• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Resources Blogs

PodChats for FutureCISO: Getting the board buy-in for cyber security in 2023

allantan by allantan
June 9, 2023

PodChats for FutureCISO: Getting the board buy-in for cyber security in 2023

Share on FacebookShare on Twitter

Gartner predicts that by 2026, 70% of boards will include one member with cybersecurity expertise.

In the meantime, however, CISOs need to acknowledge that this is important to the board. This means not only showing how the cybersecurity program prevents bad things from happening. But perhaps more importantly, how cybersecurity improves the enterprise’s ability to take risks effectively. Even better, how to use cybersecurity as a competitive advantage.

Gartner recommends CISOs get ahead of the change to promote and support cybersecurity to the board and establish a closer relationship to improve trust and support.

Importance of cybersecurity culture

EY says cybersecurity culture is about ensuring appropriate intrinsic beliefs (attitudes, normative beliefs and perceived control to perform a task) and behaviours throughout an organisation. In so doing, the right risks are addressed, employees at risk are identified, and the means to reduce these risks are defined.

Alex Tilley, head of threat intelligence for Asia Pacific and Japan (APJ) at Secureworks acknowledges that security is everyone's business. While acknowledging the massive investments in security technology, what is just as important is recognising the threats and understanding where the company stands.

He opined that in an organisation that has a security culture in place, people are not afraid to acknowledge that cybersecurity-related mistakes may have happened.

"Where we sit as an organisation in the world, all the way down to individual staff members and how they conduct their day-to-day business, things like phishing. These days it is around security culture, around being supportive and not punitive," he continued.

Related:  Every dollar lost to fraud in Hong Kong costs firms HK$3.64, study finds 

The CISO and the board

Richard Addiscott, a senior director analyst with Gartner, says increasing board oversight mandates board members attend to cybersecurity as part of their governance and oversight activities. This trend will require additional cybersecurity expertise on boards going forward.

Tilley says boards are responsible for the reliability of the business. "Increasingly, they are seeing these bad things happening to their peers around the world, and they are asking questions of their CISOs," he added.

"What are we doing to not become that headline? What is our (security) program? How are we moving our (security) program forward?"

Alex Tilley

He believes the query from the Board will only get bigger, and more in-depth, and the questions funnel to the CISO, who in turn will have questions for their security staff.

Becoming the trusted advisor

Tilly says the CISO needs to become that trusted advisor to the board. "The foundational relationship with the board needs to be established before a bad happens. "You don't want to be going in there when the bad days happening and trying to form a relationship. You want to start these little discussions early to help them understand what you are doing and how you are driving the business forward," he opined.

With the increased incidents of breaches, Tilley says CISOs are given the opportunity to engage other departments including HR, legal and marketing. He suggests the CISO use these to make connections.

Engaging in discussions around security, Tilley recommends that CISOs practise the discussion with non-security and non-technology staff.

Related:  Gartner reveals enterprise risk leaders top five fears

"Be willing to process the feedback and revisit those discussions just to make sure that you are really clear in what you're trying to get across," he concluded.

Click on the Podchat player and listen to Tilly share his recommendations on how CISOs can take cybersecurity to the board, and secure buy-in in the process.

  1. Define for us what is a security culture. Why and how important is having a security culture in today's digital world?
  2. Who should lead the adoption of a security culture in the organisation?
  3. Gartner predicts that by 2026, someone sitting on the board will likely have cybersecurity expertise. In the here and now, however, how would you describe the relationship between CISOs and the board? Do they recognise that they need each other?
  4. From the CISO's perspective, can you name steps that the CISO needs to work on to build a foundational relationship with the board? What works and what hasn't?
  5. Can you share some tips for creating a board presentation agenda that will help CISO establish his or her role as a trusted and credible leader?
  6. Conversely, what must the board do to help establish/acquire the trust of the CISO (and the rest of the executive suite)?
  7. Any advice for boards, security professionals and C-suite as regards the cyber threat landscape in 2023 and beyond?
Tags: CISOcybersecurityGartnerPodchatsSecureworks
allantan

allantan

Allan is Group Editor-in-Chief for CXOCIETY writing for FutureIoT, FutureCIO and FutureCFO. He supports content marketing engagements for CXOCIETY clients, as well as moderates senior-level discussions and speaks at events. Previous Roles He served as Group Editor-in-Chief for Questex Asia concurrent to the Regional Content and Strategy Director role. He was the Director of Technology Practice at Hill+Knowlton in Hong Kong and Director of Client Services at EBA Communications. He also served as Marketing Director for Asia at Hitachi Data Systems and served as Country Sales Manager for HDS’ Philippines. Other sales roles include Encore Computer and First International Computer. He was a Senior Industry Analyst at Dataquest (Gartner Group) covering IT Professional Services for Asia-Pacific. He moved to Hong Kong as a Network Specialist and later MIS Manager at Imagineering/Tech Pacific. He holds a Bachelor of Science in Electronics and Communications Engineering degree and is a certified PICK programmer.

No Result
View All Result

Recent Posts

  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl