Dr. Erdal Ozkaya
Search
  • Home
  • About Me
  • Home
  • About Me
  • Home
  • General, Free Events, Announcemets, Cybersecurity Leadership
  • CISO Executive Summit by Microsoft – 3 Countries

CISO Executive Summit by Microsoft – 3 Countries

Erdal2022-02-02T00:22:00-04:00

CISO Executive Summit by Microsoft

We are happy to announce the 3th edition of the CISO Executive Series – a series for an elite set of TOP Chief Information Security Officers.

Engage in candid conversations with the most influential CISO’s and subject matter experts in a day of insights , networking and learning.

Pinpoint strategies, best practices from GCC organizations , evaluate regional security trends with leading security analysts and leverage the community to drive business success

We look forward ghaving you with us

March 19 ,Burj Al Arab , Dubai UAE

March 20, Radisson Blu , Kuwait City

March 21, Hormuz Grand Hotel , Muscat, Oman

Every attendee will also receive our book which we wrote with Yuri , for free , signed 🙂

For more evets :

Table of Contents

  • For more evets :
  • Use the board’s time effectively
  • Keep the board educated on the state of cybersecurity
  • Speak to the board’s top concerns
  • Learn more

https://www.erdalozkaya.com/category/free-events/

In today’s threat landscape, boards of directors are more interested than ever before in their company’s cybersecurity strategy. If you want to maintain a board’s confidence, you can’t wait until after an attack to start talking to them about how you are securing the enterprise. You need to engage them in your strategy early and often—with the right level of technical detail, packaged in a way that gives the board exactly what they need to know, when they need to know it.

Cyberattacks have increased in frequency and size over the years, making cybersecurity as fundamental to the overall health of the business as financial and operational controls. Today’s boards of directors know this, and they are asking their executive teams to provide more transparency on how their company manages cybersecurity risks. If you are a technology leader responsible for security, achieving your goals often includes building alignment with the board.

Bret Arsenault, corporate vice president and chief information security officer (CISO) for Microsoft, was a recent guest on our CISO Spotlight Series, where he shared several of his learnings on building a relationship with the board of directors. We’ve distilled them down to the following three best practices:

  • Use the board’s time effectively.
  • Keep the board educated on the state of cybersecurity.
  • Speak to the board’s top concerns.

Use the board’s time effectively

Members of your board come from a variety of different backgrounds, and they are responsible for all aspects of risk management for the business, not just security. Some board members may track the latest trends in security, but many won’t. When it’s time to share your security update, you need to cut through all the other distractions and land your message. This means you will want to think almost as much about how you are going to share your information as what you are going to share, keeping in mind the following tips:

  • Be concise.
  • Avoid technical jargon.
  • Provide regular updates.

This doesn’t mean you should dumb down your report or avoid important technical information. It means you need to adequately prepare. It may take several weeks to analyze internal security data, understand key trends, and distill it down to a 10-page report that can be presented in 30 to 60 minutes. Quarterly updates will help you learn what should be included in those 10 pages, and it will give you the opportunity to build on prior reports as the board gets more familiar with your strategy. No matter what, adequate planning can make a big difference in how your report is received.

Keep the board educated on the state of cybersecurity

Stories about security breaches get a lot of attention, and your board may hope you can prevent an attack from ever happening. A key aspect of your role is educating them on the reasons why no company will ever be 100 percent secure. The real differentiation is how effectively a company responds to and recovers from an inevitable incident.

You can also help your board understand the security landscape better with analysis of the latest security incidents and updates on cybersecurity regulations and legislation. Understanding these trends will help you align resources to best protect the company and stay compliant with regional security laws.

Speak to the board’s top concerns

As you develop your content, keep in mind that the best way to get the board’s attention is by aligning your messages to their top concerns. Many boards are focused on the following key questions:

  • How well is the company managing their risk posture?
  • What is the governance structure?
  • How is the company preparing for the future?

To address these questions, Bret sticks to the following talking points:

  • Technical debt—An ongoing analysis of legacy systems and technologies and their security vulnerabilities.
  • Governance—An accounting of how security practices and tools measure up against the security model the company is benchmarked against.
  • Accrued liability—A strategy to future-proof the company to avoid additional debts and deficits.

When it comes to effectively working with the board and other executives across your organization, a CISO should focus on four primary functions: manage risk, oversee technical architecture, implement operational efficiency, and most importantly, enable the business. In the past, CISOs were completely focused on technical architecture. Good CISOs today, and those who want to be successful in the future, understand that they need to balance all four responsibilities.

