---
title: How CISOs Can Make Security Matter to the Business
description: Explore how Malaysia’s CISOs are shifting from reactive defenders to strategic leaders as threats rise and the Cyber Security Act 2024 reshapes expectations.
image: https://www.coriniumintelligence.com/hubfs/Featured%20Images%20(2)-1.jpg
---

[Skip to content](https://www.coriniumintelligence.com/content/how-cisos-can-make-security-matter-to-the-business#main-content)

[![Corinium](https://www.coriniumintelligence.com/hs-fs/hubfs/Corinium%20logo%20+%20branding/Corinium-logo_horizontal_reversed.png?width=646&height=196&name=Corinium-logo_horizontal_reversed.png "Corinium")](https://www.coriniumintelligence.com/)

- [Home](https://www.coriniumintelligence.com/content)
- [About](https://www.coriniumintelligence.com/aboutus)
  
  Show submenu for About 
  
    - [Services](https://www.coriniumintelligence.com/content/services)
- [Events](https://www.coriniumintelligence.com/events-calendar)
- [Data Insights](https://www.coriniumintelligence.com/content/tag/data)
- [InfoSec Insights](https://www.coriniumintelligence.com/content/tag/infosec)
- [AssetOps](https://www.coriniumintelligence.com/assetops)
- [Subscribe](https://www.coriniumintelligence.com/content/subscribe)
- [More](https://www.coriniumintelligence.com/content/how-cisos-can-make-security-matter-to-the-business#)
  
  Show submenu for More 
  
    - [Articles](https://www.coriniumintelligence.com/content/tag/articles)
    - [Videos](https://www.coriniumintelligence.com/content/tag/videos)
    - [Podcast](https://www.coriniumintelligence.com/content/tag/podcast)
    - [Reports](https://www.coriniumintelligence.com/content/tag/reports)

- [Home](https://www.coriniumintelligence.com/content)
- [About](https://www.coriniumintelligence.com/aboutus)
  
  Show submenu for About 
  
    - [Services](https://www.coriniumintelligence.com/content/services)
- [Events](https://www.coriniumintelligence.com/events-calendar)
- [Data Insights](https://www.coriniumintelligence.com/content/tag/data)
- [InfoSec Insights](https://www.coriniumintelligence.com/content/tag/infosec)
- [AssetOps](https://www.coriniumintelligence.com/assetops)
- [Subscribe](https://www.coriniumintelligence.com/content/subscribe)
- [More](https://www.coriniumintelligence.com/content/how-cisos-can-make-security-matter-to-the-business#)
  
  Show submenu for More 
  
    - [Articles](https://www.coriniumintelligence.com/content/tag/articles)
    - [Videos](https://www.coriniumintelligence.com/content/tag/videos)
    - [Podcast](https://www.coriniumintelligence.com/content/tag/podcast)
    - [Reports](https://www.coriniumintelligence.com/content/tag/reports)

#### Search:

 23 Jan, 2026

[Articles](https://www.coriniumintelligence.com/content/tag/articles)

# How CISOs Can Make Security Matter to the Business

![](https://www.coriniumintelligence.com/hubfs/Featured%20Images%20(2)-1.jpg)

*For today’s CISOs, security only works when it is embedded into how the business operates. Ahead of CISO Financial Services this February, Ellis Wong, Chief Information Security Officer at JST Capital, explains why culture, revenue-aligned risk metrics, and identity-first architecture are the foundations of effective security leadership.*

 

For many organizations, cybersecurity is still viewed as a technical function rather than a business capability. But that thinking should be consigned to the past. According to Ellis Wong, Chief Information Security Officer at JST Capital.

For Wong, security culture has little to do with awareness posters or one-off initiatives. Instead, he defines culture as repeatable behaviors that persist regardless of organizational or technology change.

That starts at the top.

Wong emphasizes the importance of leadership signals, what executives measure, model, and prioritize. In practice, this means reporting security performance alongside business outcomes such as revenue, using the same cadence and visibility.

“Culture starts with what executives measure and model,” Wong explains. “Security has to sit next to revenue, not behind it.”

At JST Capital, this approach is reinforced through regular executive engagement, including annual tabletop exercises that simulate real-world attack scenarios. By involving senior leaders directly, security becomes a shared responsibility and a shared goal.

**Designing security that people will actually use  
**

Strong culture, however, cannot exist without practical implementation of security initiatives. Wong stresses that security controls must be frictionless if they are to be adopted consistently across the business.

Zero trust frameworks, multi-factor authentication, and single sign-on only work when they are intuitive. When security tools feel seamless, users stop seeing them as obstacles and start trusting them as part of how work gets done.

This mindset shifts security from enforcement to enablement, making good security behavior the default rather than the exception.

 

[![1443-26 - CISO FS NY - Agenda Headers](https://www.coriniumintelligence.com/hs-fs/hubfs/1443-26%20-%20CISO%20FS%20NY%20-%20Agenda%20Headers.png?width=1000&name=1443-26%20-%20CISO%20FS%20NY%20-%20Agenda%20Headers.png "1443-26 - CISO FS NY - Agenda Headers")](https://ciso-fs.coriniumintelligence.com/)

 

**Translating cyber risk into business impact**

One of the most persistent challenges for CISOs is demonstrating value to non-technical executives. Wong argues that traditional cyber metrics often fail because they do not connect clearly to business priorities.

Instead, he focuses on translating cyber risk into financial terms that leaders already understand. One example is what he calls “risk to revenue at risk,” a way of mapping security exposure directly to forecasted revenue.

By tying risk tolerance thresholds and critical vulnerabilities to potential revenue impact over the next quarter or year, security conversations become grounded in business reality.

“If you can translate cyber risk into revenue at risk,” Wong says, “the conversation with leadership completely changes.”

