transcribe

Episode 199: Translating Cyber Risk into Business Decisions

CIS · 37m · transcribed Aug 2026
More from CIS Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Section Insights

# 0:00

Introduction to Cyber Security Where You Are

What is the purpose of the Cyber Security Where You Are podcast?

The podcast aims to discuss trends and threats in cybersecurity, explore best practices, and interview industry experts to enhance understanding and confidence in cybersecurity.

  • Cybersecurity impacts everyone, from individuals to organizations.
  • The podcast features discussions on current trends and expert insights.
  • It aims to clarify cybersecurity issues for a broader audience.
# 7:26

Communicating Cyber Risks to Boards

How should cybersecurity professionals communicate with boards?

Cybersecurity professionals should translate technical risks into financial terms that boards can understand, emphasizing the importance of quantifying risks and the potential impact of cyber incidents.

  • Effective communication with boards requires understanding their language.
  • Quantifying cyber risks in financial terms helps convey urgency.
  • Cybersecurity incidents can have both financial and reputational impacts.
# 14:53

Preparation for Cyber Incidents

Why is it important to prepare for cyber incidents in advance?

Preparing for cyber incidents involves familiarizing key personnel, such as general counsel, with cybersecurity issues to ensure effective response and decision-making during crises.

  • Preparation helps avoid confusion during a cyber incident.
  • Key personnel should be well-versed in cybersecurity implications.
  • Ignoring cyber risks can lead to severe consequences.
# 22:20

Understanding Cybersecurity Regulations

What is the current state of cybersecurity regulations?

Regulatory bodies like the SEC are increasingly emphasizing the need for cybersecurity expertise on boards, reflecting a growing recognition of cyber risks and their potential impact on businesses.

  • Regulatory focus on cybersecurity is increasing.
  • Boards are becoming more aware of cyber risks due to high-profile incidents.
  • Understanding cybersecurity is now a critical responsibility for board members.
# 29:47

Effective Communication Strategies for Cybersecurity

What communication strategies should cybersecurity professionals adopt when addressing boards?

Cybersecurity professionals should use plain language and avoid technical jargon, ensuring that their communication is clear and supported by data to facilitate understanding and decision-making.

  • Clear communication is essential for effective cybersecurity discussions.
  • Using plain language helps bridge the gap between technical and non-technical audiences.
  • Data-driven arguments enhance credibility and understanding.

Transcript

0:01 Welcome to Cyber Security Where You Are, the Center for Internet Security's podcast. I'm Sean Atkinson, SIZO at CIS. And I'm Tony Sager, senior vice president and chief evangelist at CIS. Cyber security affects us all. Whether we're online at home, managing a company, supporting clients, or running a state or local government. So join us on Wednesdays as we discuss trends and threats, explore security best practices, and interview experts in the industry. Together, we'll clarify these issues, creating confidence in the connected world.

0:33 Hello and welcome to the show Cyber Security Where You Are. I'm Sean Atkinson, Sizzo here at the Center for Internet Security, joined by the host with the most, the Hall of Famer, the difference maker, Mr. Tony Seager. Tony, how are you, sir? >> Hey Sean, great to be back. >> Fantastic. We're joined by a very special guest, chair of the risk committee here at CIS and part of the board of directors, Mr. Chris Painter. Chris, how are you, sir?

0:58 >> Hey, good to be with here with you guys. >> Fantastic. Great to have you back. and Chris, we're we've been doing a what we call the SIZO translation series. And, you know, why we asked you to be here was when the SIZO is talking to a risk committee, a board, it is what's the type of vernacular they should use? Is it highly technical? Is it trying to convey certain messages or is it u trying to be the the siz that cried wolf? and trying to get budget and attention and things of that nature. So we wanted to get your opinion on what is a good strategy in this space. So now Chris when you know when you walk into a board a risk committee and you know you've done this really worldwide in terms of understanding security policy and what it means to the nation and and really internationally. What's the single biggest I would say translation failure that you've seen sizos potentially myself make and why does it happen so reliably? We see that sizos potentially are missing the mark when they're trying to communicate to boards or risk committees. Any thoughts there?

