The Leadership Lessons Cybersecurity Teaches Better Than Any MBA
David Jemmett, Chief Executive Officer

“Business schools teach leaders how to evaluate markets, allocate resources, manage teams, and make strategic decisions. Cybersecurity tests those skills in real time.“
Key Takeaways
- Leaders often must act before they know all the facts.
- A response plan only works if the team has tested it.
- Clear communication keeps people aligned during a crisis.
- Cyber risk remains an executive responsibility.
- Resilient organizations use incidents and exercises to make better decisions.
Business schools teach leaders how to evaluate markets, allocate resources, manage teams, and make strategic decisions. Cybersecurity tests those skills in real time.
A serious incident rarely comes with a complete briefing. Facts change quickly, the cost of delay grows, and employees, customers, partners, regulators, and investors expect answers. Leaders have to decide what matters most before they know everything.
After years in cybersecurity, I see incident response as one of the clearest tests of leadership.
1. Decisions Cannot Wait for Perfect Information
Executives learn to gather data before making a decision. In most business situations, that is sound practice. During a cyber incident, however, waiting for complete certainty can give the threat more time to spread.
Early reports may conflict or leave important questions unanswered. Leaders may not know which systems the attacker reached, whether data left the environment, how long the intrusion lasted, or when operations can safely resume. Even so, they still have to act.
Leaders may need to decide whether to take systems offline, when to notify customers, and which business functions to restore first. They also must determine when to involve outside experts, legal counsel, insurers, or law enforcement.
The real challenge is knowing when limited information is enough to act. Leaders need clear triggers for action and must be ready to adjust as new facts emerge.
Market disruptions, supply chain failures, regulatory changes, and reputational crises create the same problem. In each case, the business may need to act before the full picture is clear.
2. Preparation Matters More Than Confidence
Many organizations believe they are prepared because they have experienced employees, documented procedures, or reliable technology. Those resources matter, but they do not show how the team will perform under pressure.
An incident quickly shows whether the team knows how to use the plan.
Employees may not know who can authorize a system shutdown. Executives may disagree about customer notifications, while vendor contacts could be outdated. The company might also have backups without knowing how long a full restoration will take.
Preparation means resolving these questions before the organization is in crisis.
Testing often exposes assumptions no one noticed during planning. Exercises and candid reviews give the team time to address those weaknesses before a real incident. Testing shows whether the plan will actually work under pressure.
3. Clear Communication Keeps the Response Moving
Technical teams do not manage cyber incidents alone. Responding to one also involves legal, finance, operations, communications, human resources, executive leadership, and often the board.
Each group enters the response with different priorities. Technical teams focus on containment and investigation, while legal counsel considers regulatory and contractual obligations. Finance evaluates interruption and recovery costs, and communications prepares for questions from employees, customers, and the public.
Leadership has to keep those teams working from the same facts and priorities. People need to know what the response team has confirmed, what it is still investigating, who owns each decision, and when to expect the next update.
Leaders should not claim certainty before the evidence supports it. Clear updates protect credibility and keep the organization aligned as the situation changes.
4. Executives Still Own Cyber Risk
Many companies treat cybersecurity as a technical function until an incident affects revenue, operations, customer relationships, or the company’s reputation. The incident reveals that those security choices were business decisions all along.
Security teams can explain vulnerabilities, recommend controls, and respond to threats. They cannot determine the organization’s risk tolerance on behalf of executive leadership.
Executives must decide how much disruption is acceptable, which operations to restore first, which investments take priority, and how much risk the organization is willing to retain.
Leaders do not need to become cybersecurity specialists, but they should understand the organization’s most important systems, data, dependencies, and areas of risk. They should also know what could interrupt the business and how the company plans to respond.
Leaders can delegate the work, but they still own the risk that requires approval.
5. Resilience Depends on What You Learn Afterward
Even well-protected organizations can experience a security incident. Since no company can prevent every attack, resilience depends on making the business harder to disrupt and better able to recover.
After an incident, exercise, or near miss, leaders should examine what slowed the response, which assumptions failed, and where communication broke down. They should also identify systems or vendors that created unexpected dependencies and decide what must change before the next event.
The review may expose uncomfortable gaps in planning, technology, and leadership. Ignoring them leaves the same weaknesses in place.
Once systems return to normal, leaders should turn the findings into revised plans, clearer roles, and specific changes to technology and operations.
Final Thoughts
Cybersecurity tests leaders when facts are changing, time is limited, and their decisions can affect operations, customers, and the company’s reputation.
An MBA can provide valuable frameworks for managing a business. Cybersecurity shows whether a leader can apply them when the situation is unclear and the consequences are immediate. That judgment matters just as much when the next disruption has nothing to do with cybersecurity.
CISO Global helps leadership teams test response plans, clarify decision-making roles, and prepare for the business impact of a cyber incident. Talk with our team about incident response planning and tabletop exercises.