How can security leaders more effectively communicate risks to the business and board?

1.9k viewscircle icon1 Upvotecircle icon5 Comments
Sort by:
Director Certifications in Education5 years ago

Tell them in simple terms what can happen to the business if risks exposure is realized and the organization's ability to meet its financial and strategic goals.  Sometimes the worst case scenario, like ransomware infection on the organization's computer systems and data.  Risk is a very tricky thing to address because it is so many that can affect an organization. Depending on your business, you may need a separate group/department to manage and address it.  A key partner should be the internal audit department.

Lightbulb on1
CIO in Software5 years ago

Security must be on every team's agenda of the organization, either it is building security, data security, infrastructure security, people security. How to influence it? CISOs should bring awareness to their peers, people up and down the hierarchy, knowledge center, policy enablement and separation of duties between teams and within teams. A continuous periodic exercise of security reevaluation is a must in the organization.

Lightbulb on2
CIO / Managing Partner in Manufacturing5 years ago

Should make sure that cybersecurity is a standing board agenda item.

Lightbulb on1
Director of Engineering in Energy and Utilities5 years ago

Finance is probably the best way to communicate risks to business and board. Real-life examples will go along a long way in communicating these risks.

Lightbulb on1
CEO in Services (non-Government)5 years ago

It’s an exercise in influence. First, identify the top priorities set by the business and specific points where better security enables or poor security blocks meeting these goals. Security is only 1 of many types of risks that businesses and boards face, and they must all be considered in the context of reaching critical company goals. You may never be able to convince them to care about security risks for the same reasons you do, instead align security with their existing motivations. They don’t need to join the band in order to play your song.

Lightbulb on2

Content you might like

AI Decision-Making Transparency33%

Data Privacy in the Age of Big Data51%

The Impact of Automation on Employment48%

Environmental Sustainability in Tech Manufacturing18%

Digital Divide and Technology Accessibility8%

View Results

Yes, for all27%

No, but we use the zero trust technology54%

Yes, for 1. No for 2.15%

Yes for 2, No for 12%

View Results