football business

The Patriots have an unusually obvious answer. Well, actually, they have two. The football team is in the business of winning football games.

That's it. Play football. Win.

But the Patriots organization is also in the entertainment business. Look around training camp. There are thousands of people here. They came because they want an experience.

So if you're responsible for security here, your job isn't simply to keep people away from the field or stop someone from recording something they shouldn't.

Your job is also to help the Patriots succeed as an entertainment business. That means keeping people safe without making the experience suck.

Security is part of the product. And there's the lesson for the rest of us.

## What business are you in?

Think about your company. What does it actually do? What does success look like What are the people in finance, sales, engineering, HR, marketing and operations actually responsible for accomplishing?

Now find the security responsibilities already hiding inside those jobs.

Take the comptroller.

If you're worried about business email compromise, you can tell the comptroller: Don't click suspicious links. Don't trust weird emails. Check the sender. Hover over the URL. Complete your annual phishing training.

Or you could recognize what their actual job is:

Make sure the company's money goes to the right people.

That's already a security responsibility.

So sit down together and build processes that make it harder for money to go to the wrong people.

Now the comptroller isn't "helping cybersecurity."

Cybersecurity is helping the comptroller. That's a much healthier relationship.

## If you're worried about the click, you've already lost

This is also why I have a problem with so much of the "human firewall" philosophy.

If your security architecture ultimately depends on somebody remembering:

*I'm supposed to click this but I'm not supposed to click that...*

You've already failed. People shouldn't have to become cybersecurity analysts before they can do their jobs safely. Look at what's happening around me at Patriots training camp. The person helping fans doesn't need to become a security guard. The PR person doesn't need to become an information-security analyst.

The reporter doesn't need a CISSP.

They need to understand the responsibilities that naturally come with their jobs, and the organization needs processes that make doing the right thing part of doing those jobs well.

That's what "security is everyone's responsibility" ought to mean.

Not:

*Don't screw up.*

But:

*We understand what you're trying to accomplish, we understand the security implications of it, and we're going to help you accomplish it safely.*

That's a security culture I can get behind.

Now, if you'll excuse me, they're practicing football about 100 yards away, and I've spent enough of Patriots training camp thinking about cybersecurity.

Time to watch practice.

Here's hoping for a great season.

Preferably a secure one.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)