The five translations: a practitioner-led approach to integrated security

How can organisations embed integrated security and ensure efforts aren’t just the responsibility of the IT department? Tilewa Olorunnisola, Senior Information Security Consultant, outlines the key considerations

In regulated organisations, information security is critical. That level of risk requires attention from decision makers, but how can we make sure such a complex discipline is properly represented in the boardroom and flows down through the business? Part of the answer is to focus on five areas of translation that embed resilience and risk management across people, systems, processes and technologies: the key areas highlighted by the National Cyber Security Centre in their recommendations for boards.

01.

Organisational objectives into critical operations

Too many security programmes begin with discussions about tools, compliance frameworks or the latest technology. That’s the wrong starting point.

“The first thing I try to do is understand the organisation. How does it make money? How does it deliver its objectives? Only then can you understand the risks that could stop it achieving those objectives.”

Whether it's a commercial business generating revenue or a public sector body delivering essential services, understanding why the organisation exists is fundamental. We then need to identify the departments, services and operations that are critical to achieving those objectives. While organisations may have dozens of systems and processes, not everything carries the same level of risk.

In reality, the business might not be able to protect every part of the organisation. It needs to understand which services, operations and people actually support its objectives and prioritise those first. Only after understanding the business, identifying its critical operations and assessing the risks should organisations begin deciding which security controls they need. If you don’t and begin with a more exciting alternative, 'AI is in the market, let's buy an AI tool,' what is likely to happen if your business isn't set up for AI enablement? First understand the business. Then understand the risks. Then find the appropriate controls.

02.

Regulation into lived controls

For many regulated organisations, security can become synonymous with passing audits. That mindset needs to change.

“Security requirements should not be something you put on a shelf and bring out when the auditor arrives. They should be embedded into what people do every day.”

Regulators are increasingly asking organisations to provide evidence that controls are operating effectively, not simply that policies exist. That means moving beyond compliance as a tick-box exercise and treating security as part of everyday business operations.

Rather than being an additional layer of work, security should be integrated into existing processes. When it becomes part of normal working practice, auditors no longer need to be shown evidence that has been pulled from a shelf. Instead, they see secure behaviours embedded throughout the organisation.

03.

Cyber jargon into board language

One common reason cybersecurity struggles to gain board-level attention is that conversations are often framed in technical language. A quick fix is to change the tone of the conversation.

“We need to start seeing information security as a business risk. It is not just something IT manages; it is something that can disrupt the business's ability to operate, serve customers and protect revenue.”

Boards already understand strategic risk, financial risk and regulatory risk. Cybersecurity should be viewed through the same lens.

Part of the responsibility lies with security practitioners themselves. Most are technologists, so when they talk to the board, they speak in technical language. This is much less likely to inspire change, so we need to start speaking in the language of business risk.

The other part lies with leadership. Cybersecurity shouldn't sit solely with the IT department because accountability never does. When major incidents occur, it's CEOs and board members who answer questions from regulators, customers and government, not the CISO. That makes cyber resilience a leadership responsibility.

04.

Security expertise into shared accountability

Organisations need to treat their CISO or virtual CISO as a trusted business adviser, bringing them into conversations about growth, partnerships, acquisitions and new services from the very beginning.

“The CISO or vCISO should be treated as a trusted ally. Bring them into conversations about growth, partnerships, new services and change early, so security risk can be planned in rather than fixed afterwards.”

If the CISO is involved at the start, they can tell you where the security risks are and help you plan for them before you deliver.

For security leaders themselves, influence depends as much on relationships as technical expertise. You want to be seen not as the department of no, but the department of yes (in a safe way, of course).

That means identifying executive champions, having regular conversations with senior leaders and becoming visible across the organisation. When the CISO understands what's happening across the business and the business understands what security can enable, cyber becomes a shared responsibility rather than something delegated to IT. Everyone has different roles, but every role is important. Working in silos is a recipe for failure.

05.

Response plans into customer-aligned recovery.

Boards need to stop asking whether a cyber incident will happen and start preparing for when it does. That change in mindset shifts the conversation from prevention to resilience. Ask yourself:

Who speaks to customers?


Who manages communications?


How quickly can critical services be restored?


Does your recovery time meet customer expectations or just your internal targets?


We then need to measure what really matters. What is the business’ mean recovery time and is it acceptable for the business and its customers? If your customers need something online in six hours but your recovery time is six days, you've missed that expectation.

Preparation also means having battle-tested playbooks that people know how to follow under pressure - not documents that remain untouched until an incident occurs.

Ultimately, cyber resilience isn't defined by whether an organisation experiences an attack. It's how effectively it continues operating when disruption occurs.

Keep reading