What if the CISO's real job is calibrating the right amount of insecurity? Information must flow. Apps must be used. Links must be clicked. To calibrate the right level of insecurity we should:
1. Learn how fast the business wants to move.
2. Define how much insecurity the organization can absorb.
3. Measure the gap between current and acceptable insecurity.