cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
AndreaMoore
Community Manager

Blog: The Importance of Board Engagement in Cyber Governance

Robert Fritz, CISSP, CSSLP discusses the importance of accountability and how officials and organizations must work together to secure the cyber domain we share.

 

Read the full blog: https://www.isc2.org/Insights/2023/09/Importance-of-Board-Engagement




ISC2 Community Manager
3 Replies
AndreaMoore
Community Manager

Related article from the Wall Street Journal: 

 

Boards Still Lack Cybersecurity Expertise

Just 12% of S&P 500 companies have board directors with relevant cyber credentials, new study says: https://www.wsj.com/articles/boards-still-lack-cybersecurity-expertise-70094266?tpl=cs&mod=hp_lead_p... 




ISC2 Community Manager
JoePete
Advocate I

I think the fundamental problem is that security professionals do not know how to speak to the business professionals. Simply if we stopped clamoring about "cybersecurity" (which itself is an exercise in questionable diction vs. the less-hip "information security"), and instead talked about quality and business improvement, we might get somewhere. Even the concept of risk, very rarely do you come across a security professional who can translate risk into business drivers. Just because something is risky doesn't mean it is a bad idea or needs to be mitigated. Bear in mind most entrepreneurs out there are burning through capital toward the goal of capturing overwhelming market share and/or investment attention. Getting them to think about something like data classification, for example, is like getting a firefighter to think about water conservation at an inferno. If instead, we get them to think "data classification will make it easier to move into the cloud or AI," then they might start listening.

 

Over the decades we have turned security into a series of specializations to the point where we produce largely people who focus on the trees and not the forest. What we are losing is that broad understanding of information, technology, and also business.

AndreaMoore
Community Manager

Free for Members

Translating Cyber Risk into Business Language for Effective Leadership (0.5 CPE credits)

Cyber leaders are required to communicate cybersecurity issues to executive decision makers. That requires an understanding of basic accounting, finance and economic principles. Learn how to relate expenditures to financial aspects, such as cash flow and return on investment.

 

Access the skill builder: https://www.isc2.org/professional-development/skill-builders/cybersecurity-leadership 




ISC2 Community Manager