7 Tips for Communicating with the Board
The key? Rather than getting bogged down in the technical details, focus on how a security program is addressing business risk.
February 6, 2019
CISOs and other security leaders are under growing pressure to improve how they communicate with boards of directors.
Cybersecurity has become a board-level issue in many organizations amid growing concerns over the regulatory, financial, and reputational implications of data breaches and security failures. In fact, Gartner expects that by 2020, 100% of large organizations will be asked to report to their boards at least once annually on cybersecurity risk — up from the 40% that are required to do so currently.
That means security leaders will need to overcome their traditional communication challenges and find new and better ways to convey technology risk.
Ensuring board awareness about key metrics of cybersecurity programs has become critically important, says Greg Reber, partner at Moss Adams, a Seattle-based accounting, consulting, and wealth management firm. Board members need to be able to track not just cybersecurity events and actions, but also new and emerging threats. They also require a continuous assessment of how a program is doing, along with a road map of cybersecurity-related projects and their goals, Reber says.
"Cybersecurity is a relatively new risk but aligns very directly within traditional BoD oversight duties," he notes.
Here are the key steps for effectively communicating with the board.
About the Author
You May Also Like
Applying the Principle of Least Privilege to the Cloud
Nov 18, 2024The Right Way to Use Artificial Intelligence and Machine Learning in Incident Response
Nov 20, 2024Safeguarding GitHub Data to Fuel Web Innovation
Nov 21, 2024The Unreasonable Effectiveness of Inside Out Attack Surface Management
Dec 4, 2024