Risk Management as coaching
Let’s first understand the game that we are playing. In the company, we have the CIO and CISO, who are playing to win. This means delivering new value to the company and protecting the enterprise from cyber and technology disruption.
Figure 11.2 – CIO and CISO as the players
The CIO and the CISO are indeed in the game. They are players playing to win and have the right to make decisions at each moment in terms of where to pass and how to attack and defend. Their roles are hard and tiring, and they must take fast action to keep up with the crowd’s demands. Should the team not win, then there is pressure from management to fire these players.
In the crowd, we have spectators. They are watching the game from a distance and cheering or booing. The spectators feel that they are playing the game but are not allowed on the field. They often will critique the game and provide feedback on what they don’...