Busy is the New Stupid
Why Your Overpacked Calendar is a Security Vulnerability
You just finished a 12-hour day, but your “To-Do” list is somehow longer than when you started. You’ve been in back-to-back Zoom calls, put out three fires in Slack, and cleared 200 emails, yet your strategic roadmap hasn’t moved an inch. If this sounds familiar, you aren’t just “hardworking”—you might be falling for the most dangerous trap in modern leadership. As G Mark Hardy and Ross Young argue in the latest CISO Tradecraft insights, “busy is the new stupid,” and it’s time to treat your time with the same tactical rigor you use to defend your network.
When a CISO is perpetually “busy,” they become strategically blind. By viewing time management through the lens of a security framework, you can identify how “time thieves” breach your schedule and how to build a defense-in-depth strategy for your life.
1. Initial Access: How Distractions Breach Your Perimeter
In cybersecurity, initial access is the first step of a breach. In your professional life, this happens through “threat vectors” like meeting overload and email bombardment. We often accept every invite under the guise of “situational awareness,” but if you aren’t the decision-maker, you’re likely just wasting cycles.
CISO Recommendation: The Zero-Based Calendar Audit Don’t just manage your meetings; justify their existence. Implement a quarterly audit where every recurring meeting must be re-evaluated. If a meeting is for “information sharing,” ask for the minutes instead. To protect your most valuable assets, schedule “no-meeting” blocks for deep work. Ross Young recommends booking lunch on your calendar—if you don’t, others will “book over your basic human needs,” leading to a “hangry” and ineffective leader.
2. Execution: The High Cost of “Memory Swapping”
We often brag about multitasking, but the human brain isn’t built for it. It functions like an old PC—every time you switch contexts, you suffer from “memory swapping,” losing time and focus as you try to regain context. When you check a Slack ping in the middle of writing a strategic board report, you aren’t being efficient; you’re degrading your output.
CISO Recommendation: Task Batching and “Eating the Frog” Adopt single-tasking. If you are working on a high-stakes PowerPoint, close Outlook, Slack, and your browser. Practice “task batching” by dedicating specific hours to email triage rather than letting it “ding” throughout the day. Most importantly, follow Mark Twain’s advice: “eat a live frog” first thing in the morning. Knock out your most difficult, most dreaded task before the “tyranny of the urgent” takes over your day.
3. Persistence: Killing the “Productivity Theater”
Persistence is how an attacker stays in your system. In the corporate world, this is the “always-on” culture where staying in the office for 70 hours a week is seen as a badge of honor. This is often just “productivity theater”—taking attendance rather than inventorying actual accomplishments.
CISO Recommendation: Shift to Outcome-Based Metrics Stop measuring your team by how many tickets they closed or hours they sat at their desks. Instead, focus on “signature accomplishments”. For example, instead of asking how many third-party risk assessments a staffer finished, reward the person who re-engineered the process to eliminate 80% of redundant questions, saving time for the entire organization in perpetuity. Additionally, implement a “digital sunset”—a hard cutoff time for work devices to ensure you remain present for your family and avoid burnout.
4. Defense Evasion: Overcoming People-Pleasing and Delegation Avoidance
Many leaders allow their time to be stolen because they want to be helpful or “people pleasers”. They avoid delegating because they think, “I can do this in one hour, but it will take my staff five”. This is a tactical error. If you don’t invest that time to train them today, you are sentencing yourself to doing that task forever.
CISO Recommendation: The “Red Ink” Leadership Model G Mark Hardy shares a vital lesson from his Navy command tours: Perfection is the enemy of success. Let your subordinates write the reports, even if they make mistakes. The “red ink” you use to correct them is an investment in their development. Eventually, they will return reports with no red ink, and you will have successfully bought back your time. When asked to take on a new task you can’t handle, use a reasoned refusal: “I can do Task A, but it means Task B will be delayed. Which do you prefer?”.
5. The Ultimate Impact: Strategic Blindness vs. Political Influence
The long-term impact of being “stupidly busy” is relationship erosion. If you are too busy responding to 50 emails to have a one-hour lunch with the CFO or CEO, you are failing at your most important job: political and relationship building. High-level leadership is often orthogonal to technical skill; it requires the “white space” to think creatively and connect with others.
CISO Recommendation: Vision Boarding and Creative Time-Blocking Don’t wait for good ideas to “strike”—they won’t. Time-block for creativity. Use exercises like “Roses, Buds, and Thorns” with your team:
Roses: What is working well?
Thorns: What needs to change?
Buds: What are the new ideas we should plant?. This collaborative approach ensures you aren’t just reacting to the latest threat but are actively shaping the future of your department.
Summary of Tactical Recommendations for CISOs
Audit the Calendar: Quarterly reviews of all recurring meetings; if it’s not for a decision, it’s an email.
Protect the Firewall of Focus: Use the Pomodoro technique or single-tasking apps to prevent context switching.
Implement JOMO: Trade FOMO (Fear of Missing Out) for JOMO (the Joy of Missing Out). Realize that being present for a child’s game or a family dinner is a higher ROI than an unnecessary after-hours Slack thread.
Pareto Your Life: Identify the 20% of activities that produce 80% of your results and ruthlessly prioritize them.
Stop Managing, Start Leading: Move from “getting work done” to “developing your people”.
The Bottom Line: You are the CISO of your own life. You wouldn’t let a random hacker dictate your network’s priorities, so stop letting a “busy” calendar dictate your career and happiness. Stop being “stupidly busy” and start being strategically impactful.
Analogy for the Road: Think of your time like a hard drive with limited storage. If you fill it up with “bloatware”—useless meetings, CC’d emails, and minor tasks—there’s no room left for the “Operating System” of strategy to run. Eventually, the whole system crashes. To keep your “leadership OS” running at peak performance, you must proactively delete the bloatware every single day.




