Boards push security heads to minimize cyber risks

May 15, 2024
1 min read


TLDR:

Security leaders are feeling pressure from boards to downplay cyber risks, leading to a growing ‘credibility gap’. A report by Trend Micro found that 79% of IT leaders have felt pressure to understate cyber threats. Only half of respondents believe their C-suite understands the risks fully. To bridge the gap, CISOs should focus on expressing cyber risks in terms of business value.

Article Summary:

Senior cyber security professionals are facing pressure from boards to minimize the severity of cyber risks, creating a credibility gap between CISOs and boardrooms. A report by Trend Micro revealed that 79% of IT leaders have felt pressure to downplay cyber threats in their organizations.

Reasons for this pressure include CISOs being perceived as repetitive or negative by the board. Despite efforts to update boards on potential risks, a third of senior security personnel reported being dismissed by the board.

Furthermore, only half of respondents believe their C-suite fully comprehends the cyber risks facing the organization. To shift these attitudes, 80% of respondents believe that a serious breach is necessary for boards to take decisive action on cyber risks.

To address this issue, CISOs should focus on expressing cyber risks in terms of the business value that cyber resilience can deliver. When security leaders can measure the business value of their cyber security strategy, they are viewed with more credibility and given more responsibility within the organization.

Experts suggest that CISOs often fail to convey cyber risks effectively to boards by relying on technical jargon and statistics. Instead, they should frame cyber risks in the context of wider business risks to justify the level of investment required to enhance cyber resilience.

Ultimately, bridging the credibility gap between security leaders and boards is crucial for organizations to effectively address and mitigate cyber risks.


Latest from Blog

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is

Get ready for a cyber attack with NewsRadio 740 KTRH

TLDR: A cyber attack recently caused a global outage of numerous Microsoft business products, highlighting the vulnerability of our technology infrastructure. Cyber security expert Matt Malone believes that the incident could serve