Share this article
It’s a core tenet of responsible information security to avoid scaremongering – even though the stories of damaging hacks, data breaches and system meltdowns can be powerful indeed. Instead, it’s important that the creation of an effective cybersecurity strategy is built on a positive outlook and the promotion of the benefits of proactive behaviour. And for this, any CISO needs to be armed with the right kind of data.
For many businesses, approval from the board of directors is essential in driving organisational change. This is certainly the case when it comes to cybersecurity, and the right metrics are vital in mapping out the need for security investments.
According to Accenture’s State of Cybersecurity Resilience Report the number of security attacks increased 31% from 2020 to 2021 alone. What’s more, the UK’s Government’s Cyber Security Breaches Survey 2022 reveals that one in five businesses have experienced negative consequences as a result of cybercrime.
With this in mind, convincing board members to act on cybercrime before disaster strikes is imperative to securing the future of your business. Putting together the right information – and delivering it in the right way – can make all the difference.
While cybersecurity is a complex and ever-changing area, the information board members want remains largely the same over time. There are certain questions that boards will always ask when it comes to cybersecurity, and it’s important to know how to answer them.
Are we secure? This question is as common as it is frustrating, because the answer will always be ‘no’ when taken literally. It is impossible for any organisation to be 100% secure. Instead, we need to rework the question to more pragmatic and realistic alternatives like: “What is our exposure level?” or “What is our current risk posture?”
This allows for a clearer and more accurate picture to be painted.
Are we compliant? This question is easier to answer, and can be evidenced by audit results. However, it’s important to remember that accreditation requirements can change at a moment’s notice, so a control framework like ISO27001 can help to provide greater confidence and demonstrate adherence to the highest standards.
Have there been any incidents? This question is broader than it may seem. And there are many sub-categories to be considered. While all incidents are valid and indicative of resilience, it is the incidents that have an associated cost or liability issue that will always catch the attention of the board. Honesty and accuracy are paramount here.
Along with these questions, board members will also want to know how effective and efficient the business’s security program is. The goal is always to translate the most detailed technical data possible into a strategic framework that is easily comprehended by board members.
Metrics need to cover various factors, including:
Keeping these in mind, a good set of core board metrics might look like this:
You’ll also need to factor in costs and value when putting your figures together. This will include your loss to value ratio (spending on cybersecurity compared to value provided), control cost per IT asset, and the risk reduced per unit cost.
Being able to show the impact of effective cybersecurity in your business in black and white is the best way to get executives on board when it comes to making positive changes. As with everything in the world of cybersecurity, the best offense is a good defence.
Find out more about improving your organisation’s cybersecurity by getting in touch with the experts at SRM today. Click here to contact a member of our team.