How Do We Build a Cybersecurity Strategy That Actually Supports the Business?

A cybersecurity strategy should explain what the organization is trying to protect, which cyber risks matter most, what capabilities are needed, where investment should go, and how cybersecurity will support the business over time.

A cybersecurity strategy is not simply a list of security projects.

It is not a framework implementation plan.

It is not a technology roadmap by itself.

And it should not be built only around the next audit.

The strategy should help leadership make deliberate decisions about cybersecurity in the context of the organization's business model, customers, risks, obligations, technology, resources and future direction.

Hotman Group helps organizations build cybersecurity strategies that connect business priorities, cyber risk, Cyber GRC, technology, implementation and ongoing operations.

Cybersecurity strategy should answer what matters, why it matters, what the organization should do about it, and what should happen first.

Who Can Help Build a Cybersecurity Strategy?

Look for a cybersecurity partner that can work across business context, cyber risk, governance, technical controls, customer requirements, compliance, technology and implementation.

Hotman Group can help organizations:

  • understand business objectives;
  • identify material cyber risks;
  • evaluate current cybersecurity capabilities;
  • understand customer and regulatory obligations;
  • define target-state capabilities;
  • prioritize investments;
  • build a practical roadmap;
  • establish governance and ownership;
  • and help implement and sustain the strategy.

Why Does Cybersecurity Strategy Need to Start With the Business?

Because cybersecurity exists to support and protect the organization.

The appropriate security strategy depends on:

  • what the company does;
  • how it makes money;
  • which systems and data are important;
  • which customers it serves;
  • where it operates;
  • what regulations and contracts apply;
  • how quickly it is growing;
  • and what business changes are planned.

A strategy built without that context may optimize security activities that are not the organization's most important priorities.

What Should a Cybersecurity Strategy Include?

A practical strategy should generally address:

  • business objectives;
  • material cyber risks;
  • critical systems and data;
  • current security capabilities;
  • major gaps;
  • customer and regulatory requirements;
  • security architecture;
  • Cyber GRC operating needs;
  • people and capacity;
  • technology;
  • investment priorities;
  • governance;
  • and a realistic implementation roadmap.

Should We Start With a Cybersecurity Framework?

A framework can provide useful structure, but it should not automatically become the strategy.

Frameworks help describe good cybersecurity practices and external expectations.

Strategy still needs to answer:

  • Which risks matter most to this organization?
  • What business outcomes are we supporting?
  • Which capabilities need the most improvement?
  • What should be done now versus later?
  • What resources are available?
  • What requirements are mandatory?
  • And what tradeoffs should leadership make?

A framework can support those decisions without replacing them.

How Does Cyber Risk Drive Strategy?

Cyber risk helps determine what deserves attention.

Strategy should consider:

  • what could happen;
  • how the business would be affected;
  • how likely or significant the exposure is;
  • what controls already exist;
  • what residual risk remains;
  • and what treatment makes sense.

This prevents the roadmap from being driven only by the loudest finding, newest tool or most recent audit request.

See what a cybersecurity risk assessment should actually tell leadership.

How Should Leadership Use a Cybersecurity Strategy?

Leadership should use the strategy to make decisions about:

  • risk tolerance;
  • investment;
  • staffing;
  • technology;
  • customer commitments;
  • prioritization;
  • and ownership.

The strategy should make it easier for executives to understand why cybersecurity work matters to the business.

See how to explain cyber risk to executives and the board.

How Do Customer Requirements Affect Cybersecurity Strategy?

Customer security requirements can materially change the strategy.

They may require:

  • new technical capabilities;
  • new certifications;
  • changes in product architecture;
  • different data handling;
  • new evidence and assurance;
  • additional staffing;
  • or new operating costs.

These should not be treated only as compliance tasks if they affect the business model.

See what to do when a customer gives you a new cybersecurity requirement.

What If Customer Requirements Are Driving Product or Revenue Decisions?

Then cybersecurity is part of the business strategy itself.

Leadership may need to evaluate:

  • whether the security investment enables the opportunity;
  • whether the capability can be reused;
  • how pricing should account for ongoing cost;
  • whether product design should change;
  • and what future markets the investment could unlock.

See how customer cybersecurity requirements can become major cost, product and business-strategy decisions.

How Should Compliance Fit Into the Cybersecurity Strategy?

Compliance should be incorporated as a legitimate business and cybersecurity requirement.

The strategy should identify:

  • which frameworks and regulations apply;
  • which customer requirements matter;
  • what assurance is necessary;
  • and how those requirements can be supported through the broader cybersecurity program.

The strategy should avoid allowing every framework to become a separate security strategy.

See how to build one cybersecurity program across multiple frameworks.

What If We Have Too Many Cybersecurity Requirements?

That can distort the strategy if each requirement is treated as equally important and independent.

