Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/17/2017
09:00 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Why Brand Trumps Tech in C-Level Conversations

Brand reputation, not technical tools, should be the focus of the CIO's conversations with board members about the importance of security.

CIOs have a spot at the executive table but struggle to hold security-focused conversations with people sitting around it. The problem: It's tough to convey the importance of security before a major breach.

"Security is like life insurance," says Larry Bonfante, founder at CIO Bench Coach. "Nobody cares about it until something has already happened."

This "seat at the table" comes with the responsibility of knowing how to communicate with board members. Instead of explaining the nitty-gritty details of security tools, CIOs should step back to think about risk mitigation and brand reputation.

Companies can invest millions in security and attackers will still get in, Bonfante explains. Part of a CIO's job is to evaluate the probability of an attack based on factors like geography and industry. When they know where the risk is highest, they can determine how much to invest, where to invest it, and how to explain that risk to board members.

The key is to frame risk in a certain way so leaders understand why attackers would specifically target them. If the business understands a risk, they'll increase the budget to fight it.

Bonfante explains his argument in the context of the US Open. With 70,000 people in attendance, broad media coverage, and location in a major city, it's easy to see why such a major event would be a "prime target." Unfortunately, he says, many leaders wouldn't view the situation from a similar perspective.

Brand reputation is powerful leverage in conversations about risk. CIOs should view themselves as educators and elevate the conversation about reputation, not about technology, Bonfante explains.

A CIO's goal should not be to help business leaders understand the latest DDoS attack happened, or how a new firewall will work, but the effects attack could potentially have on their organization. Companies value brand reputation. In the case of the US Open, an attack could mean fewer attendees in future years -- and a significant drop in profit.

"Nobody thinks it's going to happen to them," says Bonfante of security breaches. "Make them understand that this really does happen; that dark consequences could happen."

Security discussions are getting easier as more major breaches are publicized, but most CIOs still face pushback from enterprise teams when voicing their concerns. Each year, they will need to remind people about the risks they face and keep concerns on their radar.

"It's not a one-time sell," Bonfante continues. "It's a constant sell, it's a constant education process, and you never get as much as you want."

He explains how CIOs may be required to speak in terms the business will understand, but there isn't a similar expectation for board members to learn technical terms. If they want to communicate risks to the business, CIOs are entirely responsible for shaping the conversation.

While technology shouldn't lead these discussions, Bonfante recommends being prepared with the technical details of threats and tools -- just in case.

[Larry Bonfante will be speaking about "Competencies of the new CIO" during Interop ITX, May 15-19, at the MGM Grand in Las Vegas. To learn more about his presentation, other Interop security tracks, or to register click on the live links.]

Related Content

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JulietteRizkallah
100%
0%
JulietteRizkallah,
User Rank: Ninja
4/18/2017 | 10:15:56 AM
The conversation is about to get easier
True CIOs have difficulties convincing Boards about the necessities of IT Security, but it is about to get easier for 3 reasons: 1. Boards are getting more educated and want to understand the real security posture of the companies they advise and if the CIO can bring it down to business termininology vs. technical jargon then the conversation will happen; 2. Boards are looking for ways to transfer risk and are advising on using cyberinsurance. Because cyber insurers are founding their premium on the security posture of the companies, the conversation once again is happening; 3. and of course there is brand and reputation as the article mentions, board members do not want to be associated with this kind of event especially as there are more talks about what liability they should bare in the case of a data breach.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/23/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Russian Military Officers Unmasked, Indicted for High-Profile Cyberattack Campaigns
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-24847
PUBLISHED: 2020-10-23
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticat...
CVE-2020-24848
PUBLISHED: 2020-10-23
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.
CVE-2020-5990
PUBLISHED: 2020-10-23
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which may lead to local privilege escalation, code execution, denial of service or information disclosure.
CVE-2020-25483
PUBLISHED: 2020-10-23
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
CVE-2020-5977
PUBLISHED: 2020-10-23
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.