


Acritical challenge for security leaders is how to deliver their message on cyber risk to the board and executive stakeholders. There is a language barrier between boards and Chief Information Security Officers (CISOs) when it comes to cyber risk posture and mitigation. Few board members and executives are cyber security experts, yet CISOs speak the language of cyber risks through a technical lens rather than a business lens. As a result, they miss the opportunity to successfully outline the business impact of proposed risk mitigation investments and gain critical buy-in for their efforts.
Cyber security is a different kind of risk, and it can impact different businesses in different ways. Increasingly complex outsourcing and supply chains serve to define the “extended enterprise,” which faces broader cyber risks. Being aware of the ever changing cyber risk and threat landscape is critical in any enterprise cyber security program. Boards and executive leaders must be informed on how the security organization monitors and assesses this landscape.
CISOs should educate and inform on how they determine which risks and threats are relevant to the organization. It’s important for stakeholders to understand which risks are not seen as relevant and which ones are of greatest concern. Given the dynamic nature of the cyber risk space, this assessment should be an ongoing focus—to inform and educate on the threat landscape and to convey the continued alignment of the security program with current risks and threats.
CISOs should provide metrics that reflect the organization’s cyber posture and demonstrate progress in risk reduction or mitigation. As part of this, CISOs need to paint the picture of how these metrics are most relevant to risk. The things that are easiest to measure are not always the most relevant in providing a clear picture of risk posture. A common point of misalignment of CISOs and key stakeholders is when operational metrics become a focus rather than those that measure and reflect key risks. A frequent error by security leaders is presenting metrics tied to events, such as the number of attacks against the company’s web properties or the number of malicious emails received. Without context of the organization’s capabilities to detect and protect against these threats, audiences can’t understand the significance of such operational metrics.
"The ability of the security program to drive down risk and maintain alignment with the enterprise’s risk appetite represents a view of the “return on investment” of the cybersecurity program"
Risk discussions should include the context of how the CISO measures and communicates risk through risk appetite statements, connection to the enterprise risk management taxonomy, and measurement against defined risk thresholds. An area of increased focus is how to best move from a traditional qualitative approach toward risk measurement to a quantitative risk-based measurement of cyber risk. Directors and executives should clearly understand an organization’s cyber risk and loss exposure in financial terms to enable effective decision-making which balances protecting the organization and running the business.
Inherent risk—the risk that exists in the absence of any controls or countermeasures—is an important baseline for stakeholders to understand. This highlight risks that require the greatest focus or which could have the greatest impact on the organization in the event of control failures. The inherent risk of a threat type can vary, and the organization should have a structured approach toward understanding both the impact and the likelihood of given risks. Regulatory and compliance requirements, the volume and type of confidential data the organization holds, the potential reputational impact of cyber events, and the level of security training and workforce awareness, are the considerations in identifying inherent risk.
An effective CISO can clearly outline how the security program lowers the organization’s risk through effective controls and other risk mitigation strategies, such as training and secure development practices. The ability of the security program to drive down risk and maintain alignment with the enterprise’s risk appetite represents a view of the “return on investment” of the cyber security program.
How the effectiveness of cyber security controls and countermeasures are assessed is an important topic for the CISO to convey. Organizations should implement an approach that measures and monitors security control effectiveness, maintains awareness of how they impact residual risk, highlights gaps or changes, and ensures technology changes do not have unintended consequences for security controls.
The discussion of the organization’s cyber security program is incomplete without considering the people. The ability to attract, develop, and retain cyber security talent is a critical issue, and CISOs should describe their approach and plan, and provide regular updates on their status.
Business and technology strategies directly impact the organization’s cyber risk posture. Security is an overarching risk function that must be involved in business strategy as well as technology strategy, and security leaders should regularly engage with business stakeholder leadership, recognizing that they are drivers of technology change and are incurring cyber risk.
Companies have seen their technology ecosystems become far more complex and extend well beyond their traditional network borders. Successful cyber-attacks against SolarWinds and Kaseya illustrate the cyber risk associated with enterprise technology supply chains. Threat actors attacked enterprise software and service providers to create the platform used to exploit critical business networks. Such supply chain events, and the cascading cyber risk associated with them, represent a significant challenge to traditional approaches toward assessing third-party risk.
Just as lines of business and technology have strategies and associated initiatives, so must the cyber security function. CISOs should review with the Board and executive leadership their ongoing improvement plans – their roadmap – for the security function. Progress toward the target state of the cyber security program, alignment with the organization’s risk appetite, and consideration of the company’s program relative to industry peers should all be considerations discussed between board and executive stakeholders and CISO.
Focusing on risk and quantifying it in business and financial terms, educating stakeholders on the risk and threat landscape, clearly describng the link between risk mitigation and reduction and planned investments, and staying aligned with the business units will all serve to bridge the communication gap and gain critical support for your program.