---
title: "Management Buy-In - Part 1: Why You Need It"
description: Senior management support for information and cyber security strategy
image: https://www.securitycentric.com.au/hubfs/Stock%20images/Smiling%20handsome%20businessman%20with%20his%20team%20in%20a%20modern%20office.jpeg
---

[![logo (1)](https://www.securitycentric.com.au/hs-fs/hubfs/SecurityCentric_August2018/Images/logo%20(1).png?width=400&height=53&name=logo%20(1).png "logo (1)")](https://www.securitycentric.com.au)

[![Contact Us](https://hubspot-no-cache-ap1-prod.s3.amazonaws.com/cta/default/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05.png)](https://hubspot-cta-redirect-ap1-prod.s3.amazonaws.com/cta/redirect/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05)

**

** **

[![logo (1)](https://www.securitycentric.com.au/hs-fs/hubfs/SecurityCentric_August2018/Images/logo%20(1).png?width=423&height=56&name=logo%20(1).png "logo (1)")](https://www.securitycentric.com.au)

[![Contact Us](https://hubspot-no-cache-ap1-prod.s3.amazonaws.com/cta/default/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05.png)](https://hubspot-cta-redirect-ap1-prod.s3.amazonaws.com/cta/redirect/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05)

**

** **

Search

**Menu**

** **

[![Contact Us](https://hubspot-no-cache-ap1-prod.s3.amazonaws.com/cta/default/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05.png)](https://hubspot-cta-redirect-ap1-prod.s3.amazonaws.com/cta/redirect/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05)

[**Cyber Security News & Current Events](https://www.securitycentric.com.au/blog)

# Management Buy-In - Part 1: Why You Need It

by [Security Centric](https://www.securitycentric.com.au/blog/author/security-centric), on 10/12/2018 11:02:00 AM

Every information security framework and “best practice” guide to cyber security states that you need “management buy-in”, but why is it important and what does it look like?

![Management Support for Information Security](https://www.securitycentric.com.au/hs-fs/hubfs/Stock%20images/Smiling%20handsome%20businessman%20with%20his%20team%20in%20a%20modern%20office.jpeg?width=300&name=Smiling%20handsome%20businessman%20with%20his%20team%20in%20a%20modern%20office.jpeg)Management buy-in can be referred to by terms such as “top management support” or described as a need to allocate information security responsibilities to a senior member of management, such as a Chief Information Security Officer. Whichever way it is stated, the requirement means that those in the organisation that have strategic visibility over the entire organisation also have a say in the information security priorities.

The mostly important reason for management buy-in is to make sure the security program meets the business needs. Organisational goals can include such things as high availability of services, maintaining reputation, being agile or ensuring confidentiality. The information security program must work towards these business needs to provide value and justify its existence.

Secondly, organisational risks, including information security risks, are the responsibility of senior management. A good management team will need to understand the risks they are accepting so they are comfortable with their possible level of exposure. If management do no have buy-in, it is quite possible they do not understand their risks are so are “flying blind”.

At a more pragmatic level, resources are allocated by senior management. If a security program is not provided with sufficient staff, time and money then it will not be able to carry out its objectives and provide the level of protect required.

Now that we have established that management buy-in is important, how to do you tell how your organisation is faring? The following table shows some ways to identify if you currently have management buy-in. If you can relate to several of the statements in the left column, then you most likely do not have a sufficient level of management buy-in. 

 

| **Poor Management Buy-In** | **Good Management Buy-In** |
| --- | --- |
| Security requirements flow from technical staff and vendors up to management. | Security program driven by business goals which then flow detailed requirements down to implementors, service providers and vendors. |
| Lack of communication between management and those that design and implement the security measures. | Regular communication between management and other levels in the organisation to ensure risks and activities are understood. |
| Staff do not understand their role in providing and supporting information security. | Information security roles and responsibilities defined, and appropriate training is provided. |
| Fragmented security program with poorly understood links between activities. | Holistic security program with all projects working towards a single security vision. |
| Poorly resourced or prioritised security activities, compromising the effectiveness of security measures. | Resources allocated according to priority and justified in terms of the business risk they address |
| Poor morale amongst security staff and a belief that management does not care. | Security staff understand how they are contributing to the success of the organisation. |

Topics:[Fundamentals](https://www.securitycentric.com.au/blog/topic/fundamentals)

## Comments

### Finally, an actionable blog

The purpose of this blog is to make available the real-world lessons, experience, observations and mistakes that are part of the daily life of a group of cyber security professionals.

Read about:

- What mistakes organisations are making (anonymously of course!)
- What effective actions are available to quickly and economically achieve effective protection (without buying new kit)
- Trends we're seeing, via our incident response and forensic investigation capabilities
- And sometimes, just frustrations about what is wrong with cyber :|

- [Recent](https://www.securitycentric.com.au/blog/management-buy-in-part-1-why-you-need-it#recent)
- [Topics](https://www.securitycentric.com.au/blog/management-buy-in-part-1-why-you-need-it#topics)
- [Archive](https://www.securitycentric.com.au/blog/management-buy-in-part-1-why-you-need-it#archive)

