No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

Why CISOs and Boards Must Speak the Same Language on Cybersecurity

Translating cyber risks into boardroom terms is essential for resilience

by Monica Landen
February 4, 2025
in Cybersecurity
neon handshake sign

When CISOs speak in technical terms and boards focus on financial outcomes, the disconnect can leave organizations vulnerable. Monica Landen, CISO of Diligent, explores how aligning these perspectives is essential to navigating today’s complex cybersecurity landscape.

While cybercrime has sat near the top of the board agenda for the past five years, it is arguably the most pressing risk facing organizations in 2025. New global regulations, such as the revised Network and Information Security Directive (NIS2), are putting more pressure on boards and leaders to keep pace with and demonstrate an understanding of cyber risks. At the same time, increasingly sophisticated and pervasive cyber threats, especially those using AI, put organizations at risk of financial, reputational and legal consequences. 

Seeing as many directors still identify cybersecurity as one of the most challenging areas to oversee, clear communication between the chief information security officer (CISO) and board has never been more critical. To do so requires linking cyber risks to financial consequences, leveraging technology to deepen the board’s understanding of regulatory changes and ensuring CISOs have the financial acumen to speak the board’s language.

Linking cyber risks to financial consequences

As cyber threats become more advanced and widespread, it’s critical to not only have a strong risk management strategy in place but to quantify cyber risk in a way that resonates with leadership and the board.

Providing leadership with relevant benchmarking data, including supplier risk scores and credit sentiment scores, helps them be more informed on both the internal and external risk factors they’re faced with. Additionally, tying outcomes such as ransomware or data loss to financial outcomes helps clearly communicate the impact of cyber risk.

Building an effective dialogue on cyber risk calls for CISOs to use accessible, user-friendly language that effectively translates the risks associated with cybersecurity. Quantifying cyber risk using metrics familiar to the board, as well as linking cyber risk to other top priorities on the board’s agenda, is now essential to secure buy-in and resources for effective cybersecurity programs. 

Companies with advanced cybersecurity performance see 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to our research. Government oversight agencies like the SEC and FTC, as well as shareholders, lawyers and judges, think about cyber strategy in terms of operations, fiduciary obligation, revenue and implementation — so it’s crucial for CISOs to be cognizant of this as well.

small figurines connecting ethernet cable
Cybersecurity

Inside Regulators’ View of ‘Reasonable Security’

by Ryan Smyth and Joe Bruemmer
January 21, 2025

Consent orders and AVCs set standards for testing, training and incident response

Read moreDetails

How CISOs and boards can join forces to tackle regulatory compliance

For CISOs and board members aiming to drive growth and reduce risk, it’s essential to embed regulatory compliance into strategic plans. This approach ensures the organization stays aligned with evolving cyber and data regulations while fostering an environment that supports sustainable growth. 

As regulations evolve, the board’s expertise must adapt accordingly. Directors should leverage tools that highlight regulatory changes, identify areas where their organizations may face compliance risks and outline necessary disclosures to meet both regulatory and shareholder expectations.

Access to accurate, real-time data is crucial for boards and CISOs to navigate changing regulations and make well-informed decisions. As reporting timelines accelerate for cyber incident response, regulations are increasingly holding CISOs personally liable. This shift could impact how CISOs respond in high-pressure situations and may complicate efforts to attract and retain top talent. To tackle regulatory compliance effectively, CISOs require strong support and consistent engagement from company leadership and the board. 

Empowering the board & CISO relationship

With the role of CISOs becoming increasingly critical and more heavily scrutinized, there are many ways for boards to further strengthen this relationship. Given CISOs often lack the same protections as other C-suite executives, it may be worthwhile to reconsider their compensation and protection policies. It shows the board’s commitment to supporting their CISOs and acknowledging the importance and inherent risks of the role as it extends legal protections and provides indemnification coverage through an agreement. 

First, boards should ensure CISOs are covered by the company directors and officers (D&O) insurance policy. This helps protect CISOs from personal liability in the event of any legal challenges related to their cybersecurity responsibilities.

Second, consistent check-ins should also be put in place. The board director responsible for cybersecurity oversight — whether it’s the chair of the audit or risk committee, the lead director, board chairperson or the designated “cyber champion” — should establish regular monthly or quarterly check-ins with the CISO. These proactive meetings ensure ongoing alignment on cybersecurity strategy and risk management.

Third, setting a strong internal tone around cybersecurity and making it a priority at board meetings signals to the entire organization the critical importance of safeguarding sensitive information and managing cyber risks. When the board emphasizes cybersecurity, they reinforce the message that protecting data and systems is a priority, encouraging a culture of vigilance and proactive risk management across all departments.

Finally, amid rising cyber threats, boards must integrate cybersecurity as a mission-critical function across every layer of the organization, beginning with directors’ capacity to fulfill their oversight responsibilities effectively. Beyond protection policies, the board and senior leadership team also need to enroll in education and certification programs around cyber risk to effectively oversee strategy, respond appropriately, and ask insightful questions. 

Boards and CISOs should also consider developing a materiality framework for cybersecurity incidents. By setting clear, agreed-upon criteria for disclosure, both management and the board can preemptively assess the legitimacy of incidents, ensuring a consistent and informed response when they arise.

Organizations can’t afford to wait

Bridging the gap between cybersecurity and business strategy requires linking cyber risks directly to financial outcomes. A task made easier when CISOs have strong financial literacy and boards have strong cyber knowledge. This connection ensures consistent and informed decision-making about the company’s cybersecurity posture. By presenting a holistic view linking the technical stack to the business ecosystem, CISOs and boards have stronger, more informed boardroom discussions.


Tags: Board of DirectorsBoard Risk OversightCyber Risk
Previous Post

Mastering Data Retention and Legal Hold Management in a Regulatory Maze

Next Post

Definitive Guide to Conflicts of Interest

Monica Landen

Monica Landen

Monica Landen is chief information security officer (CISO) at Diligent, a GRC SaaS company. Prior to joining Diligent, she was senior vice president and CISO at FactSet, a provider of financial data and analytics solutions. She is a Certified Information Systems Security Professional (CISSP) and a Certified Secure Software Lifecycle Professional (CSSLP) through the International Systems Security Certification Consortium.

Related Posts

kroger

Blocked, Sued and CEO-Less: How Kroger’s Board Must Navigate Triple Crisis

by Conor Johnston
June 9, 2025

Failed mergers often trigger talent exodus and shareholder fury, but strategic refocusing on core competencies can turn regulatory setbacks into...

money

CCO Salary Increases Cooling Off

by Staff and Wire Reports
June 6, 2025

35% of executives give boards high marks

matrix numbers cybersecurity concept

Why Scalable Global Frameworks Like ISO 27001 Matter

by Sam Peters
May 29, 2025

Updated security standard addresses modern threats with expanded digital protections

seeing outside the box

Disrupters See the World Differently — and Act Accordingly

by Jim DeLoach
May 13, 2025

Critical differences in culture, technology adoption and talent strategies determine which organizations shape markets and which scramble to respond

Next Post
GAN Integrity Definitive Guide to Conflicts of Interest

Definitive Guide to Conflicts of Interest

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights