According to statistics that I’ve just made up, less than [cough]% of all breaches are the result of a determined / planned attack, the remaining [mumble]% are the result of inadequate security of one sort or another.
The second sort is the overwhelming majority, but yes, I do need to start doing proper research.
My proposition is simple:
- CEO doesn’t seem to care = no-one else cares;
- CEO ignores security = everyone else ignores security;
- CEO is passive-aggressive and devoid of charisma = s/he will surround themselves with talentless sycophants…
…you get the point.
I am always amazed that the kind of people who have the ability to either raise themselves to the top position, or start their own company, are often completely incapable of using their enormous influence to an end that has value and meaning. Well, beyond the self–serving kind anyway.
My absolute favourite Demotivator (www.despair.com) is this one;
Like most humour, it’s only funny if it’s at least partially true. Sadly, this is the case for many organisation in terms of leadership in the realm of security.
As I have stated WAY too many times now;
“Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities. If the organisation fails to achieve [enter any goal here], it’s the CEOs fault, and no-one else’s.“
I can think of one very good example in my own experience where the CEO actually took time out of their busy schedule to RUN the PCI assessment every year. Of course she delegates the detail to her team, but she remains the focal point for communication and issues, and gets her hands dirty every day ensuring that her entire company takes security as seriously as she does. The result is that they achieve compliance every year with a minimum of ADDITIONAL effort beyond their business as usual processes.
Unfortunately in this case her chosen consulting company also sold her a bunch of their crappy products that caused never-ending grief, but that’s life.
Despite all of the articles I’ve written on a variety of subjects, I really only have one goal for this blog; to change the perception of what security is, and what it can do for a business.
Security started out on the wrong foot by being lumped in with IT, who were already seen almost as a necessary evil. I guess it’s kinda like Scotty in Star Trek, he has saved their skins a thousand times by “giving ‘er all she’s got” but it’s always Kirk who gets the glory. And yes, I’m very aware I just completely stereotyped myself.
In reality, no other department in an organisation has a better idea of exactly HOW they do business. Every server, laptop, mobile phone (pre-BYOD), database and application is maintained by IT, and all of THAT is under the purview of security whose job it is to make sure it stays available and accurate. But that’s just the beginning, it’s what the security folks can do WITH that knowledge that brings the real benefits (see How Information Security Enables Transformational Change for one such example).
The challenge I face however, is that the benefits will only ever be achieved if the CEO supports it. Nothing happens without them, and seeing as I’m just in security, you can imagine how many CEOs I get in front of.
Still, a goal is a goal.
[If you liked this article, please share! Want more like it, subscribe!]


Well, this CEO is the most competent (with technical, company historical and other knowledge) member of the entire team, truly concerned about the security and company well-being overall. And it shows – in every aspect of company operations, especially during the important times, PCI assessment among them…
Many thanks Inga 🙂