How to simplify and strengthen cybersecurity
Cybersecurity can feel overwhelming, but it does not have to be. In this video, experts from Implement Consulting Group and Blue Water Shipping share how organizations can simplify cyber complexity, strengthen trust and turn security into a business enabler.
Why cybersecurity feels so complex
Cybersecurity has evolved from protecting IT systems to protecting entire businesses. With new technologies, remote work and growing regulation, many organizations face increasing complexity. The discussion explores how this complexity stems from people, processes and technology, and why taking a step back to focus on purpose and priorities helps simplify the challenge.
Deconstructing and prioritizing cybersecurity
The speakers share how to start small and structure efforts using frameworks like ISO or NIST while maintaining flexibility. Leadership ownership and clear priorities are essential, and so is traceability, ensuring every security activity links to a business goal. Cybersecurity must move beyond technical teams to become part of daily leadership and decision-making.
From compliance to trust
Trust is at the heart of cybersecurity. When organizations focus on communication, clear governance and continuous improvement, they not only stay compliant but also build resilience. The conversation highlights how metrics, awareness and cross-functional collaboration can turn cybersecurity from a defensive cost into a driver of trust and long-term value.
How to simplify and strengthen cybersecurity
Cybersecurity can feel overwhelming, but it does not have to be. In this video, experts from Implement Consulting Group and Blue Water Shipping share how organizations can simplify cyber complexity, strengthen trust and turn security into a business enabler.
Why cybersecurity feels so complex
Cybersecurity has evolved from protecting IT systems to protecting entire businesses. With new technologies, remote work and growing regulation, many organizations face increasing complexity. The discussion explores how this complexity stems from people, processes and technology, and why taking a step back to focus on purpose and priorities helps simplify the challenge.
Deconstructing and prioritizing cybersecurity
The speakers share how to start small and structure efforts using frameworks like ISO or NIST while maintaining flexibility. Leadership ownership and clear priorities are essential, and so is traceability, ensuring every security activity links to a business goal. Cybersecurity must move beyond technical teams to become part of daily leadership and decision-making.
From compliance to trust
Trust is at the heart of cybersecurity. When organizations focus on communication, clear governance and continuous improvement, they not only stay compliant but also build resilience. The conversation highlights how metrics, awareness and cross-functional collaboration can turn cybersecurity from a defensive cost into a driver of trust and long-term value.
View transcript
Columbia's roometop Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Hello, everyone. Thank you so much for joining us on this sunny Tuesday, where we are kicking off the new webinar, Cybersecurity, There is Still Hope. Today, I have some wonderful, very experienced people with me that we will get into in a minute. But to focus our conversation today, we will discuss some of the complexities related to cybersecurity and how to deconstruct those challenges. I myself, my name is Sophie. I'm a cybersecurity professional with 15 years work experience, also before an IT project management. And today, I'm here to represent cybersecurity and implement services where we focus on cyber information services, as well as cyber technical services. Here, we look into risk, resilience and governance, culture and academy, legal compliance, privacy, security architecture, infrastructure, incident response and also managed services. Welcome. Thank you. Thank you. Thank you. Thank you. So, a quick introduction on the speakers today. First, we have implement's very own CISO, Christophe Boulter. Thank you so much for joining us. Thanks, Sophie. It's a pleasure. You have more than 15 years of cross-functional experience looking into cybersecurity management, architecture, engineering. And from our conversations very early on. And from our conversations very early on, I very much appreciate your perspective. And I'm very much looking forward to hearing what you have to say today. So, thank you for being here. Klaus, I also had the pleasure to meet you. And you are an experienced professional who sits on the board of different organizations focusing on tech and cybersecurity. Your specialty is really to understand the variety of problems that customers face as well as well as how to simplify those challenges. And you have experience from Thompson Reuters and many other companies as well. And finally, yourself, Morten. Yeah. Global Head of Security for Blue Water Shipping. I was so impressed by our early conversation with your 15 years experience in the military and how you approach cybersecurity and with your wide experience from physical security and everything that goes on into the military. And how you approach the field and how you approach the field and how you can utilize that in organizations. I have to mention as well that Christophe as well has a consulting capacity within implement and I have the pleasure of working with you once in a while. Great. So, looking at the agenda today, we will cover