cyber resilience framework
Threatonomics

Are You Board Ready? Five Takeaways from Our Panel at RSA

We were honored to host an engaged group of attendees as founder Raj Shah moderated a panel discussion entitled “Are you board ready.”

by Brian Bochner , VP, Marketing
Published

RSA is in the rearview mirror, but we’re still thinking about all the great things we learned by mingling with our peers. We were honored to host an engaged group of attendees as founder Raj Shah moderated a panel discussion entitled “Are you board ready.” Resilience advisor Richard Siersen, Stanley Black & Decker CISO Lucia Milica Stacy, and Knostic co-founder Sounil Yu traded a few barbs but also some very practical advice for working with boards of directors. All the attendees and panelists agreed to Chatham House rules, and so we are bringing you some high-level ideas that resonated with the audience., 

Your relationship with the Board begins before you take the job.

As a CISO, you need to shape the board’s understanding of cyber risk from your first conversation. Whether your board has a sophisticated understanding of cyber risk, you need to come to a shared understanding of what you stand to lose materially as well as the prescient threats that could lead to those losses.  From there, you can have a productive conversation about what risks to accept, mitigate, and transfer. Oh, and make sure you own your communications with the board. Do not get disintermediated, especially by someone who is not a security expert. 

There are so many frameworks, yet there is no framework.

In security, we have many frameworks—from network security to AI to Zero Trust—but no framework for working with a Board of Directors. There are committee structures that define governance and decision-making, but there is no framework for a common understanding of cyber risk, like a balance sheet. CISOs have to develop their own way of communicating risks

Speak to your directors in dollars and cents.

Most Boards and CISOs don’t have a singular metric for discussing risk, and they may not even mean the same thing when they say the word risk. Many boards will ask binary questions like, “Are we secure?” rather than more nuanced questions like, “How are we protecting our most valuable assets?” CISOs need to be able to answer these questions with financial figures so everyone is speaking the same language. 

East and West or Left and Right?

A great analogy for communicating the term “risk” is around how we distinguish its application across strategy vs tactics. Strategy is at the global level – east and west, while tactics are at a street level – left and right. They’re both types of directions CISOs need to be fluent in both worlds. You can’t tell someone to get from New York to San Francisco by turning left; nor can you tell someone to go west to get to the grocery store. To do their job successfully, CISOs operate at a level of granularity that is too complex for most boards. But they must inspire confidence and influence the BOD, translating problems without creating confusion. 

Storytelling is key for the CISO 2.0…or 3.0 or 4.0.

We are almost 35 years into the internet era and 30 years since the first known CISO was appointed. First generation CISOs had to be very technical to tame the Wild West of early networks and applications. While technical skills are still important, all attendees agreed that storytelling is the top skill needed in today’s CISOs. To work effectively with directors, CISOs must be persuasive risk managers, not just technologists managing security controls and strategies.

The CISO role has evolved into one of the most interdisciplinary technical business officers, with unique requirements to both be in the weeds and see things from a macro perspective across technical and functional lines of business. Thank you to our esteemed panelists and attendees for sharing your expertise with one another; it is the truly best part of RSA. 

You might also like

Scattered Spider strikes again in recent UK retail attacks

In the past two weeks, the UK retail industry has faced an unprecedented wave of sophisticated cyberattacks, exposing critical vulnerabilities across the sector. The high-profile breaches at Marks & Spencer, Harrods, and others have sent shockwaves through the industry, with M&S alone suffering an estimated £3.8 million in lost online sales per day and seeing […]

See what a cyber attack could really cost your enterprise

Data breaches cost U.S. businesses an average of $9.36 million per breach in 2024, yet many enterprises still struggle to quantify their specific cyber risk exposure in financial terms. How do you translate complex technical vulnerabilities into language that your CFO, board members, and other stakeholders can understand and act upon? We’re excited to announce […]

A decision scientist’s perspective on AI

As the Senior Director of Cyber Resilience at Resilience, I bring a somewhat unconventional perspective to the table. Unlike many in our industry who come from traditional cybersecurity or insurance backgrounds, my expertise lies in decision science. Throughout my career, I’ve been fascinated by one central question: How can we help people make good decisions […]

What enterprises over $10 billion need to know about managing cyber risk

The role of the Chief Information Security Officer has undergone a profound transformation from a purely technical role to a strategic business one in recent years. For CISOs operating in organizations with over $10 billion in revenue—a segment that Resilience has recently expanded its cyber risk solutions to serve—the shift comes with unique pressures and […]

How to create an effective Incident Response Plan

Cyberattacks are no longer a distant threat—they are a certainty. Whether it’s a ransomware attack, data breach, or insider threat, organizations must be prepared to respond quickly and effectively. Without a solid plan in place, even a minor security incident can spiral into a major crisis, leading to financial losses, reputational damage, and regulatory penalties. […]

Understanding the ClickFix attack

Imagine a cyberattack so simple yet so deceptive that all it takes is three keystrokes to compromise your system. This is the reality of the ClickFix attack, a threat that Resilience threat researchers have observed in the wild since 2024 and that seems to be ramping up in recent weeks. ClickFix cleverly manipulates users into […]