2:09 >> Yeah, look, I think this is a problem that we've seen for years and it's not just limited to sysos and boards. It's more the technical community and the policy community or people and business community even the c seuite of places actually communicating on the same level and understanding each other. I wouldn't say any of this is about you. I mean CIS is a different kind of organization. The board is largely pretty cyber savvy. So even if you say something technical they either get it or they'll figure it out. so I don't I don't think you you evidence this in any way. But I think typically what happens is the syso is used to talking in terms of technology, in terms of failures of technology, in terms of risk that really is very technology based and very technically based and and those terms are great and they're important especially when talking to other people in your team. less important when you're talking or less salient when you're talking to the people on the board when you're talking to the seauite generally when you're talking in the government to you know senior managers and policy people like the attorney general or the secretary of state or someone like that who don't live in that world and don't understand that world. Now there's two schools of thoughts I've heard about this over the years. One of them is wrong in advance which is you know there there are some people I've run into and some people I really respect and I ran into in government and said as long as we mystify it they'll let us do whatever we want you know as long as we talk in these technical terms that sounds like oh this is oh I don't I don't know what to do about this this is really this sounds terrible go fix it you know you guys go off and do something that may have worked for a short period of time when when when people were like this is a big deal I don't know how to deal with it I'll give you resources etc. But what happens in the long term, it doesn't because what it means is those policy makers and those people in boards don't adopt this, don't own this as a real problem. They offsource it or they outsource it to the SISO and the technical team and that means they don't really take it as seriously they need to. They don't resource it the way they need to and they don't look at it which they really need to do in the paniply of all the other risks they're facing.

4:18 and so I think that's that's a challenge and I think so when I you know and I remember we had god I think like 10 years ago now at defcon or blackout or one of those places there was a whole premeating of sisos and how to talk to boards. So this is again not new, not gotten significantly better but not new. and and I think it really is what do those people need to do? What resonates with them? And it's really not the technical I mean you want to couch it in some the technology so they understand this is you know what you're talking about but then really explain it to them as if they didn't know anything about this to really put it in their terms and for boards particularly and risk committees it is what is you know what is the business risk what is the real challenge here I I'll give you one story that you know happened to me which is when I was in government you know DHS department of homeland security has run from time of memorial these cybertorm exercises.

5:14 >> and I was a co-chair of something called the National Cyber Response Coordination Group, the NCR, NCRCP flows, you know, flowingly off your tongue now, now superseded by other organizations. And I co-chared it when I was at DOJ with someone from DHS, senior person at DHS, a senior person at DoD. And we'd go through this exercise and one of the injects in the exercise is a certificate was compromised. You know, major certificate. It was really important. But the the people who were briefing us on that inject, the technical people couldn't make a didn't really make the case of why this is a big deal. And basically I said at one point during that session, why do I care? Why is why is it I care about this? I mean, I understand you you you care about it. Why should I and the other people in this room care? And that's really what I think a SISO should think about and also what the board should think about when you come in.

6:07 >> Well, I I could sense Sean's disappointment when you explained that the blank check theory of of CISO is not a winner. >> Wouldn't work for him anyway because it's a pretty savvy organization CIS. So, >> yeah. You have to move it up to like a quantum level to confuse people. >> There we go. Exactly. Ever feel like cyber security is a giant jigsaw puzzle and someone forgot to give you the corner pieces? All the box lid, the table, all the time.

6:37 Exactly. That's where the CIS secure suite platform comes in. It's your intuitive starting point for cyber security. One dashboard with the functionality of Cisco pro dashboard and CIS C set pro built in. From policy to implementation, it puts the puzzle together for you. CIS controls check. CIS benchmarks double check >> and it's built for CIS secure suite members. You're getting a streamlined experience with the guidance that turns data into decisions like seeing where your biggest risks are and knowing exactly what to do next. Share results easily with internal security teams from one great tool.

