Strictly Business: Why Security Is Always a Risk Management Function

No ratings

Presented at BSides Toronto 2026 by

Cybersecurity is always and everywhere a risk management function. NIST CSF, ISO 27001, PCI DSS, C2M2, ATT&CK; the frameworks and methodologies are many. Professional associations publish competing Bodies of Knowledge. Colleges and universities offer an expanding array of diplomas and degrees. Everyone has an answer to how we should do cybersecurity. But step back and ask a simpler question: what are we actually trying to accomplish? It's easy to lose sight of this. We get absorbed in achieving compliance, implementing the architecture du jour, or chasing the latest threat intelligence. We optimize for framework alignment rather than outcomes. We confuse the map for the territory. Author and practitioner Rick Howard offers a clarifying formulation: the purpose of cybersecurity is to reduce the probability of a material cyber event in the next business cycle. This talk traces that thread across the profession. We start with risk itself, not as an abstract concept but as the fundamental tradeoff that underpins every security decision. We examine what higher education is teaching the next generation of practitioners and what the major Bodies of Knowledge say we should master. We dissect several popular frameworks, many of which explicitly call for a risk-based approach yet are routinely implemented as compliance checklists. We close by reconceptualizing the multifaceted practice that is cybersecurity through the focusing lens of risk.