The CIO Professional Network gathered for a Roundtable discussion led by Paul Zyla on how technology organizations can strengthen cybersecurity by improving leadership, governance, accountability, and trust.
He invited members to consider the leadership conditions that determine whether an organization remains reactive or develops a more durable approach to risk. Attendees, in turn, discussed what earns technology teams credibility with business leaders, why security work often encounters resistance, and how unclear authority can delay decisions or encourage teams to bypass established processes.
The conversation made the case that stronger cybersecurity begins when leaders establish responsibility and create governance that helps people act with greater confidence.
Why It Matters: Many companies have invested heavily in cybersecurity and still find themselves responding to the same recurring problems. While these new tools may improve individual controls, they cannot resolve weaknesses in organizational leadership. The session’s message was that cybersecurity should be treated as an enterprise capability. When leaders make accountability visible and connect security decisions to business performance, cybersecurity becomes less likely to be viewed as a technical obstacle.
- Technology Leaders Earn Influence Through Business Participation: Members discussed how proactive organizations include technology leadership in important business discussions. When IT is absent, teams often learn about strategic decisions only after commitments have been made, leaving them to manage the consequences. One attendee cautioned that executive access must be continually justified through useful contributions and steady engagement. The group connected that credibility to the time technology leaders spend building relationships across the company. Those conversations give IT a clearer understanding of organizational goals and help business partners recognize that questions about an initiative are not automatically attempts to stop it.
- Security Becomes Relevant When It Is Connected to Business Exposure: Leaders emphasized that security teams lose their audience when they rely too heavily on specialized language. A discussion about controls or vulnerabilities carries more weight when it explains the broader consequences for the company. Participants described connecting security work to customer trust, particularly when serving large global organizations. A member recommended helping leaders understand the significance of a risk rather than forcing every investment into a traditional financial calculation. That approach gives the appropriate business owner enough context to determine how the organization should respond.
- External Expectations Are Raising the Standard for Cybersecurity: Some described external criticism as a force changing executive priorities. Companies may lose business opportunities or face higher insurance costs when they cannot demonstrate that appropriate controls are operating. Members added that measurable security performance can directly affect insurance renewals and draw greater attention from financial leadership. It was also suggested that many practices currently viewed as advanced will eventually become basic conditions for participating in the market.
- Less Friction When Entering the Work Earlier: One attendee described how long cybersecurity backlogs can place application teams in conflict with business deadlines. When the response is an extended delay, project owners may seek exceptions or find another route around the process. That behavior was linked to shadow IT and argued that security should be represented at the start of a project rather than shortly before launch. Members explained how application security testing can become part of the development lifecycle so problems emerge while code is still being created. Incorporating security into established workflows may require an adjustment period, but it reduces the likelihood that cybersecurity becomes a late-stage barrier.
- Governance Gives the Organization a Clear Way to Move Forward: Attendees considered why capable organizations still fall into reactive patterns, ultimately identifying a lack of decision clarity as a primary cause. Governance addresses that problem by establishing ownership and authority before an issue becomes urgent. It was noted that companies frequently recognize the need for governance but do not give its development enough attention. One leader added that slow decisions can make priorities appear unstable because teams receive inconsistent direction while waiting for an answer. A functioning governance model reduces those delays and keeps the same questions from being reopened throughout the work.
- Security Requires Visible Support Beyond the Technology Function: The group also described the need for senior leaders across the company to reinforce security expectations. Members agreed that executive advocacy is essential because employees respond differently when the message comes from business leadership. An attendee summarized the challenge by noting that technology teams cannot remain the only messengers. When cybersecurity is communicated exclusively by IT or the CISO, employees may continue treating it as a departmental concern. Visible sponsorship signals that managing risk is part of how the organization expects everyone to operate.
- Operational Discipline Creates More Value Than Tools or Checklists Alone: Members warned that a compliance checklist can satisfy an assessment without changing organizational behavior. It was shared how recognized security standards gave one attendee’s company a common direction for previously disconnected efforts. The frameworks helped employees understand the purpose of the work and gave leaders measurable evidence of progress. The group explained that compliance establishes a baseline, while governance turns it into accountability and trust. Without sound operating practices, new technology may only add complexity.
Go Deeper – Reducing Cybersecurity Risk Through Better Leadership (VIDEO) – CION Roundtable