First determine:

  • what truly applies;
  • what is mandatory;
  • what is customer-driven;
  • what overlaps;
  • what existing controls already support;
  • and what truly incremental capabilities are required.

See how to manage too many cybersecurity and compliance requirements.

How Does Cyber GRC Support Cybersecurity Strategy?

Cyber GRC helps operationalize the strategy.

It connects strategy to:

  • risk;
  • controls;
  • ownership;
  • requirements;
  • evidence;
  • findings;
  • remediation;
  • reporting;
  • and governance.

Without that connection, strategy can remain a presentation rather than become an operating program.

How Does the Cyber GRC Operating Model Fit?

Strategy defines direction.

The operating model defines how the organization executes and sustains that direction.

See how to build a Cyber GRC operating model.

How Should Controls Fit Into Strategy?

Controls are mechanisms for achieving security outcomes.

Strategy should help determine:

  • which capabilities are required;
  • which controls support them;
  • which controls are weak;
  • which controls are unnecessarily duplicated;
  • and where new controls are justified.

The objective is not to maximize the number of controls.

It is to operate the controls the organization actually needs.

How Does Control Ownership Support Strategy?

Strategy cannot be implemented if nobody owns the work.

The organization should identify:

  • who operates important controls;
  • who is accountable;
  • who addresses failures;
  • and who owns material risk decisions.

See how to create clear ownership for cybersecurity controls.

How Should Technology Fit Into Cybersecurity Strategy?

Technology should support defined capabilities and outcomes.

The organization should ask:

  • What problem are we solving?
  • What security capability is required?
  • What do we already have?
  • Can current technology be improved?
  • What integration is required?
  • What ongoing cost will the tool create?
  • And how will we measure whether it works?

Buying technology should be a strategy decision, not a substitute for one.

How Should GRC Technology Fit Into Strategy?

GRC technology should support the organization's Cyber GRC operating model.

It may help manage:

  • controls;
  • framework mappings;
  • evidence;
  • risk;
  • findings;
  • ownership;
  • workflows;
  • and reporting.

The organization should understand those needs before selecting the platform.

See how to choose the right GRC platform.

What If the Existing GRC Platform Does Not Support the Strategy?

First determine whether the problem is:

  • the platform itself;
  • the implementation;
  • the data model;
  • workflows;
  • ownership;
  • or an underlying operating-model problem.

See what to do when a GRC platform is not working.

How Should Cybersecurity Remediation Fit Into Strategy?

Findings should not sit outside the strategic roadmap.

Remediation should be prioritized alongside other cybersecurity investments based on:

  • risk;
  • business impact;
  • customer commitments;
  • regulatory obligations;
  • dependencies;
  • and strategic value.

See how to remediate cybersecurity findings.

Should Audit Readiness Be Part of the Strategy?

Yes, where assurance is important to the business.

But audit readiness should be built into normal operations rather than become the strategy's central purpose.

See how to prepare for cybersecurity audits without constant fire drills.

How Do We Build a Practical Cybersecurity Roadmap?

A roadmap should translate strategy into sequenced action.

Each major initiative should identify:

  • the problem or risk being addressed;
  • the desired outcome;
  • major activities;
  • owners;
  • dependencies;
  • resources;
  • timing;
  • and how success will be evaluated.

Avoid a roadmap consisting only of dozens of unrelated projects.

How Should We Prioritize Cybersecurity Investments?

Consider:

  • material risk reduction;
  • customer and contractual commitments;
  • regulatory obligations;
  • business dependencies;
  • implementation dependencies;
  • cost;
  • capacity;
  • and reuse across future needs.

The most expensive initiative is not automatically the most strategic.

Neither is the initiative associated with the most visible compliance score.

Should the Strategy Be Multi-Year?

Usually.

Many cybersecurity improvements require sequencing over time.

But the strategy should not become a rigid three-year plan that ignores changing reality.

Review it when:

  • the business changes;
  • major incidents occur;
  • important risks emerge;
  • new customer requirements appear;
  • significant technology changes occur;
  • or leadership priorities change.

How Often Should Cybersecurity Strategy Be Reviewed?

At least periodically and whenever significant change occurs.

The right cadence depends on the organization.

More important than the calendar is whether strategy remains connected to current business conditions and cyber risk.

What If the Company Has Outgrown Its Existing Cybersecurity Strategy?

Then the strategy should be rebuilt around the company's current reality.

Growth may have changed:

  • risk;
  • customers;
  • technology;
  • regulation;
  • staffing;
  • products;
  • and security expectations.

See what to do when a company has outgrown its cybersecurity program.

How Does Cybersecurity Maturity Affect Strategy?

Strategy should be realistic about the organization's current capabilities.

A company with immature ownership and highly manual controls may need foundational operating improvements before pursuing sophisticated automation or advanced program objectives.

See what a mature cybersecurity program actually looks like.

