439: Stop Reporting Activity, Report Risk Reduced w/ James Dunlap
You've Been Heard, Monday, July 20th, 2026
IT leaders should communicate risk reduction and business value to executives rather than technical activity metrics.
James Dunlap discusses how CIOs across healthcare, banking and legal sectors often fail to translate technical work into executive language.
He emphasizes framing security initiatives around business outcomes such as revenue impact, competitive advantage and reputational consequences rather than projects and jargon.
Dunlap shares his career journey, including stepping down from a CIO role to work under a banking CISO, and his successful paper-to-EHR implementation.
He warns about emerging governance challenges with AI agents and notes that credibility builds through consistent, unglamorous follow-through rather than heroic crisis moments.