four points. First, we will look into why has cybersecurity become so complicated. Second, we will discuss how to deconstruct the complexity Then, third, we will look at how we prioritize and reorganize within the organization. And then fourth, how do you implement these activities so that you can get going where you are. You ready to kick off? Yes. Excellent. Brilliant. So, when we look at why cybersecurity has become so complicated, I would love to hear your why cybersecurity has become so complicated. So, when we look at industry perspective, Klaus, on where do you see these complexities are stemming from? They're stemming from a lot of areas. I think when people think about this first, you have a tendency to think about technology. But it's not only technology, it's also processes, it's also people. Starting with technology, you could say that, I mean, most organizations these days are embracing cloud computing. We have internet of things. We have internet of things devices everywhere. You have post-COVID. A lot of employers working from home, at least partially. Then you have bring your own devices. You have mobile phones. You have shadow IT. So, if you sort of look at the whole attack landscape, the attack surface, I mean, it's just expanding. All the time. So, that's one complexity. New technology is being brought into the landscape on a daily basis. If you then look at also the technology aspect, ransomware as a service, AI being used to attack. So, from a technological point of view, that surface is expanding. But then coming over to processes, organizations, companies, depending on which countries they operate in or which industries they're in, depending on the size of their businesses, they have to adhere to regulation, they have to adhere to frameworks that are mandatory to operate in certain spaces. That in itself adds a lot of complexity. It's just dealing with that. Talking about processes, you can also look at companies today, there's so much integrated with the supply chain, whether it's vendors, suppliers, third-party risk, third-party risk is a big component, also integrated with customers. So, 60% of breaches actually come from third parties. It's not within your own organization. So, that's the process aspect. The last bit, the human aspect. And looking at that, if you sort of look at where breaches come, actually 90% come from humans. So, whether it's phishing, whether it's social engineering, whether it's just error. That's happening. That's happening. That's a big source. That's a big source. If you look at all these things together, there are so many points where that adds complexity. Yeah, that's a great answer. Christopher, I'd love to hear your perspective. What are some of the complexities that you are seeing in your capacity on a daily basis? Thanks, Sophie. And I think I agree with everything that you said, Klaus. But I think one of the major points that's worth reflecting on is just there's way too much at the moment. Our cyber programs that we have built have become these bloated things that we don't even know how they got to the point that we did. And I think that we've kind of engineered that ourself almost within the industry, which I think is one of the primary issues that we have to deal with. And, you know, you can look at the history to kind of see how we got there. If you think 25 years ago, you know, you know, at the start of enterprise IT, so to speak, you know, what was security's purpose? It was to protect the IT. You know, so what did we do? We threw a bunch of technology at the IT to protect it. We said, hey, there's some firewalls. Now we secure. And, you know, that became the inherent approach within security. And then, you know, as we shifted in time, we started realizing, well, maybe we need to, you know, think about this a bit better. And, you know, along came frameworks. And we started inventing management frameworks. So we could protect the data. So we could protect, you know, what we needed to protect and start thinking about things in a structured approach. But that also kind of got a bit confusing because, you know, the framework started to become more and more and more. And then we get to today where, you know, we realize we're in a position where we need to protect what the business is there to achieve. You know, cyber needs to be positioned for what we're trying to do within the business. And, you know, with that, we've got to prioritize. And what we always tend to do as people is go back to what we're used to. So we've still got that background of the technical approach and the approach that we did 20 years ago. Then we've got all these frameworks we're trying to do. And now we're trying to prioritize it for business. And we have to prioritize it for business because I saw a stat a few months ago that said we're at something like the money globally in cyber crime annually is like 80 times the amount of money globally in cyber defense. Yeah. So there's a much more lucrative, you know, business sense and going into cyber crime than cyber security. So, you know, we've got less money than the bad guys. So we need to focus that spending correctly and make sure we're putting the money in the right places. And on the back of that, we've also got so much to choose from. You know, we say that when we're in the market for a new security capability or service, it's like the app store on your phone. There's so many of the same things that do the similar thing that have similar outcomes. And we just got to really