Google AI
The Times Australia

Times Media Advertising

How to Communicate Cyber Risk to the Board

  • Written by: Adam Palmer, Chief Cybersecurity Strategist, Tenable



While today’s digitally-connected world has elevated the global economy to new heights, one cannot ignore the fact that cyberattacks and data breaches have also become a frequent problem. Research has shown that cyberattacks are on the rise among organisations, with cybercrime costing the

Australian economy over $1 billion per year. The potential for cyber threats to cost organisations millions of dollars in cleanup, lost business and reputational damage clearly demonstrates the relationship between cyber risk and business risk. With so much at stake, CISOs, the entire C-suite, and the Board require insight into cyber exposure in the same way as other risks.

This practical guide will help CISOs communicate cyber risk to the C-suite and board of directors in a way that fosters a business-based dialogue for better, more informed decision making that focuses on maximising risk reduction.

Focus on critical risks

There’s a tendency to mistakenly follow a traditional “check-the-box” approach to addressing every risk. This is akin to chasing your own tail because it provides no visibility of actual risks and consumes valuable resources and time on vulnerabilities that have a low likelihood of being exploited.

Mature organisations have evolved from this archaic approach toward risk-based vulnerability management. Utilising threat intelligence, vulnerability research, and probability data allows a CISO to focus on critical risks. These are vulnerabilities that are actually at high risk of being exploited.

A 2019 study by McKinsey Consulting found that risk-based vulnerability management allows companies a potential risk reduction of 7.5 times above their original program, at no added cost.
                                                                              
Present the board with clear answers

Let’s be honest, when the C-suite or board of directors asks a CISO, “How secure are we?” the last thing they want is a long-winded answer. They expect insight into cyber risk in the same way as other operational areas, and with the same accuracy and predictability. 

Therefore, this is an opportunity for the CISO to present a measurable view of the organisation’s cyber risk exposure using internal and external comparative benchmarks. Consider using concise and understandable language suitable to guide strategic leadership decision-making by the board.

Cyberattacks have the ability to destroy an organisation’s reputation or competitive advantage, both of which are critical to the health of the business. Therefore, CISOs must be prepared to effectively communicate this message to the board and clearly explain how this risk is being addressed across the business unit, asset, and geo-location.

Channel resources appropriately

An effective CISO should measure success by risk reduction, not milestones or tool deployment. In a crisis, it is critical to know what controls are really effective. Demand assurance that the security team is focused on identifying and reducing critical vulnerabilities that pose a business risk.

Remediation actions should be prioritised to reduce the organisation’s cyber exposure. A CISO should drill down into specific vulnerabilities or assets to identify and support controls that are more effective and truly reduce risk.

Make cybersecurity risk management a living strategy

Consider meeting with the C-suite frequently to review risk priorities and strategy. Without a solid internal governance structure, organisations will have trouble building any success. 

Oversight of security may be led by the CISO, but the entire C-suite should drive a cross-team leadership approach. Security is a team effort and a moving process. It is linked to every part of business operations and therefore requires a cross-team governance structure to support the program and resolve critical decisions.

This also assures that the security strategy will be a flexible, living strategy, with critical internal leadership support. Utilise the insights from a risk-based vulnerability management approach to adjust strategy and investment based on critical vulnerabilities that pose the greatest business risk. 

Successfully get ahead of attackers

In the fast-moving environment of cybersecurity, where the entire business may be at risk,  organisations need to understand where to focus resources and investment to maximise their cyber risk reduction. At the same time, C-suite and boards of directors require a means to objectively measure cyber exposure. This should be in non-technical terms and allow business leaders to understand how they compare to their industry peers or other organisations with best-in-class security.

Adam Palmer, Chief Cybersecurity Strategist, Tenable

Property Times

Why Australia Was Hoping For Another Interest Rate Cut

When the Reserve Bank considers interest rates, the focus is often on inflation, employment and economic growth. But beyond economists and financial markets, there is another group paying close attention: Australia's property sector. The prospect...

Why Australians need to rethink new apartments after the budget changes

As the Federal Government pushes to accelerate housing supply and incentivise new residential development amid Australia’s housing shortage, industry leaders say New South Wales is better positioned than ever to meet demand following a major transf...

Property markets react to budget signals before laws are even passed

Australia’s property market has already begun reacting to the federal budget announcements despite many of the proposed measures not yet becoming law. Across residential, commercial and industrial sectors, sentiment has shifted. Buyers, investors...

Most Australians think the Budget Just Changed the Rules on Property. They Have No Idea How Far it Actually Goes.

A generation of Australians may be entering the biggest rethink of wealth creation since the rise of the property boom, with the Federal Budget shaking confidence in the investment strategies many households spent decades relying on. The CEO of Ph...

Food & Dining

Macca’s introduces new McSmart range with more choice from $6.95

Macca’s is launching its new-look McSmart range from Wednesday,1 July, with  three new meals at three price points.More than 30 million McSmart meals have been sold across the country over the past 12  months, with McSmart becoming a go-to option for...

The Economics of a Cup of Coffee: Is Your Daily Cappuccino Costing More Than You Think?

For many Australians, a morning coffee is no longer a luxury. It is a ritual. A quick stop at the local café for a cappuccino, latte or flat white has become part of daily life. But with café coffee regularly reaching $7 per cup in many parts of A...

Two Modern Twists on the Iconic Martini Recipe: Your Guide to Celebrate World Martini Day Your Way in 2026

Few cocktails have achieved the cultural status of the martini. A fixture of cocktail culture for decades, the iconic serve has even earned its own day, with World Martini Day to be celebrated on Saturday, 20 June 2026.  Simple, sophisticated and ...

Breakfast: step up to something new at home

Australians have long loved the traditional breakfast of bacon, eggs and toast, but in an era of rising café prices there is another option: create a café-quality breakfast at home that is both satisfying and mindful of calories. The good news is ...

Business Times

The Businesses That Win First After A Crisis

When a crisis dominates headlines, most business owners focus on survival. Cash flow becomes king. Expansion plans are po...

Click and collect changes the economics of Australian shopping ce…

Australia’s major supermarkets are transforming consumer behaviour through home delivery and click and collect services, bu...

Australia’s business paradox: investing for growth while preparin…

Australian businesses are sending mixed signals in 2026. On one hand, investment remains surprisingly resilient. Companies...

Technology

Why Australian Enterprises Are Reth…

The corporate landscape in Australia has undergone a permanent structural shift over the past few ...

Local News

QLD Day

On Saturday 6 June, parkrun events across the state will be a sea of maroon, with communities  str...

Culture

Covid: The pandemic has ended but the health …

Covid is no longer the daily emergency it was in 2020 and 2021. The fear, lockdowns, border closur...

Travel

The Times Guide to Sydney's Beaches

Winter may still have a grip on Sydney, but anyone who has lived in Australia's largest city knows...

The Times Features

Pauline Hanson at the National Press Club: A Defining P…

For almost 30 years, Senator Pauline Hanson has been one of the most recognisable and controversia...

Covid: The pandemic has ended but the health story hasn…

Covid is no longer the daily emergency it was in 2020 and 2021. The fear, lockdowns, border closur...

Macca’s introduces new McSmart range with more choice f…

Macca’s is launching its new-look McSmart range from Wednesday,1 July, with  three new meals at thre...