top of page

About Energeia and Dr Rich Diston

bio.png

I’m back, security industry. That means it’s time to stop calling yourself ‘professionals’, stop bragging about passing multiple choice exams (the lowest level of assessment), stop posting pictures of your certificates (thereby fuelling credential and certification fraud) and stop claiming to be a ‘business enabler’ (you’re not. If you wouldn’t say it to the CFO, don’t say it to anyone else).

Daddy’s home. 🤣


I’ve realised that the hatred of morons is not only unavoidable, but necessary. Given that realisation, I realised that not only can I bear their hatred and abuse, I also must not allow it to discourage me from my purpose in this industry. I was this close to quitting security forever. I was fed up dealing with people who refuse to listen and act in their own best interests, yet claim to have all the answers despite not understanding the questions.

​

If you’re reading this, you might be checking me out to argue with me about something I said about security and the wider industry that you haven’t understood or that has triggered an emotional reaction for you. Poor baby. 🤣 


You’ll either dismiss my credentials or dismiss my experience…making the assumption that everything I have done is listed here, and that you’re somehow more qualified to discuss the subject than I am. I guarantee you, you aren’t. 

Credentials

Here’s just some of my credentials.

​

MSc in Security Risk Management (with distinction)
Professional Doctorate in Security Risk Management
CISM (passed twice, without even reading the book) (Cert resigned)
CRISC (Cert Resigned)
CISA (Cert Resigned)
CGEIT (Cert Resigned)
CDPSE (passed, cert not claimed)
CISSP (Expired)
Sec+ (Expired)
ISO27001 Lead Implementer (Expired)
ISO27001 Lead Auditor (Expired)
VeriSIM (Expired)
ITIL Foundation (Expired)

​

…and a load of other things I forget about, including a load of qualifications for developing, delivering and assessing adult training. I’m not bothering to put all that onto the profile here. And yeah, you should be able to infer my opinion of certification bodies from that list.


Only a desperate sucker keeps paying for nothing every year.

​

Add to all that nearly three decades as a consultant, auditor, coach and educator, working in sectors such as Fintech, Healthcare, Government, Education, NGO’s, Charity and others.


I am not a certificate-chaser, nor an academic. I am a practitioner, first and foremost. 

I was described as ‘the straight edge against which a crooked industry is measured.’


I once walked away from an agreed £100k consulting gig because I realised the CEO wasn’t serious about the work we would be doing together. That means that I’m not remotely interested in your money as my primary concern.  I choose my clients, not the other way around,  and I do so according to the quality of their character, not their bank account. People with problems and a lot of money are everywhere. People with my level of solution are FAR rarer.

Contributions

At the time of writing this, I've written four security books that have sold globally.

​

  • The Problem of Security

  • The Superior Security Practitioner - A competency framework for security practitioners.

  • Real Security Management™ - A new philosophy of value-led organisational protection.

  • The Complete Bitter Pill


…and there are two more security books on the way. These are all available from my website. I refuse to sell through Amazon on ethical grounds, even though it’d increase my reach. Principles matter.

​

Here are some of the ideas/concepts that I have contributed to the cause of security management thinking. 

The 2 Great Contexts of Security Practice™
The 3 Levels of Security Contribution™
8 Security Virtues™
The Protective Focus Prism™
NSE²C™ (An evidence-based model for demonstrating organisational protective value)
Dr D's 4 D's™
The Event Response Cycle™
Security Relativity™
The Real Security Management Model™
Real Security Management™
The Spectrum of Security™

There’s a long list of people who have tried to rip off my thinking and pass it off as theirs…but none are able to explain it properly. Many of the people who follow some of them will applaud them while they attack me for saying the same things. Whatever.


I encourage people to consider and challenge what I say, once they have understood it. There isn’t another security thinker out here who says the same.  I want you to think for yourself, not ‘believe’. I’m not saying I am right, but I AM saying the rest of the industry is getting it wrong. Rip off their shit, if you must.

I don’t consider myself an industry leader, and don’t call myself one. Others have. I DO have a vision for the industry and wider security practice, which might be considered an essential part of leadership.

In Real Security Management™, I stated this goal…

‘I truly believe that serious security practitioners deserve a rewarding career where their contribution is valued.’

Despite this, I became an industry hate figure because I made a stand against industry weakness, stupidity, dishonesty and corruption. There are Reddit threads dedicated to slandering and libelling me, proving my point about the industry and the people we have allowed into it. I operate at the doctoral level (level 8), meaning that I create new knowledge. That means that anyone with a level 2 education might struggle to appreciate what I am saying. 

Security practitioners are being taught the wrong things, in the wrong ways, for the wrong reasons…and all that holds them back. When I say this, it’s considered a personal attack. Security practitioners will never achieve what I just said if they insist on clinging to stupidity, dishonesty and bad thinking. The industry IS in crisis…and yet I’M the bad guy. Fine. So be it.

For 44 weeks, I posted polls on LinkedIn for ‘security leaders’ to assess their understanding, and every week, roughly 90-95% got basic concepts wrong. Despite this, they refused to learn. I then ran a highly offensive newsletter - The Bitter Pill - explaining the right answers and slapping the thinking that chose the wrong ones. I compiled all the newsletters into one of the books for the people who love a bit of brutal snark while they learn.

All this burned me out, frankly. The brand became toxic, and so did I. I closed Real Security Doctor Limited, fired all my clients and decided to focus on coaching. And I really thought I could. 

But…I still have a valuable contribution to make for the right people, because I still believe in serious security practitioners. Quitting the industry would be cowardice, and the decent people still need my help.

So, for better or worse, I’m back. I’m going to try to do things differently this time.

My tasks.
To teach.
To guide.
To help.
To challenge.

Your tasks, if you choose them.
To listen.
To think.
To question.
To act.

Our shared tasks.
Leading positive change for better outcomes.

I am not here to judge, and I don’t need anyone’s approval or permission. I care nothing for badges or big job titles. I am not here to argue with internet idiots with a Google-level education who think AI is a good idea and who think the CIA triad is anything to do with security (Nope, and I don’t care which idiotic Government body says it is). I’m not interested in an echo chamber. I am interested in people willing to think, challenge and grow themselves and set a positive example in the industry. But I still won’t teach for free. Serious people invest in themselves.

Oh, and fuck AI and the idiots who use it.

For a greater appreciation of who I am and what I am about, I wrote a free ebook about my journey to where I currently am, called A Swan Dive in the Shallow End. It’s a cautionary tale about choosing security as a career. It’s available right below this section.

If you’re still here and support my goal - stick around, make up your own mind, and maybe we’ll talk. My best customers stalked me for over 6 months before booking a conversation. I’m not in any hurry, and nor should you be.

Shallow end.png

A Swan Dive in the Shallow End

I wrote this as a cautionary tale, as well as a part of my own rehabilitation. I needed to reflect on why I ever decided to do this security thing, as well as why I did it the way that I did.

​

This is not 'brave', nor is it performative vulnerability. If you read it and get something from my experiences that helps you...it served its purpose. Reader discretion is advised.

​

This is a free ebook, provided for my customers and available from the Energeia Customer Portal.

bottom of page