prioritize which one we need to look at in the context of the new security capability or service. of what our business is trying to do. And I think that's where the complexity comes from is that we've just had so many different vectors coming in in building this industry that's become, from the outside, inherently so complicated, whereas if you get it onto the inside and what we're trying to do, it's not that complicated. We've just got to look at it from a different perspective. I really have so many good questions I'll come back to you on in a minute. But before we go into that part, I would love to hear your perspective Morten. What do you see from a global political perspective? Yeah, well, now that you mention political, there's geopolitics at the moment where we see something called hybrid warfare and us being part of a supply chain if we are a global company. We will then also be facing some attacks as we are suppliers to someone and we use, as you mentioned, Klaus, vendors and suppliers. So supply chain is a big thing in security at the moment. Yeah, and also mentioned AI, which is an advantage for the attackers, but it's also an advantage for the defender. And now that you mentioned the attackers has a lot more money. It's a big number. So it's a big number. It's just not even how do we manage that. And on top of that, we have a skill gap because AI is at such a fast pace that we do not really know what it is. We do not know at the moment what it is that we have to adhere to. We know that we know that we have to adhere to. We know that there's a lot of regulations, regulatory pressure from all kinds of regulations and, again, frameworks that for some that are not security professionals can be really, really hard to understand. 150 controls, 150 controls, 100, 100 controls. And it's what is relevant for us in this world at the moment. And it's really hard to, and all the different suppliers doing, supplying us with cyber defense that does the same thing. But what is the value for us in this? Yeah, some really interesting points that you mentioned for you as well, looking at people, process, technology, technology, maybe even data. And yourself, what I really appreciate as well about your perspective is that we have all these dynamics that almost seem infinite. So how do you ballot finite budgets and resource constraints within an organization to make sure that you get this right? Because there's also such a thing as overprotecting your organization to make sure that you hit the right level of value that you're adding from your cybersecurity activities against some really big, really big, really big, really big, really powerful forces that we are faced with today. But that's what we are going to dive into in this second part of the conversation. It's some of the solutions just beginning to untangle and deconstruct some of these complexities to learn from your experiences. How do you start to go about this? So, Morten, I'd love to hear your perspective from a best practice point of view, and from a framework perspective, what has worked really well for your experience? Well, for best practice or to adopt to best practice, you also have to have your own principles of how you want to do it. So from our point of view, we need to have top management to be part of it, or else you will not be able to succeed in it. We have an overarching global security policy that covers everything. And that is our CEO's statement. In the military, it would be called the commander's intent. And it covers exactly people, process, and technology. Because if we take one of those legs off the chair, we will not be able to run the business. But to protect people, process, and technology, we would have to adhere to some sort of framework or system that we utilize. Because it will help us think less for ourselves. Because we adhere to some controls that are already predefined for us. So that's how we help ourselves on the way. Yeah. Adhering to some sort of a standard, being ISO, and NIST, or whatever you want to use for your company. And how you can add that structure to your organization that Morten is talking about. I'd be very keen to hear your perspective, Christopher, in terms of an architectural perspective or principles that you have experience in utilizing. Yep. Thanks, Sophie. I think I've always approached security and the challenges that are in security from an architectural perspective. And I believe there's two fundamental parts of architecture that we have to use in security. And that's traceability and communications. Now, what I mean by that, we need traceability on one hand to determine that we've got security in the right place. So that we've got the right security for what the business is trying to achieve. So that our business objectives map to security programs that we're implementing and whatever controls we put in place. And what I mean by that, we've got to start thinking from the top down and start thinking of what is it that we're trying to achieve. We always use the example that says, say now we're a business that wants to, as a core objective, increase market share and revenue by increasing our online shopping, as an example. Now, what does that really mean? That means that, of course, if we're going to increase our revenue in online shopping, customers have to want to use our online shopping. What drives customers wanting to use our online shopping? Well, amongst other things, it's trust in our system. And in order for customers to have that trust in our