
Cybersecurity as a Business Investment – The Challenge of Measuring Cybersecurity for the C-Suite
How cybersecurity becomes a business investment: Using the CRI to make cyber risks and resilience measurable.
Topic
When & Where
Details
Format:
Management lecture
Language:
German
Session description
Speaker: Sascha Scholz
Cybersecurity is often managed merely as a technical cost center. Budgets are allocated to EDR, firewalls, SIEM, backups, or standalone external SOC services. Meanwhile, executive management receives reports filled with extensive dashboards, patch rates, and audit findings. Yet, the crucial link to business impact is frequently missing: Which critical services are at risk? How long might an outage last? Which investment offers the greatest risk reduction? And how can this be implemented—potentially with external support?
This presentation illustrates why this connection often fails in practice. The critical gaps rarely stem solely from a lack of technology; rather, they lie in the interfaces between asset and identity visibility, governance, risk asses ...

