The Times Australia
Small Business News

.
The Times Real Estate

.

How to Communicate Cyber Risk to the Board

  • Written by Adam Palmer, Chief Cybersecurity Strategist, Tenable



While today’s digitally-connected world has elevated the global economy to new heights, one cannot ignore the fact that cyberattacks and data breaches have also become a frequent problem. Research has shown that cyberattacks are on the rise among organisations, with cybercrime costing the

Australian economy over $1 billion per year. The potential for cyber threats to cost organisations millions of dollars in cleanup, lost business and reputational damage clearly demonstrates the relationship between cyber risk and business risk. With so much at stake, CISOs, the entire C-suite, and the Board require insight into cyber exposure in the same way as other risks.

This practical guide will help CISOs communicate cyber risk to the C-suite and board of directors in a way that fosters a business-based dialogue for better, more informed decision making that focuses on maximising risk reduction.

Focus on critical risks

There’s a tendency to mistakenly follow a traditional “check-the-box” approach to addressing every risk. This is akin to chasing your own tail because it provides no visibility of actual risks and consumes valuable resources and time on vulnerabilities that have a low likelihood of being exploited.

Mature organisations have evolved from this archaic approach toward risk-based vulnerability management. Utilising threat intelligence, vulnerability research, and probability data allows a CISO to focus on critical risks. These are vulnerabilities that are actually at high risk of being exploited.

A 2019 study by McKinsey Consulting found that risk-based vulnerability management allows companies a potential risk reduction of 7.5 times above their original program, at no added cost.
                                                                              
Present the board with clear answers

Let’s be honest, when the C-suite or board of directors asks a CISO, “How secure are we?” the last thing they want is a long-winded answer. They expect insight into cyber risk in the same way as other operational areas, and with the same accuracy and predictability. 

Therefore, this is an opportunity for the CISO to present a measurable view of the organisation’s cyber risk exposure using internal and external comparative benchmarks. Consider using concise and understandable language suitable to guide strategic leadership decision-making by the board.

Cyberattacks have the ability to destroy an organisation’s reputation or competitive advantage, both of which are critical to the health of the business. Therefore, CISOs must be prepared to effectively communicate this message to the board and clearly explain how this risk is being addressed across the business unit, asset, and geo-location.

Channel resources appropriately

An effective CISO should measure success by risk reduction, not milestones or tool deployment. In a crisis, it is critical to know what controls are really effective. Demand assurance that the security team is focused on identifying and reducing critical vulnerabilities that pose a business risk.

Remediation actions should be prioritised to reduce the organisation’s cyber exposure. A CISO should drill down into specific vulnerabilities or assets to identify and support controls that are more effective and truly reduce risk.

Make cybersecurity risk management a living strategy

Consider meeting with the C-suite frequently to review risk priorities and strategy. Without a solid internal governance structure, organisations will have trouble building any success. 

Oversight of security may be led by the CISO, but the entire C-suite should drive a cross-team leadership approach. Security is a team effort and a moving process. It is linked to every part of business operations and therefore requires a cross-team governance structure to support the program and resolve critical decisions.

This also assures that the security strategy will be a flexible, living strategy, with critical internal leadership support. Utilise the insights from a risk-based vulnerability management approach to adjust strategy and investment based on critical vulnerabilities that pose the greatest business risk. 

Successfully get ahead of attackers

In the fast-moving environment of cybersecurity, where the entire business may be at risk,  organisations need to understand where to focus resources and investment to maximise their cyber risk reduction. At the same time, C-suite and boards of directors require a means to objectively measure cyber exposure. This should be in non-technical terms and allow business leaders to understand how they compare to their industry peers or other organisations with best-in-class security.

Adam Palmer, Chief Cybersecurity Strategist, Tenable

SME Business News

Australian businesses face uncertainty under new wage theft laws

As Australian businesses brace for the impact of new wage theft laws under The Closing Loopholes Acts, data from Yellow Canary, Australia’s leading payroll audit and compliance platform, highli...

Self-Funded Incentive Programs – the Gift That Keeps Giving

At first glance, costing your sales incentive program might seem like a big hit. You might be feeling intimidated by the expenses of a program with unproven results. Especially when current eco...

How Virtual Team Building Is Reshaping Modern Business Dynamics

In the past years, virtual team building has established itself as one of the cornerstones in building modern business strategy. With more organizations now switching to a model of remote or ...

