Security is Communication & Stakeholder Management
I often hear security responsibles complaining that they are not being heard and that their topics end up with a low priority. On the other hand, leaders have so many topics to take care of that they most likely focus on topics they understand and that they are convinced are important. These observations can be made in SMEs, huge global organizations and startups.
This leads to two generalized conclusions:
1)????The communication from security experts to business leader and stakeholder management is not optimal.
2)????Security does not have??the importance it often claims.
I claim that security is marketing, communication and stakeholder management. You compete with other topics like environmental, health, talent attraction, diversity etc.
What I see e.g. on LINKEDIN for example are
Rarely you see how security really contributed to a business case or how a board was educated.
The same is true if you go to risk or security related conferences. How many business C-Level executives have you ever met there? Most probably not many.
The way forward is: