Session

Insert Coin: Leaders - Stop Calling Cyber Risk an IT Problem!

Subtitle: If you’re not keeping score, you’re just gambling with the business

When leadership asks, “What’s our cyber risk?”, can you actually answer it? Not vaguely. Not with buzzwords. With a number.

Most organizations can’t. Because they’re not measuring risk; they’re reacting to it. And if you’re not keeping score, you’re not managing risk… you’re just playing games.

Cyber risk isn’t an IT issue. IT doesn’t own it. The CISO doesn’t own it. The business does!!

Yet IT is held accountable without the authority or budget to fix it. That’s not a security gap. It’s a leadership failure.

Every business knows how it makes money. The real question is: what stops that?

If a critical function goes down for 30 days, what does it cost? Who accepts that risk? Was that decision ever made?

You can measure risk and make deliberate decisions…
or keep calling it an “IT thing” and hope for the best.

The coin is already in, whether you’re playing to win, or just waiting to lose.

Brad Mathis

Brad Mathis, CISSP | vCISO, Senior Information Security Consultant with Keller Schroeder

Evansville, Indiana, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top