Cybersecurity failures are often described as technology failures.
Sometimes they are.
A missing patch mattered. A compromised credential mattered. A weak control mattered. A flawed configuration mattered. A delayed detection mattered.
But many of the most consequential cybersecurity failures are not merely technical failures. They are leadership, governance, and management failures.
For years, I have argued that the cyber failure cycle has three root causes: risk illiteracy, insufficient accountability, and undervaluing enterprise cyber risk management. The first makes it difficult for leaders to understand what risk information means. The second makes it too easy for important risk decisions to drift without clear ownership. The third causes organizations to treat cybersecurity as a defensive cost center rather than as a business risk and value-creation discipline.
This article focuses on the second root cause: insufficient accountability.
Accountability Is Not the Same as Blame
When people hear the word accountability, they often think of blame after something goes wrong.
That is too narrow.
Accountability should not begin after an incident, a lawsuit, a regulatory inquiry, an insurance dispute, or a board-level crisis. Accountability should be designed before the decision is made.
Accountability means the organization knows who owns the risk, who has authority to make the decision, what evidence supports the decision, what assumptions are being accepted, what resources are being committed, what uncertainty remains, and what follow-through is required.
That is a governance discipline. It is also a management discipline.
In cybersecurity, too many organizations allow accountability to become diffuse. The Chief Information Security Officer reports. The Chief Information Officer implements. Legal advises. Compliance interprets. Internal audit reviews. Consultants recommend. The board receives updates. Committees meet. Dashboards are produced.
But when the organization must decide whether to accept, avoid, mitigate, or transfer a material cyber risk, who owns the decision?
If the answer is unclear, the accountability model is weak.
Boards Govern Risk. They Do Not Manage Technology.
Members of the board should not be expected to manage firewalls, configure identity systems, select endpoint detection tools, or supervise incident response playbooks.
Boards do not manage technology. They govern risk.
That distinction matters.
The board’s role is oversight. Members of the board should ask whether management understands the organization’s material cyber risks, whether risk information is supported by evidence, whether risk decisions are aligned with strategy and risk appetite, whether resources are adequate, whether material risks are escalated, and whether management is following through.
But the board does not run the organization.
Management does.
That means management owns the business decisions that follow from risk assessment work. Management decides what risks to accept. Management decides what risks to mitigate. Management decides what risks to transfer. Management decides what activities to stop, redesign, or defer. Management decides whether to fund controls, change processes, delay projects, accept exceptions, or elevate risks for further governance review.
Those are not merely technical decisions. They are business decisions.
The CISO May Inform the Decision, but Management Owns It
The CISO plays a critical role. So do the CIO, Chief Risk Officer, General Counsel, Chief Privacy Officer, Chief Compliance Officer, Chief Audit Executive, finance leaders, operations leaders, and outside advisors.
But advice is not ownership.
A CISO can explain threats, vulnerabilities, control weaknesses, residual risk, incident trends, remediation options, and technical feasibility. A CIO can explain architecture, operations, dependencies, and implementation constraints. Legal can explain obligations and exposure. Compliance can explain regulatory expectations. Finance can explain cost and capital allocation. Internal audit can test whether the process works. Outside experts can provide independent perspective.
All of that input matters.
But when the decision involves material business risk, management cannot hide behind the expert.
Management owns the decision because management owns the enterprise context. Management understands the business objectives, operational constraints, customer obligations, revenue implications, budget tradeoffs, talent limitations, strategic priorities, and risk appetite. Management must decide what the organization will do with the information provided.
This is especially important when the decision is to accept risk.
Risk acceptance is not a passive condition. It is not what happens when no one funds remediation. It is not what happens when a risk sits unresolved in a register. It is not what happens when a control exception expires and no one acts.
Risk acceptance is a decision.
If the risk is material, the decision should be explicit, authorized, documented, and monitored.
Accountability Requires Decision Rights
Organizations often say that “the business owns the risk.”
That statement is directionally correct, but it is not enough.
Business ownership must be translated into decision rights. Who can accept risk? At what level? For what duration? Within what risk appetite or tolerance? With what required evidence? With what required mitigation plan? With what escalation path? With what reporting obligation? With what follow-up?
Without decision rights, “ownership” becomes a slogan. With decision rights, accountability becomes operational.
A defensible accountability model should make several things clear:
- Who owns the asset, process, business function, product, service, or activity affected by the risk?
- Who is responsible for evaluating the risk?
- Who is responsible for recommending treatment options?
- Who has authority to accept, avoid, mitigate, or transfer the risk?
- Who must approve exceptions?
- Who must be informed?
- Who must monitor the risk after the decision?
- Who must report material changes?
- Who is accountable if the decision is ignored, delayed, or allowed to drift?
These are not bureaucratic questions. They are decision-quality questions.
Reasonable Decisions Require a Reasonable Record
Accountability does not require perfect prediction. Leaders cannot foresee every event, prevent every incident, or eliminate every exposure.
But they can build a reasonable record.
A reasonable record shows what was known, what was assessed, what evidence was considered, what assumptions were made, what uncertainty remained, what options were available, what decision was made, who made it, why the decision was reasonable at the time, and what follow-through was required.
That record matters before the incident. It matters during oversight. It matters when regulators ask what the organization did. It matters when insurers review representations. It matters when customers ask for evidence. It matters when buyers conduct diligence. It matters when members of the board ask what management knew and what management did.
The record does not guarantee a good outcome. It helps show whether the decision was responsible.
That is the heart of defensible risk decision-making.
Cyber Risk Accountability Is Becoming Harder to Avoid
Cybersecurity is no longer a quiet technical function buried inside information technology. It affects revenue, operations, patient safety, customer trust, privacy, regulatory exposure, insurance, M&A, public disclosure, and enterprise value.
Public companies face cybersecurity governance and disclosure expectations. NIST Cybersecurity Framework 2.0 places governance at the center of cybersecurity risk management. Enforcement agencies, regulators, plaintiffs, customers, investors, and insurers increasingly ask what the organization knew, who knew it, what decision was made, and what evidence supported that decision.
Organizations should not wait for an incident to clarify accountability.
They should clarify it now.
The Practical Test
Here is a simple test.
For each material cyber risk, can the organization answer these questions?
- What is the risk?
- What asset, process, business function, or obligation is affected?
- What evidence supports the assessment?
- What is the potential business impact?
- What are the available treatment options?
- Who owns the risk?
- Who has authority to decide?
- What decision was made?
- Why was that decision reasonable?
- What resources were committed?
- What follow-through is required?
- What would trigger escalation or reconsideration?
If the organization cannot answer those questions, it may have risk activity, but it does not yet have real accountability.
The Bottom Line
Cybersecurity accountability is not about turning executives into technologists.
It is about requiring leaders to own the business decisions that cybersecurity risk creates.
Boards oversee risk. Management owns the decision.
Risk professionals inform the judgment. Evidence supports the judgment. Documentation preserves the judgment. Accountability attaches responsibility to the judgment.
That is how organizations begin to break the cyber failure cycle.
#riskmanagement #CISO #riskassessment #defensibleriskassessment #DRA #enterprisecyberriskmanagement #cyberriskilliteracy #boardcyberoversight #boardofdirectors