How digital loyalty programs drive engagement in a value-conscious economy

Ongoing economic pressures are driving Australian retail businesses to rethink how they engage with increasingly value-conscious consumers. Rising living costs have shifted spending habits, p...

Property Times

Black Rock is a popular beachside suburb

Black Rock is indeed a popular beachside suburb, located in the southeastern suburbs of Melbourne, Victoria, Australia. It’s known for its stunning beaches, particularly Half Moon Bay, which features iconic sandstone cliffs and a shipwreck of HMV...

What factors affect whether or not a person is approved for a property loan

Several factors determine whether a person is approved for a real estate loan. These factors help lenders assess the borrower’s ability to repay the loan and the risk involved. Key considerations include: 1. Credit Score and History • Credit Sc...

Does the Sydney property market still offer rewarding investment opportunities

Investing in Sydney’s property market has historically offered rewarding returns, characterized by consistent capital growth and strong rental demand. Since the 1980s, Sydney’s average capital growth has been approximately 7.4% per year, indicating t...

Cadastral Land Survey: Defining Property Boundaries with Precision

A cadastral land survey, or cadastral boundary survey. is vital in managing lands and property ownership. Such surveys are a specific sort of study that is vital in identifying the economic limits of property throughout its historical past for assu...

Food & Dining

Lauren’s Journey to a Healthier Life: How Being a Busy Mum and Supportive Wife Helped Her To Lose 51kg with The Lady Shake

For Lauren, the road to better health began with a small and simple but significant decision. As a busy wife and mother, she noticed her husband skipping breakfast and decided to purchase The Man Shake to ensure he was starting his day right. W...

Move over mānuka – here are 5 other delicious native NZ honeys to try this summer

As I write, the summer landscape is bright with pōhutukawa flowers. Sitting in the shade of the “New Zealand Christmas tree”, I can hear bees humming as they move between flowers collecting nectar. Pulling the picnic basket near, I cut a slice o...

How the Aussie summer has a profound effect on 'Climate Cravings’

Weather whiplash describes the rollercoaster-like shifts in weather we’ve experienced this summer —a blazing hot day one moment, followed by an unexpectedly chilly or rainy turn.  As a result, Aussies are experiencing ‘Climate Cravings’ - a shif...

The Foods You Should Avoid When Drinking Rose Wine

Rose wine has been synonymous with romance, and it’s easy to know why. This light and fruity drink invites you to relax, let loose, and just enjoy life’s simple pleasures.  But drinking such a delicate type of wine can also be tricky sometimes. In...

The Times Features

Australian businesses face uncertainty under new wage theft laws

As Australian businesses brace for the impact of new wage theft laws under The Closing Loopholes Acts, data from Yellow Canary, Australia’s leading payroll audit and compliance p...

Why Staying Safe at Home Is Easier Than You Think

Staying safe at home doesn’t have to be a daunting task. Many people think creating a secure living space is expensive or time-consuming, but that’s far from the truth. By focu...

Lauren’s Journey to a Healthier Life: How Being a Busy Mum and Supportive Wife Helped Her To Lose 51kg with The Lady Shake

For Lauren, the road to better health began with a small and simple but significant decision. As a busy wife and mother, she noticed her husband skipping breakfast and decided ...

How to Manage Debt During Retirement in Australia: Best Practices for Minimising Interest Payments

Managing debt during retirement is a critical step towards ensuring financial stability and peace of mind. Retirees in Australia face unique challenges, such as fixed income st...

hMPV may be spreading in China. Here’s what to know about this virus – and why it’s not cause for alarm

Five years on from the first news of COVID, recent reports[1] of an obscure respiratory virus in China may understandably raise concerns. Chinese authorities first issued warn...

Black Rock is a popular beachside suburb

Black Rock is indeed a popular beachside suburb, located in the southeastern suburbs of Melbourne, Victoria, Australia. It’s known for its stunning beaches, particularly Half M...

Business Times

Australian businesses face uncertainty under new wage theft laws

As Australian businesses brace for the impact of new wage theft laws under The Closing Loopholes Acts, data from Yellow Can...

Self-Funded Incentive Programs – the Gift That Keeps Giving

At first glance, costing your sales incentive program might seem like a big hit. You might be feeling intimidated by the ex...

How Virtual Team Building Is Reshaping Modern Business Dynamics

In the past years, virtual team building has established itself as one of the cornerstones in building modern business st...

LayBy Shopping