{"id":88336,"date":"2019-01-31T11:15:24","date_gmt":"2019-01-31T19:15:24","guid":{"rendered":"https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/?p=88336"},"modified":"2023-05-15T22:59:29","modified_gmt":"2023-05-16T05:59:29","slug":"ciso-series-talking-cybersecurity-with-the-board-of-directors","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/01\/31\/ciso-series-talking-cybersecurity-with-the-board-of-directors\/","title":{"rendered":"CISO series: Talking cybersecurity with the board of directors"},"content":{"rendered":"
In today\u2019s threat landscape, boards of directors are more interested than ever before in their company’s cybersecurity strategy. If you want to maintain a board\u2019s confidence, you can\u2019t wait until after an attack to start talking to them about how you are securing the enterprise. You need to engage them in your strategy early and often\u2014with the right level of technical detail, packaged in a way that gives the board exactly what they need to know, when they need to know it.<\/p>\n
Cyberattacks have increased in frequency and size over the years, making cybersecurity as fundamental to the overall health of the business as financial and operational controls. Today\u2019s boards of directors know this, and they are asking their executive teams to provide more transparency on how their company manages cybersecurity risks. If you are a technology leader responsible for security, achieving your goals often includes building alignment with the board.<\/p>\n
Bret Arsenault, corporate vice president and chief information security officer (CISO) for Microsoft, was a recent guest on our CISO Spotlight Series<\/a>, where he shared several of his learnings on building a relationship with the board of directors. We\u2019ve distilled them down to the following three best practices:<\/p>\n Members of your board come from a variety of different backgrounds, and they are responsible for all aspects of risk management for the business, not just security. Some board members may track the latest trends in security, but many won\u2019t. When it\u2019s time to share your security update, you need to cut through all the other distractions and land your message. This means you will want to think almost as much about how you are going to share your information as what you are going to share, keeping in mind the following tips:<\/p>\n This doesn\u2019t mean you should dumb down your report or avoid important technical information. It means you need to adequately prepare. It may take several weeks to analyze internal security data, understand key trends, and distill it down to a 10-page report that can be presented in 30 to 60 minutes. Quarterly updates will help you learn what should be included in those 10 pages, and it will give you the opportunity to build on prior reports as the board gets more familiar with your strategy. No matter what, adequate planning can make a big difference in how your report is received.<\/p>\n Stories about security breaches get a lot of attention, and your board may hope you can prevent an attack from ever happening. A key aspect of your role is educating them on the reasons why no company will ever be 100 percent secure. The real differentiation is how effectively a company responds to and recovers from an inevitable incident.<\/p>\n You can also help your board understand the security landscape better with analysis of the latest security incidents and updates on cybersecurity regulations and legislation. Understanding these trends will help you align resources to best protect the company and stay compliant with regional security laws.<\/p>\n As you develop your content, keep in mind that the best way to get the board\u2019s attention is by aligning your messages to their top concerns. Many boards are focused on the following key questions:<\/p>\n To address these questions, Bret sticks to the following talking points:<\/p>\n When it comes to effectively working with the board and other executives across your organization, a CISO should focus on four primary functions: manage risk, oversee technical architecture, implement operational efficiency, and most importantly, enable the business. In the past, CISOs were completely focused on technical architecture. Good CISOs today, and those who want to be successful in the future, understand that they need to balance all four responsibilities.<\/p>\n Be sure to check out the interview with Bret in Part 1 of the CISO Spotlight Series, Security is Everyone\u2019s Business<\/a>, to hear firsthand his recommendations for talking to the board. And in Part 2, Bret walks through how to talk about security attacks and risk management with the board<\/a>.<\/p>\n The National Institute of Standards and Technology (NIST)\u00a0Cybersecurity Framework<\/a> is a great reference if you are searching for a benchmark model.<\/p>\n\n
Use the board\u2019s time effectively<\/h3>\n
\n
Keep the board educated on the state of cybersecurity<\/h3>\n
Speak to the board\u2019s top concerns<\/h3>\n
\n
\n
Learn more<\/h3>\n