CISO V.S CEO_ Why CISOs Need to Have a Seat at the Executive Table

Logo
Presented by

Eric Cole

About this talk

On this episode of Life of a CISO, I explain why it’s important that CISOs are expected to have a seat at the executive table. Executives all have their specialties, whether it’s growing the business or counting the beans, and a CISO is also an executive position. As a CISO, it’s your job to understand the threats that the business is facing, and to speak the language of the executives (which is money!) to enable the business. In the same way that an insurance adjuster calculates and quantifies risk, that’s what a CISO does. For example, a ransomware attack has X percent of being perpetrated against your organization, and if it were successful, it would cost Y dollars of damages. You may not realize this, but the adversary is doing his own calculations on how much he can ransom you for before you go on the offensive and fight him back; he wants to make it as painless as possible to pay him off and make your problem go away. As a CISO, you need to communicate how much money the executives can save by strengthening their defenses against attackers. This is high-level executive management, which is separate from the nuts and bolts of writing code and monitoring activity “on the ground.” That’s why a CISO is a “Chief” Information Security Officer.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (35)
Subscribers (733)
Secure Anchor Consulting - Channel