Think about cyber in business terms for a second. A description
of a cyber security program without a clear statement of program gaps is like a
balance sheet without a liabilities statement.
And yet, somehow, gaps seem to be an often minimized part of our
conversations with executives.
Perhaps as cyber leaders, we choose to avoid hard
conversations about program gaps because we want to be positive. Maybe we
avoid them because we have some level of fear of executive reaction to hearing
about gaps in the cyber security program in the context of past investments.