CHAPTER 6Business and Finance Acumen
A few years ago, I went to a CISO gathering—a small roundtable conversation that I joined during one of my travels to meet business leaders and customers. The conversation revolved around “How do you measure the success of a CISO?”
There were varied opinions in the room. One CISO said, “I measure my success by how much budget I have and power I wield in the company.” Another said, “I can’t measure my success because if the CEO and the management team don’t prioritize security, then it’s not my fault.” Many others talked about frameworks, standards, and compliance metrics.
I raised my hand and told all of them: “We are measured by the stock price and the success of the business.”
I got quite a few raised eyebrows and a lot of unhappy people. There was significant pushback on that philosophy. Thankfully, I was at a point in my career where my convictions on how to run security teams was high, so I didn’t let my narrative waver.
But I truly believe that security, in the end, is a business function. Our role is to protect and enable the business. We are there to make sure that while our customers, employees, and the business are protected, we are also thriving. The most successful and inspiring CISOs I’ve had the opportunity to work with and learn from understood that.
In this chapter, I’ll discuss how business and financial acumen elevates security leadership—from understanding the company’s revenue model and operational priorities to aligning ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access