Pretend you are the security lead so soft threat models and heroic control stories fail before a launch, vendor deal, or architecture change absorbs them.
Optimistic packages optimize for shipping. The security lead seat does the opposite. It asks which asset is out of scope, which control is described but not tested, which logging gap would blind an incident, and which third party concentrates risk without a named owner. A fluent memo is not evidence that the program can survive a careful read under pressure.
This is one of the core moves in a serious product, vendor, or infrastructure war game: after you describe the upside, seat a careful security perspective and make it try to decline. The output you want is not theater. It is a short list of material objections, the exhibits each needs, and the edits that would survive them.
How to cast the seat
Name a real mandate: protect customer data, keep production recoverable, or underwrite a change without silent gaps. Give constraints: the threat model frame you will honor, the evidence standard for controls, and the residual risk you will not invent away. Without constraints the seat becomes cartoonish. With constraints it produces questions you might actually hear in a design review or vendor diligence call.
Write the seat into the prompt as a named role with a mandate. Example: "Security lead: list the top reasons to delay this change, the claim with the weakest control evidence, the blast radius that worries you most, and the ten diligence questions you would send after review. Stay inside a realistic mandate and avoid illegal tactics."
What to demand from the pass
- Top reasons to challenge, delay, or reject this package.
- The claim that looks strongest and is least evidenced.
- The incident or abuse path that would worry you most.
- What would make you accept instead.
- The ten hardest diligence questions you would send in writing.
Run that brief in Pingpong against the real architecture notes, control inventory, and vendor exhibits. Follow with a home-team response pass so you leave with edits and source packs, not only fear. When the decision is a customer-facing claim, run this seat after product and legal attacks so it can use earlier objections as ammunition.
When the plan leans on a single identity provider, a single region, or a single on-call owner, force the seat to price concentration risk in writing. Ask what happens if that owner is unavailable, if the provider has an outage, or if sampling finds gaps. Concentration that only appears in an appendix still counts.
Pair with stress-test a security incident response, pretend you are the CTO, pretend you are the regulator, stress-test a feature flag rollout, and the war-game decisions hub. See how to run a Pingpong.