system, they've got to know that their data is secure with us. And then we start to have this need for encrypted web security and web security in place in SSL as a very trivial kind of conceptual example. And that's one of the fundamental things is that we need to make sure that we've got that two-way traceability, like in architecture for security. That everything we have in place maps to business objective. And every business objective that we have maps down to something within the security field. And how do we achieve that? That comes to the second point, which speaks to communication. Communication is especially important as an architect because you need to speak the languages, so to speak, of different stakeholders within the organization. And when we start to have these discussions with security implementation teams and business teams to kind of map these objectives between this traceability between security and business, we need to know how to speak to both of those languages. And that requires a different way of thinking to get these kind of stakeholders on board. On one hand, when we're speaking, you know, to use the web traffic example again, when we're speaking to a security team, we might say, hey, we need some web security in place to secure the data communications and that becomes the control that we want to do. But when we start to speak into business, if we want to really get their buy into something, it becomes important to kind of, you know, put something in place that, you know, we want to map to what the business is trying to do. We need to make sure that, you know, we can speak their language and we can say to them that, well, you know, you want to increase your revenue through online sales. That's not possible without this. This is what enables that trust. And so this is what enables you to achieve that target. And those are fundamental things, I think, in getting to security. And that kind of mindset, again, not as a rigid framework of the 100 frameworks that we follow, but that kind of mindset that when you have that discussion with your senior stakeholders in the business, understand what means something to them, frame what you're doing in the context of that which means something to them, and then draw that down to the rest of the teams. I think that that becomes fundamental. Yeah. Yeah. Yeah. I really like what you say about creating traceability and also the connecting link between cyber and the rest of the organization as a strategic enabler. I think that's so important. Klaus, it would be great to hear your views on how can organizations create traceability and structure through utilizing, for example, through utilizing, for example, tools that support frameworks, best practice controls, as well as can enable the communication that Klaus-Dofa is referring to. Well, in my world, it has to be supported by some technology doing that. But before talking about that, it's important, yeah, that you are able to track, measure, prove what are the security and compliance activities. So that that's in any instance, you can actually see who did what, when, where, and why. So you need to define processes in place that make sure that you have security, you have control. So if there's an incident, what was the decision? What was the action taken? And supporting that, there are a number of tools you can use. So I mean, in wide relations, that's a GRC tool, but there are also other tools like CM or ticketing systems. So in a structured way, you're able to put those processes in place and support that technologically. Also, a lot of those frameworks that companies have to adhere to either regulatory-wise or because their customers demand it, they do actually specify that. So for instance, the NIST 2 in Article 23 defines how you have to do logging. And the same thing in ISO 27001 and so on. So that is critical that you're able to implement and enforce traceability. Yes. And what you're saying is incredibly important. And it makes me think about how organizations can best utilize and look at the results of different types of tools. Mauden, I'd love to hear your perspective in terms of identifying organizational designs, governance groups, etc. How can you create structure within the organization that connects the link between and the technical team, the technical team, the technical team, the technical team, builds the communication and the escalation and the report based on facts and best practice frameworks and controls? Yes. Well, again, it comes back to traceability. Who did what, when, where and how and also why did they do it? Because it has to be in the context exactly as we have the organizational context. What we do is this. Blue Water, we are part of supply chain. We do transport and logistics. So we have some risks. So we have some risks and we have to mitigate. We do that by controlling things. And these controls are owned by either it could be IT, it could be HR department, it could be our procurement department. We would have to be able to trace that control back to who did what, when, where and also maybe a policy if that is needed. So it goes from a strategy to a policy to a policy and down in the end to a control and a trace of how we did things. So that would be the way to do it. Yeah. Yeah. That brings us to the third part of the conversation today, which is prioritizing the activities that you then identify through your business requirements, through communications, through strategic needs, as well as the tools utilized. So just staying