Exposure management tooling can act as an excellent source of truth for cybersecurity leaders as they communicate risk up to the board level. The visibility and data streaming from exposure management solutions makes it easier for CISOs to track security performance over time, quantify improvements in security maturity levels, establish better financial quantification of cyber risk and ensure the organization's exposure levels match up with industry averages.
However, it can be very easy for a security executive to get caught up in the minutiae of exposure management data and fail to see the forest from the trees. Simply dumping exposure management data into a massive slide deck is one of the worst ways to report to the board. Reams of security operational data just floods directors and other executive stakeholders with uncontextualized technical information that feels irrelevant to their concerns about business risk.
So while exposure management platforms will directly feed into the performance metrics that a CISO reports to the board, security executives should only very rarely be presenting direct exposure data. The big exception is when headline events like MOVEit or Solarwinds attacks emerge and the board wants to know current risk status.
"When there are major security events, you want to be able to show that you're proactively managing it," explains Brian Mulligan, vice president of product for security performance at Bitsight. "And then that's when you'd tell the board, we have 1,000 vendors, 800 of them are impacted, 600 of them have remediated and we're working with the other 200 to do so. That's where exposure metrics do have use in the board room."
Instead, CISOs should be thinking of how to bring context and summarization to the risk information that exposure management platforms uncover. Then they need to tell stories in business context. Here are some key tips for presenting the outcomes tracked by exposure management in a way that will be most helpful to the board and business stakeholders.
Summarize Information into a 'Wow' Report
The value of exposure management data is that it makes it possible to create accurate security performance and risk metrics relevant to board audiences. CISOs should consider working with their board constituents to summarize information about cyber KPIs that are fed by exposure data and other relevant cyber risk information into a 'Wow' report, recommends James Lam, president of James Lam & Associates, a board advisory and consulting firm, and a veteran risk management expert and corporate director. As he explains, wow is not an acronym, it's what you're trying to get directors to say once they've read it and heard the presentation.
"You want each board member to say, 'Wow, I have a better understanding about our cyber risk profile. I'm seeing information that I have not seen before," Lam says.
This means ditch the laundry lists of open or closed critical vulnerabilities and move into storytelling and business risk quantification. When Lam was on a corporate working group to develop such a reporting framework, it had six major elements:
a snappy executive summary written by the CISO about the risk profile and strategy,
- a business-audience digest of biggest threat trends impacting the org during the reporting time,
- independent security ratings and outside audit results,
- a summarized breakdown of trends from security performance data
- a section offering financial quantification of cyber risk, and
- a section detailing strategies to improve the most important KPIs detailed in previous sections.
With that kind of summarization established, Lam reports that it became much easier to establish a line of meaningful communication between security leadership and the board.
"It was updated every quarter," he says. "And this facilitated much better decision making at the board level in terms about controls, our cyber risk strategy, our cyber insurance decisions."