Paul Proctor
Paul Proctor
ability activity communication decision determine excellent executive good highly information knowledge lacking oral political report requiring risk security skills written
The ability to determine what constitutes risk, and the requirement to report that risk to executive decision makers, can be a highly political activity requiring excellent written and oral communication skills with a good knowledge of business. Generally, these skills have been lacking in traditional technically-oriented information security specialists,
business needs potential returns security understand
The CISO needs to be able to understand the business, and the potential returns on any security investment,
board change ultimately
Ultimately the change has to come from the board down.