7:14 >> Plus, it helps you align with frameworks like NIST and ISO, making you audit ready. So whether you're a small team or a cyber underdog, the platform gives you the visibility, clarity, and confidence to act. So if you're ready to stop guessing and start securing, visit ciccurity.org/secure suite to learn more. >> CIS secure suite platform cyberc simplified. But this this notion I remember the early days as you referenced Christa like every every cyber tech conference had a you know what you know how to speak to boards had a paneler or a track or whatever and then business conferences I went to had a you know what every executive should know about you know cyber and attacks and so forth and and we've tried to treat it as kind of a translation problem. you know, we just need to to learn about the others and speak the language. But it seems a little more complicated because what you described was like trade space. You know, I I h a dollar spent here is a dollar not spent there and therefore you need some basis for comparison. I mean is is the right answer to to quantify to put everything in financial fiduciary terms >> if you can. Yeah. I mean I think that's what boards are boards are substantial risk not all boards and there's other kinds of risk you know reputational risk other things that come in for for an organization like CIS a major cyber incident would not just have financial risk it would have reputational risk for instance given what our business and true for other sort of cyber security companies too so so I think it is quantifying it in a way they can understand it now a challenge is certainly it's not that easy to quantify cyber vulnerabilities. I mean, you know, there's the old adage about you you you don't know what you you prevented. You don't celebrate what you prevented because you don't know what you prevented. You know, when we had Y2K back in the day, you know, we spent lots and lots of money, nothing bad happened.

9:06 Planes weren't falling from the sky like when the that Nike commercial, nothing, you know, nothing happened that people thought were was going to happen. But on the other hand, nothing happened. And that's good. And so that's you know proving you know a non-event is is doesn't really resonate with boards I think. So so but I do think if you can quantify it and I think two you know unfortunately a recent development a recent development in terms of frequency and severity has has helped this which is ransomware where where you know before look boards for time immemorial have been hit by industrial espionage by states by non-state actors. It's a big deal, but they don't see the intellectual property walking out of the room. So, it's very high hard for them to quantify something that could be monetized in two or three years. Their research and development may be gone, but they're not going to realize it right away until the adversary, the other company starts producing their product or incorporating their technology. So, so ransomware though I think changed the game and really something I hate to say take advantage of. You know, it's the the you know, never never waste a good crisis.

10:14 changed the game because then CEOs and seuite saw oh this is business disruption this is something I understand this is something that I get and I understand how that's going to impact the business and I think that's an opportunity for CISOs to say yeah this is not the only thing that does that this is not the only thing has impact but let's let's use this as an example of how you need to prepare and why this is something that needs to be appropriately resourced and accounted for not just resourced accounted for as a risk against your your profits etc.

10:43 Completely agree and I think going through that simulation you know we've done table exercises together Chris and I think one of the things that I get from that is to see decision making from that strategic level because it really helps affect well how should I be thinking strategically one not only to communicate those types of threats and activities but also that decision-m process because it it helps that translation by being able to think as it were likable a board member, what are the types of questions that are going to be asked or what information is needed to make a decision in that space?

11:21 >> I think that's extremely important. I love the fact that you brought that up because >> it then helps us, right, to to create the playing field as it were. And I I in some cases, Chris, you've mentioned it. I'm a little spoiled, right? I I don't have to do a lot of translation because it's I can say it and yeah, we understand exactly what you're saying and here's how to move forward. Fantastic. But for others, I think that simulation makes a lot of sense. Does that make sense?

11:45 >> I think I think it does too. I think it totally does. I think the challenge there is getting the board to set aside the time to do it because you know boards are incredibly busy. They have lots of other obligations. They have lots of obligations just as board members. So to say, okay, especially for a major company, we need to set aside some time to go through this. And and you know, some people look at tabletop exercise like, oh, this just seems like a game. Why am I doing this? But they are incredibly helpful for that. You know, we even you know there there's a national level exercise every year. It's usually chem or something like that that goes up to the president and they have actually a like a fake cabinet meeting with the president presiding at the end.

