Is the CISO spending too much time selling the importance of security vs identifying & reducing risk