CISOs urged to speak the language of business, not security
Cybersecurity is most effective when it's aligned with business strategy and executive priorities. This ITWeb article explores why today's security leaders must communicate risk in business terms to build stronger organizational support and resilience. Connect with Swerve Limited to discuss how these trends may influence your organization's technology strategy.
Why should CISOs talk about business risk instead of security tools?
CISOs are being asked to rethink how they position cyber security in boardroom conversations. Instead of leading with tools, platforms and technical detail, boards want to understand:
- Business risk – What could a cyber incident cost in terms of revenue, operations and reputation?
- Customer trust – How does security protect customer data and confidence?
- Regulatory compliance – What are the legal and regulatory implications if something goes wrong?
- Operational resilience – How quickly can the organisation recover and continue delivering services?
As one executive put it, “The cost of prevention is nothing compared to the cost of a breach and recovery.” When CISOs frame requests as “funding for a technology refresh”, they often compete with revenue-generating projects. When they frame the same request as risk reduction, resilience and protection of core services, it becomes a strategic business discussion rather than a technical one.
In practice, this means shifting from “we need this tool” to “here’s how this investment reduces downtime, protects customer trust and supports our growth strategy.”
How are organisations building cyber resilience, not just prevention?
Many organisations are starting to reimagine cyber security as a resilience capability, not just a defensive one. A few practical shifts are emerging:
- Treating cyber like health and safety: At Transnet, for example, a major cyber attack in 2021 disrupted port operations and exposed the broader economic impact of cyber incidents. Since then, cyber security is treated much like occupational health and safety – everyone has a role to play, not just the IT team.
- Investing in people and processes: Beyond technology, organisations are putting money into skills development, awareness programmes and continuous testing of security controls.
- Focusing on recovery as much as defence: Leaders acknowledge that not every attack can be stopped. The priority is to recover quickly and keep delivering on the organisation’s mandate.
- Running cross-functional simulations: Incident simulations now often include executives and board members, not just technical teams. This helps clarify roles for the board, leadership and communications teams when a crisis hits.
- Sharing information across the sector: Especially in financial services, there is a growing view that “there is no competitive advantage in cyber security.” Information-sharing is seen as essential because a breach at one organisation can trigger sector-wide concern.
The underlying mindset shift is from “can we stop every attack?” to “how prepared are we to respond and recover when it happens?”
What does AI change about cyber risk and governance?
AI is starting to reshape both business operations and the cyber threat landscape, and boards are asking CISOs to guide them through this change. Several themes are emerging:
- CISO as change leader: Modern CISOs are expected to help the business balance AI’s benefits with its risks, not simply block new tools.
- Risk reduction on investment: Alongside traditional ROI, some leaders talk about “risk reduction on investment” – how AI initiatives can be designed and governed to reduce, not increase, exposure.
- Governance before scale: There is concern about employees experimenting with freely available AI platforms without understanding how their data is used. The reminder is simple: if a tool is free, you need to ask what the trade-off is.
- Data governance and clear policies: Organisations are putting emphasis on strong data governance, clear usage policies and approved AI platforms so teams can innovate safely.
For boards, the AI conversation is becoming less about the technology itself and more about how AI fits into overall risk management: protecting sensitive information, maintaining compliance and ensuring that new AI-driven services are secure by design.
.jpg)
CISOs urged to speak the language of business, not security
published by Swerve Limited
Swerve is a responsive, 100% Kiwi-owned technology business. We are headquartered in Auckland and service clients across New Zealand.
Our customers are diverse, from the engineering firms that build the infrastructure of the nation, to the Hobbiton team in Middle-earth that warm the hearts of countless international (and local) visitors.
No matter their business, each client enjoys big team capability, delivered with small team agility - and the simplicity of one responsive IT partner for everything.
We believe IT matters
Our purpose: To put people at the heart of technology, as we design, deliver, and support exceptional IT experiences that keep business humming.
Swerve was founded in 1999 and for over 25 years we've taken care of technology because we know IT matters.
IT matters because it powers the engine rooms of the Kiwi economy. Businesses like yours, that is.
IT matters because it protects IP, data, and the lifeblood of livelihoods in an age of sophisticated cyber crime. IT matters for productivity, for communication, for healthy communities, and for everything that keeps New Zealand humming in a digital world.