Eli Sofie Amdam on Cyber Security Governance
What makes cyber security governance work in practice? Eli Sofie Amdam, Managing Director in Information Security & Data Protection, shares her perspective on why security must start with the business, how to strengthen accountability and what continuous, data-driven governance looks like in practice. She also shares three recommendations for strengthening operational resilience.
PERSPECTIVES | CYBER & DIGITAL RISK
What has most shaped the way you think about cyber security, and how does that influence your work today?
What has shaped my thinking most is probably how my own approach to security has changed over the years. Early in my career, I relied much more on best practices and frameworks. Over time, I realised that something can be best practice and still be the wrong answer for a particular organisation.
I have also learned that defining what good security looks like is often the easy part. The difficult part is making it work in the real world, in a way that fits how an organisation operates and enables people to actually follow it. That has made me much more pragmatic and business-oriented in how I approach security today.
What do organisations need most from security leaders today and where do you see the biggest gaps?
The biggest shift is that we need to stop starting with technology and start with the business. We have spent years talking about IT risk as if it were separate from business risk. It isn’t. Technology is there to support the business, and security is there to help the business operate within acceptable risk.
What is the organisation here to do? What products or services do we provide, and to whom? What do we depend on to deliver them, and what could prevent us from doing so? What information, people, suppliers and technology do we depend on? Security should follow those answers, not the other way around.
The biggest gap I still see is that organisations implement frameworks and technology without connecting them sufficiently to how the business actually works. We need security governance that is business-driven, integrated and increasingly data-driven.
You have previously spoken about the risk of creating “paper tigers”. What are the clearest signs that security governance looks strong on paper but falls short in practice?
One of the clearest warning signs is when the information security management system mainly consists of PDFs in a SharePoint folder.
The organisation may have policies, procedures, risk assessments and control descriptions, but if they are not integrated into how people actually work, they have limited value. The same is true when governance is designed around generic best practice rather than how the organisation actually operates.
Another warning sign is when security governance only “lives” within the security team. The security function performs the risk assessments, writes the requirements and follows up the controls, while the rest of the organisation continues more or less as before.

How can leaders prevent requirements such as NIS2 and DORA from becoming check-the-box compliance exercises?
To avoid turning NIS2, DORA, ISO 27001 and similar requirements into check-the-box exercises, security must be built into existing roles, processes, tools and decision-making. Compliance should reflect how the organisation actually manages risk, not how complete the documentation looks.
Security governance works when security becomes part of how the business is governed, not something the security team does to the business.
Cyber risk is still often treated as the responsibility of the CISO or IT function. Which cyber risk and resilience decisions must executive teams and boards own?
Executive teams and boards need to take ownership of the business questions behind cyber risk.
Do we know what we have and what really matters to the business? Do we understand our critical processes, information, technology, suppliers and other dependencies? And do we understand the consequences if they are compromised, manipulated, unavailable or exposed?
From there, leadership needs to decide what level of risk the organisation is willing to accept, where to invest, what to prioritise and what resilience actually means for the business.
That includes being prepared for disruption and knowing what the business must continue to deliver when something does go wrong. But resilience is broader than business continuity. It is also about designing the organisation so it can anticipate and withstand threats, limit their impact, adapt to changing conditions and recover when necessary.
The CISO can provide expertise and challenge. But ownership of business risk, priorities and resilience belongs with the business.
How should accountability, risk assessment and monitoring evolve to keep pace with AI?

The problem may not be that AI is moving too fast, but that governance is moving too slowly. Annual risk assessments and manually updated documents cannot keep pace with continuous technological change.
Governance needs to become continuous and data-driven: assess risk when meaningful changes happen, automate controls and evidence collection where possible, and use operational data to identify changing risk.
Accountability must also remain with the people making and owning the business decisions, not with a separate AI, security or compliance function.
What three changes would you prioritise to strengthen an organisation’s resilience over the next 12 months, and why?
First, understand what really matters to the business. Know your critical services and processes, the data and other assets they depend on, and what happens if those dependencies are compromised or fail.
Second, implement rather than document. Security should be business as usual. Put requirements into the processes and tools people already use. Use policy as code where it makes sense, automate controls and evidence collection where possible, and design workflows so that the secure way is also the easiest way.
Third, use data to govern continuously. Move away from annual snapshots and static compliance reporting. Use operational data, meaningful KPIs and KRIs, incidents, exceptions and control performance to understand where risk is changing and where action is needed.
The goal is not to make people think about security all day. It is to make secure behaviour the natural and easiest way to get their job done.
Eli Sofie Amdam
Connect to learn more
Eli Sofie Amdam
Managing Director, Information Security & Data Protection (Cyber & Digital Risk)
eli.sofie.amdam@advisense.com
Eli Sofie Amdam is Managing Director in Advisense’s Cyber & Digital Risk team, specialising in cyber security governance, cyber risk management and operational resilience. Her approach centres on translating security requirements into effective governance embedded in everyday business operations.
Photo credit: Pia Bråthen
Read more about Cyber & Digital Risk.