Reporting to the board (an add-on for CISOs and a reference for CEOs)
Reporting to the board of directors about cyber risk should be done in plain English so that the board can quickly get a sense of what is happening within the organization. A cyber-reporting structure aligned with the business strategic initiatives or scorecard generated by the CISO may assist the board of directors in assessing existing cyber risks and tracking progress in cybersecurity.
A multi-year strategic plan, a current-year business strategy, resources, a cyber-training program, and other relevant information regarding the company’s cyber operations should all be made available to the board for a comprehensive picture of the company’s cyber activities, again in alignment with the strategic business initiatives.
According to a recent poll done by the Ponemon Institute, just 9 percent of security teams believe they are extremely successful in conveying security threats to the board of directors...