Over time every security executive learns that there’s only three important things in security:
- How big is our cyber policy?
- How do we make sure the insurance company pays out?
- Will our financial growth and policy offset the maximum potential losses if we decide not to roll out security tool X or patch Y?
That’s really it. When growth and insurance won’t cover it then you’re plugging holes until the equation balances itself out. Everything else is theater.
Doing anything other than the above ends your career...quickly.