12:25 And we did cyber one time when I was still in the government and you know that was essentially a a long-term very complicated tabletop that ended with essentially a board meeting the you know national security council the president and and I really do think there were lots of lessons learned from that and there are every time these boards put on one of these things because they either understand some of the shortcomings of the processes understand the shortcomings of the communication process between the technical team you One of the best practices that were talked about you know Tony in those seminars even years ago is the systo should be part of the seauite should be like you know you you shouldn't have them report through the CIO you should or the CTO they should be right there and that's happened in some places but not others so you know that may be a best practice but that still means you have to communicate even if you're at that level and I think having these tabletops and realistic ones not too because I've always kind of railed against you know I won't name any big consulting companies but big consulting companies that do a tabletop that is so complicated that everything breaks and it doesn't test anything and they're very clever and like oh we did all these things. That's not what a tabletop should test. A tabletop should be something that people can learn from. So it doesn't mean you know have everything go wrong and life as we know it ends. It means like figuring out key things that might require decisions. you know, you could do ransomware, you could do others that are probable, would have a high impact and then it really tests that communication and preparedness path. You know, something else we've talked to companies about for years, I know I have, I know you guys have too, is having incident response plans in place before they hit get hit with an incident. You should be shouldn't be building the plane as you're flying it, as we always say. and that started to happen. but another way to test those and make sure they're working is to again exercise it. Because if you think about a major cyber incident, it's it's you guys, you know, the siso talking to the CEO and the board. It is the public relations people. How are you going to message us, right? How are you going to talk about this? Is it lawyers?

14:33 How are you going to talk to regulators and others about this? There's multiple parts that need to be synchronized in a way that I think that most companies don't until they're actually hit with something. >> Yeah. Having been you know you you know having been around military organizations for most of my federal time you know that this exercise reex exercise you know to the point of exhaustion but there is a certain muscle memory that comes with that done well then you wind up sort of asking yourself all the questions that need to be asked right and finding those things like you know the what what they used to say the the during a cyber incident is the first is the worst time to get acquainted with your general counsel.

15:11 >> Yeah. Yeah. Exactly. head of comms. You know, that should have been worked through as a normal part of this this >> or speaking as a recovering lawyer for a general counsel to get familiar with the problem because, you know, lawyers are by nature a little more risk averse and if they don't know the subject, they may not give the best advice if they haven't worked through the implications, you know, and that includes reporting and everything else that's around it.

15:37 so, you know, I also you're quite right. The military is does this exquisitly, right? Except for this. I've noticed in some military exercises over the years that cyber becomes so hard in a general integrated exercise. They say, "Well, let's just assume the cyber aside. It's too hard for us." So you can't afford to do that. >> If if you remember that's exactly the story of you remember the famous eligible receiver. >> Yeah. 97, right? which was the the the first before that there was this tendency to say you know we're moving expensive dangerous things around right ships and and oh my god that cyber stuff is just a mess you know let's just put that aside and worry about another day and but that was the like the wakeup call in the world that I was in at the time which was to and you know there was a some some real leadership at the top senior level to say if this happened to us it'll happen you know in real life and to anyone like us right and there was a tendency before that to kind of hide all that to say, you know, yeah, yeah, but we're doing the important stuff and that cyber stuff is just kind of a distraction, but it became like, no, we better we better put bring this out in the open and talk about it.

16:46 >> Yeah. Yeah. I I I mean, I think that, you know, the other thing that as you do exercises for boards or tabletops or boards, they don't have to be pure cyber exercises. they can be a broader so it's even more effective I think if the board sees how cyber plays into a larger either incident or situation so they understand it's integrated because you know what we all I mean I know I think what we've all been saying for years is look cyber is important we care about cyber we're cyber guys we care about cyber but cyber is not distinct from the rest of the world I mean it has to be integrated you know in governments it's national security and economic security and companies as part the larger risk matrix and also in chart and as part of the opportunities that you you're looking at. And if the longer you treat cyber as this little boutique item over here that is the the the province of the syso and no one else then boards are never going to get familiar with it. It has to really be you have to start thinking about this as not this technical scary thing but something that they can understand. That goes back to your first question Sean put it in terms of financial risk but in you know boards deal with risk all the time. I mean this is not new to them. they just don't know how to deal with this one or they haven't been taught how to deal with this one.

