For most of the last two decades, the security executive’s job was framed as loss prevention. Reduce the likelihood of a bad day. Report on how much it was reduced. The metrics followed accordingly: patch latency, mean time to detect, control coverage. All useful, all internal, all fundamentally defensive.
The question being asked in board rooms now is different. It is not how much risk did you remove but what did the business get to do because you were there.
The reframe
That is not a communications trick. It is a genuine shift in where a security function sits in the value chain, and it changes what you should be measuring.
- Speed to market. A security review that takes six weeks is a business constraint. One that takes three days is a competitive advantage. That delta is yours to claim.
- Deal velocity. In most B2B sectors, security questionnaires now gate revenue. If your programme shortens the sales cycle, that is a number the CFO understands.
- Optionality. Acquisitions, new markets, new data partnerships — each has a security precondition. Meeting it early expands what the company can consider.
What this asks of us
Three things, none of them technical.
First, learn the business’s own units of measure and use them instead of ours. No board has ever made a decision on the basis of a control-coverage percentage.
Second, get comfortable saying what you are not going to defend. A strategy that protects everything equally is not a strategy, and executives recognise that immediately.
Third, build the relationships before you need them. The conversation about risk appetite goes very differently when it is not happening during an incident.
The security leaders who make this transition are not the ones with the largest budgets. They are the ones who stopped translating the business into security terms and started doing it the other way around.
This is the kind of transition our members work through together — in the monthly sessions, and in the mentoring relationships that come out of them.