The Times Australia
Small Business News

.
The Times Real Estate

.

How to Communicate Cyber Risk to the Board

  • Written by Adam Palmer, Chief Cybersecurity Strategist, Tenable



While today’s digitally-connected world has elevated the global economy to new heights, one cannot ignore the fact that cyberattacks and data breaches have also become a frequent problem. Research has shown that cyberattacks are on the rise among organisations, with cybercrime costing the

Australian economy over $1 billion per year. The potential for cyber threats to cost organisations millions of dollars in cleanup, lost business and reputational damage clearly demonstrates the relationship between cyber risk and business risk. With so much at stake, CISOs, the entire C-suite, and the Board require insight into cyber exposure in the same way as other risks.

This practical guide will help CISOs communicate cyber risk to the C-suite and board of directors in a way that fosters a business-based dialogue for better, more informed decision making that focuses on maximising risk reduction.

Focus on critical risks

There’s a tendency to mistakenly follow a traditional “check-the-box” approach to addressing every risk. This is akin to chasing your own tail because it provides no visibility of actual risks and consumes valuable resources and time on vulnerabilities that have a low likelihood of being exploited.

Mature organisations have evolved from this archaic approach toward risk-based vulnerability management. Utilising threat intelligence, vulnerability research, and probability data allows a CISO to focus on critical risks. These are vulnerabilities that are actually at high risk of being exploited.

A 2019 study by McKinsey Consulting found that risk-based vulnerability management allows companies a potential risk reduction of 7.5 times above their original program, at no added cost.
                                                                              
Present the board with clear answers

Let’s be honest, when the C-suite or board of directors asks a CISO, “How secure are we?” the last thing they want is a long-winded answer. They expect insight into cyber risk in the same way as other operational areas, and with the same accuracy and predictability. 

Therefore, this is an opportunity for the CISO to present a measurable view of the organisation’s cyber risk exposure using internal and external comparative benchmarks. Consider using concise and understandable language suitable to guide strategic leadership decision-making by the board.

Cyberattacks have the ability to destroy an organisation’s reputation or competitive advantage, both of which are critical to the health of the business. Therefore, CISOs must be prepared to effectively communicate this message to the board and clearly explain how this risk is being addressed across the business unit, asset, and geo-location.

Channel resources appropriately

An effective CISO should measure success by risk reduction, not milestones or tool deployment. In a crisis, it is critical to know what controls are really effective. Demand assurance that the security team is focused on identifying and reducing critical vulnerabilities that pose a business risk.

Remediation actions should be prioritised to reduce the organisation’s cyber exposure. A CISO should drill down into specific vulnerabilities or assets to identify and support controls that are more effective and truly reduce risk.

Make cybersecurity risk management a living strategy

Consider meeting with the C-suite frequently to review risk priorities and strategy. Without a solid internal governance structure, organisations will have trouble building any success. 

Oversight of security may be led by the CISO, but the entire C-suite should drive a cross-team leadership approach. Security is a team effort and a moving process. It is linked to every part of business operations and therefore requires a cross-team governance structure to support the program and resolve critical decisions.

This also assures that the security strategy will be a flexible, living strategy, with critical internal leadership support. Utilise the insights from a risk-based vulnerability management approach to adjust strategy and investment based on critical vulnerabilities that pose the greatest business risk. 

Successfully get ahead of attackers

In the fast-moving environment of cybersecurity, where the entire business may be at risk,  organisations need to understand where to focus resources and investment to maximise their cyber risk reduction. At the same time, C-suite and boards of directors require a means to objectively measure cyber exposure. This should be in non-technical terms and allow business leaders to understand how they compare to their industry peers or other organisations with best-in-class security.

Adam Palmer, Chief Cybersecurity Strategist, Tenable

SME Business News

Albanese government looking to acquire Rex Airlines if buyer can’t be found

The Albanese government will on Wednesday announce it is willing, as a last resort, to purchase the collapsed Rex Airlines, in its latest bid to prop up aviation services to regional and remo...

The Legal Battle Against IP Theft: What Businesses Need to Know

So you've formulated that million-dollar idea and you're ready to take your business to the next level. You were so excited to publicize your supposedly next big thing that you went on TikTok...

Top 20 SEO and Guest Post Services in Wyoming Helping Brands Expand Their Reach

Today’s business needs to have strong online visibility to grow and reach more customers. Guest post services and SEO services make it easier for the brand to rank higher on their search engine...

