Businesses are still taking it slow when it comes to security. A recent survey by TrainACE reveals that a majority of organizations are employing best practices; but don’t have the basics set up (such as an incident response plan or updated guidelines). Learning the hard way, which means getting breached, seems to be the quickest way to get those in charge to act and implement a holistic security posture; but it doesn’t have to be the only way.
The biggest challenge for security professionals is to communicate with the executive team. Learning to speak the CEO’s language on matters of security is a better solution than waiting for breach to happen. Different ways you can accomplish this is to quantify breach in cost for the company, as well as give examples of how damaging a breach can be for business (just mention Target, that should catch their attention). Some additional examples of how you can approach the security talk with the higher up include:
These are only some ideas to help you get through to the C-Suite on the importance of security for business, but you don’t have to stop here. As a security professional you are always staying up to date on the latest data security news and breach stories; use that information to help your executive team see the ramifications of a weak security posture. They may not be able to understand security per se, but they do understand costs and bad publicity.
Risks to your data are not going away and as a CIO it is your job to ensure your enterprise is secure. Don’t shy away from a conversation with your CEO or the board members because they don’t seem to understand what you try to explain regarding security. Instead, put it in a language they speak, because the front page on how your business was breached is probably the worst way to start a dialog with them.
How are you approaching security with the executive team to protect business and sensitive data?
Photo Courtesy of Mathias Rosenthal