1. Learn
  2. Align
  3. Perform
  4. Review

Principled Performance9 min read

Praestantia Principiata: A Philosophy for Work and Life

By J Damien Scott, Trusted Advisor

A personal essay on the Latin motto J Damien Scott has built his career around: Praestantia Principiata, or principled excellence. Drawing on the OCEG GRC framework, the essay traces a through-line from Marine Corps service, law enforcement, commercial diving, and private aviation to converged security consulting — arguing that governance, risk, and compliance is not a compliance function but a discipline for living and working with integrity under pressure.

A Name for What I Already Believed

I have spent my career in places where the cost of being wrong is measured in more than dollars. I started in the Marine Corps as a military policeman. I carried a Texas peace officer's badge. I spent years in high-risk protective security work in some of the most unstable environments in the world. Along the way I also learned to fly a single engine aircraft and worked as a commercial diver, with time offshore in the Gulf of Mexico. I moved into corporate security leadership, running physical security, investigations, and executive protection programs, and eventually into governance, risk, and compliance work spanning both the physical and digital domains.

Every one of those chapters looked different on the surface. A guard post, a dive site, a cockpit, a protective detail, a boardroom: none of them resemble each other at first glance. But underneath, they all ran on the same discipline. You learn the ground before you act on it. You align your standards and your resources with what the mission actually requires. You perform the work with controls that hold up under pressure. You review what happened and get better before the next rotation. I did not have a name for that discipline for most of my career. I do now.

The name is GRC, short for governance, risk, and compliance. OCEG defines GRC as 'the integrated collection of capabilities that enable an organization to reliably achieve objectives, address uncertainty, and act with integrity.' That definition matters because it heads off the most common misunderstanding I encounter in my consulting work. GRC is not simply a compliance department, a risk register, or a piece of software. It is the coordinated way an organization, or a person, sets direction, makes decisions, manages uncertainty, and behaves consistently with its values.

Principled excellence is not a credential. It is a discipline I choose to practice every day, and I intend to keep choosing it.

Introducing Praestantia Principiata

I have adopted a personal motto that captures this idea in two words: Praestantia Principiata. It is Latin I built myself rather than a classical phrase, so I will not overstate its pedigree. Praestantia is the Latin word for excellence or distinction. Principiata is my own construction from principium, the Latin root for principle or foundation. Together, I use the phrase to mean principled excellence: excellence that is not worth having unless it is built on principle, and principle that is not worth holding unless it produces real performance.

That is my own translation of what OCEG calls Principled Performance, applied past the edge of the org chart and into the rest of my life. OCEG grounds Principled Performance in three pillars: a principled purpose defined by clear mission, vision, and values; principled people of strong character who direct their energy toward that purpose; and a principled pathway that breaks down silos so governance, strategy, risk, and compliance reinforce each other instead of working at cross-purposes. I hold myself to the same three pillars as a person, not only as a professional.

The Protector's Work

OCEG has a word for the people who do this work inside organizations: Protectors. The term applies to anyone in governance, risk, compliance, security, or audit, and it rests on a simple idea. Protectors are not purely defensive. OCEG uses the image of a mountain climber to explain this. A climber produces value by making progress toward the summit, and preserves value by using ropes, anchors, and technique to keep a fall from becoming a catastrophe. A Protector does both at once. That image describes my career better than any job title has.

OCEG organizes this work into six critical disciplines: governance and oversight, strategy and performance, risk and decision support, compliance and ethics, security and continuity, and audit and assurance. I do not think of these as six separate jobs. I think of them as six lenses a converged security leader has to look through on the same problem, whether that problem is a guard force, a data center, or a client relationship.

Learn, Align, Perform, Review: The Cycle That Scales

The operating engine behind Principled Performance is a four-part cycle OCEG calls the GRC Capability Model. LEARN means understanding an organization's context, culture, and key stakeholders well enough to set the right objectives. ALIGN means matching strategy to those objectives and matching action to that strategy, through decisions that weigh values, opportunities, threats, and requirements. PERFORM means executing the actions and controls that promote what is desirable, prevent what is not, and detect problems as early as possible. REVIEW means checking whether the strategy and the actions actually worked, and using that evidence to improve.

I recognized this cycle before I had OCEG's language for it, because I had already lived it in two disciplines built entirely around it: flying and commercial diving. A pilot learns the weather, the aircraft, and the route, aligns the flight through a briefing and a checklist, performs the flight by the checklist rather than by memory, and reviews it afterward in the debrief and the logbook. A diver does the same with the site, the current, and the dive tables. Neither discipline treats that cycle as optional paperwork. Skipping a step is how people get hurt. That is the clearest version of principled excellence I know: performance that is only as good as the discipline surrounding it.

Where the Cycle Meets the Post and the SOC

This is where the philosophy stops being abstract for me, because I have spent my career on both sides of what most people still treat as two separate worlds: physical security and cybersecurity. I do not see them that way, and neither does GRC done well.

Learn looks the same whether you are mapping a guard force's post structure or an organization's attack surface. You need to know your assets, physical and digital, your stakeholders, and the threats that actually apply to your context. Align means turning that understanding into standards: post orders and access control policy on one side, identity management and detection rules on the other, both traceable back to a clearly stated risk appetite rather than habit. Perform is where the controls actually run. None of that matters without Review: after-action reviews, control testing, incident post-mortems, and audits that ask honestly whether the design held up and what needs to change.

A converged security leader's job is to make sure the same discipline governs both domains, because the people trying to do harm to an organization do not respect the line between a locked door and an open port. I built my consulting practice on that conviction, and Praestantia Principiata is the short version of why it matters to me.

Beyond the Org Chart

I said at the start that I did not learn this discipline in a boardroom. I learned it standing posts, working cases, and carrying responsibility for other people's safety in places where a mistake had real consequences. GRC gave me the vocabulary for what I had already been doing.

Praestantia Principiata is my commitment to keep doing it everywhere: in client work, in how I run my practice, and in how I show up for the people who depend on me outside of work. Principled excellence is not a credential. It is a discipline I choose to practice every day, and I intend to keep choosing it.

LeadershipGRCLeadershipPrincipled PerformanceConverged Security

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles

Review · 11 September 2026

Post Coverage Is a Protective Audit, Not a Finance Task

An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.

5 min read

Review · 10 September 2026

The After-Action Review Is Where Review Happens

Exercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.

5 min read

Review · 9 September 2026

Three Numbers a Protective Program Must Report

Activity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.

5 min read