The role of Chief Information Security Officers (CISOs) has expanded significantly, with leaders like Doug Kersten, currently the CISO of Appfire, at the forefront of this evolution. He underscores the importance of understanding how security tools and processes directly affect business costs and profitability. “CISOs need to provide input and remediation on the impact of security cost because these often-hidden costs have a negative impact on profitability,” he states. This sentiment reflects a shift that sees security professionals increasingly engaged in discussions around business risks, not merely security threats.
As the lines between security risks and business risks blur, stakeholders are recognizing that cybersecurity's impact extends beyond IT systems to influence revenue, operations, and customer confidence. Dale Hoak, CISO at RegScale, articulates the paradigm shift: “While CISOs traditionally focused on protecting systems, today’s business environment requires security leaders to understand how cyber threats impact revenue and strategic objectives.” It’s clear that being merely reactive is no longer sufficient; today’s CISOs must engage proactively with all facets of business risk.
1. Collaborate with Business Leaders
One effective approach to enhancing understanding of business risk is through collaboration. Roland Palmer, CISO at JumpCloud, admits he's still mastering this area and emphasizes learning from those who own these risks within the organization. By partnering with leaders in finance, marketing, and operations, both he and Kersten are working to establish a framework where security and business risks are jointly understood. “Security helps them understand the security risks, but they also bring to us the associated business risks and what can be done to mitigate them,” Kersten explains, highlighting a best practice that makes addressing risks a collaborative effort.
2. Tie Cybersecurity Efforts to Business Goals
Aligning security initiatives with business objectives is crucial in today’s landscape. Kersten advises that security teams should incorporate key business goals and results into their strategies. By doing so, they can identify risks that may disrupt these objectives. For instance, he actively considers how security policies may affect employee satisfaction, a vital metric for retention identified by HR. Such an integrated approach facilitates a more comprehensive understanding of the consequences of security actions on overall business health.
Richard Watson from EY echoes this need, suggesting that mapping cybersecurity controls to essential business assets allows CISOs to translate technical vulnerabilities into financial discussions, prioritizing investments accordingly.
3. Foster Networking and Build Relationships
Regular communication with colleagues across various departments is invaluable for understanding business risks thoroughly. Gary Hayslip shares that conducting informal “listening tours” helps him grasp the concerns and objectives of his peers, paving the way for more effective collaboration on security issues. These engagements not only reveal insights into operational challenges but also enable senior leaders to connect security objectives with broader business strategies.
Engagement with senior executives, including CFOs and COOs, is essential. Hoak reinforces this notion, advocating for regular dialogues that help situate security within the strategic planning process rather than relegating it to a compliance function.
4. Conduct Business-Focused Tabletop Exercises
Structured interactive scenarios, such as tabletop exercises, can yield significant insights into how prepared an organization is to handle business risks. Hayslip emphasizes that these exercises should not only focus on technical aspects but should be designed around real business decisions. This includes addressing critical incidents, like whether to pay a ransom or deciding on communication strategies in case of a data breach. Such simulations help teams understand genuine pressures and decision-making processes during crises.
5. Invest in Education About Business Risk
Knowledge is power, and Sean Murphy, CISO at BECU, takes this to heart by pursuing certifications that expand his understanding of business governance and risk management. For instance, he acquired the Directorship Certification from the National Association of Corporate Directors to enhance insights into board-level perspectives regarding risk.
Murphy recommends familiarizing oneself with corporate documents, like the annual report and earnings call transcripts, to better understand the financial landscape of the organization and what leadership prioritizes. While this deep-dive may feel tedious, it’s essential for CISOs to comprehend which areas are critical for the business's success.
6. Embed Security in Enterprise Risk Frameworks
A holistic view of risk considers cybersecurity as integral to broader enterprise risk management initiatives. As Scott Melchior points out, cyber risks should be seen as existential business risks, not just IT concerns. Hoak agrees, advocating for the incorporation of cybersecurity into the overall risk assessment framework. This alignment enables executives to view cybersecurity in the light of business objectives and helps prioritize resources effectively.
Many CISOs, including Hayslip, are now integrating their security risk assessments into their organizations' existing Enterprise Risk Management (ERM) platforms. This inclusion presents information about cyber risks on the same level as other vital business risks, fostering a competitive environment for resources and attention. With organizations increasingly moving towards quantifiable risk assessments, embracing both financial and probabilistic metrics offers heightened clarity and prioritization in decision-making.