To address this issue, the CISO should work on enhancing business engagement, involving key stakeholders in the strategy's development, and clearly demonstrating how the security strategy aligns with and supports the organization's business objectives and risk mitigation.