Results depend on decisions the leader does not control
A security leader can identify a risk, propose a remedy and set a timetable. Whether the remedy is delivered depends on technology and operational capacity, competing business priorities and funding, which sit with other executives.
Consider a known weakness in a customer-facing system. The security leader raises it, the technology team estimates the work, and competing business priorities push it back quarter after quarter. Nobody decides to accept the risk, and nobody records that it remains open. When a customer review or an incident brings it to light, the organisation cannot show who decided to leave it open, or why.
Agree four things at the outset
Each agreement commits executives outside the security function, so each needs to be made at executive team level.
- Mandate
- What the role must achieve in its first two years. Building a function, remediating known weaknesses, meeting customer security requirements and preparing for regulatory supervision each call for a different profile and a different level of investment.
- Delivery ownership and resources
- Which business leaders own delivery of the agreed priorities, and what capacity and funding they commit. A mandate without committed capacity leaves the security leader responsible for work that others control.
- Decision rights
- Who settles conflicts between security work and commercial priorities, and who can accept the risk when remediation is deferred. Each deferral should have a named owner, a recorded reason and a date for review.
- Reporting route
- How material security risks reach the executive team, whatever the formal reporting line. Direct access to the chief executive and a standing item on the executive agenda are two ways to provide it.
Expect decisions early and action by six months
Urgent risks need immediate escalation. An initial assessment of the main risks should reach the executive team within the leader's first 90 days. It will rest on incomplete information, so the uncertainty should be stated alongside each risk.
By six months, look for evidence that the arrangement produces action. Agreed priorities have funding and named delivery owners. Agreed work is progressing against milestones, and material delays have an owner and an agreed response. Disagreements the security leader could not resolve have reached someone with authority to settle them, and each outcome is recorded.
Questions for the executive team and the board
Executives can use these questions to test the arrangement they have set up, and board members can use them to seek evidence that it works.
- Priorities and resources
- Have we agreed the security leader's priorities and committed the resources needed to deliver them?
- Decisions and accepted risk
- Who resolves disagreements over security investment, and who accepts the risk of deferring action?
- Follow-through
- What evidence shows that agreed decisions are being carried out?