Alignment of business strategy and risk appetite should minimize the firm’s exposure to large and unexpected losses. In addition, the firm’s risk management capabilities need to be commensurate with the risks it expects to take.
—Jerome Powell1
Last spring, I read a WSJ article that quoted a CISO saying, “Even in a good economy, people are trying to grow the business, that’s what they want to put their funds into. Security may be important, but security doesn’t make revenue.”2 If you read ...