THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, January 14, 2021
Through this article, Tom John F. Jensen emphasises the critical need for stakeholder alignment in cybersecurity and organisational compliance initiatives. He discusses the challenges of securing buy-in for projects protecting an organisation’s existence and articulating a clear value proposition. Jensen highlights the necessity of defining success criteria and maintaining operational stability while adapting to future technological changes.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Stakeholder management & alignment with business needs
In an increasingly digital world, where businesses are progressively operating in online environments, it is ever more crucial to integrate and align business developments with security & compliance efforts to achieve lasting beneficial outcomes.
Value proposition
While the statement might seem obvious, most compliance & security professionals today lack proper stakeholder buy-in for initiatives that ultimately safeguard an organisation’s continual existence. Such initiatives are often only an afterthought or deemed a ‘necessary evil’ by most stakeholders, as it remains challenging to correlate direct value between the initiative and the bottom line. The issue, or culprit, is usually found in the value proposition or the lack of such a proposition when organising a compliance & security project. Unfortunately, many professionals in this field focus entirely on solving the problem, such as mitigating the risk, closing the gap, or reaching a certain maturity/resilience level. The consequence of such an approach is usually found in the longevity of the project's effort, as it will suffer over time without the proper buy-in and understanding from key stakeholders.
This speaks to the importance of building a business case, identifying the why, the who and the how. Without ascertaining the fundamentals, any subsequent communication to stakeholders and the project’s metrics for success will ultimately have limited value. This is in particular because most stakeholders need help understanding their own needs regarding compliance & security. Without the necessary understanding, the value proposition might still be bought into, but at a cost, which inevitably will be a mismatch between stakeholder expectations for project goals, cost/benefit, realised value, etc.
Alignment
Obtaining alignment and a mutual opinion on the success of a compliance or security project can be a daunting task. Nevertheless, we must strive for it when planning the project. Without alignment, it will become increasingly difficult to maintain ‘the burning platform’, affecting project funding, resources, priority, etc.
"Without proper stakeholder buy-in, compliance and security initiatives are often seen as an afterthought, making it crucial to build a compelling business case that correlates security efforts with organisational value and longevity"
Cyber Security Review Europe
The necessary alignment is best achieved with various actions, as there is no ‘right’ approach that universally works for all organisations. Instead, the approach should structure the value proposition and the underlying business case in a language that stakeholders can understand. The same goes for identifying and highlighting potential operational and commercial areas that stand to benefit from the initiative. This is often neglected in such projects, even though optimisations can regularly be found when operational procedures are revisited and reviewed. Finally, adding an unbiased third-party opinion to substantiate the criticality of the project and making proper comparisons to illustrate the gaps make a project far more tangible to laypeople.
Success
A project’s success criteria should always be predefined and, if possible, be in measurable metrics to gauge the quality of the project’s outcome. However, when working with compliance and security, success with an individual project can be misinterpreted by stakeholders, who may believe that no more effort, resources, or improvements will be needed for the entire area. It is, therefore, of the utmost importance that the long-term mutual definition of success is understood to be continual and lasting operational stability while using the optimal amount of resources to achieve it, impacting operational agility the least and ensuring compatibility with tomorrow's technologies.
More in News