Cybersecurity Board Communication Checklist

When communicating with high-level company executives and board members about cybersecurity issues, experts advise brevity and clarity—and emphasizing the bottom line.[1]

“When it comes to cybersecurity, one of the things that’s definitely helpful when presenting to executives and the board is to talk through cybersecurity not as an IT [information technology] issue but as something that’s critical for the business and critical for risk management,” said Teju Shyamsundar, senior product marketing manager at Okta Inc. in San Francisco.

Shyamsundar has three recommendations:

  1. Take a data-driven approach to your recommendations to show how cybersecurity is affecting various parts of the business.

  2. Align with industry standards for security.

  3. Use reports and peer insights to identify what other organizations in your industry are doing to address cybersecurity. “You don’t need to copy them, but it’s good to have a sense of what other organizations in your industry are doing,” she said.

In fact, it doesn’t make sense to have a one-size-fits-all approach to cybersecurity, even for organizations in the same industry, because needs can differ significantly, Shyamsundar said. For example, an organization that houses its data in the cloud will have different needs than an organization with its own on-site servers, she said.

This document is only available to subscribers. Please log in or purchase access.
 


Would you like to read this entire article?

If you already subscribe to this publication, just log in. If not, let us send you an email with a link that will allow you to read the entire article for free. Just complete the following form.

* required field