Doing business comes down to one simple question. How much money are you willing to lose in an attempt to make even more money? In other words…how much risk can you stomach? A good information security professional must understand this principle. They must also be willing to exercise flexibility in their personal opinions and help business leaders understand risk.
An information security professional must understand their role in the organization. If they understand it and operate within it, they can be a very useful resource. If they don’t, they become a huge liability. Security pros must understand that business decisions must be made by business leaders. Our role is to help business leaders understand risk and learn how to mitigate it. Their job is not to make the ultimate decision. That’s the role of a business leader and one I’ll talk more about in another post.
Read more: The True Role of an Information Security Professional