Turning Disruption Into Energy: The Strategic Windmill Approach

Posted by K. Brown August 10th, 2026

Turning Disruption Into Energy: The Strategic Windmill Approach

Turning Disruption Into Energy: The Strategic Windmill Approach 

Drive across West Texas on the right stretch of highway and you’ll pass through miles of wind turbines, blades turning steadily against a sky that usually looks like it’s deciding whether to behave. Stop for gas anywhere along that stretch on a bad-wind day and you’ll feel it the moment you open the car door — the kind of wind that makes you brace before you step out. Most people standing at that pump are annoyed by it. The turbines a few hundred yards away are getting paid by it. 

There’s an old line about wind farms that captures the difference exactly: it depends on whether you’re trying to build a campfire or generate electricity. The wind that ruins one is the same wind that powers the other. Nothing about the wind changed. What changed is what you built to meet it. 

I think about that every time I sit in a boardroom listening to executives talk about disruption. We spend an enormous amount of energy complaining about the wind — the regulatory changes, the economic volatility, the AI acceleration, the increasingly sophisticated cyber threats — as though it’s something being done to us that we simply have to endure until it passes. We forget we have a choice in how we’re built to meet it. 

You can build walls to block the wind. Or you can build windmills to capture it. 

The Wall Builder’s Instinct 

Most organizations, especially in the SMB space, default to walls, and it’s an understandable instinct. Walls feel safe. They’re the obvious response to something coming at you. When a new compliance mandate lands, the Wall Builder treats it as a tax to be minimized — what’s the least we can spend to pass the audit and get back to normal operations. When the economic forecast turns grim, the Wall Builder freezes budgets and hunkers down, waiting for the storm to pass. When cybersecurity threats escalate, the Wall Builder buys whatever tool clears the compliance checklist at the lowest price and hopes the storm passes them by specifically. 

The problem with walls is that they don’t generate anything. They’re a purely defensive expenditure — capital and attention spent to prevent a loss, with no upside if it works and a crisis if it doesn’t. And walls don’t actually hold indefinitely. They crack under sustained pressure, usually at the moment you can least afford it, because a wall built to satisfy last year’s threat level wasn’t built to withstand this year’s. 

The Windmill Approach requires a genuinely different posture. It asks an uncomfortable question, one most executives don’t naturally reach for under pressure: how can we use the very thing that threatens us to accelerate our growth instead of just surviving it? 

Regulation as Leverage, Not Just Burden 

Consider the regulatory environment in the two sectors we work with most heavily at Responsive Technology Partners — healthcare and accounting. The compliance burden in both has intensified meaningfully in recent years. HIPAA enforcement has gotten more aggressive. The FTC Safeguard Rule has put real pressure on financial service providers, tax preparers, and accounting firms that handle sensitive client financial data, many of whom weren’t originally built with this level of data protection requirement in mind. 

The Wall Builder looks at that pressure and asks the minimizing question: what’s the least we can do to pass the audit without a fine. It’s a rational question on its face. But it treats the investment as pure cost, with no return beyond avoided punishment. 

The Windmill Builder looks at the exact same regulatory pressure and asks a different question: if we have to make this investment anyway, how do we turn it into something a prospective client can actually see and value? Firms across healthcare and accounting have started doing exactly this — treating a genuinely strong security and compliance posture not as a background cost of doing business, but as something worth putting in front of prospective clients directly. In industries where a data breach can be existential for the client, not just the vendor, a firm that can speak fluently and specifically about how it protects sensitive data has a real trust advantage over one that can only say it’s “compliant.” Regulatory pressure that every competitor in the sector is absorbing anyway becomes a differentiator for the firm willing to do it well and talk about it clearly, instead of doing it quietly and minimally. 

That’s the windmill in practice. The wind — in this case, the mandate — didn’t change. What changed was whether the organization treated it as a cost to minimize or an asset to build. 

What a Near Miss Is Actually For 

The same principle holds at a smaller, more internal scale. Disruption often forces you to confront things you’ve been comfortably avoiding, and nowhere is that more true than after a security scare that didn’t quite become a security incident. 

When a company survives a close call — a phishing attempt that almost worked, a login attempt from an unfamiliar location that got caught just in time, a vendor breach that exposed shared credentials but not, this time, your own systems — the instinct is almost universally to patch the specific hole quietly and move on with relief. That’s the Wall Builder response: treat the near miss as a threat that was successfully blocked, full stop, nothing further required. 

The Windmill response treats the same near miss as kinetic energy. A close call is, by definition, proof that your current posture came within a hair of failing — which means it’s also the single best piece of leverage you’ll ever have to finally get budget approved for the security investment you’ve been putting off. The near miss that got caught by luck or timing rather than by architecture is exactly the argument for building the architecture. Organizations that use that moment well don’t just patch the hole. They use the adrenaline of the close call to finally implement the Zero Trust controls, the dedicated monitoring, or the incident response plan that’s been sitting in a proposal document for a year. The shock doesn’t just get survived. It gets converted into forward motion that wouldn’t have happened otherwise. 

Where This Conversation Usually Goes Off the Rails 

This is also where the conversation about internal IT teams versus dedicated security partners tends to break down, and it’s worth being direct about why. 

When the threat landscape shifts — and it has shifted considerably, with ransomware groups now targeting mid-sized businesses with a level of sophistication that used to be reserved for large enterprises — internal IT teams feel the strain immediately. They’re already carrying the day-to-day: line-of-business application support, new employee onboarding, the printer nobody can get to cooperate, the general keep-the-lights-on work that never stops regardless of what else is happening in the threat landscape. Asking that same team to also become dedicated, full-time threat hunters is asking someone to fly a plane while they’re still building the engine mid-flight. 