What If the Internal Team Is Overwhelmed?

Strategy should account for operating capacity.

A roadmap that assumes resources the organization does not have is not practical.

Determine whether workload can be reduced through:

  • control rationalization;
  • automation;
  • better technology;
  • clearer ownership;
  • process redesign;
  • or outsourcing.

See what an overwhelmed cybersecurity and GRC team should consider outsourcing.

Do We Need a vCISO to Build and Execute Cybersecurity Strategy?

Possibly.

Some organizations have capable internal teams but lack experienced executive cybersecurity leadership.

Others need Cyber GRC leadership rather than a traditional CISO role.

Others need specialized project expertise.

See whether you need a vCISO, vGRC, consultant or full-time hire.

What If Our CISO Leaves While the Strategy Is Being Executed?

The strategy should not exist only in one person's head.

Priorities, risks, decisions, ownership and roadmap activities should be sufficiently clear that the program can continue through leadership transition.

See how to keep the cybersecurity and GRC program moving after a leader leaves.

How Do We Know Whether the Strategy Is Working?

Do not measure success only by completion of projects.

Look for evidence that:

  • material risk is becoming better understood and managed;
  • control effectiveness is improving;
  • ownership is clearer;
  • recurring findings are decreasing;
  • audit disruption is decreasing;
  • customer requirements are easier to absorb;
  • leadership decisions are better informed;
  • and the program is becoming more sustainable.

See how to determine whether a Cyber GRC program is actually working.

How Hotman Group Approaches Cybersecurity Strategy

Hotman Group approaches strategy as the connection between business needs, cybersecurity risk and practical execution.

HG can help organizations:

  • understand the current environment;
  • identify material risks;
  • understand business and customer drivers;
  • evaluate current capabilities;
  • define target-state cybersecurity capabilities;
  • prioritize initiatives;
  • build a roadmap;
  • clarify governance and ownership;
  • align Cyber GRC and technology;
  • and help implement the resulting strategy.

Hotman Group can also provide vCISO or vGRC support and ongoing operating capacity where the organization needs help executing and sustaining the plan.

Why Cybersecurity Strategy Is Bigger Than a Roadmap

A roadmap tells the organization what projects are planned.

Strategy explains why those projects matter and what outcome the organization is trying to achieve.

Without that context, cybersecurity can become a permanent queue of:

  • tools to buy;
  • audits to pass;
  • findings to close;
  • and frameworks to implement.

Strategy keeps those activities connected to the business and to meaningful protection.

The Larger Philosophy Behind Cybersecurity Strategy

Cybersecurity often becomes reactive.

A new threat creates one initiative.

A customer creates another.

An audit creates another.

A new technology creates another.

Over time, the organization may become very busy without being clear about where cybersecurity is going.

Cheri Hotman's forthcoming book, Rebuilding Cybersecurity: How to Restore Trust, Leadership, and Real Protection in a Broken System, examines how cybersecurity can become fragmented by incentives, assurance activity and unclear accountability.

Strong strategy helps reconnect those activities around what the organization actually needs to protect and what leadership is trying to accomplish.

A cybersecurity strategy should make it easier to say yes, no, not yet and this matters more.

Frequently Asked Questions

What should a cybersecurity strategy include?

It should connect business objectives, material cyber risks, current capabilities, customer and regulatory requirements, target-state capabilities, investment priorities, governance, ownership and a practical implementation roadmap.

Should a cybersecurity framework be our strategy?

No. Frameworks can provide useful structure, but strategy should be based on the organization's business context, risk, obligations, resources and future direction.

How do we prioritize cybersecurity investments?

Consider material risk reduction, business impact, customer and regulatory commitments, dependencies, cost, capacity and whether the capability can support multiple future needs.

How does cybersecurity strategy support the business?

It helps leadership align cybersecurity investment and priorities with business objectives, customer requirements, growth, market opportunities, risk tolerance and important technology decisions.

How often should cybersecurity strategy be updated?

Review it periodically and whenever significant business, technology, risk or customer changes occur. The strategy should remain connected to current reality rather than follow a fixed calendar regardless of change.

Can Hotman Group help build a cybersecurity strategy?

Yes. Hotman Group can help organizations understand business drivers and cyber risk, evaluate current capabilities, define the target state, prioritize investments, build a roadmap and establish the governance and operating model needed to execute it.

Can Hotman Group help implement the cybersecurity strategy after it is created?

Yes. Depending on the engagement, HG can support implementation, remediation, GRC technology, vCISO or vGRC leadership and ongoing Cyber GRC operations.

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems.

HG helps organizations build cybersecurity strategies that connect business objectives, cyber risk, customer requirements, controls, technology, governance and practical execution.

Hotman Group can help diagnose the current environment, define the strategy, implement and remediate the required capabilities, and help operate and mature the resulting cybersecurity program.

Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.