CYBERSECURITY REVIEW8 JUNE - JULY 2024A critical challenge for security leaders is how to deliver their message on cyber risk to the board and executive stakeholders. There is a language barrier between boards and Chief Information Security Officers (CISOs) when it comes to cyber risk posture and mitigation. Few board members and executives are cyber security experts, yet CISOs speak the language of cyber risks through a technical lens rather than a business lens. As a result, they miss the opportunity to successfully outline the business impact of proposed risk mitigation investments and gain critical buy-in for their efforts.Cyber security is a different kind of risk, and it can impact different businesses in different ways. Increasingly complex outsourcing and supply chains serve to define the "extended enterprise," which faces broader cyber risks. Being aware of the ever changing cyber risk and threat landscape is critical in any enterprise cyber security program. Boards and executive leaders must be informed on how the security organization monitors and assesses this landscape.CISOs should educate and inform on how they determine which risks and threats are relevant to the organization. It's important for stakeholders to understand which risks are not seen as relevant and which ones are of greatest concern. Given the dynamic nature of the cyber risk space, this assessment should be an ongoing focus--to inform and educate on the threat landscape and to convey the continued alignment of the security program with current risks and threats.CISOs should provide metrics that reflect the organization's cyber posture and demonstrate progress in risk reduction or mitigation. As part of this, CISOs need to paint the picture of how these metrics are most relevant to risk. The things that are easiest to measure are not always the most relevant in providing a clear picture of risk posture. A common point of misalignment of CISOs and key EFFECTIVE COMMUNICATIONS BETWEEN CISOS AND KEY STAKEHOLDERSBy Kevin P. Gowen, Chief Information Security Officer, SynovusIN MY OPINIONKevin P. Gowen
<
Page 7 |
Page 9 >