Why Today's Top Security Leaders Need Business Skills, Not Just Tech Skills
In a recent interview, the group Chief Information Security Officer (CISO) of Standard Chartered, a global bank, discussed how the role of security leadership has changed over time. Rather than focusing purely on technical skills, the CISO emphasised that modern security executives need to understand the business itself — how it makes money, where its risks lie, and how to communicate security priorities in terms leaders across the organisation can act on.
The interview also touched on artificial intelligence, noting that AI is a double-edged sword in cybersecurity. On one hand, it strengthens defensive tools, helping security teams detect and respond to threats faster. On the other, cybercriminals are increasingly using AI to make their attacks more convincing and harder to detect, from more believable phishing emails to automated attempts to breach systems.
While the discussion centred on a large international bank, the underlying lesson applies broadly: security decisions should be tied to business priorities, not treated as a purely technical exercise. Small and medium businesses may not have a dedicated CISO, but the same principle holds — whoever manages cybersecurity should understand what matters most to the business and communicate risks in plain terms to owners and decision-makers.