Speakers
Matthew Helling, CEO at Arco Cyber
Jake Upfield, Head of Solutions Advisory – Cyber Security at Cybit Ltd
Introduction
This blog is based on a recent webinar hosted by Executive Leaders Network (ELN) and Cybit Ltd, focusing on the business value of cyber security investments. In the session, the hosts examined how boards, CFOs and CISOs can align cyber strategies with long-term enterprise goals. The conversation aimed to move beyond traditional compliance-driven thinking and explore how organisations can measure cyber effectiveness in ways that reflect their unique operational needs.
Rethinking Cyber Investment
Over the past decade, both cyber crime and cyber investment have risen dramatically. Yet despite this, actual risk reduction has not kept pace. Boards are increasingly aware of the threats but lack clarity on what constitutes sufficient protection and how to measure whether their investments are working. A key issue is the assumption that increased spending automatically leads to better outcomes. This is often not the case. Every business is unique and requires a tailored approach that prioritises outcomes over tools.
Compliance Does Not Equal Security
Compliance frameworks such as ISO and NIST provide important structure, but they are not guarantees of cyber resilience. Many organisations treat them as checklists or sales enablers without validating whether the implemented controls are effective. Compliance can help demonstrate maturity but cannot substitute for data-driven insights that link control performance to business outcomes. Businesses must go further than green ticks to ensure their environments are genuinely protected.
Cyber as a Business Function
The success of a cyber programme should be measured not by technical outputs but by business value. This requires a shift in how organisations view cyber risk. It is not just an IT issue but a matter of enterprise value protection. Boards need to understand cyber as they do finance, growth and brand management. This means moving away from technical language and towards a model where cyber health is reported clearly, regularly and in terms that relate to business impact.
Building Measurable Cyber Programmes
Organisations must establish a clear understanding of:
-
The assets and users in their environment
-
Their vulnerability exposure
-
The controls in place and their true effectiveness
-
Any overlaps, gaps or blind spots in protection
With this foundation, it becomes possible to monitor performance metrics and track improvement. This is not only useful for internal assurance but is also vital for engaging external stakeholders such as partners, insurers or regulators.
The Compliance vs Value Tension
Many businesses spend a significant portion of their cyber budget on achieving certifications or meeting framework standards. While these efforts support business valuation and supply chain access, they can drain funds away from operational protections. This tension must be addressed through more sophisticated prioritisation and reporting. Compliance-related spend should be recognised as a business investment, not buried in the cyber budget. Aligning cyber programmes to revenue, growth and M&A strategies ensures better business impact.
Cyber Insurance and Operational Gaps
The cyber insurance market has matured rapidly. While it was once possible to obtain cover with little scrutiny, insurers now demand proof of protective measures such as data loss prevention, endpoint detection and multi-factor authentication. Insurance is no longer simply about risk transfer. In many cases, organisations maintain policies primarily to avoid reputational damage or perceptions of negligence. The value of insurance is significantly enhanced when paired with data and evidence that controls are functioning as expected.
Incident response and continuity planning must also evolve. In many organisations, these are under-resourced or untested. When incidents occur, confidence and control in the response process are often more important than the severity of the incident itself. Businesses must ensure their people know what to do, how to act and how to communicate when systems are compromised.
Recognising Every Business is a Target
The cyber threat landscape has changed. Attackers no longer need deep technical skills to mount attacks. Tools and AI-enabled services are readily available. While large enterprises remain high-value targets, smaller businesses are increasingly vulnerable, especially those in the supply chain or those with niche specialisations. Risk assessment should be driven by the specifics of the business, its operations and its industry, not a generic sense of threat. Every company must profile its own risk and align its protections accordingly.
Key Takeaways
-
Increased cyber spend does not guarantee reduced risk. Control performance and alignment to business goals matter more
-
Compliance frameworks provide structure but are not a substitute for data-driven insight into control effectiveness
-
Cyber programmes should be aligned to business strategy and enterprise value, not just technical metrics
-
Boards require regular, clear and business-relevant reporting on cyber risk
-
Cyber insurance is most valuable when paired with strong internal controls and verified performance data
-
Incident response must be proactive, tested and communicated across the business
-
Every organisation is a potential target regardless of size or industry
Q&A
Q1: Is the CISO responsible for fixing all vulnerabilities?
No. The CISO is responsible for identifying and prioritising vulnerabilities based on the business's risk profile. Remediation is typically delivered by operational teams but accountability for strategic oversight remains with the CISO.
Q2: Is compliance enough to ensure cyber resilience?
No. Compliance provides a framework but does not measure the effectiveness of controls. Organisations need insight into how those controls perform and whether they truly reduce risk.
Q3: How should boards view cyber insurance?
Cyber insurance should be part of an overall risk strategy. Its value increases when the organisation can demonstrate strong internal controls and preparedness. It should not be seen as a substitute for security maturity.
Q4: Which types of companies are at risk?
All companies are potential targets. While financial services, retail and manufacturing remain high-value targets, attackers also target SMEs and supply chains. Risk should be profiled based on business model and industry threats.
Q5: What metrics should CISOs report to the board?
CISOs should report control effectiveness metrics, cyber health scores, and risk exposure in business terms. These metrics should be tracked over time and mapped to business value, not just technical performance.
Final Thoughts
Cyber security must evolve from a reactive, compliance-led function to a strategic, measurable business enabler. This means moving away from manual processes and towards continuous insight. Cyber decisions should be based on outcomes, not assumptions. Boards and CISOs must collaborate closely to ensure that investments reduce risk, protect value and support growth. This is no longer just an IT concern but a matter of enterprise protection and long-term viability.
Watch the On-Demand Webinar
To watch the full webinar replay, visit the on-demand page here: Watch the Webinar
#CyberSecurity #RiskManagement #CISOGuidance #CyberInvestment #BusinessContinuity #CyberResilience #ComplianceFrameworks #CyberInsurance #EnterpriseValue #IncidentResponse #DigitalRisk
Recent Articles
The Demand to Change the Accounting Profession
BlackLine - August 22, 2023
Unstructured Data: The Next Frontier
Insights from Kyle DuPont, CEO - Ohalo