1. Educate the organization on cyber risk
Traditional security awareness efforts have their place. But in an increasingly distributed ecosystem – across remote locations, business units, and geographies – these approaches are failing to facilitate the right behavior.
That’s because employees are now making decisions with cyber risk implications, often without consulting security risk management leaders. They are also faced with contradictory messages, such as the need to share information with clients or business partners versus protecting data – leaving them confused about the right thing to do.
Gartner also found that executive committees are being formed outside the purview of SRM leaders. Each of these factors contributes to an environment where SRM leaders have less direct control over many decisions that typically would fall under their purview. But it doesn’t have to be that way.
Here are some measures Gartner recommends that SRM leaders take to educate the organization that cyber risk is business risk – and hold them accountable:
- Influence employee behavior in novel ways: SRM leaders must recognize that providing information to employees about risk won’t change their behaviors. People are much more influenced by norms and cues in their environment and will better respond to targeted tools that influence their behaviors, such as security culture hacks, gamification, and branded security programs.
- Establish a security charter that stipulates that board members and executive leaders won’t make unilateral decisions that could expose the organization to unacceptable risk – and ensure these individuals buy into it.
- Formulate executive cybersecurity performance goals: SRM leaders should work with HR leaders to include these goals in executive employment contracts.
2. Elevate executive reporting
Security risk management leaders must shift their roles to shape and influence risk decisions made by executives and boards.
To do this, SRM leaders must start speaking the language of the boardroom. Instead of talking about the technical aspects of the organization’s security apparatus, such as how many intrusions the corporate firewall stopped in the last quarter, they must articulate risk in terms the C-suite and board understand. For example:
- If successful, how will intrusions affect the business?
- Did a cybersecurity incident impact critical systems?
- What are the financial or other impacts of a cybersecurity incident?
- Are there any other business-impacting vulnerabilities in the IT environment?
With data-driven executive reporting capabilities, leaders can answer these questions quickly and accurately, redefining cybersecurity as a business risk discussion.
As an example, SRM leaders can provide information about the number of vulnerabilities in the company’s digital ecosystem, as well as their severity (i.e., their likelihood of contributing to a breach) so that executives and board members can make more informed decisions about where to allocate resources and investments.
But to truly speak the language of the board, SRM leaders must quantify cyber risk in financial terms and communicate the impact to the bottom line if vulnerabilities go unaddressed.
Using advanced data analytics and automation, organizations can simulate their financial exposure across hundreds of thousands of cyber events, such as ransomware, denial of service attacks, regulatory compliance issues, and supply chain attacks.
Through these insights, SRM leaders can guide leadership discussions around cyber risk management, prioritize cybersecurity decisions, and justify new technology investments.