Learn more

Be sure to check out the interview with Bret in Part 1 of the CISO Spotlight Series, Security is Everyone’s Business, to hear firsthand his recommendations for talking to the board. And in Part 2, Bret walks through how to talk about security attacks and risk management with the board.

The National Institute of Standards and Technology (NIST) Cybersecurity Framework is a great reference if you are searching for a benchmark model.

To read more blogs from the series, visit the CISO series page.

EO CSAD
CISO executive summit Erdal Ozkaya

Comment (1)

  • 6 Facts you need to know about CISO's  | Dr. Erdal Ozkaya - Cybersecurity Blog - InfoSec Today Reply

    […] https://www.erdalozkaya.com/ciso-executive/ […]

    28/07/2021 at 17:09

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Related Posts

Cybersecurity Asia 2022

Cyber Security Asia 2022 – Happy to be back in Kuala Lumpur

Cyber Security Asia 2022 Cyber Security Asia 2022 will be taking place on  15-16 August 2022 at the Sheraton Imperial Hotel Kuala Lumpur– bringing together top experts and... read more
CISO

CISOs End to End Security Operations – ( Part 2) Powerful Tips

CISOs End to End Security Operations This is the second part of the article, you can read the first part from... read more
Hiring

I am hiring Head of Information and Cybersecurity for Pakistan -2020

Head of Information and Cybersecurity for Pakistan  I am hiring the Head of Information & Cybersecurity for Pakistan, who will be... read more

MVP Meetup Dubai 2017- Great Community

MVP Meetup Dubai It was a great community day @ Microsoft Gulf where we come together with our Microsoft Most Valuable... read more
Windows Security Erdal Ozkaya , Hasain , Raymond

Windows Security and Forensics coming soon 4 FREE

Windows Security and Forensics coming soon This week Raymond, Hasain and myself locked our self to the Microsoft Studios in Microsoft... read more
Sosyal MĂĽhendislik AyakĂĽstĂĽ Sohbetler

Sosyal MĂĽhendislik AyakĂĽstĂĽ Sohbetler

Sosyal MĂĽhendislik AyakĂĽstĂĽ Sohbetler This post will be in Turkish about our new "Social Engineering " book :) TĂĽrkiye Siber GĂĽvenlik KĂĽmelenmesi... read more
Rocheston Reinvent Penetration Testing Conference Erdal Ozkaya

Speaking at Rocheston Reinvent Penetration Testing Conference 2021 Free

Penetration Testing Conference I am happy to announce that I am one of the "Keynote Speakers" at the Rochesten Reinvent Penetration... read more
Charles Sturt University

Cybersecurity Symposium 2018 -Free to join

Cybersecurity Symposium 2018 -Free to join I am proud to announce that I will be speaking at Charles Sturt University 's... read more
Inside The Dark Web Dr Ozkaya

Inside the Dark Web , my new book is just released (2019)

Inside the Dark Web Summary Inside the Dark Web provides a broad overview of emerging digital threats and computer crimes, with an emphasis... read more
CyberTech Global Dr Erdal Ozkaya

CyberTech Global UAE 2021 Opportunity to register for free

Cybertech is proud to present the 2021 in-person Cybertech Global event in Dubai. This 8th edition of the renowned international exhibition... read more

Categories

  • About Dr Erdal Ozkaya (298)
    • Awards (96)
    • Erdal in the news (118)
    • Feedback (90)
    • My Books (54)
    • Who is Dr Erdal Ozkaya ? (2)
  • Announcemets (302)
  • Artificial Intelligence AI (11)
  • Certification (52)
  • Cloud Computing (72)
  • Cybersecurity (322)
  • Cybersecurity Leadership (52)
  • Financial Sector (31)
  • Forensics (17)
  • Free Events (156)
  • General (133)
  • How to …? (63)
  • ISO 2700x (12)
  • News (38)
  • Reviews (77)
    • Book Reviews (33)
    • Free E-Books (13)
    • Hardware Review (9)
    • Security Review / Reports (10)
    • Software Review (8)
  • Video Tutorials (101)
  • What is new? (27)
  • Windows (30)

Recent Comments

  • Erdal on Free EDR Certification Training
  • SANDEEP SHRIVASTAV on Free EDR Certification Training
  • Alicia Harlow on Core isolation Memory Integrity not available – (Get it fixed)
  • Alicia Harlow on Core isolation Memory Integrity not available – (Get it fixed)
  • Erdal on Siber GĂĽvenlik Saldiri ve Savunma Stratejileri – NEW B00K

Archives

Dr. Erdal Ozkaya © Copyright 2023. All Rights Reserved.