A Governance Lens Stops Security Teams From Wasting Resources on the Wrong Risks
Kristofer Wilson's path from data governance into security shapes how Newell Brands prioritizes risk, communicates it to executives, and scales it across a global footprint.

Make The Security Digest one of your go-to sources on Google
Traditional information security can get laser-focused on a specific vulnerability or threat and how to remediate it, without always accounting for what happens next.
A security team built around threat specialists will find every critical vulnerability on the network but may struggle to distinguish which ones affect the systems the business depends on. Severity scores don’t show what exploiting the flaw would cost the business, which can lead organizations to spend their resources on technically serious issues that pose relatively little risk. The alternative is a security function led by people who learn to read the business first and the vulnerability second, treating "how bad is this exploit?" as only half the question.
Kristofer Wilson, Governance Manager, Global Information Security at Newell Brands, approaches security from that broader organizational lens. His work in data governance and records management taught him to understand where an organization’s data lives, how it moves, and where the risks emerge. He now applies that same structural view to security, connecting technical risks to the systems, processes, and priorities they affect.
"I try to look at things more from the business side than strictly the threat and vulnerability side, making things make sense. Traditional information security can get laser-focused on a specific vulnerability or threat and how to remediate it, without always accounting for what happens next."
The value of seeing beyond the vulnerability
The strongest security teams combine technical depth with broad business understanding. "You really need both," Wilson says. "You need those specialized individuals that can go through the data and find the ways others can’t, or know the inner workings of all these things. But then you need someone else who can translate that into more of the business language." A governance-trained leader, in this model, isn't replacing the specialist. He's the translator standing between the specialist and everyone the specialist's findings are supposed to reach.
The expert who understands both the business and the security environment is better positioned to set priorities, particularly when a scanning tool hands the team a severity rating stripped of context. "You might see some infosec folks and they might get a notification that it's a highly critical vulnerability and it has to be remediated right now, and it's top of the queue for them," Wilson says. "But if you actually look at that server, it could be a server that stores everyone's favorite color. So it really isn't anything to put resources behind." A critical rating describes how easily a flaw could be exploited, not what an attacker would gain from exploiting it, and treating the two as interchangeable can leave teams racing to patch a system nobody would benefit from breaching while more pressing matters wait their turn.
Putting a dollar value on cyber risk
While red, yellow, and green risk ratings offer a fast way to signal urgency, they often raise doubts. "If you present something that's a red stop sign to an executive, they're going to say, okay, well, what does that mean?" Wilson says.
Newell Brands is leaning on a more comprehensive approach. The company has moved toward cyber risk quantification, developed with the FAIR Institute, that converts a vulnerability into a dollar-based comparison between the expected loss if it's left unaddressed and the cost of fixing it immediately. "We look at where we sit in our markets, and any kind of breaches or incidents that have happened in the past, or typical remediation costs down the line, and put everything in a formula," Wilson says. "So we can run a simulation and say, okay, we have this vulnerability. If we don't remediate it, we can expect an $80,000 cost every time it's exploited, or we can spend $200,000 to remediate it right now." It’s the context severity ratings alone lack.
Scaling governance across a global organization
The same governance program applies at organizational scale. Once the environment stops being a single server and becomes a company with tens of thousands of employees spread across regions, the challenge is no longer just deciding which vulnerability deserves attention, but where security resources and controls are needed most.
"We try to manage everything from a single point and then disperse it out," Wilson says. "And then if we do have sites that can't reach those standards, we look at specialized controls that we can put in place there." Constant scanning shows where a brand or region is falling short. Rather than forcing every site to the same timeline, the company builds the exception around its constraints.
Newell Brands is a large company with almost 25,000 employees worldwide, spread across several regions and languages. One of their biggest initiatives over the past two years has been translating key materials and making them readily available in all of the company’s official languages. "We’ve seen a lot more people reaching out from EMEA, LATAM, and even the APAC region with not just questions, but just kind of, well, thank you. We didn't know we had this documentation available. It saved us a lot of time.", Wilson explains.
The path to security leadership is rarely narrow
Wilson doesn't think his own route into security leadership is the only one, but he's specific about what separates someone who can run a broad program from someone who stays an individual contributor indefinitely. "If you're going to specialize in one thing, you can go very far in that one thing, but you're always going to be that individual contributor, or maybe the manager of a small team," he says. "If you want to grow into a leadership role, you have to diversify."
A historian who became a policy writer, then a data governance lead, then a security governance manager isn't a career path anyone would design on purpose. It's what width looks like when it's built one unrelated stop at a time, and it's the same width Wilson argues the whole function needs more of.






