About Greenhat
cyber security as a strategy
Cyber security is a strategical risk.
In my environment it isn't necessarily the common point of view. In fact I have been educated in the military cyber security environment where information and cyber security was sacred. Rules, regulations, guidelines were rigid with small room for discussion. My first few years as a security professional I found myself in a unit where more often than not officers wanted to get their jobs done (understandably) and it was apparent they felt information security was "in their way" or "interrupting their operations". Whilst at the time I had little to do about it it made me think about the 'why' of the rules I was implementing, the 'how' and 'whether' which led me to a way of thinking and executing which I am greatly proud of today.
Bottom line is - I treat cyber security as another risk to be considered in the overall strategy of the organisation.
I am responsible to make the best and perform anything and everything which might make my field the best possible but also understand there are other factors to take into consideration.
If an organisation performs an official, annual risk assessment, in regards to finances/investment/marketing/legal/development in its overall strategy, investing budgets depending on risk appetite - then cyber security should be along with them. In fact, my job is to prove why they are more important. If my CEO does not understand the exposure - that's on me. If he does but decides it is not in the organisation's risk appetite - that's on them.
Because when you are as long in the business as I am, you realise the risk is sometimes much smaller than its 'solution' which could end up impedimenting the business.
I don't believe in impedimenting the business. I believe it is my duty to do the best for the business. Sometimes it means insisting on remediation, removing and or other major solutions for the business - but sometimes It is my duty to inform the decision maker that the risk is there but treating it will cause bigger repercussions than leaving it alone and sometimes I have to say 'the risk is there but it is within your risk appetite'.
Yes, I will strive to make my organisation the best, I will do all in my power to make cyber security effective and functioning. BUT! I maintain in my head that cyber security is just one piece of the whole strategic picture.

