Business leaders need to rethink how they handle oversight of cybersecurity teams. Are leaders asking the right questions and understanding how cybersecurity programs work?
Overseeing cybersecurity programs, whether at the board or executive level, has always been a challenge. Typical questions executives ask range from the general question, “Are we secure?” to more detailed questions about metrics, such as “How many vulnerabilities did you fix last quarter?” The answers to these questions may not help reveal the true effectiveness of the program. These types of questions often signal a lack of understanding of how cybersecurity teams work and a lack of vision for how cybersecurity can truly help grow the business.

Efforts have been made to help leaders ask the right questions of cybersecurity team leaders to improve their effectiveness. The National Association of Corporate Directors (NACD) has provided some excellent guidance on what questions to ask and what approaches business leaders should take to get the most out of their cybersecurity teams.
Change the mindset of cybersecurity oversight
Chief information security officers (CISOs) need to be held accountable for more than just their responsibilities regarding the risk of cyber threats. When thought through the lens of a traditional SWOT (Strengths, Weaknesses, Opportunities and Threats) model, cybersecurity oversight typically leans toward the weaknesses and threats of the equation. CISOs tend to focus heavily on these areas to address issues that may prevent an organization from achieving its goals. However, by focusing solely on weaknesses and threats, cybersecurity becomes more of a security program than a potential driver of growth.

While it’s not wrong to think about threats and vulnerabilities in terms of oversight and risk management, it often leads to financial conversations that resemble discussions about buying insurance policies. Questions like, “What percentage of the budget should be allocated to cybersecurity ?” are used to make decisions about budgeting, for example. This is similar to pricing insurance coverage for your business or home based on its value. The conversation should actually be much broader, because otherwise it leaves out the strengths and opportunities of the equation.
Shifting the mindset to focus on strengths and opportunities completely changes the meaning of the conversation and the potential outcomes. Of course, cybersecurity and risk management are used to protect the business by addressing weaknesses and threats, but what if there were ways for cybersecurity teams to identify strengths and opportunities? Are there areas of the business that security teams are not currently focusing on? It’s entirely possible that a CISO working across the enterprise will have new ideas that will help the business.
New lines of questioning
In any meeting, the goal is to leave with new information and new guidance for oversight and approval processes. CISOs need to be challenged to think about their work from the perspective of improving the business and its contributions to overall business goals, creating capabilities and opportunities.
The best example of this is when security is “shifted” to changing performance control in the early stages. In a development process, developers are better off fixing problems during creation rather than waiting to test a finished product. The latter approach is particularly annoying for developers who have to interrupt their work to stop and fix problems during the process. Traditional KPIs (key performance indicators) in the development process include metrics such as reducing the number of vulnerabilities or defects, as they will now have been identified in the process. While this is an effective measure of cybersecurity, it does nothing to really highlight the business impact.
The real-world implications of this tactic are that fewer defects mean increased productivity for developers, less reworked code, faster product , and faster time to revenue for new features and products. As an added benefit, a new force could be increased awareness among developers about how to write secure code. This new force could also be measured to show increased productivity over time and subsequently a differentiated product in the marketplace.
Challenge your CISOs to think about how to find ways to grow the business, highlight strengths, and explore opportunities. Questions that can complement more traditional risk oversight questions include:
- What product improvements can we make to differentiate us in the market?
- What is your trend towards reducing supplier delivery times or shortening the sales cycle?
- What percentage of time do teams spend investigating or responding to security-related issues? How does this track over time?
Obviously, the questions will depend on the type of business, but changing the mindset and oversight of CISOs is crucial. With this shift, CISOs are forced to look outside the walls of team , to better understand the business, thereby creating more productive insights.