- [Authentication (6)](https://www.securitycentric.com.au/blog/tag/authentication)
- [Cloud Security (1)](https://www.securitycentric.com.au/blog/tag/cloud-security)
- [Compliance (11)](https://www.securitycentric.com.au/blog/tag/compliance)
- [Compromise (2)](https://www.securitycentric.com.au/blog/tag/compromise)
- [data breach (3)](https://www.securitycentric.com.au/blog/tag/data-breach)
- [Essential Eight (1)](https://www.securitycentric.com.au/blog/tag/essential-eight)
- [featured (2)](https://www.securitycentric.com.au/blog/tag/featured)
- [Fundamentals (13)](https://www.securitycentric.com.au/blog/tag/fundamentals)
- [Governance (7)](https://www.securitycentric.com.au/blog/tag/governance)
- [Insider (4)](https://www.securitycentric.com.au/blog/tag/insider)
- [IRAP / ISM (1)](https://www.securitycentric.com.au/blog/tag/irap-ism)
- [managed security services (1)](https://www.securitycentric.com.au/blog/tag/managed-security-services)
- [Managed Services (2)](https://www.securitycentric.com.au/blog/tag/managed-services)
- [Penetration Test (3)](https://www.securitycentric.com.au/blog/tag/penetration-test)
- [Pentesting (5)](https://www.securitycentric.com.au/blog/tag/pentesting)
- [Phishing (6)](https://www.securitycentric.com.au/blog/tag/phishing)
- [Ransomware (5)](https://www.securitycentric.com.au/blog/tag/ransomware)
- [Red Teaming (4)](https://www.securitycentric.com.au/blog/tag/red-teaming)
- [regulations (4)](https://www.securitycentric.com.au/blog/tag/regulations)
- [Report Roundup (4)](https://www.securitycentric.com.au/blog/tag/report-roundup)
- [Risk Assessment (15)](https://www.securitycentric.com.au/blog/tag/risk-assessment)
- [risk profile (3)](https://www.securitycentric.com.au/blog/tag/risk-profile)
- [Secure Remote Work (2)](https://www.securitycentric.com.au/blog/tag/secure-remote-work)
- [Security Centric (1)](https://www.securitycentric.com.au/blog/tag/security-centric)
- [Threat Advisory (4)](https://www.securitycentric.com.au/blog/tag/threat-advisory)
- [Verizon DBIR (1)](https://www.securitycentric.com.au/blog/tag/verizon-dbir)

[More...](https://www.securitycentric.com.au/blog/management-buy-in-part-1-why-you-need-it#)

- [November 2018 (4)](https://www.securitycentric.com.au/blog/archive/2018/11)
- [December 2018 (4)](https://www.securitycentric.com.au/blog/archive/2018/12)
- [April 2019 (4)](https://www.securitycentric.com.au/blog/archive/2019/04)
- [December 2021 (4)](https://www.securitycentric.com.au/blog/archive/2021/12)
- [February 2025 (4)](https://www.securitycentric.com.au/blog/archive/2025/02)
- [January 2022 (3)](https://www.securitycentric.com.au/blog/archive/2022/01)
- [May 2015 (2)](https://www.securitycentric.com.au/blog/archive/2015/05)
- [December 2020 (2)](https://www.securitycentric.com.au/blog/archive/2020/12)
- [June 2021 (2)](https://www.securitycentric.com.au/blog/archive/2021/06)
- [March 2022 (2)](https://www.securitycentric.com.au/blog/archive/2022/03)
- [April 2014 (1)](https://www.securitycentric.com.au/blog/archive/2014/04)
- [February 2016 (1)](https://www.securitycentric.com.au/blog/archive/2016/02)
- [November 2016 (1)](https://www.securitycentric.com.au/blog/archive/2016/11)
- [May 2017 (1)](https://www.securitycentric.com.au/blog/archive/2017/05)
- [September 2017 (1)](https://www.securitycentric.com.au/blog/archive/2017/09)
- [February 2018 (1)](https://www.securitycentric.com.au/blog/archive/2018/02)
- [May 2018 (1)](https://www.securitycentric.com.au/blog/archive/2018/05)
- [October 2018 (1)](https://www.securitycentric.com.au/blog/archive/2018/10)
- [March 2019 (1)](https://www.securitycentric.com.au/blog/archive/2019/03)
- [May 2019 (1)](https://www.securitycentric.com.au/blog/archive/2019/05)
- [June 2019 (1)](https://www.securitycentric.com.au/blog/archive/2019/06)
- [March 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/03)
- [April 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/04)
- [May 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/05)
- [July 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/07)
- [September 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/09)
- [November 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/11)
- [February 2021 (1)](https://www.securitycentric.com.au/blog/archive/2021/02)
- [August 2021 (1)](https://www.securitycentric.com.au/blog/archive/2021/08)
- [September 2021 (1)](https://www.securitycentric.com.au/blog/archive/2021/09)
- [February 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/02)
- [April 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/04)
- [June 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/06)
- [September 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/09)
- [November 2023 (1)](https://www.securitycentric.com.au/blog/archive/2023/11)
- [May 2024 (1)](https://www.securitycentric.com.au/blog/archive/2024/05)
- [June 2024 (1)](https://www.securitycentric.com.au/blog/archive/2024/06)
- [November 2024 (1)](https://www.securitycentric.com.au/blog/archive/2024/11)

[More...](https://www.securitycentric.com.au/blog/management-buy-in-part-1-why-you-need-it#)

### Subscribe to Updates

### Security Centric

Level 34, 201 Elizabeth St  
Sydney, NSW 2000  
Call us: [+61 2 9199 0000](tel:61291990000)  
[tel:800-000-0000](tel:800-000-0000)

<https://www.facebook.com/472832472726921><https://www.instagram.com/securitycentric><https://www.linkedin.com/company/3254708><https://twitter.com/SecurityCentric>

### Contact Us

Copyright © 2020 Security Centric. All Rights Reserved.

![](https://dc.ads.linkedin.com/collect/?pid=469476&fmt=gif)