How To Talk To Your Board And C-suite About Cyber-preparedness

By Alex Tilley, Head of Threat Intelligence, Asia Pacific & Japan, Secureworks

Digital transformation and remote work have reshaped the business landscape and cyber threats have become the modern barbarians at the gate. The vulnerabilities of organisations are constantly targeted, posing risks that range from financial losses and intellectual property theft to legal cases, fines, and reputational damage. As the guardians of an organisation’s strategic direction and risk management, the board of directors and the C-suite must take cyber-preparedness seriously.

The task of conveying the gravity of cyber risks to the board and C-suite is a challenging feat. It requires breaking through the veneer of casual conversations and the norms of polite protocols. Instead, a comprehensive and strategic approach to cyber-preparedness communication is essential and the Chief Information Security Officer (CISO) shoulders a crucial responsibility for this challenge.

The CISO-Board Interdependence

The board looks to the CISO to execute due diligence in cybersecurity and to guide its understanding of the risks and the organisation's efforts to mitigate them. However, securing the board's buy-in for necessary cybersecurity investments can be challenging, mainly when their comprehension of cyber risks is limited.

The CISO must establish himself or herself as a credible and trusted figure to build a foundational relationship with the board. This involves conducting business-wide crisis management exercises. The outcomes of these exercises provide insight into how the board prefers to receive information and expose any disparities between its expectations and reality. Conducting such exercises outside of crisis scenarios is key; it fosters an understanding of roles and responsibilities, ensuring that the board has confidence in the CISO's ability to provide meaningful reports even under pressure.

Regularly scheduled briefings during board meetings further strengthen this relationship by maintaining open lines of communication and demonstrating the CISO's commitment to transparency and collaboration. However, solely relying on the cybersecurity team is insufficient and it’s becoming blatantly clear that fostering a security culture is essential.

The Impact of Security Culture

Security culture in an organisation boils down to protecting the organisation and its interests in an increasingly hostile environment. In the battle against cyber threats, the CEO must recognise that cybersecurity is a collective effort and that every individual within an organisation is responsible for safeguarding sensitive data and systems. All staff need to feel confident working together and “doing their bit” to secure their organisation and ensure it thrives!

This culture should emphasise trust, collaboration, and empowerment. When employees are encouraged to proactively report cyber incidents without fear of backlash, the organisation becomes better equipped to prevent costly breaches. A security culture enhances disaster recovery efforts and provides a robust defence against cyberattacks.

With the persistent ransomware threat and reduced dwell times, an organisation’s security culture will provide a significant defensive edge against existential threats from well-resourced, experienced, and motivated attackers.

Techniques for Effective Reporting

Communication with the board and C-suite demands the presentation of realistic, meaningful metrics highlighting the organisation's progress in its security journey. To ensure their relevance, the CISO should initiate discussions with the board, presenting metrics that align with pain points and progression requirements. This approach ensures that the chosen metrics resonate with the board's concerns and priorities.

Breach reporting is another area that needs to be addressed and the CISO needs to work with the board before a breach event to help them understand the types of things it should expect to be told. Then, they can agree on acceptable and understandable terms and include other business units to show their inputs into the breach detection, notification and response process.

Crafting a Compelling Board Presentation

A successful board presentation hinges on several factors. First, it requires understanding what the board truly needs to hear. This means distilling complex technical information into actionable insights that align with the company's strategic goals. Clear and concise language is essential, as jargon and extraneous details can obfuscate the message.

The ability to collect, analyse, and present critical information in a meaningful way is paramount. Anticipating questions from the board, often unexpected, prepares the CISO for thorough discussions. Practising the delivery of the presentation with non-technical individuals helps ensure that the content is accessible and well-understood by all stakeholders.

In addition, showcasing the CISO's willingness to engage with business units beyond IT demonstrates his or her commitment to holistic cybersecurity. This step reinforces his or her role as a credible leader and underscores the collaborative nature of cyber-preparedness efforts.

The take-out

Cyber-preparedness is no longer a niche concern confined to the IT or security department. It is a critical business imperative that demands the full attention of the board and C-suite. Effectively communicating the intricacies of cyber risks and the strategies to mitigate them is a nuanced challenge that requires strong relationships, a supportive security culture, meaningful metrics, and compelling presentations by the CISO.

By aligning these elements, CISOs can bridge the understanding gap and empower boards and C-suites to make informed decisions that safeguard their organisations from modern-day barbarians.

© Scoop Media

Did you know Scoop has an Ethical Paywall?

If you're using Scoop for work, your organisation needs to pay a small license fee with Scoop Pro. We think that's fair, because your organisation is benefiting from using our news resources. In return, we'll also give your team access to pro news tools and keep Scoop free for personal use, because public access to news is important!