on that topic with you, Morten for a minute, I'd love to explore to the degree you can share or at a very broad level, maybe, how do you ensure the top level requirements for cybersecurity are driven through and prioritized at a leadership level? Well, for us, it has become, I'll not say easy, but because we are set on the needs too. So top management are held liable for our actions. So that's the easy part. The hard part is to, if we look into an ISO framework, because we use that in Blue Order, it's the planning, the doing, the checking, the acting, and the continuous improvements that is the hard part, because people come and go in businesses, but the actions and the controls all have to stay the same and we'll see still have to be create these continuous improvements. So when we create a plan for what it is that we want to do with our business in regards of cybersecurity, we have to go and do it. And then we also have to check and measure upon are these actions that we want to do, do they provide the results that we want? And then we have to act and go back and see, okay, did they do what they want? And then create some, maybe some improvements and some new controls. And we will be able to then improve on a continuous basis if we follow that framework, the PDCA cycle. And before we move to a question that I have for you, Christopher, just a final point with you, Morten. How do you make sure that people actually do act and check? What change activities, if any, do you require? There are different ways that you could do it because cybersecurity has become part of daily management and daily leaderships. And there are different ways for a manager to do that because cybersecurity is constant change. If we do not change, then we will have a breach in it. So we could use all kinds of different tools for that. We could go back and use old change management tools from theory to the theory from the 50s by Levin or Cutter or whatever framework you do if you do not have to adhere to an ISO certification or whatever it is that you have to do. So again, when you do your planning, you're doing checking and acting, and then you control the act, the task has to be put up on somebody with an exact deadline because if you do not have that and you do not have a reporting program that can you can go back and check on, then simply people will not do their controls. Yes, and that makes you audit ready as well. Great. Thank you so much. Gustav, I'd love to hear your perspective, particularly from both your CISO role, but also your consulting, vast consulting experience. How do you see leadership prioritizing cybersecurity and how do they go about it in a structured way? I think there's many different avenues to getting that leadership prioritization in place. I mean, on one hand, it's been mentioned a few times, we've got this NIS2 perspective which starts to hold people and individuals within management accountable. But, you know, that's almost the by force approach, which, you know, I prefer to say, I mean, based on the conversations you and I have had, you know, I prefer to stay away from that kind of mindset within cyber that by force, we are here to do this approach. And first and foremost, and I think you mentioned it as well, Morten, it comes to understanding and engaging with their leadership so they can understand, you know, the importance of cyber. And, you know, there's no silver bullet within that regard. You know, the approach that I take, especially within leadership discussions when trying to prioritize cyber in, you know, my various roles that I have is first and foremost having that conversation, you know, almost that casual conversation. Yeah. Which is, what is success for you in the business going forward? What's going to be your, you know, big bonus, so to speak, if this, you know, that's going to give you that, you know, for the business in going forward? And how can, how do you see activities for the business kind of adapting to, you know, help you in achieving what you're trying to do there? And then you don't speak about security. You don't speak about, you know, what security can do there, but that's just about gaining that understanding. Yeah. And then in the background, you, in your kind of role that you're doing within security, your role is to really break that down into what that potentially means for security. And you've got to then translate that back into how that's going to enable that key objective for that key business stakeholder and communicate it to them without speaking about security. Yeah. Yeah. So that they can understand in the regular catch-ups that you have on how this is achieving that situation. Yeah. But also then how you can have that abstracted view to the technical team down. Yeah. So that they can understand what they're trying to do and the effect that it has on, on, on business and, you know, protecting what's important with regards to that key business impact. Yes. I really like what you say about metrics and starting with the end goal in mind. Yeah. Because then you're working towards something in a strategic, way and then balancing that with the risk-based approach. I just love to hear your view before I go to you, Klaus, is how do you balance strategy and risks? Do you look at critical processes? What are some tools that you can utilize to assess impact on business? Well, I think that's, that's an important thing to consider. And, you know, always, I was actually faced with the question about two weeks ago, the talk that