What CISOs Should and Should Not Do When Measuring Cyber Risks

For years, cybersecurity has largely been an abstract practice. The Chief Information Security Officer (CISO) is responsible for protecting the organization from relatively vague and undefined threats. You know that the threat is hiding somewhere, but you cannot define the risk in concrete or tangible terms.

26 Jun 2024 SintelSedat Akfidan 5 min read
What CISOs Should and Should Not Do When Measuring Cyber Risks

James Pearce, NCC Group RM&G (Risk Management and Governance) President

CISOs: What to Do and Not to Do When Measuring Cyber Risks For years, cyber defense has largely been an abstract practice. The Chief Information Security Officer (CISO) is responsible for protecting the organization from relatively vague and undefined threats. You know that the threat is somewhere hidden, but you cannot define the risk in concrete or tangible terms.

However, as technology becomes essential to all aspects of business operations and threats become increasingly widespread and costly, the role of the CISO has grown in criticality. Instead of playing a secondary role focused on keeping machines running and fixing errors, the CISO is now expected to make a significant contribution to the organization's agility and growth.

Due to the shift toward more strategic expectations, the CISO must translate cyber security (risk, prevention, mitigation and ultimately agility) into a business language that is suitable for the entire organization.

Quantitative Risk Quantification (QRQ) has emerged as a valuable tool to do exactly that - help direct decisions and actions, and by defining risk in financial terms, enable the organization to understand investment returns and become more agile.

QRQ is more than just a "nice-to-have." As organizations are increasingly being asked to be more accountable by boards, governments and regulatory bodies, QRQ is becoming a real necessity for many organizations.

However, conducting an assessment alone is not enough. Even if CISOs understand the risks and their consequences, it may be difficult to communicate them clearly to the rest of the organization, executives and the board of directors.

Here are some tips to help you make the most of QRQ and get support for the investments you need to make.

WHAT TO DO: Communicate Risk in Financial Terms

Business leaders make decisions based on business metrics. As a CISO, you need to contextualize risk in a language they can understand, and define it with fixed numbers rather than traffic lights and graphs. Cyber security is just like talent, processes, innovation and technology - it's a function that needs to be managed. We invest in tools to manage risk and optimize performance in these areas - cyber security can't be any different.

WHAT NOT TO DO: Alarmism

You would like to present evidence of potential risks and possible damages, but avoid being overly threatening or using a dismissive tone. Accept that the executive team or board is trying to balance the needs of the entire organization. Even though they take cyber risks seriously, the sky isn't falling and an overly enthusiastic approach may appear disconnected from business realities or out of context.

DO: View It as Protection for Other Investments

For decision-makers, balancing the needs of the organization involves ensuring that other investments have the best chance of success. This is where cyber security comes into play; you can protect the investments you have made so far and will make in the future. Think of it this way: You wouldn't buy an expensive sports car without a garage to store it or insurance to cover the loss if it were stolen or damaged. Similarly, investing in cyber security makes all other initiatives in the organization more resilient, more complete and less likely to fail.

DON'T: Be Too Technical

Your manager colleagues and board members may not need to hear technical details about what the latest cyber criminals are using (and probably won't want to). They simply want to know whether there is a chance of an attack, what the potential damage could be and whether the organization has the equipment to prevent it. Explain it in terms they can understand, such as probability and impact. Think of the traditional 5x5 risk matrix commonly used across various industries to measure risk. If an event has a significant impact but is not very likely, naturally, it will be difficult to get buy-in. However, if the impact is real, regardless of the probability, it will be a very challenging situation.

DO: Highlight the Risk of Doing Nothing

Demanding millions of dollars to completely remove old systems may seem too difficult unless it's required for compliance. It suddenly becomes a bit more relevant. If you do nothing, what security vulnerabilities are you exposing? Are there compliance issues and potential monetary penalties? Are you risking new business opportunities? Are you risking customer data? Decision-makers need to understand the possible consequences of inaction.

DON'T: Jump Too Far Ahead

Even though QR is becoming increasingly important, do not invest in a QR assessment until you have established a solid foundation for cyber security. For example, suppose you're using the CMMI Maturity Scale. And your total score for the maturity of cyber controls is less than 2.5. In that case, any assessment would show the basic controls that can be applied without even needing to measure risk - therefore, think in steps when considering your approach. I don't even mention the negative consequences of documenting cyber risks without first developing the capacity to deal with them.

DO: Clarify Personal Accountability

CISOs and other business leaders can be held personally accountable (and have been) if it is determined that they are aware of security vulnerabilities but choose not to act or cover them up. The organization needs to have a legal strategy for responding to cyber incidents, including the possibility of holding individuals personally accountable for any dishonesty or suspected obstruction. This is most common in the United States, but other countries are also starting to do the same thing with their own guidelines.

WHAT NOT TO DO: Promise to Eliminate All Risks

This is not just unrealistic, it's also an undesirable situation. Certain levels of risk must be accepted for all businesses to operate and innovate. An acceptable level of operational risk allows you to go further and be more competitive, but it doesn't mean being overly cautious to the point of stopping. Business leaders understand risk-benefit analysis, so measure risk in these terms and decide what level you're willing to tolerate.

As a CISO, you're aware of cyber security risks. You can assess your organization's risk by understanding threats from expert vendors, news in the media, networking in professional forums and understanding your organization's infrastructure. However, just as you wouldn't be able to design the most cautious financial strategy for an upcoming merger or cost-effective employee benefits package, don't expect your colleagues in finance and HR to understand how they should manage cyber risk. And actually, your board of directors can't even know all the details of every role.

Therefore, CISOs must be able to express and measure cyber risk in business terms, speak the same language as other business leaders, and explain how it affects all other areas of the business.

Source: What to Do and Not to Do When Measuring Cyber Risks for CISOs (itsecurity.pt)