"Good advice changes something. Great advice changes the right thing."
Organisational Risk and Governance
Professor Sele: Security governance is the framework within which an organisation makes security decisions, allocates resources, and holds itself accountable. Without governance, security becomes whatever the most senior person present decides — inconsistent, unaccountable, and legally exposed.
Section 1 — What Is Security Governance?
Security governance is the framework of policies, oversight structures, accountability mechanisms, and performance standards that guide how security is managed within an organisation. Good governance ensures: security decisions are made at the right level; resources are allocated against assessed risk, not habit or preference; performance is measured and reviewed; accountability is clear when things go wrong; and legal and regulatory compliance is maintained.
Section 2 — The Security Governance Structure
A professional security governance structure typically includes: Board / Senior Management — set the security risk appetite and approve the security policy. Security Director / Manager — responsible for implementing the security strategy. Security Operations Committee — cross-functional body that reviews security performance, approves significant changes, and oversees major incidents. Internal Audit / Compliance — independent review of whether security controls are functioning as intended. External Assessment — periodic independent review by an external expert (such as SafeHaven).
Section 3 — Risk Appetite
Risk appetite is the level of risk an organisation is prepared to accept in pursuit of its objectives. It is a strategic decision made by senior leadership — not a technical security determination. The security function's role is to: present the risk picture accurately and completely; implement controls to reduce risk to within the agreed appetite; and escalate when risks exceed the appetite without adequate controls.
A security function that makes its own risk appetite decisions — without senior management engagement — has assumed authority it does not have.
Section 4 — Security Performance Measurement
Governance requires measurement. Key security governance metrics: percentage of staff who have completed mandatory security training; number of incidents by category and trend over time; audit findings (open vs. closed); policy compliance rates (measured through spot checks and audits); time to respond to and resolve critical incidents.
These metrics are reported to senior management on a regular schedule — typically quarterly — as part of the governance cycle.
- •Security governance provides the framework for decisions, accountability, and performance management
- •Governance structure: Board → Security Director → Operations Committee → Internal Audit → External Assessment
- •Risk appetite is a senior leadership decision — the security function informs it but does not set it
- •Governance requires measurement: training compliance, incident trends, audit findings, policy compliance
- •Escalate when risks exceed appetite — this is a governance obligation, not an operational choice
"A client's security manager had been approving exceptions to the access control policy at his own discretion for two years — 'temporary' exceptions that never got reversed. The board had no idea this was happening. When I audited, I found 47 active exceptions — almost one third of the regular entry passes were operating outside the approved policy. The security manager thought he was being helpful. He had actually created a governance vacuum. Security governance is not a constraint on the security function — it is the foundation that gives the security function its authority."
What is "security governance" in an organisational context?