17:58 >> Chris just so because of the I think nature of technology right there's been a lot of work over decades. I I used to track this stuff for different models of of security and insecurity you know and things like you know probability of occurrence and you know technology. Yeah. And is that helpful because it's it's often comes from a mathematical basis for sort of a a model and models are you know good for what they're good but how is that consistent with the way boards take in and make decisions or is it is it complimentary or >> I think it's complimentary I wouldn't I wouldn't focus as much on the math necessarily in terms of but but in part there are risk modeling things that apply to the physical world and have forever right there's you know for instance if I'm a company that makes medicine. I factor in, you know, my chances of getting sued, of liability, of neglactor all that in. Is it a precise science? No. You can't you can't guess completely. But I think, you know, coming up with some models and and the idea of, you know, one of the the easy ones is what's a low a low probability, but high impact versus a high probability, low impact, and what what do you really care about in that in that spectrum? I think that helps boards think about it too that it's like look I'm telling you that this particular thing is unlikely to happen but if it happens we're dead you know so you know I think that and then I think they can understand those terms and and and I think the system can also estimate the probability of something happening based upon the investment and based upon the technology they're seeing out there or today based upon and this is harder because AI is moving so fast and you know especially what we've just seen with some of the AI sponsored attacks when they escape. you know, it's it's it's hard to it's a little harder to do that risk analysis. On the one hand, if you want to be Machavelian about it, that might scare boards and say, well, we're really, you know, really screwed now. We need to do something >> back to that blank check theory. Sean's John's listening.

20:04 >> But on but on the other hand, I think that becomes an equilibrium over time. I think that AI, these AI discovery tools will absolutely play a huge role in privileging the the bad guys and the people trying to exploit systems in the short term, but over time I think that balances out, but it's important to invest in the balancing out by having the capabilities to to fight those attacks. >> Yeah, I I'd like and I like the way you framed it, right? I used to have a team that that that focused on these models and if you remember a fault tree analysis, you know, I think it originally came out new weapons and things, but you know, every bad thing that could happen and then you sort of back up all the events and they would have experts gather and you know, everyone estimate the probabilities at every node big complicated thing. And I once sat down with the team and I said, "Boy, I I tell you one thing. I I appreciate all the work you're doing, but I wouldn't give you a nickel for the probabilities that you came up with. But the value was the value was that they enumerated all the possibilities right to based on the experience of a lot of really smart people and and being able to say something not get hung up in the math as you said or the precision but to say >> these are low likelihood things but I mean the consequence is off the charts we have to think about these you know and vice versa is really I think an important discussion and you want to have all the kind of the whole picture in front of you.

21:19 >> Yeah it's also demonstrating those consequences. So in other words, if you just go in and say if this happens like everything's gone, you know, we're in, you know, deep water, >> that doesn't have as much impact. You say, well, here, you know, and if you could tie it to other examples, and that's not always that easy. If you could say, okay, this company got hit, this is what happened to this company. >> Unfortunately, or fortunately, depending on how you're looking at, some of the companies have been hit, their stock goes down, they come back up again, you know, so it's harder to say to a word, hey, but but they lose customer confidence. There are other metrics to look at that that I think can make a difference and it is hard to predict. I just saw this movie last night u pressure. Do you know this movie? It's about it's about the planning for D-Day.

21:58 it's about it's a weather movie. It's all about this guy this British for meteorologist and forecasting for D-Day and and how you know they were going to invade and they decided not to invade because the weather wasn't going to be good. But one meteorologist saying it was going to be great and the other one said no it's not. looking at the different indicators it you know that's why I said this this kind of prediction happens in the physical world all the time and you can never be 100% precise I mean no one's ever 100% precise or accurate but but you can make some good estimations of this is what the impact will be this is some of the challenges we're facing and this is some of the things that in a in a way that's cost effective we need to do to bite that I mean if you just say I want all the tools and all the money they're going to tell you to get out of town you know it's it's they have to operate too and they have to make money if they're a company that you know a public company or not you know a traded company. So you have to say okay here is what's reasonable and you know the other thing that's happened and John and Tony you know this is although it's still in its early stages I mean a the SEC and others have been more and FDC and others have been and and European regulators have been a little more vocal about having some cyber security expertise and understanding and talking about cyber risk. Now, it's still a little wishy-washy about what's a material incident or not, but still, I think that's changing the game to some extent. You know, I I think I think some cyber people wanted the rule from the SEC that every board had to have a cyber security person on it, which didn't quite happen. But I did say that, you know, you have to have understanding these issues. You can't just ignore them. And I think there's more appetite and understanding in boards now than there used to be because of that. And and because quite frankly, you know, they read the paper, too. I mean they see these big incidents happen and they see particularly around ransomware again business disruption they kind of get okay this is something I have to worry about this is on my plate of things I need to figure out.

