Soft Skills Every CISO Needs to Inspire Better Boardroom Relationships

In a recent survey of CISOs, 86% of respondents said the role has changed so much that it's almost become a different job altogether from what it once was.
In addition to their traditional responsibility of defending organizations from an increasingly complex threat landscape, CISOs need to reach across their organization, work closely with the C-suite, and provide high-level business strategy as it relates to risk.
This new connection between cybersecurity and business risk has pushed CISOs into the boardroom, where they are being asked to justify their investments by aligning security strategies to the board's vision for the organization.
To walk this line, CISOs have to develop critical soft skills that allow them to bridge the natural divide that has traditionally existed between operations and security teams.
These so-called soft skills - such as communication, leadership, and emotional intelligence - are now requirements of the job, allowing CISOs to navigate this delicate balance and provide high-level risk assessment and guidance for their organizations.
Collaboration Digital transformation and the emergence of the agile, customer-led business model have destroyed the silos that once permeated organizations.
Teams often operated in seclusion - heads down and focused solely on the task in front of them, with little to no visibility into what other business units were up to.
From a CISO perspective, this means looking at every aspect of the organization - from sales and marketing to the supply chain, all the way up to the board of directors - through the lens of cybersecurity risk.
CISOs now need to understand how to communicate with stakeholders and the boards around an incident.
Working together allows the CISO to break down these silos, ensuring close collaboration toward business goals without adding unnecessary cybersecurity risk.
With the appropriate transparency, any additional measures that are needed to combat a new or emerging risk or regulation should be easier to accept.
CISOs are finding that stakeholders - from regular users to the board - are more technical than ever before.
People understand the impact of working in a hybrid model or moving applications to the cloud and trust the CISO to weigh the risks with the productivity and agility benefits.
This requires educating everyone on threats, compliance, and other risks through the lens of business language and metrics that they can understand.
By educating stakeholders on how implementing a new security strategy, process, or tool can contribute to business goals - such as expanding into an emerging market, improving development velocity, or driving up stock prices - CISOs can better communicate budget needs.
Bridging the gap between technical capabilities and business results puts CISOs in a key advisory and thought leadership position that can lead to greater success.
Storytelling CISOs also have to be good storytellers, using data to craft a narrative around how the business is mitigating growing risk.
CISOs Continue to Evolve Now, more than ever before, CISOs have an opportunity to impact business strategy and change the culture of their organization.
Everyone - from the customer service rep to the chairman of the board - is listening and relying on them for guidance on how growing cybersecurity risks impact everything from their day-to-day to broader business initiatives.
CISOs need to develop new so-called soft skills to meet this challenge - using all their communication, collaboration, teaching, and storytelling skills to mitigate risk, create operational efficiencies, improve resiliency, and drive business growth.


This Cyber News was published on www.darkreading.com. Publication date: Fri, 15 Dec 2023 15:00:11 +0000


Cyber News related to Soft Skills Every CISO Needs to Inspire Better Boardroom Relationships

