InsightIQ GOVERNANCE THE MODEL →
Cyber security governance, made intelligent.

The board never actually asked whether we are secure.

It asked whether the organisation is in a defensible position, and whether there is evidence that position is being held. That is a different question, and unlike the first one it has an answer.

The Reasonable Allocation Model begins from an uncomfortable premise: a CISO’s primary output is not cyber defence. It is a defensible allocation of resources — not too much, not too little — and proof, afterwards, that the level chosen was the right one.