Why is top management a stakeholder of cyber security architecture, and what do they get out of it?
Because they are the ones answerable for the company's risks — cyber risks included — so they must ensure those risks are handled appropriately; architecture gives them the transparency to do that.
The chain of reasoning is short and hard to escape. The company's leadership carries responsibility for the risks the company runs. Using IT, OT, cloud and IoT creates risks. Therefore leadership is responsible for those too, and specifically for ensuring an appropriate way of dealing with them — a duty that in many jurisdictions and industries is a legal one, not merely a good idea.
What architecture supplies for that duty:
- Making the situation transparent — an estate nobody can depict cannot be governed.
- Analysing and assessing it — turning "we have a lot of systems" into "these are the exposures, ranked".
- Deriving appropriate measures — the word appropriate is doing the work: proportionate to the risk, not maximal.
How deeply leadership engages depends on how IT-affine it is. Either they take on cyber security architecture directly as a strategic topic, or they delegate it to experts — both are legitimate; what is not legitimate is not knowing which of the two has happened.
There is a second role beyond risk ownership: for far-reaching changes — above all a change of the fundamental security paradigm — management acts as the client (Auftraggeber). Such programmes redraw budgets, working practices and org charts, so they cannot succeed on technical conviction alone; they need a sponsor with authority. Here too the architecture is the deliverable that makes the decision arguable: a decision paper and a before/after picture instead of a plea.
Go deeper:
Wikipedia — ISO/IEC 27001 — the standard makes management commitment a requirement, not a nicety — leadership is its own clause.