-

Tactics for Effectively Communicating Cybersecurity Risk to Boards of Directors Outlined in New ISACA Paper

SCHAUMBURG, Ill.--(BUSINESS WIRE)--The recent hack of network monitoring service company SolarWinds, impacting a massive swath of U.S. federal agencies, state and local governments and other organizations, has served as a wake-up call to many enterprises—and likely spurred enterprise leaders and boards of directors to ask their cybersecurity teams about their own cyberrisk.

ISACA’s new white paper, Reporting Cybersecurity Risk to the Board of Directors, outlines how cybersecurity and risk professionals can effectively communicate with their boards of directors about cybersecurity and its link to business objectives.

Reporting Cybersecurity Risk to the Board of Directors provides cybersecurity and risk professionals with a foundational understanding of how boards of directors are structured, as well as offers guidance around how to present cybersecurity as a business issue—including helping boards understand their legal and regulatory obligations, the potential disruption to systems, and risk of data loss and theft. The paper also guides cybersecurity and risk professionals in translating information around threat intelligence, risk identification and scenario analysis, risk management, cyberrisk economics and budgeting in ways that will resonate with leadership.

Some approaches for doing so include:

  • Offering peer comparisons, including through third parties like CMMI, which provides an assessment of enterprise cybersecurity maturity through its CMMI Cybermaturity Platform
  • Presenting risk quantification through dashboards, illustrating metrics like key performance indicators, key control indicators and key risk indicators in categories like data loss and theft, data reliability, systems reliability and fraud
  • Applying thresholds in categories of risk capacity, appetite and limits when discussing potential actions the board can take

“It is imperative that board directors understand how cybersecurity risk can impact their business and how vital it is to dedicate resources to reducing that risk and building their enterprise’s cyber maturity,” says Tracey Dedrick, ISACA board chair, and former EVP and Head of ERM for Santander Holdings US. “In order for that to occur, cybersecurity professionals need to understand how to communicate effectively with directors and how to cultivate those relationships in order to drive that awareness and advance their security goals.”

Reporting Cybersecurity Risk to the Board of Directors is complimentary and can be downloaded at www.isaca.org/bookstore/bookstore-wht_papers-digital/whprcr. Visit www.isaca.org/resources/cybersecurity for additional ISACA cybersecurity resources. For more information on IT risk, including ISACA’s complimentary Risk IT Framework and Risk IT Practitioner Guide, visit www.isaca.org/resources/it-risk.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews/

Contacts

Emily Van Camp, +1.847.385.7217, communications@isaca.org
Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org

ISACA


Release Versions

Contacts

Emily Van Camp, +1.847.385.7217, communications@isaca.org
Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org

Social Media Profiles
More News From ISACA

ISACA Unveils 2026 Global Events Slate for Digital Trust Professionals

SCHAUMBURG, Ill.--(BUSINESS WIRE)--ISACA, a global association empowering the workforce advancing trust in technology, has released its 2026 event schedule, with both in-person and virtual opportunities. ISACA’s events offer expert insights in the areas of digital trust, cybersecurity, audit, governance, risk, privacy and emerging technologies for leaders worldwide. Flagship Conferences: ISACA North America Conference | 6-8 May 2026 | Las Vegas, Nevada, USA & Virtual The premier event for b...

2026 ISACA Awards Honor Exceptional Tech Professionals

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Every year, ISACA members and technology professionals around the globe demonstrate exceptional dedication and make remarkable impacts on their organizations, industries and communities. ISACA is honoring technology professionals in the areas of IT audit, risk, governance, privacy and cybersecurity with the 2026 Global Achievement Awards and Hall of Fame induction for their accomplishments and contributions in the professional tech community. The recipients of...

New ISACA Study: Privacy Teams Are Shrinking, Increasingly Stressed

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Privacy professionals are facing a data-dominated landscape, a complex web of regulations and more limited resources this year. According to the State of Privacy 2026 survey report from ISACA, these professionals are feeling increasingly strained, with 65 percent saying their roles are more stressful now compared to five years ago. This report, with insights gathered from more than 1,800 privacy professionals in the ISACA community worldwide, finds that respon...
Back to Newsroom