24:02 >> Exactly right. I took the words right out of my mouth. It's become you know the cyber risk really is a business risk. It's integrated really into many many practices and processes within an organization. And it's it's interesting the way you phrase it because when you see that you know it's what what was the adage? you know, we don't want to be on the front of the New York Times, right, in terms of an incident, those types of things. And it's >> as we start to see that, it's interesting the feedback, you know, we get from a siz perspective as to are we vulnerable to this? Could could this happen to us? And it it's yes, it could.

24:37 Let's go through this. you know, g get me up to speed on where we are. you know, the the question, are we safe? Are we protected from this? It is that's an interesting analysis and process. Yeah, >> because I also think it's it's what's in the domain, Chris, as well that that gets the attention and so it should. you know, we've, as you mentioned, agent escape and and doing some very interesting capabilities that that's a whole another podcast, but that is gives us an opportunity to get back that seat at the table or at least the attention in some cases for that five minutes as it were because like you say boards high level executive leadership very busy, lot of responsibility, a lot of things and that they need to understand and compute as it were as part of their decision- making during the day. but getting, you know, that attention is always good. And I think those, you know, the way I frame it as well, Chris, is that's kind of like the elevator pitch is you've got this discreet amount of time. Convey to me why I should care and what we're doing to protect ourselves or what you need to get us to answer that question positively. Are we safe? Any thoughts there? Yeah, I mean it it does I don't think it works to say talk in technical terms about that. Again, coming back to that or in product terms like we have X firewall, we have X software to protect us. I don't think that resonates with them unless they're really familiar with that particular product. I think it's like we're doing we're taking the following things to both prevent this and importantly to mitigate it if it happens. Right? So part of this is some things are maybe unavoidable or will happen. The metric can't be and and you guys know this too. this has long been true. The metric can't be that if something goes wrong. When nothing goes wrong, everything is great, you're great. And when something goes wrong, the system loses their job.

26:32 That can't be the metric. It can't be a binary metric. So, so I think it's really and and also in fairness describing to them that the risk is still there, but you you're mitigating it just like you mitigate other risks, right? so that they understand that this is not a binary thing but you're doing everything within the resources that are appropriated to to make sure that this is handled and and you're also looking at the new issues that are coming down. I'll give you you know one example that I'm I'm concerned about a bit is if you I think if you go to every boardroom around the country or maybe around the world everyone wants to embrace AI. It's like oh AI we need AI.

27:07 They don't necessarily know why they need AI but they want AI. But I would bet that the percentage of those boards that say oh and we also need to secure the AI we actually you know we need to have cyber security not just generally but also to secure from prompt injections all the other things that can happen to AI when you have AI and you're relying on AI for critical parts of your business and that demand curve needs to catch up and I think that's something sysos can educate a little bit about saying look great AI wonderful good go with God but you know here are the additional exposures that you get from employing these highle models and here are some suggestions of how you can mitigate that so something doesn't go wrong because that could cause all the you know financial damage reputational damage etc.

27:52 >> Absolutely. Well, I think in, you know, in that space and a really good topic, Chris, because when we look at AI in some cases, the acceleration to get there and then it's coming back to, like you say, the sizzo and say, well, are we secure? I I I you know, I don't know. I think so. this is so new. It's moving so fast. >> Party product is, you know, this is true. this not not just true in cyber but your supply chain also has something to do with whether you can say you're secure and if you don't own your supply chain and no company really does or many don't you know you have to then vouch for all the products you have in your supply chain that they're there and that gets more complicated as these new products come on on tap >> absolutely well I even with AI and we've seen a number of organizations Chris outsource their AI development so now it's not just a prime part of the supply chain, it's all the the other components, right, that are now contributive and that, you know, you're just spreading the risk really across many different organizations. And then you're trying to find out from a governance perspective, well, how you know what's if we input our data into the system, where's it go, where's it stored, what countries, you know, these types of things. And it it you start to lose that effect and the the confidence in the answer starts to from the vendor starts to well I think and whenever I hear I think it becomes >> I don't know right >> exactly yeah I mean I think that's right I think that's right and that will sort itself more over time too because the market will help drive that but right now I think that's still up in the air a lot of times and and I think you know one one thing I'd recommend for sisos especially is it wouldn't be bad if your company will help fund it or even sometimes if they don't to take some some of these trainings that are given for directors.

