Why national security must become a business priority


This article has been reviewed by a Digital Journal editor and may be licensed for reuse.

For Mitch Lawrence, founder of Lawrence Solutions, the conversation about classified security should begin with a business question: What does security mean for the organization’s ability to perform its mission?

A 2026 Government Accountability Office (GAO) review found that the Defense Counterintelligence and Security Agency (DCSA), which oversees the Department of Defense’s portion of the National Industrial Security Program, conducts less than 40% of the security reviews required at contractor facilities. GAO said the shortfall puts classified information at risk.

GAO also reported that in fiscal year 2025, DCSA conducted more than 4,600 security reviews, documented more than 800 security violations, and identified more than 1,000 open security vulnerabilities associated with cleared contractor facilities. The report also found that DCSA relied on more than 470 industrial security mission personnel and spent more than $160 million on its industrial security mission that fiscal year.

Lawrence believes those figures illustrate why security leaders should be able to explain security issues in terms that senior executives can use when making business decisions.

He argues that security leaders need to understand the organizations they protect, including their products, customers, contracts and operational pressures. Lawrence says his own career has included work with intelligence agencies and industry, including corporate security leadership roles. 

“Security professionals kind of hide in their castle,” Lawrence says. “They don’t think they have to know the business that hired them. Whether the organization builds aircraft, manufactures equipment, or develops technology, security leaders need to understand its products, customers, contracts, and operational pressures. They also need to learn the language used by the rest of the executive team.”

Lawrence notes that understanding should influence how security teams measure and report their work. In his view, a metric such as the number of visitors processed or credentials issued may demonstrate activity, but it does not necessarily tell an executive what that activity means for the organization.

“You have to answer the common question: ‘What’s in it for me?’” Lawrence says. “You have to extrapolate how those numbers mean something to the CEO, the COO, or the EVPs, and translate it.”

A 2026 NIST quick-start guide addresses communication about cybersecurity risks and workforce decisions at both the organizational and enterprise levels. NIST says that, at the enterprise level, senior leaders have risk-management responsibilities spanning multiple organizations and that organizations can use cybersecurity risk information to inform workforce and risk decisions.

Lawrence says that framework reinforces what he considers an important principle: security leaders should be able to explain not only what a control requires, but also what a security decision means for the organization.

That principle also shapes what Lawrence calls his “pathway to yes” approach. He argues that security professionals should understand the applicable requirements, involve legal and financial stakeholders when appropriate, consider operational realities, and identify compliant options before concluding that a request cannot be accommodated.

For Lawrence, the objective is not to weaken security requirements. He says it is to find a compliant way to accomplish legitimate business objectives when the circumstances allow.

He illustrates the point with a hypothetical example: requiring flood insurance for a person who lives on a mountain. In Lawrence’s view, an executive presented with a security requirement that appears disconnected from the actual risk may reasonably ask why the requirement applies and what purpose it serves.

Lawrence uses the phrase “Semper Gumby,” or “always flexible,” to describe the mindset he believes security organizations should adopt when circumstances permit flexibility.

“Executives make a costly mistake when they treat classified security as an area where they can hire inexpensive, inexperienced personnel and expect them to learn on the job,” he says. “In a classified environment, a security failure can affect contracts, mission delivery, reputation, and the organization’s ability to continue performing sensitive work.”

GAO’s 2026 review found that DCSA had gaps in its ability to assess and respond to risks and recommended that the Department of Defense enhance analytic tools, address the risks associated with a limited industrial-security workforce, assess DCSA’s risk-response efforts, and strengthen stakeholder engagement. 

GAO also reported that DOD relies on 200,000 private companies in the defense industrial base for goods and services ranging from weapon systems to maintenance. Those companies often use and store sensitive information in their computer systems, according to GAO. Citing DOD’s cybersecurity strategy, GAO noted that malicious cyber activity targeting the defense industrial base can expose sensitive government data, proprietary information, and intellectual property and disrupt business operations.

Lawrence says those realities make accountability important for both security organizations and the executives who oversee them.

“Security leaders should bring confidence, business knowledge, meaningful metrics and options to senior management. They should raise difficult issues while offering practical alternatives,” he adds.

He believes executives, in turn, should expect security teams to present choices that account for government requirements, legal considerations, financial realities and operational needs.

Lawrence applies the same thinking to government acquisition. He points to the traditional emphasis on cost, schedule and performance in acquisition decisions and argues that security considerations should receive explicit attention when classified work is involved. For Lawrence, the point is not that security should override business considerations. He argues that security decisions should be incorporated into those considerations early enough to influence how an organization plans and executes its work.

Lawrence believes classified security should be managed with the same attention to organizational objectives. “The strongest security organizations earn their place at the executive table by making security an enabler of the mission,” he says. “You can be compliant and still fail.”

For Lawrence, that distinction is central to what he calls the business of security: demonstrating that security is not simply a collection of controls and compliance obligations, but a function that should be understood in relation to the mission, risks and decisions of the organization it serves.



Why national security must become a business priority

#national #security #business #priority

Leave a Reply

Your email address will not be published. Required fields are marked *