In short, cybersecurity needs to be understood and treated as a core business issue, much like legal and finance. No organization would make a significant business decision without consulting business and finance. In the 21st century very few business decisions ought to be made without considering their cybersecurity aspects.
There are many additional steps an organization needs to take to comprehensively address cyber risk which will be described in succeeding chapters.
Taking the right steps entails reconsidering corporate structure (as discussed in Chapter 3) and using modern cyber risk assessment tools that go beyond the traditional frameworks and checklists (as discussed in Chapter 4), as well as engaging personnel from across the enterprise in addressing a series of specific cyber issues (as discussed in Chapter 6).