Master the 3 Levels of Risk Decision-Making
Download resourcesAbout this session
Nathan Wenzler, Chief Security Strategist at Tenable and a 25-year security leadership veteran, argues that security teams struggle not with technology but with communication, and offers a three-level framework for tailoring risk conversations to executive, strategic and tactical audiences. At the executive level he recommends simple stoplight or letter-grade indicators instead of volume-based metrics, illustrated by a story where a 34 percent vulnerability reduction was dismissed by general counsel as an incomplete job. At the strategic level he advocates hunting for positive and negative outliers, using a real example where one country's patch team beat every service-level target through a self-built automation script later rolled out globally, cutting non-compliant countries from thirty-six to one. At the tactical level he reframes technical pushback as a human trust problem: engineers resist because they feel their work goes uncredited, and empathy plus anonymized, gamified metrics rebuild buy-in. He closes with a live dashboard demo tying technical asset risk to a dollar figure the CFO cares about, and an audience question and answer on CISO reporting lines and dashboard freshness.
Key takeaways
- Match your metric to the audience: stoplight colors or letter grades for the C-suite and board, trend and prioritization views at the strategic level, individual scores for tactical teams.
- Never lead a board or executive conversation with volume-based metrics (raw vulnerability counts); ask your executives directly what format helps them decide fastest.
- Actively hunt for positive outliers, not just failing ones; when one team or region wildly outperforms its peers, investigate why and replicate the practice.
- Anonymize and gamify tactical-level metrics rather than publicly shaming underperforming admins; public blame kills the cooperation you need to fix root causes.
- Translate technical risk into a dollar figure tied to a business asset (e.g. revenue-per-month of a website) so the CFO and board immediately understand the stakes of underinvestment.


