Explore · note

How Do Security Leaders Learn to Talk Business? An Open Question

Published 26 Sep, 2026 · question

Security leaders lose decisions when they report on controls instead of choices. A question-stage note: why I think the translation fails, what the SEC's 2023 rule implies about who carries it, and a way to start practising this week.

How Do Security Leaders Learn to Talk Business? An Open Question

I keep seeing the same thing happen in budget and board conversations. A security leader walks in with a solid program and walks out with polite nods and no decision. The work was fine. The language wasn’t.

My working view: the translation fails because we report on controls, executives decide on outcomes, and almost nobody teaches security people how to get from one to the other. When that gap stays open, the remediation team’s budget gets pushed back, the security leader loses standing with the board, and the business ends up carrying risk it never knowingly chose.

I’m building a communication model for how security framing should change as a program matures. This note is the question underneath that model. It isn’t a method yet — just one sourced anchor, a hypothesis, and what I haven’t worked out.

The board won’t learn our language

When the SEC adopted its 2023 cybersecurity disclosure rules, it required public companies to describe how the board oversees cybersecurity risk, and what role management plays in handling it. The SEC also dropped a proposed requirement to disclose directors’ cybersecurity expertise. Its reasoning was that directors with broad risk and strategy skills can oversee this well without deep subject knowledge (final rule, Release 33-11216).

My read, and this is interpretation rather than the SEC’s words, is that the job of translating falls to the security leader. Whether the rule applies to your organization is a question for your own counsel. The point about who does the translating holds either way.

Controls aren’t decisions

A control gap is a place where a safeguard you expect to have is missing or not working. It’s a fact about the program. An executive can’t act on it until someone turns it into a choice.

Here are two illustrations. They aren’t scripts:

Technical framingBusiness framing
“We have unpatched critical vulnerabilities on internet-facing systems.”“A customer-facing service has a known weakness. Fixing it costs a weekend maintenance window. Not fixing it means accepting a chance of outage or breach on that service. Which do we choose?”
“Our logging coverage has gaps.”“If something goes wrong in these systems, we can’t say what happened or prove what didn’t. That slows recovery and limits what we can tell customers and regulators.”

The right-hand column has a shape: what’s exposed, what acting costs, what not acting risks, and who owns the call.

Why I think nobody teaches this

This part is a hypothesis. In the security careers I’ve watched, people get promoted for technical depth. The best analyst becomes the lead, and the best lead becomes the manager. Business translation becomes part of the job just when they’ve had the least practice at it. I haven’t seen training that closes this gap. I also haven’t looked hard enough to say none exists.

What I haven’t worked out

  • Technique or exposure? Can this be taught as a technique, or do people mostly pick it up by spending time in rooms where business decisions get made?
  • Maturity. How should the framing change as a program matures? That’s what the model I’m building is meant to answer, and it isn’t ready.
  • Dollar figures. Some executives want one. In environments I’ve seen, a shaky number costs more credibility than no number. Where that line falls depends on your business and your audience.

If you’ve found a way to teach this, tell me. I’d rather be corrected than confident.

Where to start

Good (this week): Take one item from your last leadership update and rewrite it as a decision: what’s exposed, what acting costs, what not acting risks, and who decides.

Better (this quarter): Before your next board or budget meeting, ask a peer outside security to read your material and name the decision they think you’re asking for. If they can’t name one, you’ve found the gap.

Best (this half): Keep a log of which framings got a decision and which got a follow-up question. Over time, that log becomes a translation guide tuned to your own leadership.

For a worked case of framing security for executive buy-in, see 4 Essentials for Executive & Business Buyin on your Incident Response Plan and Top 5 things for a Successful Cyber Response ‘IR’ Plan.


David O’Neil is a CISO who builds things and writes about what works in the field, including the unfinished problem of turning security risk into decisions leadership can act on.

board communication · security operating model

What would move this forward

question working theory (0 of 4 met)

  • Three to five of David's own technical-to-business translations he has used, described generically (open)

  • A stated thesis on why the translation fails, such as speaking about controls instead of decisions or loss (open)

  • An explicit tie to the Mountain Maturity Communication Model showing where each translation fits (open)

  • A way for readers to practise the translation (open)