Talking To The Board: How To Improve Your Board's Cyber Security Literacy – UK Edition

Post on 15-Apr-2017

779 views 1 download

transcript

Talking to the Board:How to Improve Your Board’s Cyber Security LiteracySeptember 16, 2015

2

Today’s Presenters

Amar SinghFounder Give01Day

& Cyber Management Alliance & Interim CISO

Ray StantonExecutive Vice President, BT

Gary CheethamCISO, NFU Mutual

Paul EdonDirector of Customer Services, Tripwire

What details are the board looking for and why?

How do you engage and manage your board's expectations?

What language do you use to speak to the board?

How much emphasis do you place on compliance, risk and security in your communication?

Is there a "Golden Ticket" that gains you immediate access to budget?

8

Three Key Takeaways

Consider, understand and focus on the business processes that when disrupted would get the board involved.

Encourage the board and senior executives to be trained/educated in cyber and privacy basics.

The board members are presented business risks. Integrate, not align, your risk framework and register with the same risk ecosystem.

9

Three Key Takeaways

Clarity of what is important to the board, and messaging to suit.

Remaining unemotional when delivering messages, passion not emotion – it’s not personal.

Deliver the message with business context, not security or risk babble.

10

Three Key Takeaways

Never miss an opportunity to get your message across.

Focus on the impacts to them in their role and prioritise.

Keep it simple and in their language – technobabble doesn’t work!

11

Three Key Takeaways

Don’t try to answer the question “Are we secure?” but rather “How secure are we?”

Build and maintain your credibility with the board.

Prepare, plan and then prepare some more.

12

Tripwire Product PortfolioDetecting and Responding to indicators of breach, compromise, and vulnerability

13

Threat Intelligence

Tripwire Adaptive Threat Protection

Adaptive Threat

ProtectionEndpoint Intelligence

Vulnerability Intelligence

Threat Analytics

Forensics

Zero-Day Detection

Threat Response

Log & Event Intelligence

SUBTITLE STYLE

http://www.tripwire.com/cyberliteracy

tripwire.com | @TripwireInc

THANK YOU