-

Tactics for Effectively Communicating Cybersecurity Risk to Boards of Directors Outlined in New ISACA Paper

SCHAUMBURG, Ill.--(BUSINESS WIRE)--The recent hack of network monitoring service company SolarWinds, impacting a massive swath of U.S. federal agencies, state and local governments and other organizations, has served as a wake-up call to many enterprises—and likely spurred enterprise leaders and boards of directors to ask their cybersecurity teams about their own cyberrisk.

ISACA’s new white paper, Reporting Cybersecurity Risk to the Board of Directors, outlines how cybersecurity and risk professionals can effectively communicate with their boards of directors about cybersecurity and its link to business objectives.

Reporting Cybersecurity Risk to the Board of Directors provides cybersecurity and risk professionals with a foundational understanding of how boards of directors are structured, as well as offers guidance around how to present cybersecurity as a business issue—including helping boards understand their legal and regulatory obligations, the potential disruption to systems, and risk of data loss and theft. The paper also guides cybersecurity and risk professionals in translating information around threat intelligence, risk identification and scenario analysis, risk management, cyberrisk economics and budgeting in ways that will resonate with leadership.

Some approaches for doing so include:

  • Offering peer comparisons, including through third parties like CMMI, which provides an assessment of enterprise cybersecurity maturity through its CMMI Cybermaturity Platform
  • Presenting risk quantification through dashboards, illustrating metrics like key performance indicators, key control indicators and key risk indicators in categories like data loss and theft, data reliability, systems reliability and fraud
  • Applying thresholds in categories of risk capacity, appetite and limits when discussing potential actions the board can take

“It is imperative that board directors understand how cybersecurity risk can impact their business and how vital it is to dedicate resources to reducing that risk and building their enterprise’s cyber maturity,” says Tracey Dedrick, ISACA board chair, and former EVP and Head of ERM for Santander Holdings US. “In order for that to occur, cybersecurity professionals need to understand how to communicate effectively with directors and how to cultivate those relationships in order to drive that awareness and advance their security goals.”

Reporting Cybersecurity Risk to the Board of Directors is complimentary and can be downloaded at www.isaca.org/bookstore/bookstore-wht_papers-digital/whprcr. Visit www.isaca.org/resources/cybersecurity for additional ISACA cybersecurity resources. For more information on IT risk, including ISACA’s complimentary Risk IT Framework and Risk IT Practitioner Guide, visit www.isaca.org/resources/it-risk.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews/

Contacts

Emily Van Camp, +1.847.385.7217, communications@isaca.org
Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org

ISACA


Release Versions

Contacts

Emily Van Camp, +1.847.385.7217, communications@isaca.org
Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org

Social Media Profiles
More News From ISACA

IBM Joins CMMI Institute’s AI Content Development Initiative

SCHAUMBURG, Ill.--(BUSINESS WIRE)--ISACA’s CMMI Institute announced today that IBM has joined ISACA’s CMMI Performance Solutions as a founding sponsorship lead of the CMMI Artificial Intelligence Working Group (AI WG). This working group is leveraging industry experience and curating best practices for planned updates to the CMMI Model to incorporate AI content. The AI WG has been providing best practice research, examples, process and tool demonstrations, and other curated information to add t...

ISACA Updates CDPSE and CRISC Exams to Reflect Latest Risk and Privacy Priorities

SCHAUMBURG, Ill.--(BUSINESS WIRE)--To keep pace with the evolving risk and privacy professions, ISACA has updated the exams and review materials for the Certified Data Privacy Solutions Engineer (CDPSE) and Certified in Risk and Information Systems Control (CRISC) credentials. The updated CDPSE exam will be available on 2 June 2025, and its new exam preparation materials will be available starting 2 April 2025. The updated CRISC exam will be available on 3 November 2025, and its preparation mat...

ISACA Study: 1 in 3 Tech Pros Switched Jobs in Past Two Years, Leaving 74% of Firms Worried About IT Talent Retention

SCHAUMBURG, Ill.--(BUSINESS WIRE)--A career in tech can bring invigorating work, solid compensation and high satisfaction, but can also come with its own stresses—and can be challenging to break into in the first place—according to new research from global professional association ISACA. The global ISACA Tech Workplace and Culture survey of 7,726 technology professionals explores career satisfaction, pay, levels of authority, mentorship, retention factors and more, including similarities and di...
Back to Newsroom