I have been thinking a lot about organizational influence and the relationship of security to corporate governance. A corporation is like the solar system. The Sun consists of the Boardroom, the CEO, the CFO and probably the general counsel.The first thing you’ll note about the Sun is that it’s a big ball of gas. (Sorry, irresistible.)The second thing you’ll notice is all the planets revolving around the Sun. Information technology is a planet. Human resources too, and operations and others. Security is one of these planets as well.I may have dozed through my droning college astronomy lectures but I faintly recall something about apogees and perigees—suffice to say that, periodically, certain planets move closer to the Sun, while others move farther away. The closer a function is to the Sun, the better its status and influence in the company. In the late ’90s, galactic forces called e-business and e-commerce drew Planet IT’s orbit nearer the Sun. IT basked in the tropical climes. (They got a lot of money and they reported at every Board meeting.) But there’s a fine line between getting a nice tan and getting toasted. After the dotcom market bubble burst (and after CEOs concluded their Y2K spending was money down the drain), CIOs got toasted. And Planet IT was banished to do some time in an outer orbit.After 9/11, CEOs in the United States decided that, hey, this risk management stuff really is important. But some security leaders, perhaps having witnessed the hazardous warming of Planet IT, would prefer it if Planet Security remained a safe, cool distance from the Sun, thanks very much. Even if the Boardroom seems to be extending a chummy invitation to parley about risk, these CSOs and CISOs seem to sense that the closer the orbit, the worse the ending. So they keep their heads down. The most irksome thing about such CSOs is that they won’t return phone calls from the press, a.k.a. me! (The nerve!) But there’s more to it than that. Some security heads say they have nothing to report to the Board, that security value can’t be measured and that risk mitigation procedures and statistics are meant to be kept secret. That the disclosure of a breach is more to be feared than the breach itself. That a risk management department is just a security group that’s gotten too big for its britches. So these CSOs are happy to keep their basement offices and to keep their doings safely out of sight of the Boardroom.I’ll concede that the Sun may yet decide to burn Planet Security. The inner circle of control is guarded most jealously—they’d generally prefer to handle the decision making themselves. If a risk management backlash happens, it will start with this (rhetorical) question from the Boardroom: “All this money we spent on risk management—what did we get for it?” This is how the question was phrased about IT in 2000 and 2001. After that question echoes for a bit, the CSO will get cooked and Planet Security will be flicked by a cosmic thumb back to the outer ring. With a reduced budget and a spot at the bottom of the org chart. Demoted like Pluto, our newly crowned Dwarf Planet.Maybe. But still I’d rather hang with the CSOs who aspire to more influence and more visibility—something more than the dusty cold of space. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe