Skip to main content

Second Renaissance

Learning How to Build A Cybersecurity Program: Lessons from The Princess Bride

Learning How to Build A Cybersecurity Program: Lessons from The Princess Bride

Everything I know, I’ve learned from The Princess Bride. It’s how I landed my first job, played a key role in my wedding proposal, and inspired me to learn how to swordfight, which led to an Olympic Gold Medal. I’ll let you figure out which part of that is real.

Building an enterprise cybersecurity program often feels like preparing to storm the castle. Far too many organizations tackle this challenge in a piecemeal, purely reactive manner. They buy a shiny new security tool every time a scary headline appears, patch together disconnected software, and hope for the best when an incident inevitably strikes.

Before you go throwing money at every new cybersecurity product on the market, it helps to pause, take a breath, and take inventory of what you actually have. As it turns out, one of the best frameworks for strategic planning comes directly from a classic 1987 film.

“If We Only Had a Wheelbarrow!”

In The Princess Bride, Westley, Fezzik, and Inigo Montoya find themselves outside Prince Humperdinck’s castle. They are facing sixty gate guards, an impossible deadline, and Westley is still paralyzed from being mostly dead all day.

When Inigo asks what the plan is, Westley doesn’t just start wildly swinging a sword. He asks for a clear assessment of their situation: their liabilities and their assets.

Westley: “What are our liabilities?”

Inigo: “There is but one: The castle is-a guarded by sixty men, and we have to rely on your brain, which is sluggish, to say the least.”

Westley: “What are our assets?”

Inigo: “Your brains, Fezzik’s strength, my steel.”

Westley immediately notes that this isn’t nearly enough to breach a gate guarded by sixty men. Inigo despairs, exclaiming, “If we only had a wheelbarrow, that would be something!” To which Fezzik casually replies, “Where are we going to find a wheelbarrow?”

Suddenly, Fezzik reveals they already have a wheelbarrow (along with a cloak fit for a Holocaust cloak salesman). By simply stopping to inventory what they actually had on hand, a seemingly impossible task suddenly became manageable.

Stop Buying Wheelbarrows You Already Own

When building or upgrading a cybersecurity program, IT leaders frequently fall into the “if we only had…” trap.

(If we only had another monitoring platform! If we only had a new firewall!)

In reality, most companies are sitting on a treasure trove of unused capabilities. You are likely already paying for built-in security features within your existing cloud ecosystem (like Microsoft 365 or AWS) that simply haven’t been turned on, configured correctly, or integrated into your workflows.

Before diving into complex new security initiatives, you need to conduct a clear assessment of your own assets and liabilities:

  • Identify Your Critical Assets: What data, systems, or processes actually keep your business running? You can’t protect what you don’t know you have.
  • Audit Your Current Tech Stack: What security controls, features, and licenses are you already paying for that lie dormant?
  • Recognize Your Liabilities: Where are your actual operational bottlenecks, skill gaps, or legacy vulnerabilities?

Rushing out to buy new tools without taking inventory first leads to overlapping software, bloated budgets, and a false sense of security.

Build Your Program with Purpose

Storming the cybersecurity castle doesn’t require a miracle—it requires clear visibility, smart resource allocation, and a structured strategy. By taking stock of your existing tools and aligning them with your true risk profile, you can build a resilient defense without wasting time or capital.

Want to make sure your strategy stays on the right track? Download our whitepaper, 5 Traps to Avoid When Building A Cybersecurity Program, to discover common missteps companies make when structuring their defenses—and how your organization can sidestep them.

more insights

Led Zeppelin rocking out in front of the letters M.F.A.
IT Consulting
Austin Clements

A Case Study in MFA Rollout

A Case Study in MFA Rollout If you ask any cybersecurity professional for the single most effective, low-hanging fruit to secure an organization, Multi-Factor Authentication (MFA) usually tops the list.

Read More »
Space Invaders arcade game PAUSED.
Assessment and Audit
Austin Clements

CMMC Paused But Not Forgotten

CMMC Paused But Not Forgotten If you work anywhere near the defense industrial base (or spend your days tracking federal cybersecurity mandates just for fun like I do), the recent

Read More »