
Cybersecurity concerns are no longer the domain of the IT department. They permeate every aspect of an organisation’s operations and governance – and cyber security is increasingly being discussed at the board level.
However, boards aren’t always well-equipped to talk to cybersecurity professionals about cyber risk. This is where cybersecurity professionals should step in. There is an immense opportunity for cybersecurity professionals to guide boards as they oversee current and looming cyber threats.
In this blog post, we’ll discuss three key tips security leaders can implement to talk to boards about cybersecurity.
Boards are interested in strategic issues, not operational problems (until they have a strategic impact). To gain their understanding, cyber security needs to be viewed through the lens of risk and opportunity to the organization as a whole. This can be challenging for security professionals who often focus on specific threats and vulnerabilities that are likely to be meaningless to board members) rather than the broader organizational impact.
Board members don’t need to know about the details of the organisation’s insurance policy, just that it is current, appropriate and regularly reviewed.
In practice, this means security leaders should focus on:
Benchmarking your organization against industry standards can also be helpful in selling your security message to the board.
The board is responsible for governing, not managing, security risk. What this means is that, while the board must be curious enough about security risk to adequately assess it – board members are not required to be well versed in the technical language of cyber security.
Instead, security leaders must be well-practised at speaking the language of the board – clear and plain English that’s free of technical jargon to the largest possible extent. This comes with a host of benefits, including:
Finally, by using language relevant to the board, board members are more likely to be motivated and interested in learning more. This opens the door for security leaders to share valuable resources to help boards further their understanding of the cyber security landscape – like the UK Government’s Cyber Security Board Toolkit.
CSO Online reported that “while most CISOs are experiencing noteworthy increases in security funding, impractical expectations of budget holders are leading to significant amounts being spent on what’s hitting the headlines instead of strategic, business-centric investment in security….”
To be frank, we hardly blame the boards for focusing on the headlines. In the wake of the mammoth Latitude Financial, Medibank, HWL Ebsworth and Optus breaches (amongst many others), the risk of a data breach caused by cyber criminals is likely top of mind for board members. However, cybercriminals are hardly the only risk – and security leaders must make sure boards are aware of threats and opportunities that aren’t in the news.
If there’s a silver lining for security leaders in the rapidly evolving security threat landscape, it’s that the heightened awareness of the threat opens the (boardroom) door for these discussions. In other words, security leaders are in a unique position in that board members are now more likely to listen to security leaders discuss the full scope of risks and what addressing them would entail.
Privacy 108 is owned and led by one of Australia’s leading security and privacy professionals, Dr Jodie Siganto. The Privacy 108 team includes lawyers, consultants and trainers who between them hold many years of experience in delivering privacy and security solutions for Australian organisations.
We have worked as in-house counsel and senior executives, and understand the pressures faced by executives, CISOs, Chief Privacy Officers, procurement teams and in-house lawyers. Our team’s industry experience is complemented by extensive legal knowledge and a desire to assist our clients with high-quality practical advice.
If your organisation could benefit from improved cyber security management, reach out. Our experienced team would love to help.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.