Cybersecurity Blog
You Run the Business. You Also Make the Security Decisions. That Is the Problem.
In a business with fewer than 50 or 100 people, there is rarely a Chief Information Security Officer. There is rarely a dedicated Chief Financial Officer either. There is usually a founder, an owner, or a CEO making most of the significant decisions across both of those functions simultaneously. That sounds efficient. In many ways it is. But it creates a security problem that larger organizations pay specialists to solve, and smaller ones often do not notice until something goes badly wrong. When the same person is both approving the security budget and evaluating whether it is adequate, there is
You Approved the Budget. Can You Explain What It Protects?
Many of us have seen the following situation many times, but little has changed over the years. You sit in the budget meeting. The security team presents the annual request. The numbers are significant. You ask a few questions, adjust the total slightly, and approve it. Now for a different question. Not from the meeting. From me, right now. What does that budget actually protect? I am not looking for an answer in technical terms. Instead, I am looking for it in business terms and this may require a little more thinking to answer. Which specific parts of your business
The People, Process, And Technology Security Control Stack
Seven questions will change how you think about cybersecurity. Who defines the direction of the company? Who owns the data? Who allocates and approves capital and operational expenses? Who is responsible for business risk? Who defines which data is most important and how strongly it should be protected? Who defines the most critical business processes? Who applies security controls and manages protection of the data? Six of those seven answers point to business leadership. One points to IT. So why does executive leadership delegate cybersecurity responsibility to IT? This is the question the cybersecurity industry does not want you to