In this episode of MSP 1337, episode 300, Chris Johnson sits down with Matt Lee for a candid fireside chat on one of the most misunderstood topics in business and cybersecurity: governance. Using relatable examples, from concrete truck deliveries to vacuuming a floor, Matt breaks down why governance isn't about policies, paperwork, or compliance checklists. It's about setting clear goals, assigning accountability, managing risk, and ensuring everyone works toward the same outcome. The conversation explores why governance has historically been treated as an afterthought in IT and security, why separating security from IT often creates more problems than it solves, and how organizations can build stronger operational resilience through shared leadership, stakeholder alignment, and intentional decision-making. More importantly, Matt challenges listeners to stop viewing governance as a bureaucratic exercise and start seeing it as the foundation that enables security, operations, and business success. Because when governance is missing, even the best tools, frameworks, and people struggle to deliver consistent outcomes. If you've ever wondered why organizations with great technology still experience recurring failures, it's tied to the absence of governance. Key Takeaway: Security doesn't create accountability. Compliance doesn't create resilience. Governance creates the conditions that make both possible.

