Why is a business unit (Fachbereich) — sales, production, marketing — a stakeholder in cyber security architecture, when its people do not build any of it?
Because the business unit is the client for IT: it describes the work to be done, IT realises it, and the security architecture sets the boundary conditions that its ideas must live within.
* Asked during design, security shapes the idea; asked at the end, it only blocks or forces a redesign. *
A business unit carries out the company's actual professional tasks, and describes them in business plans, business architectures and task descriptions. Realising them takes IT — which puts the unit in the role of requester and client. Whatever the security architecture prescribes therefore lands on the unit as a constraint, whether or not anyone consulted it.
The stakes rise sharply as business fields become digital, where the architecture takes on a defining role and can cut either way:
- As a blocker: a hoped-for digital business field turns out, once cyber security is properly considered, to be impossible or uneconomic. The honest version of this outcome is discovering it during design; the expensive version is discovering it after building.
- As an enabler: the architecture makes a new business field reachable that would otherwise have been too risky to enter — customer self-service, partner integration, connected products.
Which is exactly why the timing advice is what it is: collaborate with the business architecture early, while the idea is still in the design phase. Security requirements that arrive at the end are either bolted on badly or force a redesign; requirements known during design shape a solution that can actually be secured, and occasionally point at a different product that is both viable and safe.
Go deeper:
Wikipedia — Secure by design — the general form of the argument for moving the security question to the front of the process.