Governance should distinguish advice from approval

Security advising that something is risky is not the same as security refusing it.

Conflating them makes the security team a bottleneck and, more damagingly, makes them accountable for business decisions they do not own. Being clear about which conversations are advisory and which require an approval, and from whom, is what stops "security said no" becoming the explanation for everything.

More on Governance and risk