Everything You Need to Know About PLR Digital Products to Resell for Maximum Passive Income

In the ever-evolving digital product world, the concept of Private Label Rights (PLR) has emerged as a lucrative opportunity for entrepreneurs who aim to generate passive income. PLR digital prod...

Property Times

Floor Tiling: Choosing the Right Tiles for Every Room

Choosing floor tiles is more than just grabbing the first design that catches your eye at the showroom. You need to think about how the floor tiling option will fit into your space, how durable it is, and whether it’s safe for that particular area...

Yes, Australia needs new homes – but they must be built to withstand disasters in a warmer world

Australia’s housing crisis has created a push for fast-tracked construction. Federal, state and territory governments have set a target of 1.2 million new homes[1] over five years. Increasing housing supply is essential. However, the homes must ...

Don't Get Burned—Smart Insurance for Your Investment Property

Real estate investment offers lucrative opportunities even though it brings operational risks. Real estate investment protection fundamentally depends on obtaining the correct insurance policy. Your financial security and asset protection require you...

The Importance of Pre-Purchase Building Inspections

Purchasing a property is quite possibly one of the most significant financial decisions you'll ever make. The allure of a new home or investment can often overshadow the necessity for meticulous evaluation, potentially veiling costly pitfalls lurki...

Food & Dining

7 Tips to Brew Perfect Mullein Tea Every Time

Brewing the perfect cup of mullein tea can often feel elusive, especially with all the conflicting advice available online. You might struggle with weak flavour, overpowering bitterness, or even the challenge of floating leaves in your cup.  Fortu...

Fresh Ideas for Celebrating the Year of the Snake

The Lunar New Year is here, and with it comes the Year of the Snake—a time for fresh beginnings, family connections, and, of course, delicious food. As celebrations kick off, Australian families are turning to summer’s bounty of fresh produce to ...

Drop of Sunshine | The perfect gift for that special someone this Valentine’s day

Drop of Sunshine: A Toast to Women, Our Connections & The Stories That Bring Us Together Treasury Wine Estates (TWE), one of the world’s leading wine companies, has launched a new line of premium wines,  Drop of Sunshine, in partnership wit...

Delicious and Healthy Vitamix Recipes for Optimal Nutrition

🍏🥦 Enjoy tasty Vitamix recipes packed with nutrients for optimum health. Healthy eating 🥕🍓 made fun & delicious! 💪🍹 #Nutrition #VitamixRecipes Healthy Eating and Optimal NutritionRenowned for its versatility and unparalleled blending capabilitie...

The Times Features

What’s the difference between wholemeal and wholegrain bread? Not a whole lot

If you head to the shops to buy bread, you’ll face a variety of different options. But it can be hard to work out the difference between all the types on sale. For instance...

Expert Tips for Planning Home Electrical Upgrades in Australia

Home electrical systems in Australia are quite intricate and require careful handling. Safety and efficiency determine the functionality of these systems, and it's critical to ...

Floor Tiling: Choosing the Right Tiles for Every Room

Choosing floor tiles is more than just grabbing the first design that catches your eye at the showroom. You need to think about how the floor tiling option will fit into your spa...

Exploring Family Caravans: Your Ultimate Guide to Mobile Living and Travel

Australia is the land of vast horizons, spectacular coastlines, and a never-ending adventure. As landscapes and adventures vary across the country, Voyager will route you, carava...

Energy-Efficient Homes in Geelong: How a Local Electrician Can Help You Save Money

Rising energy bills don’t have to be the new normal. With Victoria’s energy prices up 25% last year, Geelong homeowners are fighting back and winning, by partnering with licenced...

Eating disorders don’t just affect teen girls. The risk may go up around pregnancy and menopause too

Eating disorders impact more than 1.1 million people in Australia[1], representing 4.5% of the population. These disorders include binge eating disorder, bulimia nervosa, and...

Business Times

Albanese government looking to acquire Rex Airlines if buyer can’…

The Albanese government will on Wednesday announce it is willing, as a last resort, to purchase the collapsed Rex Airline...

The Legal Battle Against IP Theft: What Businesses Need to Know

So you've formulated that million-dollar idea and you're ready to take your business to the next level. You were so excit...

Top 20 SEO and Guest Post Services in Wyoming Helping Brands Expa…

Today’s business needs to have strong online visibility to grow and reach more customers. Guest post services and SEO servi...

LayBy Shopping