What Direct means
Direct is where strategy becomes a plan someone can actually execute. Having decided what matters and discovered where the real risk sits, the next job is sequencing: what gets fixed first, what it will cost, and who does the work. This is also where CSISC's role is most easily misunderstood — an Executive Cyber Leader directs the work, prioritises it, and holds it accountable; they don't sit inside your IT team running tickets. The distinction matters, because it's what keeps the roadmap strategic rather than becoming another item on someone's technical backlog.
Good direction is proportionate. It resists the temptation to chase every possible control and instead concentrates effort on the handful of things that would actually reduce the risk identified in Discover — a roadmap with twelve items nobody will finish is worse than one with four that actually get done.
The board question
What your board should be able to answer at this stage
“Is our roadmap protecting the things that matter most — or just the easiest wins?”
In practice
What good looks like
- A written roadmap with owners, costs, and realistic timelines — not just a list of good ideas
- Controls are applied consistently across the estate, not just where it was easy
- Existing IT or MSP relationships are directed, not duplicated or undermined
- Priorities are visibly tied back to the risks identified in Discover, not applied generically
Where this shows up