How Should You Communicate With Your Senior Management Team?

When it is time to talk to your senior management about information security, what is the most effective way to do so? That question was recently posed on this LinkedIn forum of IT security managers. The answers were thoughtful and varied, and can serve as good examples for your own strategy.

Discussing Security in Business Terms

One of the first comments was very specific and prescriptive: “Put the issues in business terms.” This is a common suggestion, especially when talking to executives.

“Try to shift [management’s] thinking away from it being an IT issue,” said another commenter. That way, you can create a business-based discussion and focus on the overall enterprise risk management objectives.

It’s important to relate to the particular risk appetite that your firm finds acceptable and understand how to mitigate that risk with the proper security investments. There needs to be a match — otherwise, your message won’t have the necessary impact.

Speak the Language of Management

One participant emphasized the importance of knowing your audience and conversing with executives in terms they understand. “Never talk down to them, [or] try to confuse them with buzzwords or lingo,” the security manager advised. IT professionals often get caught up in this jargon and can’t see the forest through the trees.

Another commenter said that IT managers should lead by example and share their experiences dealing with security breaches. They could explain any lessons they learned and discuss strategies to avoid breaches in the future.

It’s also crucial, an IT manager pointed out, to “speak to the social business benefits.” Some professionals place too much emphasis on business profit and loss numbers, and as such they fail to consider the many intangible factors that influence customers to buy their products and services.

Know Your Audience

Finally, IT managers should study their subjects and know their motivations. “Spend a little time upfront trying to find out what keeps your CEO and board of directors awake at night relative to information protection,” one commenter advised. “You might be surprised at the responses.”

These kinds of interviews can help set the appropriate tone for your conversation. I have often attended meetings in which several speakers repeatedly refer to acronyms, only for a participant eventually speak up to ask what it means. That can be embarrassing for everyone.

Listen to the six-part podcast series: A CISO’s Guide to Obtaining Budget

Share this Article:
David Strom

Security Evangelist

David is an award-winning writer, speaker, editor, video blogger, and online communications professional who also advises numerous startup and well-established technology ventures. He began his career as an in-house IT analyst and has founded numerous technology print and online publications, such as editor-in-chief of Network Computing magazine and as part of the launch team of PC Week's Connectivity section. David has written two books and spoken around the world at various conferences and been on national radio and television talking about network technologies. He continues to build websites and publish articles on a wide variety of technology topics geared towards networking, security, channel, PC enthusiasts, OEMs, and consumers. In addition to these activities, he consults to vendors and evaluates emerging technologies, products, strategies, and trends to help position and improve their technology products.