How do I push back on the business without becoming the department of no?

To avoid being perceived as the "department of no," security practitioners must reframe their role as risk advisors and business enablers. This involves articulating security concerns in terms of business risk, proposing alternative solutions, and fostering collaborative dialogue. By aligning security objectives with organisational goals and demonstrating a clear understanding of business priorities, security can become a trusted partner rather than a barrier, facilitating secure innovation and operational resilience.

Effective pushback requires understanding the business objective behind a request and translating security implications into tangible business risks. Instead of an outright refusal, present the identified risks, such as potential financial loss, reputational damage, or regulatory non-compliance, using language the business understands. Propose alternative approaches or compensating controls that achieve the business goal while mitigating the security risk to an acceptable level. This consultative approach demonstrates a commitment to enabling the business securely, aligning with ISO 27001's emphasis on managing information security risks in the context of the organisation's objectives.

A common pitfall is to focus solely on technical vulnerabilities without explaining their business impact. Practitioners should avoid absolute "no" responses and instead offer a range of options, detailing the risk profile associated with each. Continuous engagement and education are crucial; regularly communicate the value of information security, not just its costs or restrictions. This fosters a culture where security is integrated into decision-making, rather than being an afterthought. Establishing clear communication channels and defining roles and responsibilities for information security helps ensure that security advice is heard and considered within the broader organisational context.

Sources

  • ISO 27001:2022, Clause 6.1 (Actions to address risks and opportunities)
  • ISO 27001:2022, Clause 7.4 (Communication)
  • ISO 27001:2022, Annex A.5.1 (Organisational roles, responsibilities and authorities)

Related