Managing Your Security Function in the Always-On Security Environment: A Board Playbook
Boards often hire CISOs to "prevent breaches and maintain compliance." In always-on security environments, that's the wrong job description . The real job is: "Build a team that learns faster than the threat landscape changes." That requires you, the Board, to engage in different hiring, different measurement, different patience, and different incentives. You don't want to incentivize the wrong behaviors, and you definitely don't want to repeat past mistakes with cybersecurity leadership. Here are two models that sound the same, but they incentivize almost opposite behaviors. The Prevention Model (what Boards usually want): Minimize incidents through defensive posture Follow best-in-class frameworks (NIST, ISO, etc.) Measure : "Did we get breached? Are we compliant?" Reward : Avoiding bad things Risk tolerance : Low The Learning Model (what the always-on security environment requires): Detect novel threats fast, respond faster, extract lesso...