Soft Skills Every CISO Needs to Inspire Better Boardroom Relationships - In a recent survey of CISOs, 86% of respondents said the role has changed so much that it's almost become a different job altogether from what it once was. In addition to their traditional responsibility of defending organizations from an ...
6 months ago Darkreading.com
CISO Conversations: Nick McKenzie and Chris Evans - In this edition of CISO Conversations, SecurityWeek discusses the role of the CISO with two CISOs from the major crowdsourced hacking organizations: Nick McKenzie at Bugcrowd and Chris Evans at HackerOne. The purpose, as always, is to help aspiring ...
2 months ago Packetstormsecurity.com
The Role of the CISO in Digital Transformation - Modern-day demands require organizations to be flexible and digitally savvy, getting work done remotely and in the public cloud as often as in a centralized physical location, if not more so. As companies continue to modernize their workflows and ...
7 months ago Darkreading.com
Encouraging Ethical Hacking Skills in Students - This article delves into the significance of encouraging ethical hacking skills in students and the numerous benefits it offers to individuals and society as a whole. Possessing ethical hacking skills can provide students with a competitive advantage ...
6 months ago Securityzap.com
Is the vCISO model right for your business? - It's getting harder to justify not having a CISO, so many businesses that have never had a CISO are filling the gap with a virtual CISO. A vCISO, sometimes referred to as a fractional CISO or CISO-as-a-Service, is typically a part-time outsourced ...
5 months ago Darkreading.com
3 Ways to Close the Cybersecurity Skills Gap - Cybersecurity jobs continue to be the most in demand, as the industry cannot keep up with the number of openings, which currently sit at more than 700,000. 66% of professionals in cybersecurity roles report feeling significantly stressed at work, due ...
7 months ago Darkreading.com
Appointments of New Chief Information Security Officers in the United States in January 2023 - Corporate security is undergoing a lot of changes as businesses attempt to keep up with the ever-changing threat landscape. To ensure the safety of both employees and customers, many companies are now hiring a Chief Security Officer or Chief ...
1 year ago Csoonline.com
CISO Conversations: Three Leading CISOs in the Modern Healthcare Sector - All three are CISOs in one of the world's most attacked sectors: healthcare. All three of our CISOs entered cybersecurity via IT. Dougherty had led the creation of an MSP where he became VP operations. This is a recurring theme in this series of CISO ...
6 months ago Securityweek.com
Key cybersecurity skills gap statistics you should be aware of - As the sophistication and frequency of cyber threats continue to escalate, the demand for skilled cybersecurity professionals has never been bigger. The skills gap is not merely a statistical discrepancy; it represents a substantial vulnerability in ...
5 months ago Helpnetsecurity.com
How the Evolving Role of the CISO Impacts Cybersecurity Startups - It helps startups striving to meet the ever-evolving needs of CISOs, who are simultaneously seeking the elusive but paramount buy-in from business users and executives. The CISO role has evolved dramatically in the past few years in response to ...
7 months ago Darkreading.com
Definition from TechTarget - The CISO is a senior-level executive responsible for developing and implementing an information security program, which includes procedures and policies designed to protect enterprise communications, systems and assets from both internal and external ...
6 months ago Techtarget.com
Why CISOs and CIOs Should Work Together More Closely - Although there are overlaps in the goals and responsibilities of the CIO and the CISO, there are also challenges that get in the way of a more cohesive relationship, including reporting lines, organizational structures, budgets, and risk appetites. A ...
6 months ago Feedpress.me
Cybersecurity is a Team Sport - Good security hygiene needs to be a fundamental part of company culture, and leadership should make it clear that proper security practices are part of achieving business objectives. Infusing security and operational resilience throughout the ...
6 months ago Darkreading.com
Microsoft Is Getting a New 'Outsider' CISO - In a Tuesday blog post, Microsoft executive vice president of security Charlie Bell announced that as part of its new strategic focus on security, the company will shift Bret Arsenault out of his longtime role as CISO and into a chief security ...
6 months ago Darkreading.com
Microsoft Is Getting a New 'Outsider' CISO - In a blog post on Dec. 5, Microsoft executive vice president of security Charlie Bell announced that as part of its new strategic focus on security, the company will shift Bret Arsenault out of his longtime role as CISO and into a chief security ...
6 months ago Darkreading.com
The New CISO: Rethinking the Role - Dating back to the 1990s, the role of CISO was more technical and IT-focused. CISOs face more risks than can be resolved, are expected to balance security with operational capability, and must convince leaders to invest in protection. Today, CISOs ...
3 months ago Darkreading.com
AI literacy gap extends beyond technical skills - Even as organizations accelerate AI adoption, the majority don't understand the AI skills their employees possess, if any, or have an upskilling strategy to develop them, according to Pluralsight. Executive AI investments exceed employee proficiency. ...
6 months ago Helpnetsecurity.com
Embracing the Virtual: The Rise and Role of vCISOs in Modern Businesses - In recent years, the task of safeguarding businesses against cyber threats and ensuring compliance with security standards has become increasingly challenging. Unlike larger corporations that typically employ Chief Information Security Officers for ...
5 months ago Cysecurity.news
Navigating the Cybersecurity Skills Gap in Critical Infrastructure - Addressing the cybersecurity skills gap stands out as a paramount challenge in fortifying companies' cyber resilience today. Transforming the educational system to align with the modern requirements of cybersecurity professionals or retraining ...
4 months ago Cybersecurity-insiders.com
Expert Insight: How more diverse perspectives can lead to more innovative solutions - For some time now, there has been a worrying lack of the requisite skills around cloud security, data security, and application security. Part of the reason is that cloud architectures and the ever more distributed systems we are now used to today ...
3 months ago Itsecurityguru.org
Expert Insight: How more diverse perspectives can lead to more innovative solutions - For some time now, there has been a worrying lack of the requisite skills around cloud security, data security, and application security. Part of the reason is that cloud architectures and the ever more distributed systems we are now used to today ...
3 months ago Itsecurityguru.org
Expert Insight: How more diverse perspectives can lead to more innovative solutions - For some time now, there has been a worrying lack of the requisite skills around cloud security, data security, and application security. Part of the reason is that cloud architectures and the ever more distributed systems we are now used to today ...
3 months ago Itsecurityguru.org
Expert Insight: How more diverse perspectives can lead to more innovative solutions - For some time now, there has been a worrying lack of the requisite skills around cloud security, data security, and application security. Part of the reason is that cloud architectures and the ever more distributed systems we are now used to today ...
3 months ago Itsecurityguru.org
Expert Insight: How more diverse perspectives can lead to more innovative solutions - For some time now, there has been a worrying lack of the requisite skills around cloud security, data security, and application security. Part of the reason is that cloud architectures and the ever more distributed systems we are now used to today ...
3 months ago Itsecurityguru.org
Expert Insight: How more diverse perspectives can lead to more innovative solutions - For some time now, there has been a worrying lack of the requisite skills around cloud security, data security, and application security. Part of the reason is that cloud architectures and the ever more distributed systems we are now used to today ...
3 months ago Itsecurityguru.org

Cyber Trends (last 7 days)