The Roles · Who defends it

Security leader

Written from published sources

The top of the management arm, in security. The framework describes the work as establishing vision and direction for an organisation's cybersecurity operations and resources, with the authority to make decisions that reach the whole organisation, approve policy and engage stakeholders. The ladder below it runs manager, then director, then this — and each rung trades proximity to the work for reach across it.

What the day looks like

  • Setting direction, and holding it while the quarter argues with it.
  • Acquiring resources: budget, headcount, and the authority to require things of teams elsewhere.
  • Approving policy, and owning the consequences when it is applied to a business the policy inconveniences.
  • Advising senior management and the board, in terms of risk to the organisation rather than in terms of technology.
  • Communicating the value of the programme to stakeholders, which is the task the framework names and the one most easily deferred.

What it answers for

  • The organisation's security posture, including the parts owned by teams elsewhere.
  • The programme having a strategy that connects to the organisation's actual risks.
  • What the board is told, and whether it was accurate at the time.

What it is measured on

  • Risk reduction, which resists measurement and is measured anyway.
  • Incidents and their consequences, which are visible and partly outside the role's control.
  • Audit and regulatory outcomes, and programme delivery against plan.

Who it receives from

The operations and response teams
What is happening, at the fidelity the tooling allows.
The business
Where it is going, which decides what has to be protected next.
Regulators, auditors and insurers
Obligations that arrive with dates attached.

Who it serves

The board and executive
Risk expressed in terms they can decide with.
The security teams
Direction, resources, and cover when a decision proves unpopular.
The rest of the organisation
Policy that can be followed by people whose job is something else.

Who else has a stake

  • Customers and the public, whose data the organisation holds.
  • Every team whose work the policy constrains.
  • Insurers, regulators and, after an incident, the courts.

What it takes

  • Technical credibility sufficient to be told the truth by the people who have it.
  • Fluency in risk, budget and the language a board makes decisions in.
  • The composure to be accountable for outcomes produced by systems and people beyond direct control.
  • The judgement to say what the organisation is choosing to accept, and to have it recorded as a choice.

What the job turns on

The role is accountable for an outcome it produces through other people's budgets and other people's priorities. Authority over policy is real and authority over the engineering that implements it usually belongs to somebody else, so the work is persuasion carried out with a mandate. Leaders who last make the risk legible to the people who hold the budget, and record what the organisation decided to accept — because the record is what turns a later incident from a failure of the programme into a consequence of a decision somebody made knowingly.

The published sources

Where it leads

The work itself

The Practice covers how this work is done — triage, escalation, evidence, handover — across the whole corpus.

Read The Practice