Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Report . 2026
License: CC BY
Data sources: ZENODO
ZENODO
Report . 2026
License: CC BY
Data sources: Datacite
ZENODO
Report . 2026
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

Decision-Centric Security Trilogy – Part I Why Your Expensive Experts Are Obsolete

A Cost-Optimization and Accountability Framework under NIS2
Authors: Beierle, Stefan;

Decision-Centric Security Trilogy – Part I Why Your Expensive Experts Are Obsolete

Abstract

About this Publication This publication is Part I of the Decision-Centric Security Trilogy. It challenges a long-standing assumption in cybersecurity: that failures are primarily caused by missing tools, insufficient frameworks, or a lack of certifications. Instead, it demonstrates that modern security failures are fundamentally organizational failures, rooted in the absence of clear, accountable decision ownership. Under regulatory regimes such as NIS2, the Cyber Resilience Act (CRA), and GDPR, cybersecurity is no longer a purely technical or compliance-driven activity. It has become a management responsibility—one that must be demonstrable, traceable, and defensible under regulatory, legal, and economic scrutiny. To address this shift, the book introduces the concept of Decision-Centric Security and the role of the Decision Manager: a clearly mandated function responsible for making, documenting, and defending security decisions under time pressure and regulatory oversight. This role is positioned where existing security frameworks remain intentionally vague—at the point where risk must be accepted, mitigated, or escalated. Using cost models, organizational analysis, and regulatory reasoning, the book shows how security organizations can reduce structural overhead, accelerate response times, and improve regulatory readiness by restructuring security operations around decisions rather than roles, and accountability rather than activity. This work is intended for CISOs, CFOs, executive management, boards, and risk owners who are required to make defensible security decisions in increasingly regulated environments—and who must be able to justify those decisions long after the incident has passed.

الملخص التنفيذي يقدّم هذا العمل الجزء الأول من سلسلة Decision-Centric Security، ويجادل بأن فشل الأمن السيبراني الحديث لا يعود إلى نقص الأدوات أو الأطر أو الشهادات، بل إلى غياب ملكية واضحة ومسؤولة لاتخاذ القرار داخل المؤسسات. في ظل أطر تنظيمية مثل NIS2 و قانون المرونة السيبرانية (CRA) و اللائحة العامة لحماية البيانات (GDPR)، لم يعد الأمن مسألة تقنية أو امتثال شكلي، بل أصبح مسؤولية إدارية يجب أن تكون قابلة للإثبات، والتتبع، والدفاع عنها أمام الجهات التنظيمية والقانونية. يطرح الكتاب مفهوم الأمن المرتكز على القرار (Decision-Centric Security) ودور مدير القرار (Decision Manager) بوصفه جهة مخوّلة باتخاذ قرارات أمنية حاسمة تحت ضغط الوقت وضمن رقابة تنظيمية واضحة. ومن خلال نماذج تكلفة، وتحليل تنظيمي، ومنطق تشريعي، يوضح هذا العمل كيف يمكن للمؤسسات تقليل الأعباء التشغيلية، وتسريع الاستجابة، وتعزيز الجاهزية التنظيمية عبر إعادة هيكلة الأمن حول القرار والمسؤولية بدلاً من الأدوار والإجراءات.

Keywords

CEO, Risk Management, Cybersecurity, CFO, AI in Cybersecurity, CTO, Security Architecture, NIS2, Decision-Centric Security, Security Governance, Regulatory Compliance, Board, CISO, Accountability

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green