Risk
4/17/2017
09:00 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Why Brand Trumps Tech in C-Level Conversations

Brand reputation, not technical tools, should be the focus of the CIO's conversations with board members about the importance of security.

CIOs have a spot at the executive table but struggle to hold security-focused conversations with people sitting around it. The problem: It's tough to convey the importance of security before a major breach.

"Security is like life insurance," says Larry Bonfante, founder at CIO Bench Coach. "Nobody cares about it until something has already happened."

This "seat at the table" comes with the responsibility of knowing how to communicate with board members. Instead of explaining the nitty-gritty details of security tools, CIOs should step back to think about risk mitigation and brand reputation.

Companies can invest millions in security and attackers will still get in, Bonfante explains. Part of a CIO's job is to evaluate the probability of an attack based on factors like geography and industry. When they know where the risk is highest, they can determine how much to invest, where to invest it, and how to explain that risk to board members.

The key is to frame risk in a certain way so leaders understand why attackers would specifically target them. If the business understands a risk, they'll increase the budget to fight it.

Bonfante explains his argument in the context of the US Open. With 70,000 people in attendance, broad media coverage, and location in a major city, it's easy to see why such a major event would be a "prime target." Unfortunately, he says, many leaders wouldn't view the situation from a similar perspective.

Brand reputation is powerful leverage in conversations about risk. CIOs should view themselves as educators and elevate the conversation about reputation, not about technology, Bonfante explains.

A CIO's goal should not be to help business leaders understand the latest DDoS attack happened, or how a new firewall will work, but the effects attack could potentially have on their organization. Companies value brand reputation. In the case of the US Open, an attack could mean fewer attendees in future years -- and a significant drop in profit.

"Nobody thinks it's going to happen to them," says Bonfante of security breaches. "Make them understand that this really does happen; that dark consequences could happen."

Security discussions are getting easier as more major breaches are publicized, but most CIOs still face pushback from enterprise teams when voicing their concerns. Each year, they will need to remind people about the risks they face and keep concerns on their radar.

"It's not a one-time sell," Bonfante continues. "It's a constant sell, it's a constant education process, and you never get as much as you want."

He explains how CIOs may be required to speak in terms the business will understand, but there isn't a similar expectation for board members to learn technical terms. If they want to communicate risks to the business, CIOs are entirely responsible for shaping the conversation.

While technology shouldn't lead these discussions, Bonfante recommends being prepared with the technical details of threats and tools -- just in case.

[Larry Bonfante will be speaking about "Competencies of the new CIO" during Interop ITX, May 15-19, at the MGM Grand in Las Vegas. To learn more about his presentation, other Interop security tracks, or to register click on the live links.]

Related Content

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JulietteRizkallah
100%
0%
JulietteRizkallah,
User Rank: Moderator
4/18/2017 | 10:15:56 AM
The conversation is about to get easier
True CIOs have difficulties convincing Boards about the necessities of IT Security, but it is about to get easier for 3 reasons: 1. Boards are getting more educated and want to understand the real security posture of the companies they advise and if the CIO can bring it down to business termininology vs. technical jargon then the conversation will happen; 2. Boards are looking for ways to transfer risk and are advising on using cyberinsurance. Because cyber insurers are founding their premium on the security posture of the companies, the conversation once again is happening; 3. and of course there is brand and reputation as the article mentions, board members do not want to be associated with this kind of event especially as there are more talks about what liability they should bare in the case of a data breach.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.