Menu

Call us on 03450 21 21 51

Give the board of directors what they want: how to showcase the value of effective cybersecurity with hard evidence rather than horror stories
The SRM Blog

Give the board of directors what they want: how to showcase the value of effective cybersecurity with hard evidence rather than horror stories

Tim Deakin

Written by Tim Deakin

25th May 2022

Share this article

CISO board meeting

It’s a core tenet of responsible information security to avoid scaremongering – even though the stories of damaging hacks, data breaches and system meltdowns can be powerful indeed. Instead, it’s important that the creation of an effective cybersecurity strategy is built on a positive outlook and the promotion of the benefits of proactive behaviour. And for this, any CISO needs to be armed with the right kind of data.

For many businesses, approval from the board of directors is essential in driving organisational change. This is certainly the case when it comes to cybersecurity, and the right metrics are vital in mapping out the need for security investments.

According to Accenture’s State of Cybersecurity Resilience Report the number of security attacks increased 31% from 2020 to 2021 alone. What’s more, the UK’s Government’s Cyber Security Breaches Survey 2022 reveals that one in five businesses have experienced negative consequences as a result of cybercrime.

With this in mind, convincing board members to act on cybercrime before disaster strikes is imperative to securing the future of your business. Putting together the right information – and delivering it in the right way – can make all the difference.

What are the main cybersecurity questions from boards?

While cybersecurity is a complex and ever-changing area, the information board members want remains largely the same over time. There are certain questions that boards will always ask when it comes to cybersecurity, and it’s important to know how to answer them.

Are we secure? This question is as common as it is frustrating, because the answer will always be ‘no’ when taken literally. It is impossible for any organisation to be 100% secure. Instead, we need to rework the question to more pragmatic and realistic alternatives like: “What is our exposure level?” or “What is our current risk posture?”

This allows for a clearer and more accurate picture to be painted.

Are we compliant? This question is easier to answer, and can be evidenced by audit results. However, it’s important to remember that accreditation requirements can change at a moment’s notice, so a control framework like ISO27001 can help to provide greater confidence and demonstrate adherence to the highest standards.

Have there been any incidents? This question is broader than it may seem. And there are many sub-categories to be considered. While all incidents are valid and indicative of resilience, it is the incidents that have an associated cost or liability issue that will always catch the attention of the board. Honesty and accuracy are paramount here.

What are the most relevant cybersecurity metrics for company boards?

Along with these questions, board members will also want to know how effective and efficient the business’s security program is. The goal is always to translate the most detailed technical data possible into a strategic framework that is easily comprehended by board members.

Metrics need to cover various factors, including:

  • IT assets, such as the number of users, servers, devices and apps
  • Process controls, including user accounts, incident detect/respond, vulnerability detect/patch etc.
  • Usage activity, including flows, messages and sessions
  • Real-time controls, including email security, firewalls, antimalware and password protection
  • Incidents and their respective costs, both financially and legally

Keeping these in mind, a good set of core board metrics might look like this:

  • Cyber risk: the percentage of risky usage activities compared to all usage activities
  • Cyber exposure: average number of usage activities per IT asset
  • Cybersecurity efficiency: percentage reduction in risk level provided by real-time cyber controls
  • Cyber resilience: average number of real-time controls applied for each usage activity
  • Risk aversion ratio: acceptance of productivity impairment compared to allowance of malicious activity (aka false positives versus true positives)

You’ll also need to factor in costs and value when putting your figures together. This will include your loss to value ratio (spending on cybersecurity compared to value provided), control cost per IT asset, and the risk reduced per unit cost.

Being able to show the impact of effective cybersecurity in your business in black and white is the best way to get executives on board when it comes to making positive changes. As with everything in the world of cybersecurity, the best offense is a good defence.

Find out more about improving your organisation’s cybersecurity by getting in touch with the experts at SRM today. Click here to contact a member of our team.