The board’s interests in cybersecurity
Cyber risk should not be considered in isolation, and cyber-risk data should not be presented as random numbers or lists when discussing it with the board. Management must clearly communicate to the board how one risk impacts another risk, including cyber, so all parties can effectively formulate a solution, rather than creating confusion and disinterest.
The capacity to demonstrate how cyber risk is interconnected with other risks is just as critical as the ability to demonstrate how cyber-risk mitigation measures are succeeding. In turn, this can assist the board in prioritizing expenditures on mitigation efforts, understanding the actual return on such investments, and recognizing the value the CISO brings to the organization by developing programs and providing tangible insight into which initiatives are successful and which are not. This enables you and the board of directors to assess whether initiatives are having an effect and...