HFS highlighted in Cyber Security Services: What’s in Store For 2018? that cybersecurity is a business rather than a technical concern. To achieve a capable security posture, you must address the business first; this cannot happen when the chief information security officer (CISO) and the executive board do not engage enough. Here, we outline the barriers to the CISO and the executive board working together and provide recommendations to both parties to improve the situation.
Why the CISO and the Board are rarely on the same page
Table 1 outlines some reasons for the lack of communication between the executive board and security leaders.
Table 1: The disconnect between the CISO and the executive board
|
CISO and security leaders |
Executive board |
|
Subject matter technical expert
Struggles to position IT security in the business context |
Business issues-focused
Struggles to understand the technical and organizational requirements to achieve a good security posture |
|
Focus: Enterprise IT security products and services to solve specific security concerns |
Focus: Enterprise risk and brand protection concerns |
|
Must manage their own budget to facilitate necessary spending on cybersecurity |
Sometimes requires CISO to report to the CIO or another executive, which can create competition for budget and lead to inadequate spending on cybersecurity |
Source: HFS Research, May 2019
Increasing interconnectivity and technological development mean enterprises are handling more data. However, unless customers trust you to secure their data, they may not allow you to have it going forward. Every news story about a data breach or data failure hammers another nail in the corporate trust coffin, as no enterprise wants to be the subject of this headline. However, it is more important to be able to communicate a robust and credible story about how you will protect your customers’ data and keep it safe when doing business with you. To do this, your enterprise board and the CISO team need to change their working relationship to achieve a strong enterprise security posture. The trust that used to be a given increasingly requires proof.
What does the executive board need to do? Empower the CISO
The enterprise executive board has traditionally lacked experience and expertise in cybersecurity. It’s all very well to understand that cybersecurity is an important issue, but the knowledge is useless if the enterprise is not able to achieve a meaningful cybersecurity strategy. Our top three tips for the executive board are
Exhibit 1: Lack of C-Level support puts the security of an organization at risk
Which of the following are the biggest inhibitors to your organization’s security readiness? (top inhibitor) N=300

Source: HFS Research, 2019
In return, the CISO needs to get business savvy or work elsewhere
HFS estimates that CISOs only keep their jobs for three years on average. They are not typically incompetent, but they often lack business acumen. The board, therefore, fires them, or the CISO becomes frustrated and moves on. Our top three tips for CISOs are:
The Bottom Line: The executive board and the CISO need to change their approach to cybersecurity to effectively protect their enterprise
Security is no longer a dirty word—a digitally enabled business needs to think about cyber security as part of its day-to-day and strategic decision making. The absence of a close working relationship between executives and a CISO will leave an enterprise vulnerable.
Register now for immediate access of HFS' research, data and forward looking trends.
Get StartedIf you don't have an account, Register here |
With the exception of our Horizons reports, most of our research is available for free on our website. Sign up for a free account and start realizing the power of insights now.
Our premium subscription gives enterprise clients access to our complete library of proprietary research, direct access to our industry analysts, and other benefits.
Contact us at [email protected] for more information on premium access.
If you are looking for help getting in touch with someone from HFS, please click the chat button to the bottom right of your screen to start a conversation with a member of our team.