← All insights

Security is an organisational capability

Resilience depends on the way leaders connect risk decisions, technical controls, people, and operating responsibilities.

Security requires an organisation that can make and carry out sound risk decisions. Controls matter, but their effectiveness depends on ownership, skills, coordination, and the ability to respond when conditions change.

The NIST Cybersecurity Framework 2.0 places governance alongside identifying, protecting, detecting, responding, and recovering. This supports an enterprise view of security: leadership sets the conditions under which technical and operational work can protect the business. (NIST source)

Design the responsibilities around the work

Begin with the services and information that matter to the organisation. Identify who owns their business use, who designs and operates the supporting systems, who tests the controls, and who can authorise a response.

These responsibilities may sit in several teams. The design challenge is to make their interaction clear. A development team needs timely security advice. A security team needs visibility of business priorities and upcoming changes. Operating teams need a practical route for reporting concerns and resolving exceptions.

Build capability before multiplying titles

New job titles can clarify a growing area of work, but a title alone does not create the capability. Define the decisions, skills, relationships, and authority the role requires. Then assess whether those responsibilities can be supported at the organisation’s size and level of risk.

For an illustrative midsize business, the immediate need may be a clear service owner, access-review discipline, and a tested escalation arrangement. A complex structure that the business cannot staff or sustain may add ambiguity rather than protection.

Make risk visible to leadership

Leaders need a view of risk that connects technical findings to business consequences. Explain what could be affected, what is being done, who owns the remaining decision, and when it will be reviewed. Track whether improvements work in practice.

Enterprise architecture helps by showing how services, information, systems, and third parties depend on one another. That perspective supports security decisions across the full operating environment.

A resilient organisation develops both technical protection and the capacity to act. Security leadership should strengthen that connection through clear responsibilities, practiced response, and continuous learning.

Revised from my original essay on The Loop. This edition develops the argument for a leadership audience; the original preserves its coursework context and bibliography.

Original article: The Loop, 23 October 2025.

Bring this topic to your team or event. Connect with David.