Carter Schoenberg is a highly respected figure in cybersecurity, with extensive experience across both public and private sectors. Drawing from this background, he offers insights into what strategies succeed and fail within the cybersecurity landscape.
Robert F. Kennedy once said, “Only those who dare to fail greatly can ever achieve greatly,” a sentiment echoed by motivational author Denis Waitley, who said, “Failure should be our teacher, not our undertaker. Failure is delay, not defeat. It is a temporary detour, not a dead end.” These quotes have resonated with me throughout my career, particularly since I began serving as a CISO for state government in 2002.
My journey has been marked by numerous setbacks. In fact, I once wrote an article for CSO Magazine in January 2006 titled “Are You the Party Pooper?” where I admitted that many of my colleagues saw me as the person who always said “no.” Those early missteps as a CISO nearly cost me my job, but they also provided invaluable lessons in leadership, team-building, and mentorship.
Fast forward to December 2023, and my colleague and friend, Carter Schoenberg, published a book titled Why Cybersecurity Fails in America. Before diving into the book, let’s first understand who Carter Schoenberg is.
Carter’s Amazon profile describes him as a Certified Information Systems Security Professional (CISSP), Boardroom Qualified Technology Expert (QTE), and a CMMC Certified Assessor (CCA). His firm, an approved CMMC Third Party Assessor Organization (C3PAO), has been guiding defense contractors through CMMC and DFARs compliance since 2021. With over three decades of experience in criminal investigations, cyber threat intelligence, cybersecurity, cyber risk management, and cyber law, Carter’s expertise has been featured at forums hosted by MITRE, the Department of Defense, and the Department of Homeland Security, among others.
His contributions have shaped key reports like the GSA/DoD Final Report to the White House on improving cybersecurity and resiliency through acquisition. His work has been utilized by numerous agencies and organizations, including the Department of Education, DHS, Smart Cities, and the Georgia Bar Association. He also co-authored NIST’s “Guidance for Smart Cities and Municipalities Cyber Supply Chain Risk Management (C-SCRM).” His book explores the complex interplay between the U.S. Government, Human Resources, academic institutions, corporate boards, and cybersecurity professionals, shedding light on why cybersecurity often falls short.
I first met Carter over 17 years ago when he was a client engagement manager at Motorola, and I was the Michigan CISO. His expertise, attention to detail, and work ethic left a lasting impression on me. Over the years, as he transitioned into various leadership roles across different companies and sectors, I continued to rely on him as a trusted expert on a range of cybersecurity issues, including federal compliance.
About the Book: Why Cybersecurity Fails in America
According to its Amazon listing, Carter’s book delves into the interconnected roles of government, human resources, higher education, corporate boards, and cybersecurity professionals in the persistent shortcomings of cybersecurity. It aims to help security practitioners, HR professionals, and executives rethink legacy approaches to enterprise risk management. The goal is to empower readers to drive positive change by enhancing operational effectiveness and efficiency.
The book covers a wide range of topics, including:
- Case Studies and Presumptions
- Flaws in Legacy Risk Modeling
- Safeguarding vs. Resilience
- The Impact on Corporate Bottom Lines
- Failures in Government and Higher Education
- The Role of HR in Cybersecurity
- Degrees vs. Certifications vs. Apprenticeships
- The Effects of Regulations and Change Management
- The Importance of Cybersecurity Professionals Understanding Corporate Culture
- Strategies for Engaging and Retaining Board Attention
Carter’s narrative is rich with personal anecdotes, detailing interactions, decisions, successes, and failures from his career. These stories are not only engaging but also offer valuable lessons for cybersecurity professionals, especially those early in their careers.
His insights often resonated with my own experiences. For instance, the story on page 33 reminded me of challenges I faced as a CISO. In that excerpt, Carter discusses the role of Information System Security Officers (ISSOs) and the common perception of them as naysayers. He recounts a meeting with a government CISO, Jeff Eisensmith, who emphasized that ISSOs should focus on identifying risks and proposing alternatives rather than outright rejecting ideas—a perspective I found refreshing.
Carter also offers practical advice throughout the book, such as on page 56, where he discusses the importance of understanding the business context when evaluating risk modeling techniques. He urges cybersecurity professionals to look beyond technical threats and consider business implications, providing actionable guidance for improving risk assessment.
The section on HR and cybersecurity roles is particularly insightful, offering lessons that should be required reading for both public and private organizations striving to attract and retain cyber talent.
Carter’s Perspective on Recent Cyber Events
Before concluding this review, I want to share Carter’s thoughts on some significant cybersecurity events from 2024. I asked him about the CrowdStrike/Microsoft incident and the broader implications of such failures.
Carter noted that while the issue with their SDLC caused significant disruptions, it’s important to evaluate the impact in the context of historical cyberattacks. He expressed surprise that only a few hundred thousand assets were affected, contrasting this with past incidents like Code Red, Nimda, and WannaCry. He also questioned whether this event would influence how boards of directors evaluate CEOs, citing the significant drop in CrowdStrike’s market value as a potential turning point.
Carter also discussed his recent success in communicating cyber risk to global companies, emphasizing the importance of translating technical issues into business terms. He highlighted the effectiveness of aligning cybersecurity initiatives with a company’s risk tolerance levels to gain executive buy-in.
Final Thoughts
Carter’s book, with its provocative title, grabs attention for all the right reasons. While the $35 price tag may seem steep, the wealth of knowledge and practical advice it offers makes it well worth the investment. Carter’s stories and insights can help readers navigate the complex world of cybersecurity, turning potential failures into opportunities for success.



