Cybersecurity is not one-size-fits-all and is dependent on the type of organization and the level of risk the organization is willing to accept, says Eric Cole, fellow and cyber defense lead at the SANS Institute. The board of directors, led by the CEO, should lead collaboration and security awareness across the enterprise, says Steve Durbin, managing director at the Information Security Forum. When the board is in sync with the efforts of information security teams, policies are developed and assets prioritized to be secured.”]