Businesses run on various processes, with variable inputs and outputs, leveraging a multitude of tools and a team working toward a common goal. Cybersecurity, however, is often laid out separately from these processes. As a governing body that strives to keep the bad guys out through various security controls, we have started leveraging new tools, methodologies, and information to add context to cybersecurity events. Has it helped? At the end of the day, are new Cybersecurity initiatives bringing value to the business? Do we know enough about our organization’s business objectives? Is the new context we are adding to our threat alerts the correct context? Maybe it’s time for a new strategy… Steve will provide some insight based on issues he has seen, and propose a new strategy to help gain traction with Cybersecurity by putting the business first.