{"id":6722,"date":"2024-12-23T09:00:00","date_gmt":"2024-12-23T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-cisos-communicate-boards-effectively"},"modified":"2024-12-23T09:00:00","modified_gmt":"2024-12-23T15:00:00","slug":"how-cisos-can-communicate-with-their-boards-effectively","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/12\/23\/how-cisos-can-communicate-with-their-boards-effectively\/","title":{"rendered":"How CISOs Can Communicate With Their Boards Effectively"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta2c37bdc93040c41\/671a4a28686c4370db41b061\/Boardroom%281800%29_Stephen_Barnes-Business_Alamy_Stock_Photo.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The role of the chief information security officer (CISO) today is&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/new-ciso-rethinking-the-role\">not the CISO&#8217;s role of the past<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The ever-evolving threat landscape, adoption of new technologies like&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/genai-powered-attacks-change-the-game\">generative AI<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;(GenAI), increased regulatory pace, ongoing employee education and training programs, and maintaining operational resilience have found CISOs under increased pressure and stress. On top of this,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.trellix.com\/solutions\/mind-of-the-ciso-crossroads\/\">49% of CISOs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;now <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/soft-skills-every-ciso-needs-inspire-better-boardroom-relationships\">report to their board<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;on at least a weekly basis, presenting them with a new skill they need to master: the art of communication.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Historically, board support increased only after a cyberattack, putting CISOs in a reactive rather than proactive role. But with today&#8217;s increased visibility of breaches, product failures, and the legal ramifications amplified by the media, there&#8217;s a microscope on cybersecurity practices within every organization. Boards are now interested in understanding the security status of their organization and the security decisions being made at the highest level. This increased desire requires&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/how-to-get-your-board-on-board-with-cybersecurity\">extended engagement with the board<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which has also elevated the CISO&#8217;s position and visibility within the company.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Today&#8217;s CISOs report to the board on topics covering cybersecurity risk management, assessment and mitigation plans, high-level strategic overviews, planning and alignment, and regulatory compliance and audit results. This information helps boards understand the organization&#8217;s overall preparedness and standing relating to the latest regulatory guidance and threats, as well as future planning and alignment with the overall business strategy.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While CISOs agree board engagement is helping to drive positive changes in their cybersecurity strategies, communication and knowledge barriers still exist. Speaking the business language is a skill many CISOs still need to develop to align with their board and succeed in securing additional budgets and resources for their programs.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Here are a few tips for CISOs to keep in mind when reporting to their board, and ones I&#8217;ve found success with:&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Preparation Is Key\">1. Preparation Is Key<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Go into these meetings with a high degree of preparation and understanding, with clarity on the numbers. Collaborate with your C-suite ahead of time and ensure alignment on specific strategies \u2014 this will help position your initiatives alongside innovation.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Find an Ally\">2. Find an Ally<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Try to find a sympathetic ear on the board beforehand \u2014 someone who wants to lean in and understand cybersecurity a little better. Run your presentation by them in advance to ensure you&#8217;re delivering the right level of content.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Less Is More\">3. Less Is More<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The deck should start with a high-level overview. Understand there is a lot more you want to say, but there&#8217;s only so much the board will receive. Summarize anything less important so you can call their attention to the items that really matter. Stick all the items that aren&#8217;t essential in the appendix.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"4. Stay on Topic\">4. Stay on Topic<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Pass out copies of your presentation to each board member before you present \u2014 and avoid reading your slides. The slides ultimately become an addendum to the discussion that happens in the room \u2014 but it&#8217;s important you move each discussion along succinctly to ensure there&#8217;s enough time to cover the most important topics.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"5. Align Your Cybersecurity Objectives With Business Goals\">5. Align Your Cybersecurity Objectives With Business Goals<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Align your initiatives with business goals and frame them in terms of business value \u2014 enabling growth, protecting brand reputation, and preventing financial losses. Many, if not all, board members don&#8217;t have the cybersecurity expertise or technical background you do, and they won&#8217;t understand the technology jargon. Up-level your messaging and align it with the key business goals. It&#8217;s not about what you need to run the department; it&#8217;s about what they need to run the business.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"6. Communicate in Terms of Risk\">6. Communicate in Terms of Risk<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Aligning with business goals and communicating risks in financial terms will help you bridge the knowledge gap and further position you as a valuable seat at the table. People understand numbers \u2014 focus on the ones that have an impact. Your program is an investment \u2014 so what are the results? Are there any areas that need more investment \u2014 or less?<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"7. Include Industry Insights\">7. Include Industry Insights<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Include insights into something currently or recently happening at another company in your industry and what it could mean for you. If the same thing happens to you, would the impact be material? That&#8217;s the question you need to have an answer to. Focus on business and operational resilience, as well as crisis communications preparedness.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the increased frequency of board reporting, CISOs need to ensure their interactions are brief, productive, and valuable. The CISOs who will succeed in this expanded role are those who can evolve beyond technical acumen to adopt a more business-focused lens and master the art of storytelling.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-cisos-communicate-boards-effectively\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The role of the chief information security officer (CISO)<\/p>\n","protected":false},"author":12,"featured_media":6723,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6722","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/how-cisos-can-communicate-with-their-boards-effectively.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6722","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6722"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6722\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6723"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6722"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6722"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6722"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}