Corporate cybersecurity leaders still underestimate themselves and the value they can bring to the business to boards, making it difficult to engage business leaders on cyber, according to experts speaking at Infosecurity Europe. It is said that
Paul Watts, a prominent analyst at the Information Security Forum, says that while board leaders are nominally more focused on security than they used to be, they often lose focus due to commercial and other pressures, and there argued that the CISO should intervene in
But more often than not, CISOs go back to hunting themselves down and continuing to look at their functions purely from a governance, risk, and compliance (GRC) perspective.
“If companies continue to look at us only for risk and compliance, we will always have a ticking time bomb of breach events. Narrowing our mandate is a bad idea,” he argues. bottom.
For more information, see Information Security Europe: How to Survive the Coming Cybersecurity Storm.
Accenture’s global cyber strategy lead, Valerie Abend, highlighted a few other common mistakes CISOs make when interacting with the board. These include data overload, use of intimidation tactics, overconfidence, not asking enough questions of executives, and not taking the time to understand individual business units and organizations. Explain how security adds value.
“As security professionals, it is very important to have a deep understanding of the processes across critical business functions, speak their language, and explain how we can deliver value,” she explained.
Watts agrees, saying that gaining board involvement often requires CISOs to revitalize security brands, lead by example, and be better negotiators and marketers. claimed.
“We exist across the business value chain. We need to celebrate our success and the markets that can bring that value to different places across the value chain,” he said. . “Adding or removing security controls has a huge impact on cost and agility, so working alone defeats what the business is trying to do.”
In the experience of Paul Midian, CISO of Easyjet, articulating cybercrime in business terms can be eye-opening for board members. In effect, realizing that rivals are under attack, and understanding which assets are at risk and why, makes the whole discussion easier to understand, he explained.
Deborah Haworth, director of information security at Penguin Random House, added that CISOs should reach out to the community more often. Because the community can be a great resource to help advise on tactics for board engagement.
Most importantly, she argued, security chiefs shouldn’t leave relationship-building efforts up to the board of directors.
“They are the seniors you work with,” Haworth said. “We need constant engagement with cybercriminals because when cybercriminals are under attack, we need to have open and trusting conversations. We may not be able to understand each other and help each other.”