Cybersecurity is a risk management discipline at its core. Most cybersecurity programs have focused very little on addressing business risk management. CIOs must be aware of these issues and understand the plans and programs to address the issues so they can properly represent and support these initiatives across the organizations broader IT investments. A recent study by the Deason Institute for Cyber Security at Southern Methodist University in Dallas, Texas, sponsored by IBM, outlined some best practices for accomplishing this goal. It is crucial for organizations to shift their cybersecurity programs towards a. risk management focus.”]
Source: https://securityintelligence.com/questions-every-cio-ask-cybersecurity-leader-part-1/

