Wil Klusovsky

Wil Klusovsky

LinkedIn

@wilklu

Shared posts
2
Last activity
1 month ago
Media
2 media

Author posts

tgroenwals shared this post · Aug 19
Wil Klusovsky

Most cyber risk isn’t accepted.
It’s inherited by assumption.

Shadow IT was only the beginning….now the shadows are everywhere.

Used to be someone used an unapproved tool.

Someone spun up a system nobody knew about.

Now it’s bigger.

→ Shadow AI
→ Shadow data
→ Shadow cloud
→ Shadow access
→ Shadow procurement
→ Shadow risk acceptance
→ Shadow automation / APIs

And here’s what leadership needs to understand:

Most shadow activity doesn’t happen because people are trying to create risk.

It happens because the business is trying to move.

A team needs a tool now.

Jason Vanzin Shadow activity is often a signal that governance is not keeping pace with how work gets done.

The fix is not tighter policy alone. It is faster intake, clearer ownership, and approved paths people will actually use.
Holly Moe When controls lag behind how teams actually work, people naturally find faster routes. Better governance makes the safe path practical by embedding security into everyday workflows rather than adding friction after the fact. Wil Klusovsky
tgroenwals shared this post · Aug 13
Wil Klusovsky

The board does not need more cyber detail
It needs business clarity.

Not because leaders don’t care about security…because they’re hearing it in the wrong language.

Security talks about controls.
Finance talks about exposure.
Operations talks about downtime.
The CEO talks about business risk.

Too many cyber plans stay inside the security function.

The result: security speaks in tools and vulnerabilities while the business is thinking about margin, continuity and growth.

That gap slows decisions.

🧙🏼‍♂️ CROWN gives leadership teams a shared lens for cyber planning.

Kurt Zimmerman The translation piece is critical. Leadership doesn’t need every technical detail, but they do need to understand what a cyber decision means for continuity, cost, and the ability to operate. That’s where the conversation becomes actionable.
Kalana (Kal) Maldeniya This is where cyber maturity becomes less about the number of controls and more about decision quality. The board doesn't need to understand every vulnerability. It needs to understand the exposure it is accepting.