As cybersecurity leaders face growing pressure to reduce risk while proving business value, the role of the CISO is increasingly defined by the ability to connect security decisions to measurable outcomes. Kristin Lowery, Field Chief Information Security Officer at Optiv, brings extensive experience leading information technology and cybersecurity initiatives across Fortune 500 enterprises. Her background spans cybersecurity controls, cloud computing, vulnerability management, data protection, governance, business continuity, and large-scale technology transformations, with a focus on helping organizations reduce threats while supporting resilience and sustainable growth.
Throughout her career, Lowery has worked closely with senior executives and cross-functional teams to develop security strategies, strengthen governance, improve operational efficiency, and align technology investments with business priorities. In this edition of CISO Tips, she shares a practical perspective on making security programs more effective, from evaluating the real problem before buying another tool and cutting unnecessary complexity to translating technical vulnerabilities into business exposure and establishing clear decision ownership during an incident. Her advice centers on a simple principle: security teams should focus less on activity for its own sake and more on measurable risk reduction, business impact, and the resilience to keep moving forward.
Complete this sentence: “Before you buy any new security tool, first...”
Before you buy any new security tool, first get clear on the problem you’re trying to solve. Too often, teams add technology before confirming whether they already own a tool that can do the job—or whether the real issue is process, ownership, or adoption. I also think it’s important to regularly review your existing technology footprint, because many organizations are not getting full value from the solutions they already have. One recent conversation that stuck with me was with a CISO who asked his team to review their top tools and validate actual usage, especially as new AI capabilities continue to emerge.
What’s one rule you enforce on your team that other teams would find strict?
If we can’t connect a recommendation to risk reduction or a business outcome, we need to rethink it. Security teams can generate a lot of activity, but activity is not the same as progress. To me, progress means measurable operational risk reduction or an increase in business capability.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
I pay close attention to the balance between effort and actual risk reduction. If something takes significant time, creates operational drag, and does not meaningfully reduce risk, that is usually a signal to simplify it. I also believe key performance indicators and risk appetite should be reviewed at least annually so they remain relevant and useful.
What’s one line that works when asking the board or CFO for a budget?
“This is not about buying another security tool. It is about reducing the likelihood and impact of an event that could disrupt the business, affect customers, or slow recovery.” CFOs and other leaders do not want to hear about the latest shiny tool. They want to understand impact, value, and how the investment fits into the broader environment.
What should a CISO cut from their program tomorrow with zero regret?
I would cut anything that creates noise without improving decision-making. That might include duplicate tools, reports no one uses, or processes people follow simply because “we’ve always done it that way.”
What’s your 60-second test for whether a vendor pitch is worth your time?
I want to quickly understand what risk they reduce, where they fit in the environment, what problem they solve better than what I already have, and how I would know the solution is working. If they can’t explain that clearly, it’s probably not the right conversation.
What’s one meeting, report, or process you eliminated, and what replaced it?
I’m a big believer in replacing status-for-status-sake meetings with decision-focused conversations. Instead of walking through dashboards, I’d rather ask: What changed? What matters? What decision do we need? Who owns the next step? I’m also comfortable canceling meetings that are no longer needed or ending them early. Staying connected with leaders and teams matters, but the agenda should support that purpose.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
Teams understandably jump into technical triage, but they often skip defining business impact and decision ownership. Early on, someone needs to clarify what is affected, who needs to know, and who is empowered to make decisions.
What’s one question every CISO should ask their team this week?
“Where are we making security harder than it needs to be?” That question usually opens an honest conversation about complexity, ownership, and whether our controls are working the way we think they are.
What’s a phrase or framing you use to translate a technical risk for executives?
I try to shift the conversation from “technical vulnerability” to “business exposure.” For example: “This is not just a system issue; it could affect operations, customer trust, recovery time, or our ability to meet business commitments.”
What’s your best tip for surviving the CISO role in exactly five words?
Stay curious, practical, and resilient. Keep moving forward—don’t spend too much time looking backward, because that’s not where you’re going.
More tips from the series:


