{"id":40766,"date":"2019-08-28T12:26:27","date_gmt":"2019-08-28T11:26:27","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=40766"},"modified":"2019-08-28T14:07:10","modified_gmt":"2019-08-28T13:07:10","slug":"gartner-contributor-on-the-five-security-questions-your-board-will-definitely-ask","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/08\/28\/gartner-contributor-on-the-five-security-questions-your-board-will-definitely-ask\/","title":{"rendered":"Gartner contributor on the five security questions your board will definitely ask"},"content":{"rendered":"\n<p><em>With cyberattacks on organisations a fact of life, Kasey Panetta, on behalf of Gartner, explains how CISOs can deal with the inevitable questions asked by board members seeking reassurance that their company\u2019s risks are being effectively managed. <\/em><\/p>\n\n\n\n<p><strong>Know how to respond to your board\u2019s most likely\nsecurity questions.<\/strong><\/p>\n\n\n\n<p>How secure are we? Why do we need more money for security,\nwhen we just approved X last year? What do you mean we\u2019ve had four incidents? I\nthought you had everything under control.<\/p>\n\n\n\n<p>Chances are, most security and risk leaders have heard\nthese questions, possibly multiple times, from their boards of directors. But\nthe problem is that these questions are unanswerable. They are driven by\nexaggerated, incomplete or contradictory public information and are a\ndistraction from more relevant questions. <\/p>\n\n\n\n<p><strong>Are we 100% secure? Are you sure?<\/strong><\/p>\n\n\n\n<p>Gartner estimates that by 2020, 100% of large enterprises\nwill be asked to report to their boards of directors on cybersecurity and\ntechnology risk at least once a year. Boards today are\nmore informed about security risk, with just 15% of directors reporting\ntheir boards have very little to no knowledge of cyber-risk, down from 22% in\n2015. <\/p>\n\n\n\n<p>Further, boards are using the\nincreased focus on cybersecurity to guide business decisions. In 2019, a\nGartner survey of security and risk leaders found that four of every five\nrespondents noted that risk influences decisions made at the board level.<\/p>\n\n\n\n<p>Additionally, security leaders need to be able to give the\nboard something that they care about and that is meaningful to them. Beyond\nindividual passions and concerns, boards collectively generally care about\nthree things:<\/p>\n\n\n\n<p><strong>Revenue\/mission:<\/strong>\nOperating or non-operating income and enhancing non-revenue mission objectives<\/p>\n\n\n\n<p><strong>Cost: <\/strong>Future cost avoidance and\nimmediate decrease in operating expenses<\/p>\n\n\n\n<p><strong>Risk:<\/strong> Financial, market, regulatory\ncompliance and security, innovation, brand, and reputation<\/p>\n\n\n\n<p>\u201cAs board members realise how critical security and risk\nmanagement is, they are asking leaders more complex and nuanced questions,\u201d\nsays Sam Olyaei, Director Analyst, Gartner. \u201cBoards today are becoming more\ninformed and more prepared to challenge the effectiveness of their companies\u2019\nprogrammes.\u201d&nbsp; <\/p>\n\n\n\n<p><strong>Most board questions can be categorised into\nfive areas. <\/strong><\/p>\n\n\n\n<p><strong>1. The trade-off question: What it sounds like:\nAre we 100% secure? Are you sure? <\/strong><\/p>\n\n\n\n<p><strong>Why it\u2019s asked: <\/strong>Questions\nlike this are often asked by board members who don\u2019t truly understand security\nand the impact to the business. It\u2019s impossible to be 100% secure or protected.\nThe CISO\u2019s role is to identify the highest-risk areas and allocate finite\nresources towards managing them based on business appetite.<\/p>\n\n\n\n<p><strong>How to respond: <\/strong>Begin\nwith something like: \u201cConsidering the ever-evolving nature of the threat\nlandscape, it\u2019s impossible to eliminate all sources of information risk. My\nrole is to implement controls to manage the risk. As our business grows, we\nhave to continually reassess how much risk is appropriate. Our goal is to build\na sustainable programme that balances the need to protect against the need to\nrun our business.\u201d <\/p>\n\n\n\n<p><strong>2. The landscape question<\/strong><\/p>\n\n\n\n<p><strong>What it sounds like:<\/strong> How\nbad is it out there? What about what happened at X company? How are we compared\nto others? <\/p>\n\n\n\n<p><strong>Why it\u2019s asked:<\/strong> Board\nmembers will come across threat reports, articles, blogs and regulatory\npressure to understand risks. They will always ask about what others are doing,\nespecially peer organisations. They want to know what the \u2018weather\u2019 looks like\nand how they compare to others.<\/p>\n\n\n\n<p><strong>How to respond:&nbsp;\n<\/strong>Avoid guessing at the root cause of a security issue at a\ndifferent company by saying: \u201cI don\u2019t want to speculate on the incident at company\nXYZ until more information is available, but I\u2019ll be happy to follow up with\nyou when I know more.\u201d Consider discussing a series of broader security\nresponses such as identifying a similar weakness and how it\u2019s being fixed or\nupdating Business Continuity plans.<\/p>\n\n\n\n<p><strong>3. The risk question<\/strong><\/p>\n\n\n\n<p><strong>What is sounds like: Do we know what our risks\nare? What keeps you up at night? <\/strong><\/p>\n\n\n\n<p><strong>Why it\u2019s asked: <\/strong>The\nboard knows accepting risk is a choice (if they don\u2019t, that\u2019s a challenge you\nneed to solve). <a>They want to know that the company\u2019s\nrisks are being handled<\/a>. CISOs should be prepared to explain the organisation\u2019s\nrisk tolerance to defend risk management decisions. <\/p>\n\n\n\n<p><strong>How to respond:<\/strong>\nExplain the business impact of risk management decisions and ensure that your\npositions are supported by evidence. The second part is vital because boards\nare making decisions based on the risk tolerance. Any risks outside the\ntolerance level requires a remedy to bring them within tolerance. This doesn\u2019t\nnecessarily require dramatic changes in short periods of time; beware of\noverreacting. The board will be seeking assurances that material risks are\nbeing adequately managed, and that subtle, long-term approaches may be\nappropriate in some instances.<\/p>\n\n\n\n<p><strong>4. The performance question<\/strong><\/p>\n\n\n\n<p><strong>What it sounds like:<\/strong> Are\nwe appropriately allocating resources? Are we spending enough? Why are we\nspending so much? <\/p>\n\n\n\n<p><strong>Why it\u2019s asked: <\/strong>The\nboard will want reassurance that security and risk management leaders are not\nstanding still. Board members will want to know about metrics and ROI.<\/p>\n\n\n\n<p><strong>How to respond:<\/strong> Use a\nbalanced scorecard approach in which the top layer expresses business\naspirations and the performance of the organisation against those aspirations\nis illustrated using a simple traffic-light mechanism. As much as possible,\nexplain aspirations in terms of business performance, not technology.\nPerformance is underpinned by a series of security measurements that are\nevaluated using a set of objective criteria.<\/p>\n\n\n\n<p><strong>5. The incident question<\/strong><\/p>\n\n\n\n<p><strong>What it sounds like: How did this happen?<\/strong> I\nthought you had this under control? What went wrong? <\/p>\n\n\n\n<p><strong>Why it\u2019s asked: <\/strong>This\nis asked when an incident or event has occurred and the board either already\nknows or the CISO is informing them of it. <\/p>\n\n\n\n<p><strong>How to respond: <\/strong>An incident is inevitable, so be factual. Share what you know and what you are doing to find out anything you don\u2019t currently know. In short, acknowledge the incident, provide details on business impact, outline weaknesses or gaps that need to be worked out and provide a mitigation plan. Be cautious not to endorse one option as the ultimate choice when in front of the board. The responsibility for oversight of security and risk remains with the security leader, but the accountability has to always be defined at the board\/executive level.<\/p>\n\n\n\n<p>\n\nGartner is holding the Gartner Security &amp; Risk Summit in Dubai on October 28 and 29. Click <a href=\"https:\/\/www.gartner.com\/en\/conferences\/emea\/security-risk-management-uae\">here<\/a> to find out more.  \n\n<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With cyberattacks on organisations a fact of life, Kasey Panetta, on behalf of Gartner, explains how CISOs can deal with the inevitable questions asked by board members seeking reassurance that their company\u2019s risks are being effectively managed. Know how to respond to your board\u2019s most likely security questions. How secure are we? Why do we [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":40769,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[7298,3971,10045,5205],"class_list":["post-40766","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-board","tag-cyberattack","tag-garnet","tag-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/40766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=40766"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/40766\/revisions"}],"predecessor-version":[{"id":40784,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/40766\/revisions\/40784"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/40769"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=40766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=40766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=40766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}