The Times Australia
Fisher and Paykel Appliances
Small Business News

.

How to Communicate Cyber Risk to the Board

  • Written by Adam Palmer, Chief Cybersecurity Strategist, Tenable



While today’s digitally-connected world has elevated the global economy to new heights, one cannot ignore the fact that cyberattacks and data breaches have also become a frequent problem. Research has shown that cyberattacks are on the rise among organisations, with cybercrime costing the

Australian economy over $1 billion per year. The potential for cyber threats to cost organisations millions of dollars in cleanup, lost business and reputational damage clearly demonstrates the relationship between cyber risk and business risk. With so much at stake, CISOs, the entire C-suite, and the Board require insight into cyber exposure in the same way as other risks.

This practical guide will help CISOs communicate cyber risk to the C-suite and board of directors in a way that fosters a business-based dialogue for better, more informed decision making that focuses on maximising risk reduction.

Focus on critical risks

There’s a tendency to mistakenly follow a traditional “check-the-box” approach to addressing every risk. This is akin to chasing your own tail because it provides no visibility of actual risks and consumes valuable resources and time on vulnerabilities that have a low likelihood of being exploited.

Mature organisations have evolved from this archaic approach toward risk-based vulnerability management. Utilising threat intelligence, vulnerability research, and probability data allows a CISO to focus on critical risks. These are vulnerabilities that are actually at high risk of being exploited.

A 2019 study by McKinsey Consulting found that risk-based vulnerability management allows companies a potential risk reduction of 7.5 times above their original program, at no added cost.
                                                                              
Present the board with clear answers

Let’s be honest, when the C-suite or board of directors asks a CISO, “How secure are we?” the last thing they want is a long-winded answer. They expect insight into cyber risk in the same way as other operational areas, and with the same accuracy and predictability. 

Therefore, this is an opportunity for the CISO to present a measurable view of the organisation’s cyber risk exposure using internal and external comparative benchmarks. Consider using concise and understandable language suitable to guide strategic leadership decision-making by the board.

Cyberattacks have the ability to destroy an organisation’s reputation or competitive advantage, both of which are critical to the health of the business. Therefore, CISOs must be prepared to effectively communicate this message to the board and clearly explain how this risk is being addressed across the business unit, asset, and geo-location.

Channel resources appropriately

An effective CISO should measure success by risk reduction, not milestones or tool deployment. In a crisis, it is critical to know what controls are really effective. Demand assurance that the security team is focused on identifying and reducing critical vulnerabilities that pose a business risk.

Remediation actions should be prioritised to reduce the organisation’s cyber exposure. A CISO should drill down into specific vulnerabilities or assets to identify and support controls that are more effective and truly reduce risk.

Make cybersecurity risk management a living strategy

Consider meeting with the C-suite frequently to review risk priorities and strategy. Without a solid internal governance structure, organisations will have trouble building any success. 

Oversight of security may be led by the CISO, but the entire C-suite should drive a cross-team leadership approach. Security is a team effort and a moving process. It is linked to every part of business operations and therefore requires a cross-team governance structure to support the program and resolve critical decisions.

This also assures that the security strategy will be a flexible, living strategy, with critical internal leadership support. Utilise the insights from a risk-based vulnerability management approach to adjust strategy and investment based on critical vulnerabilities that pose the greatest business risk. 

Successfully get ahead of attackers

In the fast-moving environment of cybersecurity, where the entire business may be at risk,  organisations need to understand where to focus resources and investment to maximise their cyber risk reduction. At the same time, C-suite and boards of directors require a means to objectively measure cyber exposure. This should be in non-technical terms and allow business leaders to understand how they compare to their industry peers or other organisations with best-in-class security.

Adam Palmer, Chief Cybersecurity Strategist, Tenable

Property Times

Why the Prevailing RBA Mortgage Interest Rates Are Not to Blame for the Continuing Rise in Residential Dwelling Prices

Australia’s housing market remains one of the most debated economic issues of the decade. Despite successive Reserve Bank of Australia (RBA) interest rate hikes aimed at cooling demand, residential dwelling prices across most capital cities and man...

