Cybersecurity conversations often begin in technology:
- tools,
- controls,
- frameworks,
- audit findings.
Yet cybersecurity failures rarely occur because of missing technology.
They occur because of:
- unclear ownership,
- misaligned priorities,
- funding that isn’t tied to business impact.
Most post-incident reviews don’t reveal a technical flaw.
They reveal a decision flaw.
Cyber risk is not merely a technical challenge.
It’s a prioritization, alignment, and leadership challenge.
Cyber needs a strategic front end — not more tactical urgency
Technical security leaders (vCISOs, engineers, security operations) are indispensable.
They excel at:
- architecture,
- assessment,
- implementation,
- incident response.
But expecting them to also:
- build cross-functional alignment,
- drive prioritization,
- gain executive support for funding,
places them in a role without authority over business tradeoffs.
That isn’t a capability problem.
It’s a structural problem.
Boards already have the right operating model — just not applied to cyber
When facing decisions like:
- entering a new market,
- restructuring operations,
- M&A integration,
boards start with strategy, not execution.
They use the firms they trust for sequencing and clarity:
McKinsey, Bain, BCG, or similar partners.
These firms explicitly frame cybersecurity as strategic:
McKinsey & Company:
“Executives must treat cybersecurity as a strategic business issue, not only as a technology problem.”
— McKinsey Global Cybersecurity Report
Bain & Company:
“Cybersecurity is now a strategic issue that requires engagement at the most senior levels.”
— Why Cybersecurity Is a Strategic Issue (Bain Brief)
BCG (Boston Consulting Group):
“The role of the board in cybersecurity is oversight of business risk, not technical risk.”
— BCG on Board Cyber Oversight
Boards don’t need to learn the technology.
They need a model that connects cyber decisions to business decisions.
The model that works:
Strategy leads. Technical executes.
Front End — Strategy / Business / Board
- Align on the few cybersecurity priorities that matter most
- Tie decisions to revenue, risk, and customer impact
- Sequence and fund in alignment with business goals
Back End — vCISO / Security / Technical Teams
- Assess controls
- Implement solutions
- Manage operations
This model doesn’t replace the vCISO or the technical teams.
It enables them.
Why this resonates with boards
Directly from board surveys:
“Our greatest cyber challenge isn’t knowing what to do — it’s aligning the organization to do it.”
— NACD (National Association of Corporate Directors) survey
“Boards struggle to understand the business impact of cyber decisions, not the technology.”
— Gartner Board Cybersecurity Research
“Cybersecurity must be discussed in terms of business outcomes, not maturity scores.”
— Deloitte Board Governance Center
Boards don’t need more cyber detail.
They need:
- prioritization,
- alignment,
- and a clear business case for funding.
Ken’s Take
Cybersecurity isn’t lagging because of insufficient tools, time, or effort.
It’s lagging because cybersecurity is often approached as a technical effort instead of a strategic business priority.
Strategic problems require strategic leadership.
Technical teams excel when the business is aligned.
Stop asking technical teams to solve strategic problems.
Start giving them a strategic structure to succeed.

