top of page


IT Wants to Have a Talk With You About Cybersecurity — And You’re Not Going to Like It
Most organizations assume IT owns cybersecurity, but that assumption creates a cyber governance gap that exposes the business to real cyber risk. When IT is consumed by business process demands, security monitoring slips, alerts go ignored, and incidents escalate. This post explains why cybersecurity governance — not more tools — is the foundation for effective cyber risk management, and how leadership, IT, and cybersecurity can realign to build measurable resilience.

Hector R. Lopez
Dec 8, 20256 min read


A Working Definition of “Reasonable Security” in Cybersecurity
“Reasonable security” is not a checklist or a dollar figure — it is a governance-driven, scalable approach to cybersecurity. This blog defines it through due care (board and executive attention to risks) and due diligence (verification, monitoring, and documentation). Drawing on negligence law, regulatory enforcement, and compliance principles, it offers boards a roadmap to achieve defensibility, accountability, and proportional safeguards.

Hector R. Lopez
Oct 1, 20256 min read
bottom of page