**The investment Wong would make earlier**

Looking back on his journey, Wong is clear about what he would do differently. He would invest earlier in an identity-first, zero trust architecture.  
Rather than deploying authentication, device trust, and access controls in isolation, Wong now advocates for a unified approach, bringing together identity, authorization, secrets management, and just-in-time access within a centralized framework.  
“I wish I had invested in an identity-first architecture from day one,” he reflects. “Integrating later is always more expensive.”  
The lesson is not about buying a specific product, but about designing for coherence and scalability from the outset.

Why CISOs need strong peer communities

For Wong, leadership development does not happen in isolation. Industry forums play a critical role in helping CISOs benchmark their thinking, pressure-test assumptions, and learn from peers who are navigating similar challenges.

That is why he sees events like CISO Financial Services as an opportunity not just to network, but to exchange practical lessons that can accelerate maturity across the industry. Open discussion, particularly around what did not work, helps security leaders avoid repeating costly mistakes.

As he puts it, when CISOs contribute openly, everyone benefits.

 

---

Join us at [CISO Financial Services 2026](https://ciso-fs.coriniumintelligence.com/) to learn more about the latest challenges and developments for infosec executives the US. 

 

 

## Related Posts

[![](https://www.coriniumintelligence.com/hs-fs/hubfs/Malaysia.png?width=352&name=Malaysia.png) ](https://www.coriniumintelligence.com/content/embracing-digital-transformation-amidst-shifting-threats-in-malaysia)

### [Embracing Digital Transformation Amidst Shifting Threats in Malaysia](https://www.coriniumintelligence.com/content/embracing-digital-transformation-amidst-shifting-threats-in-malaysia)

 Cybersecurity Malaysia CEO discusses the evolving global threat landscape and how companies in...

[![](https://www.coriniumintelligence.com/hs-fs/hubfs/Malaysias%20Act%20854.png?width=352&name=Malaysias%20Act%20854.png) ](https://www.coriniumintelligence.com/content/malaysias-act-854-what-it-means-for-cybersecurity-leaders-in-the-country-and-beyond)

### [Malaysia's Act 854: What It Means for Cybersecurity Leaders in the Country and Beyond](https://www.coriniumintelligence.com/content/malaysias-act-854-what-it-means-for-cybersecurity-leaders-in-the-country-and-beyond)

 The gazetting of Cyber Security Act 2024 on 26 June 2024 by Attorney General's Chambers marks a...

[![](https://www.coriniumintelligence.com/hs-fs/hubfs/From%20Firefighting%20to%20Foresight.png?width=352&name=From%20Firefighting%20to%20Foresight.png) ](https://www.coriniumintelligence.com/content/malaysias-cisos-are-stepping-into-a-new-era-of-strategic-cyber-leadership)

### [From Firefighting to Foresight: Why Malaysia’s CISOs Are Stepping into a New Era of Strategic Cyber Leadership](https://www.coriniumintelligence.com/content/malaysias-cisos-are-stepping-into-a-new-era-of-strategic-cyber-leadership)

 Malaysia’s cybersecurity landscape is entering one of its most transformative periods yet. With...

[![Corinium-logo_horizontal_reversed](https://www.coriniumintelligence.com/hs-fs/hubfs/Corinium%20logo%20+%20branding/Corinium-logo_horizontal_reversed.png?width=646&height=196&name=Corinium-logo_horizontal_reversed.png "Corinium-logo_horizontal_reversed")](https://www.coriniumintelligence.com)

Corinium Global Intelligence  
20-22 Wenlock Road, London, N1 7GU  
0203 432 2335

#### Our Recent Posts

- [About Us](https://www.coriniumintelligence.com/aboutus)
- [Subscribe](https://www.coriniumintelligence.com/content/subscribe)
- [Privacy Policy](https://www.coriniumintelligence.com/privacy-policy)

#### Follow Us

[Follow us on LinkedIn ](https://www.linkedin.com/showcase/corinium-data-%26-analytics/?isFollowingPage=true) [Follow us on Facebook ](https://www.facebook.com/coriniumglobal/) [Follow us on Twitter ](https://twitter.com/coriniumglobal) [Follow us on YouTube ](https://www.youtube.com/channel/UCnuGiXMWAH5bhfXOfWkPIuw) [Follow us on Facebook ](https://open.spotify.com/show/4op8cNfQRNrZMP5i79Aze9) [Follow us on Facebook ](https://podcasts.apple.com/gb/podcast/the-business-of-data-podcast/id1528796448) 

![](https://px.ads.linkedin.com/collect/?pid=182706&fmt=gif) ![](https://px.ads.linkedin.com/collect/?pid=306561&fmt=gif) ![](https://px.ads.linkedin.com/collect/?pid=60306&fmt=gif) ![](https://px.ads.linkedin.com/collect/?pid=1749329&fmt=gif) ![](https://px.ads.linkedin.com/collect/?pid=5553244&fmt=gif) ![](https://px.ads.linkedin.com/collect/?pid=5583316&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Eleen Meleng",
    "url" : "https://www.coriniumintelligence.com/content/author/eleen-meleng"
  },
  "dateModified" : "2026-01-26T14:06:01.717Z",
  "datePublished" : "2026-01-23T17:18:28.000Z",
  "headline" : "How CISOs Can Make Security Matter to the Business",
  "image" : [ "https://www.coriniumintelligence.com/hubfs/Featured%20Images%20(2)-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.coriniumintelligence.com/content/how-cisos-can-make-security-matter-to-the-business",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.coriniumintelligence.com/hubfs/Corinium-logo_+tagline_horizontal_web-header.png"
    },
    "name" : "Corinium Global Intelligence Limited"
  }
}
```