The Reason Business Doesn’t Take InfoSec Seriously



I saw a thread recently where someone was complaining about Dave Kennedy making a hilarious inside joke on CNN without any of the participants knowing. Evidently people on Twitter said this is why InfoSec isn’t taken seriously.



Then someone else showed up with this reply, which prompted my response.



The reason infosec is not taken seriously is because we can’t map risk to money.

Until then we’re scary magicians with attitudes.

— ᴅᴀɴɪᴇʟ ᴍɪᴇssʟᴇʀ (@DanielMiessler) October 8, 2017


The reason information security is not taken seriously by the board room and other senior executives is because we cannot translate risk into financial terms.



Yes, being hacked is being taken seriously. And they’re certainly ready to throw some money at the problem in order to fix it (or look like they’re trying). But this isn’t the same thing as respect.



Most industries are about to talk about ROI. Sales, marketing, etc. You have a certain amount of spend, and you get a certain amount of return.



That’s missing in information security, and until that changes we’re going to be considered dirty mages with arcane powers.



They’ll keep us around, of course, but we don’t get to eat with them. Our kids can’t date their kids. Etc. It’s not real business because it’s not based on arithmetic.



So, yeah, we have a bad reputation for being mischievous and such, but that’s not what’s hurting us. Our real obstacle is our inability to have adult conversations about return on investment.



Until then we get to eat at the kids table.


_


If you enjoyed this, you can explore my other content, subscribe to my newsletter, and/or show support for my work.

 •  0 comments  •  flag
Share on Twitter
Published on October 08, 2017 20:03
No comments have been added yet.


Daniel Miessler's Blog

Daniel Miessler
Daniel Miessler isn't a Goodreads Author (yet), but they do have a blog, so here are some recent posts imported from their feed.
Follow Daniel Miessler's blog with rss.