Go to Scoop Pro Find out more


Football news:

<!DOCTYPE html>
Kane on Tuchel: A wonderful man, full of ideas. Thomas in person says what he thinks
Zarema about Kuziaev's 350,000 euros a year in Le Havre: Translate it into rubles - it's not that little. It is commendable that he left
Aleksandr Mostovoy on Wendel: Two months of walking around in the middle of nowhere and then coming back and dragging the team - that's top level
Sheffield United have bought Euro U21 champion Archer from Aston Villa for £18.5million
Alexander Medvedev on SKA: Without Gazprom, there would be no Zenit titles. There is a winning wave in the city. The next victory in the Gagarin Cup will be in the spring
Smolnikov ended his career at the age of 35. He became the Russian champion three times with Zenit

1:33 Trans-tasman Commute No Barrier For Engineer Thriving In Reserve Force Career
1:31 Water Treatment Plant Back In Service For Muriwai
0:54 Brother New Zealand Launches Groundbreaking Printer Pick Up Initiative
0:23 Diversity Toolbox A Key Driver For Trucking Industry
0:21 ANZIIF Making A Difference Award Recognises Ben Marsh's Contributions During 2023 Natural Disasters
0:07 Air New Zealand Unveils New Look Premium Check-in At Auckland International Airport
23:19 Kordia Broadens Coverage For Mission-critical Business With Starlink Internet
22:31 Health And Safety Practices Key To Winning Contracts As Construction Industry Shows Improvement
22:00 New Zealand Business Demography Statistics: At February 2023
21:39 West Coast Black Garlic Co Tastes Success, Now Levelling Up Their Culinary Offering
21:31 Gaming Machine Revenue Hits $1bn Again This Year, Community Groups Set To Benefit
21:30 Farmers Facing Heightened Challenges
21:19 Kingspan Seeks Clearance To Acquire Conqueror
17:03 Telco Providers Fail To Improve Their Billing Apps For The Second Year In A Row
2:58 North Harbour Business Leaders To Be Inducted Into Hall Of Fame
2:47 JB Hi-Fi To Celebrate Second Christchurch Store Opening With Drax Project
7:00 Criminals Could Benefit From Health Ministry Vape Database
6:48 National In Danger Of Swapping One Middle-Class Subsidy For Another
2:49 New Zealand PM celebrates Mid-Autumn Festival in Chinese community
22:19 100 new public EV chargers to be added to national network
15:10 Safeguarding Tuvalu language and identity
13:37 Timor-Leste President welcomes PM Modi's decision to open Indian Embassy in Dili
13:18 MoS Ranjan Singh, New Zealand PM take part in 1st India Business Summit 2023
12:16 Quarterfinals take shape as group stages culminate at Rugby World Cup
9:16 Quarterfinals take shape as pool stages culminate at Rugby World Cup
7:55 "He knocks over big batters...": Dale Steyn picks up Siraj as one of pacers to watch out for in World Cup
7:40 What Is Debt Relief And How Does It Work?
6:21 OneRoof House Price Report: New Zealand Records First Rise In Over A Year
2:55 "My knee held up pretty well": Kane Williamson following WC warm-up match against Pakistan
19:27 New Zealand, Bangladesh register comprehensive victories in respective warm-up matches
18:37 ICC announces commentators for ODI World Cup
10:27 Junior Women's Hockey team in top gear ahead of World Cup
8:56 All-Reality, On-Demand Service Hayu To Launch In New Zealand
7:55 New Zealand captain Kane Williamson to miss opening match of World Cup against England
5:27 PCB chief stirs controversy, refers to India as "Dushman Mulk" in viral video
5:13 How To Talk To Your Board And C-suite About Cyber-preparedness
5:10 Paessler AG Announces Acquisition Of Swiss Technology Company ITPS AG
3:32 DHL Express Announces Annual Price Adjustments For 2024
3:22 Airport Reinforces Lifeline Infrastructure And Connector Roles
0:45 Deer Farmer Fined $12,000 For Not Tagging 278 NAIT Animals
23:26 Nutanix Rolls Out Elevate Partner Program’s Latest Updates And Incentives
22:44 LPC Releases Annual Results For Financial Year 2023
22:38 Balance Of Payments And International Investment Position: Year Ended 31 March 2023
22:11 Funding For Electric Bus Depot Welcomed
22:11 Pāmu Releases Integrated Report And First Climate-related Disclosure
22:07 Transpower And PowerNet Seek Input For Southland's Future Electricity Needs
22:03 Alena Kamper Wins 2023 North Island Young Winemaker Of The Year
