• Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
  • Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
HBS logo
HBS Logo
  • Infrastructure
    • CLOUD

      • Cloud Solutions
      • Public Cloud
      • Hybrid Cloud
      • Infrastructure as a Service
      • Cloud Security Solutions
      • Backup, Replication and Disaster Recovery
      • HBS Cloud Hosting Services

      DATA CENTER

      • Data Center Solutions
      • Traditional Data Center
      • Hyperconverged
      • Colocation
      • Directory Services
      • Cloud Email and Calendar Solutions

      NETWORK AND ACCESS

      • Network Infrastructure
      • Enterprise Mobility
      • Wireless Solutions
      • SD-WAN
      • Structured Cabling
      • Staff Augmentation
      Data Center Solutions blue gradient background badge with white text
  • Managed Services
    • MANAGED ONE

      • Managed One Overview
      • Managed Backup and Disaster Recovery
      • Managed Email and Collaboration Security
      • Managed Firewall

       

      • Managed HaaS and SaaS
      • Managed IT Help Desk
      • Managed Network and Server Monitoring

      HBS + PARTNER SOLUTIONS

      • HBS Secure with Verkada
      • HBS Collaborate with Webex
      • Managed XDR
      HBS Managed One Megamenu Graphic
  • Modern Workplace
    • MICROSOFT

      • Microsoft Licensing Management
      • Microsoft Modern Workplace
      • Microsoft Copilot
      • Microsoft Fabric
      • Microsoft Funding Opportunities

       

      • Dynamics 365 Business Central
      • Dynamics 365
      • Dynamics GP

      COLLABORATION

      • Audio Visual
      • Unified Communication Solutions
      • HBS Collaborate with Webex
      HBS Collaborate with Webex blue gradient background badge
  • Professional Services
    • ADVISORY

      • Virtual CISO
      • Virtual CIO
      • Project Management
      • IT Business Consulting

      ENGINEERING SERVICES

      • Staff Augmentation

      AI & ANALYTICS

      • Artificial Intelligence
      • AI Advance
      • AI Predict
      • AI Assist
      • Data Management and Analytics
      • Microsoft Copilot
      • Microsoft Fabric

      APPLICATION INNOVATION

      • Website Development
      • Application Development

      DOCUMENT MANAGEMENT

      • Document Management Services
      • Document and Check Scanners
      Discover your AI Readiness blue gradient background with white text. Bottom right photo of young man in glasses smiling while looking at laptop. Red to green temperature gauge png
  • Security
    • CYBERSECURITY

      • Managed XDR
      • Penetration Testing
      • Vulnerability Scanning
      • Email Security Services
      • Digital Forensics and Incident Response
      • Backup, Replication and Disaster Recovery
      • Firewalls
      • Cloud Security Solutions

       

      • Virtual CISO
      • Virtual Security Team
      • Virtual Security Engineer
      • Cybersecurity Risk Assessment
      • Governance and Compliance
      • SOC 2
      • CMMC
      • Managed Security Awareness Training

      PHYSICAL SECURITY

      • Security Solutions
      • HBS Secure with Verkada
      Cybersecurity Risk Assessment Megamenu Graphic
  • Search
Contact Us
Blog

The True Role of an Information Security Professional

  • Written by: Dave Nelson
  • April 26, 2016
Animated Scale with Risk and Reward Balanced

Information security professionals must understand their role in helping business leaders balance the risk vs. reward equation when evaluating cybersecurity efforts. They must also be willing to exercise flexibility in their personal opinions and help business leaders understand IT risk management. Doing business comes down to one simple question. How much money are you willing to lose in an attempt to make even more money? In other words…how much risk can you stomach? Doing business in the digital world today involves more risk than ever before. Cyberattacks are simply a cost of doing business. 

Information security professionals are responsible for helping business leaders understand cybersecurity risk and how to properly mitigate it. When this occurs, they can be a very useful resource. But, if they do not understand that responsibility, they become a liability to the organization they are trying to help. Security professionals must understand that business decisions must be made by business leaders. 

Assisting with Business Decisions 

If you are an information security professional, you can let down your leaders in several ways. The first is to attempt to make business decisions. Saying “no” because something is too risky isn’t your job. You should identify the risk, communicate the risk so executives can understand it, and then provide options for accomplishing the task with less risk. Let the executives make the call. This way you are seen as an enabler of the business and not a road block to progress or change. 

Flexibility and Compromise 

A second pitfall is to pick the wrong battles. If you are seen as inflexible and unwilling to compromise, you lose the trust and respect of leaders around you. If, however, you display a willingness to negotiate and compromise on a regular basis, the times when you do push back and fight hard for something, your opinions will be respected. If there is a high level of trust, they may even defer to your position simply on that trust factor.  

Staying Engaged 

A third pitfall is complacency and ineffectiveness. Every security professional comes to a point in their career when their effectiveness seems to be dwindling. For whatever reason, their effectiveness in the organization has diminished to a point where they are no longer making a difference. Sometimes this is because of the individual, sometimes a management change, and sometimes the company’s culture is changing do to growth and maturity. The important thing to do is to find out the reason for the change and try to correct it. Simply going through the motions of security will result in critical failures. 

Communicating with Management 

Ultimately it comes down to this. Are you still able to recognize and communicate cybersecurity risks in a way that management understands and is able to act on? Are you able to provide solutions that protect the company while allowing it to function and grow? If the answer is “Yes”…then carry on. If the answer is “No”, then you need to dig deeper. What changed? Why? Can you fix the issue? Can you reestablish mutual trust and be effective again? 

Information security isn’t about being in control. It’s about helping business leaders make wise decisions based on their knowledge of the business environment and market forces. Information security professionals who understand this and provide value to their business leadership are worth their weight in gold. 

Related Content

Risk Matrix Likelihood Impact

Risk Assessment: Likelihood and Impact

Assess risk effectively with the risk assessment likelihood and impact matrix. This decision-making matrix assesses risk based on the likelihood and impact of threats in your organization.

Learn More »
Fractional IT Leadership strategic IT leadership fractional cost

Fractional IT Leadership: Smart, Strategic, and Scalable

Not sure what your business needs from IT? A fractional CIO gives you expert technology leadership—without the full-time cost. Here’s what that looks like.

Explore More »
vCISO services

Virtual CISO

Strengthen your cybersecurity with a Virtual CISO from HBS: Expert leadership and strategic guidance customized to meet your security challenges efficiently.

Read More »
  • IT Leadership, Security
Blog

Connect:

[email protected]  |  800.236.7914

HBS logo

HQ | 1700 Stephen Street
Little Chute, WI 54140
Locations

HBS Remote Support | Service & Technical Support | E-Bill Portal
Standard Terms & Conditions | Cookie Policy | Privacy Policy | Onboarding Form | End User Agreements | E-Bill FAQ | Site Map
Any purchase is governed by the HBS Standard Terms and Conditions.
©2026 Heartland Business Systems. All rights reserved.

Halo from HBS
This chat may be recorded as described in our Privacy Policy.