For years, the cybersecurity industry has been telling CISOs that they need to communicate better.
They need to speak the language of business. They need to simplify their message for the board. They need to translate technical risk into financial impact. They need better metrics, better dashboards and better storytelling.
There is some truth in all of that, of course. Communication matters at senior level, and CISOs cannot expect boards or CEOs to engage meaningfully with a stream of technical jargon.
But I think we have been looking at the problem from the wrong end.
The biggest hurdle in getting everybody aligned behind a clear cybersecurity strategic message is not finding the right words. It is getting the organisation to agree on what cybersecurity is actually there to achieve — and who is accountable for making it happen.
That is fundamentally a leadership and governance challenge, not a communications challenge.
Everybody Sees Cybersecurity Through A Different Lens
In most large organisations, cybersecurity cuts horizontally across business and technology silos. That is precisely what makes it difficult to manage.
The board may see cybersecurity through the lenses of resilience, regulatory exposure and corporate reputation. The CIO may see technology stability and operational delivery. The CISO may see vulnerabilities, threats and control gaps. Internal audit may focus on compliance. Business executives may be primarily concerned with customers, costs and speed of execution.
None of those perspectives is necessarily wrong.
The problem starts when they are not connected by a common strategic direction.
Then cybersecurity becomes an accumulation of initiatives driven by different agendas: an audit finding here, a regulatory requirement there, a security product somewhere else, followed by a transformation programme in response to a new threat or a fresh wave of investment after an incident.
You end up with activity everywhere, but not necessarily with strategic alignment.
A List Of Security Projects Is Not A Strategy
This is where I think many organisations struggle.
Cybersecurity strategy is too often approached as a collection of projects, technologies, controls, maturity targets and compliance objectives.
But those things should come after the strategic message, not constitute it.
The starting point should be much simpler: What are we trying to protect, why does it matter to the business, and how do we organise ourselves to protect it consistently?
Cybersecurity exists to protect the organisation and its ability to operate, grow and withstand attacks.
That should be the anchor.
Technology, compliance, third-party security, identity management, cloud security, AI governance and everything else should sit underneath it.
Once cybersecurity is positioned in those terms, the conversation starts to change because it becomes connected to the purpose and priorities of the organisation itself.
Stop Expecting The CISO To Solve The Problem Alone
This is also where the traditional narrative around the CISO becomes problematic.
We have been saying for years that CISOs need to “speak the language of business”, as if cybersecurity alignment depended primarily on their personal ability to explain themselves.
I think that argument has become shallow.
Of course, CISOs need to communicate effectively. But if the organisation fundamentally regards cybersecurity as an IT problem, if senior executives have conflicting objectives, if accountability is fragmented across silos, or if the CISO lacks the authority to drive change, no amount of communication training is going to fix the underlying problem.
You cannot communicate your way out of a dysfunctional governance model.
And you cannot expect the CISO alone to create alignment across an organisation if senior management has never agreed on the objectives behind the cybersecurity agenda.
That alignment has to come from the top.
Short-Termism Keeps Pulling The Organisation Apart
There is another dimension to this problem that has always been central to the “Cybersecurity Spiral of Failure”: Endemic business short-termism.
Over the past decade, many large organisations have been operating against a backdrop of relentless disruption. Cyber incidents, ransomware, geopolitical instability, regulatory pressure, cloud transformation, supply-chain problems and now AI have all competed for management attention.
The result is often a cycle of reaction.
Something happens. Attention moves towards cybersecurity. Money becomes available. Projects are launched. Then priorities change, management attention moves elsewhere and the organisation waits for the next trigger.
That creates fragmented security programmes and fragmented messages.
One year the priority is ransomware. The next it is cloud security. Then third parties. Then AI. Tomorrow it may be post-quantum cryptography.
Those issues can all be important, but they cannot become substitutes for strategy.
A mature cybersecurity strategic message should survive changes in the threat landscape because it is anchored in the culture of senior executives and the protection of the business, not in whatever security topic happens to dominate the agenda at a particular point in time.
The “What” Is Rarely The Hard Part
This goes back to something I have been arguing for many years around cybersecurity transformation.
The “what” is rarely the hardest part.
We have decades of security standards, frameworks, regulatory requirements, industry guidance and accumulated experience telling organisations broadly what good cybersecurity looks like.
The real difficulties are the “how” and the “who”.
How do you drive change across organisational silos? How do you maintain momentum over several years? How do you deal with competing priorities? How do you embed cybersecurity into operating models that were never designed around it?
And, critically, who owns all of that?
This is why slogans such as “security is everyone’s responsibility” can be misleading. Everybody may have a role to play, but accountability cannot be diluted across thousands of employees.
Transformation requires clear ownership.
Somebody has to own priorities. Somebody has to arbitrate conflicts. Somebody has to provide resources. Somebody has to remain accountable for outcomes.
Without that clarity, the strategic message will inevitably fragment.
The Message Has To Become The Business’s Own
Ultimately, I think we need to stop treating cybersecurity alignment primarily as a messaging exercise.
If the CEO, board, CIO, CISO and senior business executives cannot give broadly compatible answers to the question “What is cybersecurity trying to achieve for this organisation?”, the problem is unlikely to be the wording of the CISO’s presentation.
It points to something deeper around culture, governance, ownership and leadership.
Cybersecurity cannot remain something the CISO is expected to sell upwards to senior management year after year. Nor should the CISO have to manufacture a “business case” every time basic protection capabilities require attention.
The objective should be to create a cybersecurity narrative that the business recognises as its own.
That means starting with business protection. It means connecting cybersecurity to operational resilience, strategic objectives and the organisation’s ability to withstand inevitable attacks. It means making accountability explicit and ensuring that investment decisions follow from an agreed strategic direction rather than from the latest incident, audit finding or technology trend.
Once that foundation exists, communication becomes considerably easier.
Without it, organisations can produce better dashboards, sharper board presentations and more sophisticated metrics, but different stakeholders will continue pulling cybersecurity in different directions.
And that is the real hurdle.
The challenge is not getting everybody to repeat the same cybersecurity message.
It is getting everybody to believe they are pursuing the same objective.
JC Gaillard
Founder & CEO
Corix Partners
Contact Corix Partners to find out more about developing a successful Cyber Security Practice for your business.
Corix Partners is a Boutique Management Consultancy Firm and Thought-Leadership Platform, focused on assisting CIOs and other C-level executives in resolving Cyber Security Strategy, Organisation & Governance challenges.
