A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Semler Gruppen A/S

Stakeholder Management & Alignment with Business Needs

Tom John F. Jensen

Through this article, Tom John F. Jensen emphasises the critical need for stakeholder alignment in cybersecurity and organisational compliance initiatives. He discusses the challenges of securing buy-in for projects protecting an organisation’s existence and articulating a clear value proposition. Jensen highlights the necessity of defining success criteria and maintaining operational stability while adapting to future technological changes.

Stakeholder Management & Alignment with Business Needs

In an increasingly digital world, where businesses are progressively operating in online environments, it is ever more crucial to integrate and align business developments with security & compliance efforts to achieve lasting beneficial outcomes.

Value Proposition

While the statement might seem obvious, most compliance & security professionals today lack proper stakeholder buy-in for initiatives that ultimately safeguard an organisation’s continual existence. Such initiatives are often only an afterthought or deemed a ‘necessary evil’ by most stakeholders, as it remains challenging to correlate direct value between the initiative and the bottom line. The issue, or culprit, is usually found in the value proposition or the lack of such a proposition when organising a compliance & security project. Unfortunately, many professionals in this field focus entirely on solving the problem, such as mitigating the risk, closing the gap, or reaching a certain maturity/resilience level. The consequence of such an approach is usually found in the longevity of the project's effort, as it will suffer over time without the proper buy-in and understanding from key stakeholders.

This speaks to the importance of building a business case, identifying the why, the who and the how. Without ascertaining the fundamentals, any subsequent communication to stakeholders and the project’s metrics for success will ultimately have limited value. This is in particular because most stakeholders need help understanding their own needs regarding compliance & security. Without the necessary understanding, the value proposition might still be bought into, but at a cost, which inevitably will be a mismatch between stakeholder expectations for project goals, cost/benefit, realised value, etc.

Alignment

Obtaining alignment and a mutual opinion on the success of a compliance or security project can be a daunting task. Nevertheless, we must strive for it when planning the project. Without alignment, it will become increasingly difficult to maintain ‘the burning platform’, affecting project funding, resources, priority, etc.

Cyber Security Review Europe

The necessary alignment is best achieved with various actions, as there is no ‘right’ approach that universally works for all organisations. Instead, the approach should structure the value proposition and the underlying business case in a language that stakeholders can understand. The same goes for identifying and highlighting potential operational and commercial areas that stand to benefit from the initiative. This is often neglected in such projects, even though optimisations can regularly be found when operational procedures are revisited and reviewed. Finally, adding an unbiased third-party opinion to substantiate the criticality of the project and making proper comparisons to illustrate the gaps make a project far more tangible to laypeople.

SUCCESS

A project’s success criteria should always be predefined and, if possible, be in measurable metrics to gauge the quality of the project’s outcome. However, when working with compliance and security, success with an individual project can be misinterpreted by stakeholders, who may believe that no more effort, resources, or improvements will be needed for the entire area. It is, therefore, of the utmost importance that the long-term mutual definition of success is understood to be continual and lasting operational stability while using the optimal amount of resources to achieve it, impacting operational agility the least and ensuring compatibility with tomorrow's technologies.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top