Many organizations are adept at deploying information security controls, but these measures are often reactive, meaning they are designed to mitigate incidents after they occur rather than prevent them. Understandably, it is not feasible to deploy proactive security controls for all potential InfoSec incidents. This is where the DMAIC (Define, Measure, Analyze, Improve, Control) approach from the Six Sigma methodology can be valuable. In this article, I explain how to use the DMAIC approach with a real-time case study, demonstrating a proactive reduction in information security tickets/incidents using the Six Sigma project methodology.