Communicating Business Risk: Why Existing Cybersecurity Metrics Fall Short
by Robert Huber on September 16, 2020
How do you communicate the business risk context of your cybersecurity program to your organization’s C-level executives? This is a question I grapple with every day in my role as a cybersecurity leader.
Security and risk management leaders have an arsenal of frameworks and controls at our disposal with which we can measure the most granular facets of our programs. While such metrics are invaluable in helping us manage the day-to-day operations of our teams, they fall short when it comes to finding a way to speak to our business leaders.