I gave with this, you know, how do we prioritize, you know, we're getting different messages. Either we must prioritize business outcomes or must prioritize risk when we're looking at cybernive. You know, those are the same thing. Because if we're looking at business outcome, the thing we need to understand is what is that business trying to achieve? And in understanding that, we need to know what sort of risks are the key risks to that outcome. Yes. And then that's what translates that into a risk discussion. But, you know, I think the key tool in balancing that is to make sure that, as I said, you've got that objective focus mindset with the risk. Yeah. And I think, you know, we need to know what's the risk. And I think, you know, we need to know what's the right way to do. And I think, you know, we need to know what's the right way to do. And I think, you know, sometimes that's not always the correct way. We need to have those discussions with them to guide them so that they can understand exactly, or help them so that we can help them understand exactly, you know, how these business objectives that they have, are potentially affected by risk and what security can do to afford that. It's not something you want to throw over the wall and then, you know, wait for a response to be thrown back at us. I think that's a great answer. Thank you so much. Klaus, one of the things I would love to hear your perspective on is how are businesses taking to working with cyber metrics specifically? And what do businesses want and need when you meet them in your capacity in order to put a measure or a language to cyber threats to their organization? Yeah, I would say that there are two main areas. One thing is that there are a lot of different operational metrics that make sense. So you have to figure out which metrics do you need operationally. One thing is with the core people responsible for cybersecurity, but also in the different business lines. Like one could be in HR. There's a metric in terms of saying how many have completed an awareness training. So that's operational. The second thing is actually at a board level, at an executive level, taking some of those metrics that might be core, it could be like a risk exposure metric, and putting that in board reporting. I think we see that more and more now that it is important that some of that information comes up to a board level, just like we see in more places, CISOs actually having a dotted line or direct reporting into board. So that shows that you have to apply those metrics both operationally, but also they have to come up to a board level, some of them. Yes. I really like that point. And it also ties in with what you mentioned, Morten, about making sure that cybersecurity, what you're all three are saying is not the technical team alone today anymore. No. But it has to actually cut across and be cross-functional in the organization across HR, maybe communications, legal, and many other functions as well. So that leads us to the fourth segment of today, which is how do we then go about implementing cybersecurity across the organization? And so, Morten, I'd love to hear your perspective. What are some of the ways that you have seen cybersecurity being successfully adopted and implemented across different functions today? Well, it is exactly with incorporating HR, procurement, compliance, and IT in the same team. Because there is a lot of technical stuff that people in HR does not understand. Because when onboarding processes and all the life cycle of people getting onboard, different identities they have to use during their career and all that kind of stuff that HR will have to use in IT department for creating some sort of control. And also the procurement department, because they are the ones who in the end is responsible for our procurement policies. And they will also have to use in IT department. And they will also have to tap into the IT department so that we create some sort of differentiating policies for, for example, it could be system suppliers or whatever. And because there's a difference, at least for us, for somebody providing us with physical tools used at a harbor and somebody providing us with software and systems. That is how I see it being done across, because cross-functional teams also create some sort of, at least we start to see some risks that we did not know that was there because we have made this cross-functional team between HR, procurement, and IT. That is of great value, at least to us. Yeah. And I think it's so interesting because that also pins down the point you made earlier on that you suddenly need to have this whole user, internal stakeholder, external stakeholder landscape across the organization in a RACI or whatever other tool you utilize. in order to make sure that every activity, artifact role, as well as third-party suppliers are managed. Because like you say, they impact the change, the procurement. If there is an exit, what does that mean? You know, if there is a new migration happening next to it, there are so many elements that go into it. And because of the technological transformation that we've been through, the technical setups are also very complicated and very deeply often integrated into order. So it takes a lot of organizations. So it takes a while to exit. And what type of risk does that in itself pose in the interim? So such an interesting point. Christopher, how do you go about successfully implementing cybersecurity within the wider organization as a part of