There’s always been a communication gap between CISOs and their fellow C-suite members.
The fact that they’re even part of the C-suite is up for interpretation because cybersecurity has often been considered a separate side of the house, dealing with a whole different set of problems and speaking a whole other language.
With security breaches growing in both number and severity and pressure amping up from the feds, it would seem this gap would be improving — but, in fact, it’s as bad as ever, according to a new report from FTI Consulting.
Notably, 66% of CISOs say senior leadership at their company struggles to fully understand their role, while nearly one-third (31%) of C-suite execs find it difficult to understand the return on cybersecurity investment.
“If these two groups — information security and the C-suite — are speaking past, rather than to, each other, it can create an unbalanced understanding of the cyber risks a company is facing,” Evan Roberts, senior managing director and co-leader of FTI Consulting’s cybersecurity and data privacy communications practice, told SDxCentral. “This can, in turn, lead to a lack of preparedness and disjointed efforts should an incident occur.”
Job descriptions evolve in a changing cybersecurity landscapeNavigating C-suite perceptions and expectations is the second in FTI’s “CISOs Redefined” series. The consulting firm surveyed nearly 800 C-suite executives across seven sectors, including telecom, financial services and retail.
Both sides of the table reported numerous challenges. On the CISO side, the survey found the following:
- 82% felt a need to make things sound better to the board.
- 58% said they struggle to translate technical language to senior leadership in a meaningful way.
On the nonsecurity side, FTI Consulting found the following:
- 31% of executives said they believe their CISO paint a brighter picture than reality and 30% said they think CISOs are hesitant to raise concerns about vulnerabilities.
- 28% think their CISO have a hard time translating technical terms into business terms and 30% said this is true when expressing cybersecurity risk in financial and material terms.
- 62% reported that their CISO’s direct communication skills do not exceed their expectations.
“The importance of CISO-to-C-suite communications fundamentally comes down to risk — in many ways, a primary role of the CISO is to help their fellow leaders understand their risk profile, risk tolerance and the impact risk mitigation actions will have on the business,” said Roberts.
He pointed out that much of the disconnect comes down to how much the CISO role has changed. “What was once purely a technical function has truly evolved to be both a business leader and a communicator.”
That traditionally hasn’t been in the job description. Many CISOs have been in information security for a long time, “and to have the expectations placed on their roles change so dramatically has put many in a disadvantaged position,” said Roberts.
“Traditionally, CISOs have simply not been trained on effective communications and message delivery skills the way other C-level leaders have been,” he said.
With incidents increasing, security leaders and C-suite must communicateThe survey also gauged sentiment about cybersecurity in general. Findings reveal that a majority of C-suite executives increasingly view cybersecurity as a critical or high priority. Additionally, over the last 12 months respondents cited the following:
- 94% believe cybersecurity issues increased in prominence.
- 90% said they have experienced a cyber incident.
As a result, 87% of execs have increased their CISO’s decision-making responsibilities.
Clearly, the threat landscape is widening and becoming increasingly complex, making CISO-C-suite collaboration imperative.
Businesses need to understand that responding to a live cyber incident requires a “whole-of-company effort,” said Roberts, rather than simply a response from the security side of the house.
“This is only possible if security leaders and the C-suite mutually understand each other before the crisis occurs,” he said.
Increased emphasis on trainingWhile the report reflects serious challenges, it also indicates that leaders are eager to address these and close skills gaps. In fact, nearly all C-suite executive respondents (98%) said they support more funding for CISO training, and nearly half said this need is immediate.
The biggest gaps to address in training are related to cyber risk, anticipating threats, raising employee awareness and communicating ROI. The top five attributes executives would like to see in CISO include the following:
- Effectively managing security budgets and resources
- Easily translating technical jargon into understandable terms
- Skillfully leading during crisis
- Ability to build and manage external relationships
- Ability to develop and maintain internal relationships
Skills programs and training are emerging to meet these demands and help CISOs improve their communications and soft skills — including FTI’s training program “Secure Your Seat” — and both security and non-security leaders should explore them, said Roberts.
“C-level executives need to support CISOs pursuing these types of trainings,” he said, “giving them space and time to invest in themselves, and make an effort to meet them halfway by familiarizing themselves with the CISO's role and the associated pressures and demands that it entails.”
Comments