THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


FROM QUALITATIVE MATRICES TO FINANCIAL REALITY
Nick Bellette
Early in my career, I relied heavily on qualitative risk matrices. Over time, I realised that approach rarely holds up at the executive or board level. Ultimately, decisions are driven by financial impact. If you can’t articulate risk in terms of value at risk, securing investment becomes difficult, and even putting a value on information assets can be a challenge.
That shift has shaped my approach. Security decisions need to align to business and customer outcomes. Risks should be clearly understood, quantified where possible, and managed in a way that enables growth rather than restricts it.
In practice, most organisations are trying to improve, but results are mixed. Some become over-governed and slow down delivery. Others struggle to secure funding because their risk narrative doesn’t resonate with leadership. Many are better at demonstrating due care than meaningfully improving their security posture, and some are still meeting baseline expectations without reducing risk in a meaningful way.
THE GROWING GAP BETWEEN COMPLIANCE AND REAL SECURITY
One of the clearest trends that is transforming cybersecurity, privacy and enterprise risk strategies is the growing gap between compliance and real security outcomes. Compliance does not equal security, yet many organisations still treat it as the goal. Recent high-profile breaches show that many affected organisations were highly compliant on paper, yet still vulnerable in practice.
Compliance plays a critical role in maintaining trust and accountability, but it should be treated as a baseline, not a proxy for effective security.
Artificial intelligence is also reshaping the landscape. It is improving defensive capability through automation, but its more immediate impact is increasing both noise and risk. Automated vulnerability discovery and exploitation are raising the baseline threat level across the board.
At the same time, the proliferation of frameworks such as SOC 2, CPS 234, NIST, and ISO is driving the need for unified control environments. Managing each framework in isolation is no longer practical.
"Compliance Plays A Critical Role In Maintaining Trust And Accountability, But It Should Be Treated As A Baseline, Not A Proxy For Effective Security."
Tooling remains a challenge. Too many tools increase complexity, expand required skill sets, and introduce additional points of failure. There is a constant tension between consolidation and maintaining best-of-breed capability.
While tooling continues to evolve, detection itself feels largely unchanged. It has become more operationally intensive, but not necessarily more effective.
FROM CONTROLS TO CULTURE TO CAREER
Security should enable the business, not restrict it. That requires applying risk management pragmatically, not enforcing controls for their own sake. Risks need to be clearly documented, understood, and, where appropriate,deliberately accepted within defined authority and appetite. This allows the business to move at pace within an accepted risk profile.
The goal is to act in the best interests of both the business and its customers. Security decisions should support growth and trust, not create unnecessary friction. Overly rigid controls can be just as damaging as weak ones if they prevent the organisation from achieving its objectives.
Building that kind of enabling security culture, however, requires more than the right controls. There is no single method that works for everyone. Fear, incentives, and making things easy can all be effective, but only in the right context. People respond differently, and leadership requires adapting your approach. The biggest mistake is relying too heavily on one method of influence. Building a strong security culture requires flexibility and a clear understanding of human behaviour.
For professionals looking to build a career in this space, the same principles apply. The biggest differentiator is business focus. Security exists to support the organisation, not operate in isolation. Technical depth remains important, particularly in smaller teams. However, business understanding and the ability to communicate risk are what separate those who move into leadership roles.
If you want to progress, focus on influence. The ability to engage executives, align security with business goals, and drive change will have more impact than any specific tool or certification. The people who succeed are those who can translate complex risk into clear business decisions.