iso27diy-corp/marketing/publications/posts/s01p02en - All security risks start with a decision.md

2.4 KiB
Raw Blame History

title language proposition series-id series-title series-part audience channels linkedin-account content-type status publish-dates published-urls notetype isotags tags
All security risks start with a decision en advisory s01 Security as an organisational challenge 2
leadership
linkedin
personal
post
published
linkedin
2026-05-14T17:15:00Z
linkedin
https://www.linkedin.com/posts/richardkranendonk_managingsecurity-activity-7460739462822592512-sZ68
publication

Posted on 14 May 2026 19:15 CEST to LinkedIn personal stream

All security risks start with a decision

Most information security risks don't start with a technical problem. They start with someone making a choice.

The HR department gets the green light for implementing new software, without getting confirmation of the state of information security at the vendor's side. The employee deciding to use his private mail account with an online file conversion tool. The employee given access rights while they haven't been formally defined yet for her new function. The project that started without identifying the owner of the new data source.

This is the blind spot of information security: daily decisions in organizations that are in constant flux, taken by employees that are not aware of the risks they are introducing.

The most secure organizations are those, where leadership realizes that every decision touches on security, and you can't make information security the exclusive responsibility of IT.

Strong security is achieved by integrating risk assessments in decision making, and integrating business processes and IT processes. Expensive tools and complex implementations are not required.

Do you want some examples? Here are four simple initiatives:

  1. Create a standard information security questionnaire for Purchasing, to hand out to any proposed vendor.
  2. Have HR check with IT on access rights when they're writing the new job profile not when the new employee enters the door.
  3. Make risk analysis a mandatory part of each project plan.
  4. Debrief leaving employees on the tools they actually used and take proper care of transferring accounts and information.

Don't just ask the question: "How will we make this a success?", but also ask: "How do we prevent things going wrong, and who owns that?"

— Security as an organizational challenge — post 2/3

#managingsecurity