your day-to-day job? I think it largely speaks to, you know, what you spoke about as well, Class, which is, you know, really about the metrics and how we're measuring, that success criteria for what we're doing. I spoke a little bit earlier about getting that top-level perspective about what's important to the business and having cyber trace from there down. But that's equally important on a departmental perspective because every single department has their own KPIs of things that are important to them as a department for taking things forward. And cyber, when we start to trace things and start to pull those metrics apart and looking at the operational side and the other perspectives, we can adapt those metrics to what those different departments to what those different departments to do. I mean, in the context of, you know, what we're thinking potentially back to that, you know, web scenario again, you could think of something along the lines of number, decrease in the number of failed web transactions due to a security issue or something along those lines. And then, you know, someone on the business side can start to see a perspective to say, hey, that security I invested in, I actually can see a decrease now in the number of failed transactions, which are related to a security issues as a trivial example to what we spoke about earlier. So I think that's one thing. But, you know, another thing is also to continuously have those discussions that help the people, especially when you're in an organization, such as a consulting organization, help them understand that, you know, this is about enabling you to do your job more effectively. Yes. As opposed to, like I said earlier, you know, getting away from the message that says, hey, you know, we're here to push this. And, you know, you know, by force. Yeah. I really appreciate your view on trust as well, because what happens if you suddenly lose the trust? Exactly. What happens if organizations have a cyber attack or their businesses go down? How do you rebuild and how do you rebuild the trust and what's the impact on consumers? And I think metrics is such an interesting view. And I'd love to hear your thoughts as well. Klaus, because metrics, because metrics, when you utilize key risk indicators or KPIs, if you look at phishing campaigns, of course, the numbers will go up when you implement these. So at least for a period while people get used to the new ways of working with controls. So how do you go about communicating metrics effectively in the organization and educating organizations on their new strategic path for cyber initiatives? Well, it comes top down. There has to be a strategy. And in that strategy, cybersecurity is part of that. And it's clearly communicated why that is. And then as part of that, you have metrics, metrics at a company level. And as you said, metrics on a departmental level. So in terms of the ongoing communication you're happening, whether it's town halls or whether it's department meetings, making sure that those metrics are being used. I mean, on a month by month, a week by week, whatever makes sense basis. And also, to the extent it makes sense, communicating back down to a team or even individuals. It could be, I mean, some places people like to use gamification or other sort of psychological behavior things to increase an interest in cybersecurity. So that could be, for instance, that you track how many have, what are the numbers of reports on phishing to sort of alert. And you make the monthly hero about doing that. So those are how you can use metrics. But it has to be done in the context that makes sense for that organization. So you have to look at what's relevant for you. A completely different organization might have to use some other metrics and tools. Yes, that's a great answer. I'm really curious. Yes, Chris? And I think, you know, to touch on the point that you made as well with regards to trust, you know, metrics, there's different flavors we can put metrics in place. But in the end, money is always, you know, the biggest thing with the biggest impact when we're talking metrics. And, you know, to use that example, when, you know, you can show how trust potentially increases or decreases with inclusion of cybersecurity and, you know, programming the decrease in incidents, which is increasing trust. That becomes very, very valuable when you put that against the cost of an incident. Yes. When there was nothing in place, because that erodes trust and the cost to get back to that point that you were. And you'll find that far exceeds, you know, the cost that you've spent on that kind of, you know, ongoing perspective. And that's such a brilliant point, because it's connecting what you started with saying in why is it that we look at cybersecurity and think about the customer? This is the reason why. It's because you have to think about the potential cost and risk to losing that customer if you do not have your security measures in place. Yeah. It's a brilliant point. And maybe not even being allowed to work together with them. Yeah. We do not have them in place. Yeah. Exactly. Exactly. And that we see more and more of now. Yeah. Yeah. Final question, Morten. I'll leave that with you. What's the best way to get ownership in your organization? Not just at the top level, but thinking top down and bottom up to make sure things are escalated and equitable? Tough question. Tough question. Well, one is metrics. We at Blue Order know how hard a cyber attack hits, meaning that one