Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Fortitude Re
Elliott Franklin, Senior Vice President & Chief Information Security Officer
Building Security Architecture that Serves the Business, Not the Other Way Around


Elliott Franklin
Business Security Architect
Shifting from Point Solutions to Strategy
Security programs that grow organically around tools and point solutions often become complex, costly, and difficult to manage. A modern architecture needs to begin with strategy, not products. At Fortitude Re, one of the first steps we took was to assess our environment using a recognized framework like NIST CSF. This strategy gave us a baseline and a roadmap. From there, every decision about tools, policies, and controls had to align with business objectives, not just check a compliance box.
Embedding Security into Business Functions
Security cannot be an afterthought, bolted on at the end of projects. We integrated information security directly into enterprise functions like project governance, third-party risk management, and change management.
Architecting for Agility and Resilience
The attack surface is shifting—from endpoints to cloud platforms, APIs, and identity systems. That means architecture must prioritize identity as the new Perimeter, zero trust principles, and resiliency planning. For us, this included strengthening IAM with best-of-breed solutions, improving monitoring through managed detection and response, and focusing on automation to streamline access reviews and privileged account management.
At the same time, architecture has to be flexible. Regulations evolve, new risks emerge, and businesses pivot. A successful design is not rigid—it provides guardrails that can adjust to new realities without tearing down and starting over.
It’s about designing a system that enables the business to move fast, stay resilient, and meet its obligations
Measuring What Matters
Finally, the most sophisticated architecture means little if you cannot explain its value. Boards and executives don’t want to see a dashboard full of threat counts; they want to know: How does this reduce risk to the business? By building metrics tied to regulatory expectations, audit findings, and real risk reduction, CISOs can translate architecture into language the business understands.
Final Thought
Cybersecurity architecture is not about building the tallest walls. It’s about designing a system that enables the business to move fast, stay resilient, and meet its obligations. The leaders who can bridge security, technology, and business strategy will not only reduce risk but also earn trust and create lasting value.