21:49 2023 KiwiNet Awards Winners: Turning Science Discoveries Into Transformative New Technologies For The World
21:30 Insights & Connectivity With Malaysia
20:48 Regional Cruise Strategy Has Growth And Sustainability As Focus
20:24 Vista Group Launches Industry Leading App To Help Cinema Executives Seize New Business Opportunities In Real Time
20:21 Chapman Tripp Advises Pepper Money On Prime Residential Mortgage Portfolio Acquisition
19:55 "Pakistan or any other team will not match India": Former cricketer Waqar Younis
17:23 Audience Demand For Travis Kelce Soars To New Heights Following Taylor Swift Appearance [Parrot Analytics]
17:20 Consumer Ranks Salt And Vinegar Chips From Best To Worst
7:01 Māori Women’s Development Inc Māori Businesswomen’s Awards 2023:
6:55 Gautam Gambhir offers prayers at Andhra's Tirupati temple, conveys best wishes to Team India for World Cup
6:55 I didn't want to create another controversy: Tamim Iqbal after ODI WC snub
6:01 Apple's 2023 Fall High-End Product Launch: A Boon For Suppliers
5:58 KFC Launches Necklace Collab With Iconic Kiwi Jeweller
4:18 Indian diaspora in New Zealand welcomes MoS Rajkumar Ranjan at Mahatma Gandhi Centre in Auckland
2:56 NZICC Appoints Tracey Ha As Director Of Customer Experience
2:44 Market exchange rates in China -- Sept. 28
2:13 ANZIIF Appoints Industry Leaders Tim Tez And Sarah Phillips To Board.
2:04 Commpete Chair Michelle Lim To Step Down
1:58 How Crypto Rebels Are Thriving On The Edge Of The Market Abyss
23:25 Norton Introduces New Small Business Solution With 24/7 Triple-Lock Cybersecurity For Small Teams
21:45 Employment Indicators: August 2023 – Information Release
21:16 Uruguay recover to beat indisciplined Namibia at rugby World Cup
20:52 New Zealanders' Priorities For Infrastructure Investment Shifts After Extreme Weather Events
20:49 Lemon Angels Planning To Raise $1 Million To Help Children And Parents With Critical Illness Expenses
20:48 The Warehouse Group FY23 Annual Result Announcement - Strong Sales At The Warehouse In A Challenging Year
20:44 New Zealand And UK Audit Authorities Agree Mutual Recognition Of Audit Qualifications
20:01 Meta Connect 2023: Quest 3, AI Advances, Next-Gen Smart Glasses, & The Road To The Metaverse
19:03 Kane Williamson reveals his challenges to get fit in time for WC campaign opener
18:27 PCB announces three-year contract list for men's cricket team
17:36 Former Cabinet Minister, Stuart Nash, To Join Global Recruitment Company Robert Walters
17:32 Premium Clean's Builder Clean Services to Properties
16:27 Led by Babar Azam, Pakistan team arrive in Hyderabad ahead of warm-up game against New Zealand
8:55 Xinhua world economic news summary at 0900 GMT, Sept. 27
4:55 Bangladesh launch new jersey for ICC Cricket World Cup 2023
4:55 Brendon McCullum turns 42: A look at numbers of New Zealand cricketing icon
3:55 Will sell offline tickets of ODI WC for the local fans: HPCA Secretary Avnish Parmar
2:31 Over Half A Million Kiwis Ready To Switch To Car Subscriptions
1:56 Enter Dairy Industry Awards To Win A Trip To Queenstown!
1:48 Emerging ELearning Trends: Future Technologies To Watch
1:20 Falling Employment Confidence Further Indication Of Weakening Economy
23:19 CoreWeave And VAST Data Join Forces To Build The Data Foundation For A Next Generation Public Cloud With NVIDIA AI
23:02 Kiwis Spend Six Figures On Luxury Travel
22:56 Final Policy Consultation Commences On Review Of The Insurance (Prudential Supervision) Act 2010
22:50 Wellington Airport Kicking Off Lyall Bay And Rongotai Revitalisation Projects
22:21 Poutini Ngāi Tahu And Wētā Workshop Fuse Culture And Technology For World-class Visitor Experience
22:08 Two New Attorneys For Chapman Tripp Patents
21:31 TUANZ Welcomes New Board Members
21:30 Ethical Investment Week To Address Obstacles To Investing In A Sustainable Future
21:28 Customers Refunded Nearly $480k In Settlement With ComCom
21:00 Wheeling Out Baggage Tracking In Air NZ App
18:03 "Top four is a small goal for us, we want...": Pakistan skipper Babar Azam
17:26 PAHM Emphasizes The Need For Technological Advancements For Tax Administrations In The Pacific
16:55 Sharesies Taps Māori Fintech BlinkPay To Pave The Way For Open Banking