The Wall Builder’s response to that strain is to hire one more generalist, ask the existing team to absorb more hours, and hope sheer effort keeps pace with a threat landscape that isn’t slowing down to accommodate anyone’s bandwidth. It’s an understandable response and it rarely works, because the gap isn’t a hands problem. It’s a specialization problem. General IT competence and dedicated security focus are different disciplines that happen to share some tools, and treating them as interchangeable is how gaps open. 

The Windmill Builder recognizes that the shift in the threat landscape has changed the actual rules of the game, not just the volume of work. Security now requires dedicated, full-time attention — monitoring that runs continuously rather than during business hours, threat intelligence that gets acted on rather than filed, incident response plans that get tested rather than written once and shelved. The Windmill Builder doesn’t ask their internal team to become something it isn’t. They bring in a specialized, co-managed partner to carry the 24x7x365 monitoring, the threat intelligence, and the incident response, while the internal team stays focused on what it’s actually built to do well — supporting the business day to day and driving the technology decisions that touch growth and user experience directly. 

The disruption of a harder threat landscape doesn’t break that organization. It forces a better operating model than the one they’d have chosen voluntarily, and most leaders will tell you, a year or two later, that the forcing function turned out to be the best thing that happened to their IT strategy. 

There’s a version of this same tension inside larger organizations too, between the security function and everyone else. A dedicated security posture can feel, from the outside, like friction — another approval step, another policy, another reason a project takes longer to launch. The Wall Builder experiences that friction as pure cost and looks for ways to route around it. The Windmill Builder understands that the friction is doing something: it’s the resistance a well-designed system creates on purpose, the same way a turbine blade creates resistance against the wind instead of just letting it pass through unchanged. Remove all the resistance and you don’t get a faster system. You get a system that isn’t converting anything into anything. 

The Newest Gust: AI 

If regulation and cyber threats are the wind most leaders have learned to at least brace for, AI is the gust nobody fully saw coming and everybody’s still arguing about how to stand in. 

The Wall Builder response to AI is a familiar one by now, and understandable given how much genuine uncertainty surrounds it. Block the tools outright. Write a policy that says employees can’t use ChatGPT or any similar platform on company devices. Treat the entire category as a liability to be contained rather than a capability to be developed, and hope that containment holds while competitors figure out how to use it. 

That instinct isn’t irrational. There are real risks — sensitive company or client data being pasted into a public AI tool with no data governance behind it, employees relying on outputs they don’t verify, a false sense of productivity that masks declining quality. Those risks are legitimate, and a wall built purely out of denial that AI exists is a worse strategy than no wall at all. 

But the Windmill response doesn’t deny the risk. It builds around it deliberately. Instead of blocking AI outright, the Windmill Builder asks what a secure, governed path to AI adoption actually looks like — one with a data firewall so sensitive information doesn’t leave the organization’s control, with a clear-eyed rollout that starts small and expands as trust and competence build, with actual usage policies employees understand rather than a blanket ban they’ll quietly work around anyway. The same disruptive force that terrifies the Wall Builder becomes, for the Windmill Builder, a genuine operational advantage — faster internal workflows, better client-facing responsiveness, employees who spend less time on drudgery and more time on the work that actually requires a human. 

The organizations handling this well right now aren’t the ones with the loudest AI strategy on LinkedIn. They’re the ones that treated the arrival of AI the same way they’d treat any other major disruption: not as something to survive by pretending it isn’t happening, but as pressure worth building real infrastructure around, deliberately and with eyes open to both the upside and the risk. 

Disruption Isn’t a Weather Event 

We have to stop treating disruption like an anomaly — a storm that will eventually pass so things can get back to normal. It isn’t, and normal in the sense most leaders mean it isn’t coming back. 

The pace of AI acceleration isn’t going to slow down so anyone can catch their breath and consolidate. Regulatory bodies aren’t going to conclude they’ve issued enough mandates and take a few years off. Threat actors aren’t going to decide they’ve made enough money and retire from the field. Disruption, at this point, is simply the permanent operating condition of running a business — not a phase to be endured before things settle, but the actual, ongoing climate. 

The wind is going to keep blowing. It will very likely blow harder next year than it did this year. 

You can spend your capital, attention, and organizational energy building thicker and taller walls, hoping they hold long enough for the storm to move somewhere else. Plenty of organizations will choose exactly that, and plenty of them will be fine for a while, right up until the wall that was sized for last year’s pressure meets this year’s gust. 

Or you can look at the same pressure and ask a different question: what would it take to attach a turbine to this instead of a wall. What would it take to build an organization that gets stronger, more differentiated, and more resilient specifically because of the pressure everyone else is treating as pure cost. 

That question doesn’t have one universal answer, and it shouldn’t. A healthcare practice building around HIPAA pressure is going to arrive at a different set of investments than an accounting firm building around the FTC Safeguard Rule, and both are going to look different from a manufacturer building around AI-driven efficiency gains. What they’ll share, if they build it right, isn’t the specific turbine. It’s the underlying decision to treat the wind as something worth engineering for, rather than something to be endured until it, hopefully, eventually, dies down. 

It won’t. That’s the part worth sitting with longest. The choice was never whether you’d face the wind. Every organization in every industry is standing in the same weather right now, whether they’ve admitted it to themselves yet or not. The only real choice left is whether what you’ve built turns that wind into something that knocks you over, or something that powers you forward. 

 

About the Author: Tom Glover is Chief Revenue Officer at Responsive Technology Partners, specializing in cybersecurity and risk management. With over 35 years of experience helping organizations navigate the complex intersection of technology and risk, Tom provides practical insights for business leaders facing today’s security challenges.

Eliminate All IT Worries Today!

Do you feel unsafe with your current security system? Are you spending way too much money on business technology? Set up a free 10-minute call today to discuss solutions for your business.

Archives