The key to successful security programs? Look to your business

Conducting security risk analysis is a challenge. Start with your business leaders, who can speak to their operations best.

Team collaborating on laptops with a connected world map overlay, illustrating global cybersecurity and business alignment
Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

The article explains how IT should move beyond siloed awareness campaigns and partner continuously with business leaders to sustain cybersecurity momentum year-round. It outlines a practical framework where risk analysis, governance, and self-assessment testing form a feedback loop that requires business input on priorities, acceptable use, and risk appetite to shape policies and controls. The piece also highlights DNS as a critical monitoring and control point—via DNS logging and policy enforcement—to give security operators visibility into device intent and manage network traffic effectively.

Why is it important for IT to involve business leaders in risk analysis?

Involving business leaders in risk analysis is important because they understand business operations, priorities, and the impact of outages or data loss in ways IT alone cannot. Business leaders can identify which systems are most critical, the real-world consequences of downtime, and which technologies the organization relies on, enabling IT to spot relevant vulnerabilities and prioritize remediation. The article stresses that IT should not attempt to answer these operational-impact questions alone; instead, risk analysis must combine IT’s technical knowledge with the business’s operational context to produce accurate, actionable risk assessments.

How should governance decisions, like blocking categories of websites, be made according to the article?

The article recommends that governance decisions be made through discussions with business leaders rather than unilaterally by IT. While security teams bring subject-matter expertise about threats and controls—such as blocking shopping, sports, gambling, or social media domains to reduce malware exposure—policies affect employee experience and operations. IT should facilitate conversations on acceptable use, appetite for risk, and organizational culture, presenting implications and alternative controls so leaders can decide what aligns with business objectives. This collaborative approach ensures policies are both secure and acceptable to the organization.

What role does DNS play in ongoing cybersecurity operations and testing?

DNS plays a dual role in cybersecurity operations as both a monitoring source and a control enforcement point. DNS logging provides visibility into successful and failed queries, capturing device intent across the network in a way many other telemetry sources cannot. Additionally, because devices must perform DNS lookups before accessing domains, DNS is a strategic first hop where policies can be applied to control traffic and block malicious domains. The article recommends leveraging DNS logging and DNS-based controls as part of continuous security monitoring and as tactical mechanisms for implementing governance and closing gaps identified by self-assessments.

Cybersecurity Awareness Month has come and gone. Hopefully you’ve used this opportunity to  focus on end user awareness, roll out new capabilities, and interface with the business. Now how do you continue that momentum throughout the year?

The key is to deepen your engagement with the entire enterprise.

IT is no longer just an enabler; it is a driver. That means a siloed, sidelined IT organization is an antiquated notion. Business today calls for IT to lead and guide others. As technology shapes each area of the business, it becomes increasingly more challenging for leaders to navigate. Here, IT can play the role of forest rangers who guide the business through the metaphorical woods.

Cybersecurity plays a large role in that. From stricter compliance requirements to more intelligent threats, no part of the business is immune to any security risk. And above all, the costs of a breach are too high.

As your attention shifts away from awareness campaigns, work alongside your business leaders to keep cybersecurity top of their mind and run your security programs successfully.

Risk analysis, governance, and self assessment testing work together as a feedback loop for cybersecurity. Each are programs you should be running year-round. But how is the business involved in the security programs?

Leaning on your leaders to answer the burning questions

In the areas of risk analysis and governance, an understanding of the business operations and their objectives is mandatory. (Remember, IT cannot operate in a silo.) Conducting security risk analysis is a challenge if you’re not versed in the business. Frankly, how can you spot the vulnerabilities if you don’t know where to look?

Start with your business leaders, who can speak to their operations best. Where you understand the information systems and assets, the business knows the impact and effects of any risk to their operations. These are questions they should answer for you. Do not attempt to answer them on your own.

  • What are the most critical parts of your business?
  • What are the consequences of any downtime or outages?
  • What technologies do your business absolutely rely on?

Governance for cybersecurity takes many forms: policies, procedures, standards, compliance, culture. As subject matter experts, your knowledge in best practices, tools, and controls is most valuable here. But again, policies and standards cannot be created on your knowledge alone.

Rethinking governance through conversations with the business

Unlike risk analysis, governance actively shapes how a business operates and influences how employees feel about their employer. For example, the concept of least privilege means end users only have access and rights to the resources they absolutely need to perform their job.

A business can implement a policy to block access to all shopping, sports, gambling, and social media websites for users who do not need them for their job. From the cybersecurity perspective, hackers target popular websites and use them to host and deliver malware. Naturally, blocking domains is the solution but a business may receive backlash from users that see this as unnecessarily restrictive.

As a security professional, you can facilitate a discussion about acceptable use with leaders to determine if a decision like this is appropriate for your business. It cannot be a decision made independently. Guiding the business through the possible implications or identifying alternative controls are insights only you can provide. Cybersecurity professionals are the subject matter experts and need to be business partners for governance.

These are some preliminary questions you can pose to the business. They will help the leaders think about security differently and help you understand the type of organization you have.

Bridging the gaps identified through self assessments

Self assessment testing is another area where working with the business is valuable. Testing should be based on governance and information gathered from the risk analysis. The results should show where you are, compared to where you want to be. Bridging that gap is the joint endeavor.

Awareness and education programs are part of closing some gaps identified through self assessments. At the same time, these tactics have become tired over time. Remember to partner with the business here to understand how to engage with their units more effectively. Instead of a presentation or email communication, consider some of these options:

  • User-created testing: Challenge non-IT folks to create phishing emails (with the help of IT). Prizes go to the most effective campaign and employees that report it.
  • Find opportunities to gamify: Testing your security controls, identifying vulnerabilities, or assessing knowledge can all be made into games.
  • Report on progress: Have your awareness campaigns been a hit? Then share it with everyone and celebrate that success.

How DNS helps you

For cybersecurity operations of any maturity, being able to monitor your network is necessary. DNS is one of the most effective ways to monitor network traffic. Through DNS logging, security operators have visibility into all successful and failed queries. This data captures the intent of each device on the network in a way others cannot.

Implementing controls through DNS is another effective way security operators can leverage DNS. A device must ping a server, indicating which domain it wants to go, whenever it wants to carry out an action. That first hop onto the network is a strategic point where network traffic can be controlled, like applying policies.

To learn how you can leverage DNS in your cybersecurity operations, check out our eBook “DNS in the Cybersecurity Stack.”


Published in:


An avatar of the author

Jadecy Kidane is the Marketing Content Manager at BlueCat.

Related content

Close-up of interlocked metal chain links symbolizing connected network objects and relationships in IPAM

How to map your network with user-defined links in Integrity X

Map your network with user-defined links in Integrity X to define and manage custom relationships, such as dual-stack and NAT environments.

Read more
Flock of geese flying in formation across a blue sky, framed by a pink graphic border, symbolizing coordinated network migrat

Automate your DDI modernization path by migrating with Micetro

Automate cross-platform DNS and DHCP migration with Micetro to reduce risk, eliminate manual effort, and modernize infrastructure faster.

Read more
Three armored figures walking toward a futuristic Las Vegas skyline with pyramids, glowing orb, and "Welcome to Fabulous Las

Your journey to intelligent NetOps begins at Cisco Live

Visit BlueCat’s booth or book a meeting now to learn more about how our solutions can help you build a network that supports constant change.

Read more
Stacked colorful wooden directional arrows on a post by a calm seaside with distant hills and blue sky

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more