LinkedIn·Friday, 7 August 2026·19d ago
"Are we secure?" Someone asks it near the end. Item seven, after the budget, ten minutes left. We used to answer it. A slide, three green…
Curios
996 followers
"Are we secure?"
Someone asks it near the end. Item seven, after the budget, ten minutes left.
We used to answer it. A slide, three green indicators, a number moving the right way. Everyone nodded.
Nobody asks a second question. Not because they're satisfied. Because asking "what does that actually mean" in front of eleven people feels like admitting you don't follow it.
So comfort gets recorded as governance.
Four questions that work better:
→ What are the three things most likely to put us on the front page?
→ If we were breached this morning, how long before you could tell us what was taken?
→ Which risks have we formally accepted, and who signed?
→ What would we stop doing if the security budget dropped 20%?
You don't need to understand the technology. You need to know which risks you own.
Which of those four would your last board meeting have survived?
#vCISO #BoardGovernance #NIS2 #CyberSecurity
↻ 1
View on LinkedIn Cross-referenced
Related on the wire
Before you sign the next penetration test, check who the scope was written for. If it was written to satisfy an audit, it will pass an…
One of this week's 394 Microsoft fixes mentions us. CVE-2026-70324, elevation of privilege in SharePoint. The acknowledgement reads…
GDPR. NIS2. DORA. CRA. The AI Act. Five years ago your security program answered to one regulator. Soon it answers to five. The frameworks…
Every vulnerability you've ever patched had a name before you met it. Someone gave it that name. This week, that someone was one of ours.…
The CCB inspection notice lands on a Tuesday morning. No drama. Just a date. You registered long ago. But registration was never the finish…