HomeSecurity, Governance, & Risk

CISOs Work The Risk Register Faster When Business Impact Sets The Order

August 31, 2026

Masato Yamanishi, Owner of Liaison Works and former global CISO at Olympus, on why business impact should decide the order of the risk register before cost enters.

CISOs Work The Risk Register Faster When Business Impact Sets The Order
Credit: CIOnews

Get the latest from CIOnews.

Enterprise AI, governance, risk, and leadership insights for CIOs, CTOs, CISOs, and technology leaders.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
"Governance is making sure security initiatives are creating actual business impact."

Masato Yamanishi

Owner, Liaison Works
@
ex-CISO Olympus

Most enterprise security teams can produce a long list of risks. The harder part is putting that list in order. Someone has to say which risk would cost the business the most money, and someone outside the security team has to be accountable for reducing it. Public companies in Japan and other markets already publish risk management information for investors, so the analysis often exists somewhere in the company. It rarely reaches the meetings where budgets get set. Almost every company already has more identified risks than it can address, and AI tools keep adding to the count.

Masato Yamanishi is the Owner of Liaison Works, a Japanese advisory practice that mentors sitting and incoming CISOs and helps executive teams build out their security function. He spent close to five years at Olympus, most recently as SVP and Global CISO, where he helped build the company's security governance organization. Before that he held information security leadership roles at Nissan Motor Corporation and Santen Pharmaceutical, including a period running global infrastructure and security from the United States. He sorts that list with a single test.

"Governance is making sure security initiatives are creating actual business impact," Yamanishi said. So every policy, control, and security platform has to answer one question. What did it change for the business? That question gets hard to answer when a security leader is in a budget review explaining why one initiative got funded and another didn't.

  • Filed for investors only: Security programs get judged by what they've installed. Control counts and policy coverage look good in a board deck and they're easy to compare against last year. Risk registers get treated the same way. The corporate governance code requires one, so companies build it, review it, and refresh it on a schedule. The audience is investors. "Risk management is a very powerful tool to prioritize and to measure the actual business impact of security initiatives," Yamanishi noted. That register has everything a CISO needs to decide what to fund next. The version written for investors just answers a different question.

  • Cost comes second: When teams do rank their risks, price tends to creep into the decision. A risk with a cheap, obvious fix moves up the list. A risk with an expensive fix, or no clear fix at all, slides down, even when it threatens more of the business. Yamanishi keeps those two decisions apart. "Risk priorities should be decided only from business impact," he added. Rank the risks first, then work out what each one costs to reduce. A CISO can put a price next to every item, show the business how much risk each one buys down, and let the company decide how much it's willing to live with. Teams that price first end up with a list of what was cheap to fix.

That leaves the question of what to do about the risk at the top. AI is good at breadth. It can gather what hundreds of companies have done about a given class of risk and lay out the options in minutes, work that takes a single team weeks. Yamanishi puts it to work at that point in the process. The ranking itself has to come from people. A supply chain outage means one thing to a hospital and something else to a retailer, so the number that sets the order depends on knowing the business.

  • Shadow decision making: At most large companies, AI handles operational work while decisions stay with people. That's the official picture. Individuals ask AI for help while working up a recommendation, then bring the recommendation to the meeting without mentioning it. "People never say that the decision was suggested or recommended by AI," Yamanishi said. Leaders still want proof that a model's answer holds up for their own company. And there's nowhere in the approval process to write down that AI helped. So nobody says it.

  • Explaining the recommendation: Accountability doesn't transfer to a model. Whoever signs off on a control investment still has to justify it to a board, an auditor, or a regulator, and where the idea came from doesn't change that. "The accountable person should be able to explain why the AI proposal is appropriate," Yamanishi noted. Pointing at the tool isn't an explanation. The same goes for the ranking. A CISO who puts one risk above another has to be ready to say why.

A risk only gets fixed if someone with budget agrees to pay for it, and that person usually doesn't work in security. "If only the CIO or CISO is the risk owner, it's very difficult to mitigate that risk because the business side has different priorities," Yamanishi said. Say a vulnerability in a plant's control systems could halt production for a week. That belongs to the manufacturing head, not the CISO, because the manufacturing head is the one who loses a week of output. Working out what the week costs is what turns it into their problem. It becomes one more threat to production, sitting alongside equipment failure and supply delays, and it competes for their budget on the same terms.

  • Priorities that travel down: A risk owner at the top doesn't help much if the people doing the work don't know what they're working toward. A manager assigns a task using words from the risk register, the engineer hears something slightly different, and the work drifts. Most governance programs stop at the executive layer. Yamanishi takes it further down. "Even members need to understand what is listed as the top five or top 10 risks in their company," he added. A team that knows which risk it's reducing can check itself at every milestone by asking whether the work is moving that risk.

A security team can spend a year in meetings about tools and controls and still leave the same risks unfunded. What changes that is how people talk about the work. "Everybody should talk about business impact rather than technical matters. If everybody in the organization talks about business impact, that's a very capable governance organization and a very capable security organization," Yamanishi said.

research report

From the Edge to the Core:
Bringing Agentic AI to the Heart of the Enterprise.