Cover of Cyber Risk is Business Risk by Chris Thatcher

A Marque Publishing book

Cyber Risk is Business Risk

You can delegate the decision, but not the liability.

Three decades in cybersecurity, distilled into the decisions that actually matter — written for the executives and board members who have to make them. Not a technical manual. The book I wish I could hand to every leader I've ever advised.

Chris Thatcher

A note from Chris

Author · Cybersecurity advisor · 30 years in the field

I've been carrying this book around for at least fifteen years. Piles of notes, a thesis, a clear sense of what I wanted to say — and a life that kept getting in the way. What kept pulling me back was something I'd watched happen in room after room: smart people trying to explain an idea across a conference table, and failing. The words were accurate. The reasoning was sound. But the message never landed, because the person on the other side didn't speak the same language.

I've always been able to take something complicated and make it simple. In security, that turned out to be the whole game. I've sat through too many meetings where good people couldn't get through to the executives they were asking to fund the work — and watched the company pay for it later. This book is my answer to that.

"I don't want you to nod and push through the next briefing. I want you to stop and ask the right question."

So I didn't write it for technical people or security people. I wrote it for the C-suite and the boardroom — for the executive who has to make the call. The readers who've seen early chapters all say the same thing: it makes sense. They can cut through the noise and the jargon, ask the right questions, and get meaningful answers. I owe a lot of that to a bank president you'll meet in the introduction, who taught me what it really means to communicate with the person across the table. And I owe the nudge to a friend and mentor who told me, almost a year ago, that it was time to finally write it. He was right.

If you take one thing from these pages, I hope it's this: don't nod politely and move on to the next item on the agenda. Pause. Ask the right question. Demand the answer you actually need. If you're the person whose signature ends up on the risk, this book is for you — and I hope you buy a copy for everyone on your leadership team. Not because I want to sell books, but because clear conversations about the things that matter are worth it.

— Chris

Who it's for

If Your Signature Ends Up on the Risk

This isn't a book for the security team. It's for the people they answer to.

Board members

You approve the risk, but you didn't write the report. Learn to read past the jargon and ask the questions that surface what actually matters.

CEOs & the C-suite

You can delegate the decision, but not the liability. Understand cyber risk as the business risk it is — without becoming a technologist.

Newly promoted leaders

Suddenly responsible for decisions you were never trained to make? This is the plain-language briefing no one gave you.

"Chris Thatcher has created a timely and practical guide that every executive, board member, and security leader should have on their shelf. He reframes cybersecurity as a business discipline, translating complex cyber risk into language that executives can understand and act upon."
— Christopher Peters, CISSP, Senior Security Architect, Microsoft