{"id":5138,"date":"2024-09-04T09:00:00","date_gmt":"2024-09-04T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/how-cisos-can-effectively-communicate-cyber-risk"},"modified":"2024-09-04T09:00:00","modified_gmt":"2024-09-04T14:00:00","slug":"how-cisos-can-effectively-communicate-cyber-risk","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/04\/how-cisos-can-effectively-communicate-cyber-risk\/","title":{"rendered":"How CISOs Can Effectively Communicate Cyber-Risk"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt730562b46d0b78c5\/66be4145fa2d5811b851cb52\/Risk%281800%29_Andriy_Popov_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More than half of chief information security officers (CISOs) struggle to effectively&nbsp;communicate cyber-risk to their leadership teams, according to&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/fticommunications.com\/wp-content\/uploads\/2024\/03\/FTI_CISO_REDEFINED_Study_2024.pdf\" rel=\"noopener\">FTI Consulting<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. If you&#8217;re part of this majority, you&#8217;re not alone. I spend countless hours each month in conversation with CISOs, talking about their concerns and challenges. Time and again, I hear the same frustration: translating complex <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\" rel=\"noopener\">cyber-risks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> into a digestible narrative for leadership is an uphill battle.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The challenge is multifaceted:&nbsp;<\/span><\/p>\n<div data-component=\"basic-list\" class=\"BasicList BasicList_nestedLevel_0 BasicList_variant_ordered BasicList_limited\">\n<ol data-testid=\"basic-list-ordered\" class=\"BasicList-OrderedList BasicList-OrderedList_nestedLevel_0 body-normal\">\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_ordered\" readability=\"11.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_ordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"18\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs are competing for attention in a sea of business risks. In many modern enterprise organizations, security teams exist alongside enterprise risk management (ERM) or governance, risk, and compliance (GRC) teams that track business risk holistically. Cyber concerns are just one item on a lengthy list of priorities, including financials, broader economic factors, geopolitics, climate issues, and personnel challenges.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_ordered\" readability=\"10.395781637717\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_ordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"15.841191066998\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Traditional risk communication tools aren&#8217;t effective storytelling vehicles. When ERM or GRC teams review <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/soft-skills-every-ciso-needs-inspire-better-boardroom-relationships\" rel=\"noopener\">risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with leadership, they often present heat maps that reduce complexity, or risk registers that overwhelm with hundreds, if not thousands, of lines of content. In either case, the nuances of cyber-risk get lost in the data, which means that leaders are disconnected from the details that matter.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_ordered\" readability=\"6.2771739130435\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_ordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"8.3695652173913\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The stakes are higher than ever. With the average cost of a data breach&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ibm.com\/reports\/data-breach\" rel=\"noopener\">reaching $4.88 million in 2024<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the need for clear, compelling risk communication has never been more critical.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<\/ol>\n<\/div>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Decoding Cyber-Risk: What Goes Into a Proximity Resilience Graph\">Decoding Cyber-Risk: What Goes Into a Proximity Resilience Graph<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the face of rising cyber threats and communication challenges, how can CISOs present their data to leadership in a clearer, more compelling way? I recommend creating a proximity resilience graph \u2014 a powerful visual tool that transforms abstract risk data into an engaging, actionable narrative.&nbsp;<\/span><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.png?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Cyber-Risk Index graph\" title=\"Cyber-Risk Index graph\"><\/p>\n<p class=\"ContentImage-Link\">Source: Recorded Future<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Let&#8217;s break down the components of the graph to see why it&#8217;s so useful:<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The Y-axis<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, labeled&nbsp;Resilience, represents an organization&#8217;s cybersecurity muscle. It encompasses all controls, efforts, plans, processes, technologies, and resources, going well beyond standard GRC checklists. For example, imagine implementing a gamified phishing training program. As employee engagement and resilience against social engineering improve, you&#8217;d see this reflected in a downward movement along the Y-axis. This axis is crucial because it showcases the tangible impact of an organization&#8217;s security investments and initiatives.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The X-axis<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, labeled&nbsp;Proximity&nbsp;(as in&nbsp;Attack Proximity), captures the totality of threats surrounding an organization. When mapping this axis, a CISO should use all the security and threat data available to them from internal security telemetry, external threat telemetry, and public cyberattack events. For instance, if a healthcare company discovers a spike in ransomware attacks targeting its sector, attack proximity would shift right. Similarly, if a manufacturing firm&#8217;s security operations center (SOC) detects a surge in phishing attempts, that internal telemetry signal would move proximity to the right as well. This axis provides vital context, showing how internal and external factors influence an organization&#8217;s risk posture.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The graph midlines<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;help viewers visualize movement, and the top label is the absolute reference to anchor time increments. The amount of movement and the midline labels are flexible, turning it into a dynamic story that shows the evolution of an organization&#8217;s security posture. A CISO should choose a time segment that&#8217;s large enough to show movement. If they meet quarterly with their board or directors, they can use the start of a quarter as the label.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The quadrant labels<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014&nbsp;Unstable, Stable, Exposed, and Covered&nbsp;\u2014 are simple and expressive, but a CISO can adjust or eliminate them as needed after seeing their effect on audience engagement and comprehension.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">the data points<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;represent the five key risk impacts:&nbsp;Operational Disruption, Brand Impairment, Financial Fraud, Competitive Disadvantage, and Legal or Compliance Failure. Ultimately, the proximity resilience graph provides value by highlighting movement, showing whether resilience is improving or getting worse for a particular risk impact. For example, after a successful ransomware tabletop exercise, the&nbsp;Operational Disruption<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">&nbsp;<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">point would shift down on the Y-axis, indicating improved resilience. This granular approach allows for nuanced discussions about specific risk areas, rather than generalizing all cyber-risk.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On the X-axis, threat categories fuel risk impact movement, and it&#8217;s up to CISOs to translate how threat categories map to various risk impacts. For example, a business email compromise (BEC) primarily creates a Financial Fraud risk impact, but it might also trigger Brand Impairment if the event becomes public.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Bridging the Communication Gap: Build Your Proximity Resilience Graph\">Bridging the Communication Gap: Build Your Proximity Resilience Graph<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Not only does a proximity resilience graph offer a more accurate representation of risk than heat maps and risk registers, it also allows CISOs to tell a complex story in a single visualization. It avoids subjective labels and allows for different interpretations so leaders can see where and how resilience is changing and start asking informed questions. It also eliminates the chance of cyber-risk getting lost in the noise of broader business risk.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A proximity resilience graph enhances leaders&#8217; risk comprehension and engagement, boosts their confidence in the timing of present and future cybersecurity investments, and improves perceptions of the security team&#8217;s value.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-cisos-can-effectively-communicate-cyber-risk\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY More than half of chief information security officers (CISOs)<\/p>\n","protected":false},"author":12,"featured_media":5139,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/how-cisos-can-effectively-communicate-cyber-risk.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5138"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5138\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5139"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}