29:43 You know what a there's lots of things out there. There's NACD. There's a bunch of groups out there that do director training. So you can you can kind of get a feel for what a director is being asked to do. Not what the SISO is being asked to do, but a director is being asked to do. And that helps you think about what language is going to be most effective when you talk to them. And basically the bottom line there is plain language, plain words, you know, don't don't try to overwhelm folks with the technology. Have the data to back have the data to back it up to be sure because if they ask then it's like, okay, I can show you.

30:14 >> Agreed. >> Yeah. I I think Tony, as Chris mentioned earlier, whenever we talk about the technical elements, I always think of you you're calling out the wizardry, right? everything we do back here, it's all magic. You don't need to know it. It just happens. Leave us alone. Just give us the money, right? Give us the people and the money and leave us alone. It always resonates me when when that comes up because one of the one of the things I observed in the in the defense department was the you know again people that get to those really senior jobs, right? Stars on their shoulders and stuff. These are extraordinary people. They're decisive.

30:49 They're, you know, they're hard charging and so forth. But that as it became kind of foundational to everything the department did what what I saw was people who didn't grow up in it didn't have a they didn't they didn't have what I call decision intuition yet you know in their normal domain right you know and you know the language is can I can I project force right with confidence or things like that they have they they have a pretty strong sense of u when they hear a good argument a weak argument you know their intuition is tuned because that's their world and then this IT stuff and it's like they're trying to map it to what they know and sometimes that works but a lot of times it doesn't and they struggle with that right they they and so you get in this so the commander says can I confidently predict force and the IT guy goes I don't know we don't have all the IVAs in place and we got a million scans in the last that doesn't help right that that that that gives no intuition and it and that's you know observing that so will things get better as we all conversant Yeah, I think they already have and I think they'll get better. I mean, it used to be I used to use the analogy of u you know, someone goes into like, you know, a cabinet secretary in the US and they start talking about cyber and their eyes roll back in the back of their heads and they kind of run screaming from the room because it's like I don't know this, I don't understand. When they deal with nuclear technology all the time, right? You don't have to be a coder >> to understand the geopolitical issues or the business issues around cyber. It just has to be explained to you in those terms. and and you raised, you know, going back to this movie I saw last night, General Eisenhower was demanding this meteorologist, I don't want you to tell me how this is all working. I want you to tell me where the high pressure zones are, >> go or no go.

32:33 >> Exactly. >> U, >> and it's a little unfair because you can't be categorical, right? So, but at the same time, you can be you can give certain levels of certainty and that's why I think boards >> Yeah. because it turns out I used to tell the story of my I don't if you knew this my dad was an army sergeant supply sergeant and what what I learned from that was there's always uncertainty or fog in the system you know because he was he said one to me one time he said well the inspector is coming right to see all the equipment that he's got he's responsible for he says so I have to take all the equipment that's not on the books load it in a deuce and a half a big truck and send it for a drive through the gun range while the inspector's here because if if I don't have that stuff I nothing to trade with the other supply sergeants for the stuff that they've lost. And and the decision intuition there is that and by the way the commander knows this, right? There's no perfect inventory of hardware, software or military equipment. But we know that you know when we say the planes are ready to fly, that doesn't mean literally every plane is 100% ready to go completely fueled. It means that we have enough experience to know that I can make a rational though imperfect decision. We have we don't really haven't got to that stage.

33:44 >> And I do think it's getting better. I mean, you know, it's gone from people being afraid of their technology. I mean, there are exceptions. Like I remember when I was at DOJ, Janet Reno cared deeply about cyber cyber crime. I mean, she way ahead of her time. I mean, she used to grill incoming del, you know, from other countries, you know, South Africa, other places. What are you doing about cyber crime? And they'd be So you know so that there there were people like that but most of the folks were just I don't know I don't care it's magic to me or it's like too complicated but that has changed I think people understand it more because you know it's more in the public eye people understand the damage it causes either you know dam financial damages or infrastructure damages or even human toll. I mean there's a lot of work around the actual human costs of a lot of these incidents. you know, a friend of mine's working on that. And so, I think there's more understanding. Is it perfect yet? No.

