When it is time to talk to your senior management about information security, what is the most effective way to do so? That question was recently posed on this LinkedIn forum of IT security managers. The answers were thoughtful and varied, and can serve as good examples for your own strategy.

Discussing Security in Business Terms

One of the first comments was very specific and prescriptive: “Put the issues in business terms.” This is a common suggestion, especially when talking to executives.

“Try to shift [management’s] thinking away from it being an IT issue,” said another commenter. That way, you can create a business-based discussion and focus on the overall enterprise risk management objectives.

It’s important to relate to the particular risk appetite that your firm finds acceptable and understand how to mitigate that risk with the proper security investments. There needs to be a match — otherwise, your message won’t have the necessary impact.

Speak the Language of Management

One participant emphasized the importance of knowing your audience and conversing with executives in terms they understand. “Never talk down to them, [or] try to confuse them with buzzwords or lingo,” the security manager advised. IT professionals often get caught up in this jargon and can’t see the forest through the trees.

Another commenter said that IT managers should lead by example and share their experiences dealing with security breaches. They could explain any lessons they learned and discuss strategies to avoid breaches in the future.

It’s also crucial, an IT manager pointed out, to “speak to the social business benefits.” Some professionals place too much emphasis on business profit and loss numbers, and as such they fail to consider the many intangible factors that influence customers to buy their products and services.

Know Your Audience

Finally, IT managers should study their subjects and know their motivations. “Spend a little time upfront trying to find out what keeps your CEO and board of directors awake at night relative to information protection,” one commenter advised. “You might be surprised at the responses.”

These kinds of interviews can help set the appropriate tone for your conversation. I have often attended meetings in which several speakers repeatedly refer to acronyms, only for a participant eventually speak up to ask what it means. That can be embarrassing for everyone.

Listen to the six-part podcast series: A CISO’s Guide to Obtaining Budget

More from CISO

Poor Communication During a Data Breach Can Cost You — Here’s How to Avoid It

5 min read - No one needs to tell you that data breaches are costly. That data has been quantified and the numbers are staggering. In fact, the IBM Security Cost of a Data Breach estimates that the average cost of a data breach in 2022 was $4.35 million, with 83% of organizations experiencing one or more security incidents. But what’s talked about less often (and we think should be talked about more) is how communication — both good and bad — factors into…

5 min read

Ransomware Renaissance 2023: The Definitive Guide to Stay Safer

2 min read - Ransomware is experiencing a renaissance in 2023, with some cybersecurity firms reporting over 400 attacks in the month of March alone. And it shouldn’t be a surprise: the 2023 X-Force Threat Intelligence Index found backdoor deployments — malware providing remote access — as the top attacker action in 2022, and aptly predicted 2022’s backdoor failures would become 2023’s ransomware crisis. Compounding the problem is the industrialization of the cybercrime ecosystem, enabling adversaries to complete more attacks, faster. Over the last…

2 min read

Do You Really Need a CISO?

2 min read - Cybersecurity has never been more challenging or vital. Every organization needs strong leadership on cybersecurity policy, procurement and execution — such as a CISO, or chief information security officer. A CISO is a senior executive in charge of an organization’s information, cyber and technology security. CISOs need a complete understanding of cybersecurity as well as the business, the board, the C-suite and how to speak in the language of senior leadership. It’s a changing role in a changing world. But…

2 min read

What “Beginner” Skills do Security Leaders Need to Refresh?

4 min read - The chief information security officer (CISO) was once a highly technical role primarily focused on security. But now, the role is evolving. Modern security leaders must work across divisions to secure technology and help meet business objectives. To stay relevant, the CISO must have a broad range of skills to maintain adequate security and collaborate with teams of varying technical expertise. Learning is essential to simply keep pace in security. In a CISO Series podcast, Skillsoft CISO Okey Obudulu recently said,…

4 min read