Times Media Advertising

The Times Australia
Small Business News

.

How to Communicate Cyber Risk to the Board

  • Written by: Adam Palmer, Chief Cybersecurity Strategist, Tenable



While today’s digitally-connected world has elevated the global economy to new heights, one cannot ignore the fact that cyberattacks and data breaches have also become a frequent problem. Research has shown that cyberattacks are on the rise among organisations, with cybercrime costing the

Australian economy over $1 billion per year. The potential for cyber threats to cost organisations millions of dollars in cleanup, lost business and reputational damage clearly demonstrates the relationship between cyber risk and business risk. With so much at stake, CISOs, the entire C-suite, and the Board require insight into cyber exposure in the same way as other risks.

This practical guide will help CISOs communicate cyber risk to the C-suite and board of directors in a way that fosters a business-based dialogue for better, more informed decision making that focuses on maximising risk reduction.

Focus on critical risks

There’s a tendency to mistakenly follow a traditional “check-the-box” approach to addressing every risk. This is akin to chasing your own tail because it provides no visibility of actual risks and consumes valuable resources and time on vulnerabilities that have a low likelihood of being exploited.

Mature organisations have evolved from this archaic approach toward risk-based vulnerability management. Utilising threat intelligence, vulnerability research, and probability data allows a CISO to focus on critical risks. These are vulnerabilities that are actually at high risk of being exploited.

A 2019 study by McKinsey Consulting found that risk-based vulnerability management allows companies a potential risk reduction of 7.5 times above their original program, at no added cost.
                                                                              
Present the board with clear answers

Let’s be honest, when the C-suite or board of directors asks a CISO, “How secure are we?” the last thing they want is a long-winded answer. They expect insight into cyber risk in the same way as other operational areas, and with the same accuracy and predictability. 

Therefore, this is an opportunity for the CISO to present a measurable view of the organisation’s cyber risk exposure using internal and external comparative benchmarks. Consider using concise and understandable language suitable to guide strategic leadership decision-making by the board.

Cyberattacks have the ability to destroy an organisation’s reputation or competitive advantage, both of which are critical to the health of the business. Therefore, CISOs must be prepared to effectively communicate this message to the board and clearly explain how this risk is being addressed across the business unit, asset, and geo-location.

Channel resources appropriately

An effective CISO should measure success by risk reduction, not milestones or tool deployment. In a crisis, it is critical to know what controls are really effective. Demand assurance that the security team is focused on identifying and reducing critical vulnerabilities that pose a business risk.

Remediation actions should be prioritised to reduce the organisation’s cyber exposure. A CISO should drill down into specific vulnerabilities or assets to identify and support controls that are more effective and truly reduce risk.

Make cybersecurity risk management a living strategy

Consider meeting with the C-suite frequently to review risk priorities and strategy. Without a solid internal governance structure, organisations will have trouble building any success. 

Oversight of security may be led by the CISO, but the entire C-suite should drive a cross-team leadership approach. Security is a team effort and a moving process. It is linked to every part of business operations and therefore requires a cross-team governance structure to support the program and resolve critical decisions.

This also assures that the security strategy will be a flexible, living strategy, with critical internal leadership support. Utilise the insights from a risk-based vulnerability management approach to adjust strategy and investment based on critical vulnerabilities that pose the greatest business risk. 

Successfully get ahead of attackers

In the fast-moving environment of cybersecurity, where the entire business may be at risk,  organisations need to understand where to focus resources and investment to maximise their cyber risk reduction. At the same time, C-suite and boards of directors require a means to objectively measure cyber exposure. This should be in non-technical terms and allow business leaders to understand how they compare to their industry peers or other organisations with best-in-class security.

Adam Palmer, Chief Cybersecurity Strategist, Tenable

Property Times

Budget Shockwaves: What the Federal Budget Means for Australia’s Property Market

Australia’s property market does not operate in isolation. Every federal budget sends signals to buyers, sellers, investors, developers, banks and renters about the direction of the economy, taxation, confidence and household spending. This year’s ...

Real Estate and the Federal Budget: Early Signs Emerging Across Australia’s Property Market

Australia’s federal budget has landed, and while economists, investors and political strategists continue dissecting its long-term implications, the property industry is already searching for early signs of where the market may be heading next. Re...

Since the Budget: How the Real Estate Industry Reacted

Australia’s real estate industry has reacted to the federal budget with a mixture of optimism, caution, frustration and uncertainty. For developers and some first-home buyers, parts of the budget have been welcomed as a long overdue attempt to pus...

What Has the Federal Budget Done to Relieve Mortgage Stress?

For millions of Australians struggling with rising home loan repayments, the federal budget prompted one overriding question: did the government actually do anything meaningful to relieve mortgage stress? The answer depends partly on politics, par...

Food & Dining

The Rocks and Circular Quay: Ten Restaurants

Restaurants That Showcase Sydney Dining at Its Best Sydney’s dining scene has always benefited from one enormous advantage: location. Few places in the world can combine harbour views, historic sandstone laneways, luxury hotels and globally influenc...

Korean Food and Longevity

South Korean Food and Longevity: Why the World Is Suddenly Paying Attention For years, people around the world associated South Korea with technology, K-pop, beauty products and fast economic growth. Now another export is attracting global fascina...

Restaurants Are Packed Again — So Why Are Australians Spending Less?

Australians still love dining out. Despite years of inflation, rising interest rates, higher rents and mounting pressure on household budgets, cafes, pubs and restaurants across the country continue to fill tables every weekend. Walk through dining...

Dining Out Is Expensive. Buying High Quality Meat and Fish at the Supermarket Is Becoming the New Luxury

For many Australians, dining out has quietly shifted from a weekly habit to an occasional indulgence. Restaurant prices have climbed sharply over recent years as businesses face higher wages, soaring electricity bills, increased insurance premiums...

Business Times

“AI Will Kill Jobs”: Why Millions Fear What’s Coming Next — But S…

Artificial intelligence is rapidly changing the workplace and for many Australians the mood is shifting from curiosity to a...

Ariana solidifies strategic pathway to advance Zimbabwe’s largest…

Ariana Resources has strengthened its war chest for the development of its Dokwe project – Zimbabwe’s largest undeveloped g...

Businesses Want to Grow — But the Banks Are Holding the Purse Str…

Australian businesses say obtaining finance has become significantly harder as lenders tighten standards, interest rates re...

The Times Features

Property Still Attractive To Investors Post Federal Bud…

Australia’s federal budget may have shaken the property sector, but it has not destroyed investor ...

What to Expect from Your First Invisalign Treatment Con…

Thinking about straightening your teeth but not keen on traditional braces? You’re not alone. A lo...

Day Spa Culture in Australia: What to Look For Before B…

The modern day spa is no longer viewed as an occasional luxury reserved for celebrities, honeymoon...

The Rocks and Circular Quay: Ten Restaurants

Restaurants That Showcase Sydney Dining at Its Best Sydney’s dining scene has always benefited from...

Australian Fashion Week: Local Style Takes Centre Stage

Australian fashion is once again stepping onto the global stage as Australian Fashion Week draws d...

Selling a House in Sydney: Did the Budget Make It More …

For many Australians, selling a home should be one of life’s simpler financial transactions. Find...

Cheap Wine in Australia: The Golden Age of Affordable D…

Australia has long enjoyed a reputation as one of the world’s great wine-producing nations, but fo...

Korean Food and Longevity

South Korean Food and Longevity: Why the World Is Suddenly Paying Attention For years, people aro...

Pretty Woman: The Movie That Keeps On Giving

Some films entertain audiences for a few months and quietly fade into cinematic history. Others be...