34:38 There's still this bubble, I think, of of cyber, but I think it's getting better and it will continue to get better as, you know, we have more generational shift and people just grew up with this stuff. Not that everyone who grew up with it understands security either because lots don't to be fair. >> That's very true. Well, Chris, that brings us to the end of the episode. Thank you so much again. Really looking from your lens and really valuable in order to understand the the types of communication how to communicate and we even got a I think a movie recommendation pressure with Brendan Frasier I think is is in that one. So >> is he I'm not sure. It's it's it's it's I think he is actually. You're right. I think he plays Eisenhower. It's it's it's an interesting movie. I can't say it's a you know a total mystery because you know what happens but right but it's it's it's pretty it's a pretty interesting take which I haven't seen before and and I I should just say Sean been a pleasure to be on but also both Sean and Tony you guys are you're models of this. I think you understand No, you are. I think you understand it and it I think you've learned this over the years of how to communicate in a way that I think people take it seriously and understand it including people who don't know this issue and I think that needs to be replicated a million fold. We need to have lots more people out there who can do that.

35:59 >> I understand it's hard you know I'm going, you know, I'll be in Las Vegas for Defcon and that I think they're they've gotten better in talking to the policy community. There's a policy track there for instance. but but it's always been a problem and it's not just a cyber versus you know business or policy thing. This this goes to other areas too but I think cyber can really use a lot more of the translators and building better translators and people to do it.

36:26 >> Fantastic. Well thank you Chris. I really appreciate it and Tony thank you sir. Fantastic episode. >> Always a pleasure. >> Thank you Chris and thank you to our audience. Make sure to subscribe in all the usual ways through your preferred podcast provider. Catch us on YouTube at thecurity. You have a question, comment, please reach out to us at podcastcurity.org. And with that, we'll talk to you soon. Thank you for listening to the podcast today. >> The thoughts and opinions expressed by our podcast guests are solely theirs and do not necessarily reflect those of CIS.

37:00 Tune in on Wednesdays for a new episode and in the meantime, visit our website at ciccurity.org. Together, we'll continue our efforts of creating confidence in the connected world.

Summary

The podcast episode features discussions on effective communication strategies for Chief Information Security Officers (CISOs) when addressing boards and risk committees. Chris Painter emphasizes the importance of translating technical jargon into business risks and aligning cybersecurity with broader organizational goals to ensure proper understanding and resource allocation.

- Cybersecurity is a critical issue that affects all sectors, including government and business.
- CISOs often struggle to communicate effectively with boards due to a reliance on technical language.
- Successful communication should focus on business risks rather than technical details to foster understanding and ownership of cybersecurity issues.
- Quantifying cybersecurity risks in financial terms can help boards grasp the potential impact on the organization.
- Ransomware incidents have heightened board awareness of cybersecurity as a business risk.
- Tabletop exercises can enhance decision-making and communication between technical teams and board members.
- The integration of cybersecurity into overall business strategy is essential for effective risk management.
- Ongoing education for CISOs about board dynamics and language can improve communication effectiveness.

Questions Answered

What is the purpose of the Cyber Security Where You Are podcast?

The podcast aims to discuss trends and threats in cybersecurity, explore best practices, and interview industry experts to enhance understanding and confidence in cybersecurity.

How should cybersecurity professionals communicate with boards?

Cybersecurity professionals should translate technical risks into financial terms that boards can understand, emphasizing the importance of quantifying risks and the potential impact of cyber incidents.

Why is it important to prepare for cyber incidents in advance?

Preparing for cyber incidents involves familiarizing key personnel, such as general counsel, with cybersecurity issues to ensure effective response and decision-making during crises.

What is the current state of cybersecurity regulations?

Regulatory bodies like the SEC are increasingly emphasizing the need for cybersecurity expertise on boards, reflecting a growing recognition of cyber risks and their potential impact on businesses.

What communication strategies should cybersecurity professionals adopt when addressing boards?

Cybersecurity professionals should use plain language and avoid technical jargon, ensuring that their communication is clear and supported by data to facilitate understanding and decision-making.

© transcribe · For agents Built with care and craft by Gokul Rajaram