How Real Estate Agent Commissions Work in Australian States and Territories

When buying or selling property in Australia, one of the biggest costs—beyond the property price itself—comes from real estate agent commissions. These commissions are the fees agents charge for marketing, negotiating, and finalising the sale of ...

Understanding Centrelink Investment Property Valuation: A Guide for Australian Property Owners

Introduction Owning an investment property in Australia can bring financial stability — but it also comes with responsibilities, especially when it comes to Centrelink assessments. Whether you’re applying for age pensions, disability benefits, or ...

Rubber vs Concrete Wheel Stops: Which is Better for Your Car Park?

When it comes to setting up a car park in Perth, wheel stops are a small feature that make a big difference. From improving driver accuracy to preventing costly damage, the right choice between rubber and concrete wheel stops could save you time, mon...

Food & Dining

Farm to Fork Australia Launches Exciting 7th Season on Ten

New Co-Host Magdalena Roze joining Michael Weldon, Courtney Roulston, Louis Tikaram, and Star Guest ChefsDual Entertainment is proud to announce that Australia’s beloved food and farming series, Farm to Fork Australia, makes its much-anticipated retu...

Renowned Sydney Restaurant, Alpha Dining, Welcomes New Executive Chef: Riccardo Pazzona

Sydney’s modern Greek dining institution, Alpha Dining, has announced the appointment of Riccardo Pazzona as Executive Chef.  Operated by the Dedes Waterfront Group and located in the heart of Sydney’s CBD, Alpha has long been at the forefront o...

Shane Delia's Malta serves up a Mediterranean summer on SBS

One of Australia’s most celebrated chefs, Shane Delia invites you to the vibrant archipelago of Malta; a Mediterranean crossroads where cuisine and culture collide. From turquoise harbours to olive groves, every corner of Malta bursts with rich h...

Meet Ella’s Elbow: The citrus squeezer and shot measurer redefining form and function

We recently got our hands on the new Ella’s Elbow, a patented citrus squeezer that’s made to feel as though it was designed for squeezing blood from a stone. It cleverly doubles as a shot measurer, making it an all in one, cocktail making behemoth. W...

Active Wear

Business Times

Intuit QuickBooks Launches Australia's Most Advanced Open Banking…

Intuit Australia Pty Limited, subsidiary of Intuit Inc. (NASDAQ: INTU), the global financial technology platform behind I...

Alpha HPA appoints Peter Ware as Chief Operating Officer

Alpha HPA appoints Peter Ware as Chief Operating Officer today, bringing extensive industrial leadership experience to supp...

Australia after the Trump–Xi meeting: sector-by-sector opportunit…

How the U.S.–China thaw could play out across key sectors, with best case / base case / downside scenarios, leading indic...

The Times Features

How airline fares are set and should we expect lower fares any time soon?

Airline ticket prices may seem mysterious (why is the same flight one price one day, quite anoth...

What is the American public’s verdict on the first year of Donald Trump’s second term as President?

In short: the verdict is decidedly mixed, leaning negative. Trump’s overall job-approval ra...

A Camping Holiday Used to Be Affordable — Not Any Longer: Why the Cost of Staying at a Caravan Park Is Rising

For generations, the humble camping or caravan holiday has been the backbone of the great Austra...

Australia after the Trump–Xi meeting: sector-by-sector opportunities, risks, and realistic scenarios

How the U.S.–China thaw could play out across key sectors, with best case / base case / downside...

World Kindness Day: Commentary from Kath Koschel, founder of Kindness Factory.

What does World Kindness Day mean to you as an individual, and to the Kindness Factory as an organ...

HoMie opens new Emporium store as a hub for streetwear and community

Melbourne streetwear label HoMie has opened its new store in Emporium Melbourne, but this launch is ...

TAFE NSW empowers women with the skills for small business success

Across New South Wales, TAFE NSW graduates are turning their skills into success, taking what they h...

The median price of residential land sold nationally jumped by 6.8 per cent

Land prices a roadblock to 1.2 million homes target “The median price of residential land sold na...

Farm to Fork Australia Launches Exciting 7th Season on Ten

New Co-Host Magdalena Roze joining Michael Weldon, Courtney Roulston, Louis Tikaram, and Star Guest ...