AI & ML

CISOs Must Evolve: Integrating Business Risk into Security Strategy

Security leaders are redefining their roles by embracing business risk management to enhance profitability and operational effectiveness.

Jun 22, 2026 3 min read
Sign in to save

As cyber threats continue to evolve, Chief Information Security Officers (CISOs) are finding their roles expanding far beyond traditional security concerns. Doug Kersten, CISO at Appfire, exemplifies this shift; he's now responsible not only for safeguarding systems but also for the business risks associated with security tools and processes used within customer offerings. This transition underscores a critical trend: it's no longer enough for CISOs to prioritize security in isolation; they must understand and influence business risk to drive profitability.

Kersten’s perspective reflects a broader change within the industry. “CISOs need to provide input and remediation on the impact of security cost because these often-hidden costs have a negative effect on profitability,” he asserts. “These are typically overlooked by finance teams when calculating the true cost of goods sold.” This highlights the importance of integrating security leadership into discussions about business risk, ensuring that those making financial decisions recognize the implications of their choices.

Understand the Blurred Lines Between Risks

The growing intersection between security and business risks is acknowledged by many leaders in the field. Dale Hoak, CISO at RegScale, notes that while CISOs traditionally focused on protecting data and infrastructure, the current business landscape demands a more nuanced understanding of how cyber threats directly impact revenue, customer trust, and operational integrity. “The distinction between business risk and security risk is becoming increasingly blurred,” he comments, emphasizing the need for security leaders to adopt an enterprise-wide perspective.

This integrated viewpoint is crucial for CISOs to serve as true enterprise risk leaders. Their role now includes advising executive leadership on how security decisions align with organizational objectives, rather than confined to technological concerns. This obligation to adapt and understand the bigger picture requires tools, strategies, and collaboration with other departments.

Collaborate with Business Risk Owners

To successfully navigate this expanded scope, CISOs would do well to partner with those who inherently understand business risks. Roland Palmer, CISO at JumpCloud, acknowledges his journey toward mastery in business risk and emphasizes collaboration with leaders from legal, finance, marketing, and operations to build a cohesive understanding of organizational risk appetite. “We form a great team to understand risk,” Palmer notes, pointing out the essential nature of inclusion in establishing robust risk management practices.

Kersten's approach mirrors this sentiment—he collaborates closely with business leaders to gain insights into security risks and their associated business consequences. By assigning business leaders to articulated security risks, he has been able to uncover previously unknown vulnerabilities and develop proactive mitigation strategies.

Align Security Objectives with Business Goals

Successful CISOs take an active role in aligning cybersecurity initiatives with business objectives. Kersten implements company goals and key results (OKRs) into his security strategy, allowing him to understand which security risks could derail business aims. “I build out plans to address those business objectives and key results,” he explains, adapting his strategies to interlace operational needs with security measures.

Richard Watson, global cybersecurity leader at EY, echoes the importance of this alignment. He advises CISOs to map cyber controls to critical business processes and assess their financial implications. This method not only allows for clear communication of technical risks in business terms but also aids in prioritizing investments according to overall business strategies.

Networking as a Key Tool

CISOs should leverage networking to uncover valuable insights into business risks. Gary Hayslip, a cybersecurity executive, advocates for regular interactions with business colleagues through informal settings, like a listening tour, to better grasp their challenges and objectives. “I feel it’s important to understand their objectives, the technologies they use, and what keeps them up at night,” Hayslip shares. Engaging in dialogues helps build trust and fosters an environment where security leaders can address concerns collaboratively.

Tabletop Exercises Centered on Business Risk

For a more structured approach to understanding business risk, conducting tabletop exercises can be immensely beneficial. Hayslip suggests that these exercises shouldn't just focus on technical responses but should simulate real-world decision-making scenarios under pressure. By challenging executives to grapple with situations like ransom decisions or breach disclosures, these exercises teach the security team how their peers react during crises and stress-test the company's response mechanisms.

Invest in Learning About Business Risks

To truly excel in this role, continuous education on business risk is essential. Sean Murphy, CISO at BECU, pursued the Directorship Certification to deepen his understanding of governance and risk oversight. “The certification helps me delve into what the board cares about,” he states. By familiarizing himself with how boards view risk, he can effectively translate that knowledge back to his security team.

Other veteran leaders recommend that CISOs read the company’s annual reports and investor presentations to gain insights into revenue drivers and potential risks articulated by executives. By doing so, security leaders can align their priorities with those deemed critical for the organization’s success.

Integrate Cybersecurity with Enterprise Risk Management

Ultimately, to master business risk, CISOs must integrate security into the organization’s broader enterprise risk management framework. As Scott Melchior of ISACA notes, cyber threats now represent existential business risks rather than just IT problems. Security cannot be an afterthought; it has to be woven into the fabric of business strategy.

Hoak underscores the need for a unified approach in which security risks are considered alongside operational, legal, and financial threats. By adopting a cohesive view, organizations can evaluate risks holistically, making it easier for executive leadership to recognize cybersecurity efforts within the context of overall business objectives.

Hayslip has implemented such integration by aligning his security risk register with the entity's enterprise risk management platform. This practice not only elevates the visibility of cyber risks but also ensures they are assessed on par with other critical business risks. “Moving from qualitative heat maps to financial impact numbers allows the CISO to demand attention and resources on equal footing,” Hayslip emphasizes, reflecting an essential strategic evolution in today’s threat landscape.

Source: Robert Smith · www.csoonline.com

Comments

Sign in to join the discussion.