metric that we introduced, one example, is that people have to do awareness trainings. These awareness trainings and how many have been doing those, those metrics go directly to top management. And if we have somebody that has not finished them, then the immediate manager would get to top management. You have somebody in your department that hasn't done their awareness training. Please get them to do their awareness training. That's one of them. So that creates a pressure from the top that goes directly to the bottom of the organization. And that's one of the parts to adhere to. But it also has to create some value at the bottom level. And that has something to do also with the awareness training, because people, people will have to, in some way or the other, learn a new skill set and learn a new behavior. Because that's part of the attacker's metrics that we have to become better at spotting them, because AI will be a real challenge in the future, especially in advanced phishing campaigns or what they will find out. So behavior and adopting a new skill set. And that will also be a real challenge, because are we able to educate and train our colleagues at the same speed as the technology evolves? So that's, I don't know if I could answer this completely. No, I think that's a great answer. It is. And it's not an easy answer, as you say. And it's not a quick fix solution. Because with transformational and organizational change, it takes a while. Because humans are humans. Humans have humans. Humans have humans. Yeah. So when planning, I guess, just summarizing what you've been saying, is thinking with the end goal in mind, what's your strategic objective for cybersecurity? And what's a realistic timeline to change that? And what steps in changing an operating model for an organization are you going to go through? And how do you make that adaptive as well through the phases, so that you can respond through yearly, every other year, every third year, to say, we've implemented this, we have goal for the next phases of a cyber operating model, but what's happened in the interim, so that organizations become really agile to respond to those political landscapes you mentioned? Yeah, that's one of the other things. Because even though that you have a strategic direction, when you do security, you can suddenly come into a tactical solution instead, because things are evolving so fast. So, yeah. And that may create a new direction for your strategy. Final point? That's something we always have to deal with, because business always continues. I mean, it's great to set that as a milestone, and this is an objective for something going forward, but stuff is still happening every day. Yeah. And that's what we have to do, is put that balance in place, and that's something that, yeah. There's no golden bullet for that yet, but, you know. With your help, it might come. Hopefully. Excellent. So, that concludes the four first sections, but we're not done yet. Just to make you aware that in a moment, we will go into the Q&A session, and you will have an opportunity to post your questions utilizing Minty with a QR code that should be shared on the screen with you as well. But before we go into the Q&A, what would be great is just to summarize some of the amazing things that we talked about. We can all agree that cybersecurity and the complexities that it brings are vast. They are both broad and deep from a global political perspective, deep technical process-related people, issues, or opportunities, as well as end customers, as well as end customers and strategic objectives, and the trust that it requires to drive your business. Today, we've discussed some of the frameworks and tools looking into ISO as well as seeing how regulatory compliance needs actually drives the need for transformation, as well as some of the threats and risks that organizations have today, including the deep connection that end customers and the need for transformation, as well as some of the threats and risks that organizations have today, including the deep connection that end customers have with the threat of losing them have with the threat of losing them to a cyber attack if cybersecurity is not dealt with. There's also a very big learning curve, I think, even for us in the room today, on how to constantly look at the evolving threat actor landscape, translate these into KPIs, key risk indicators as well, key goal indicators for the organization, and train your people in So what we would love to do now is we would love to hear from the audience if there are any questions. So what we can see here is that we have some questions coming in already, which is brilliant. Someone is asking, someone is asking, we have had a hard time quantifying risk so that it makes sense to the executive leadership team and board. How can we make cyber risk more understandable? Klaus? Yeah, I think that's a good question. So, I mean, there are two aspects. I'm looking at what is the likelihood of impact, defining some scores that make sense on that front, for that organization, for that organization, and the second thing is what is the business impact if some of that happens. So that's a sort of generic framework that's very useful to use. That would be one way to assess that. Christopher? I can add that I think I agree with Klaus, and I think one piece to add, you know, we can see value in that is to stop thinking about what the technology is trying to do, and what I mean by that is to start thinking about the business processes.