Innovative Solution Helps Critical Infrastructure Organizations Understand Cyber-Physical Damage Risk and Offer Sustainable Coverage for Exposure
Welcome to Part II of Axio’s 2020 Resolution Series. We’re one week closer to some well-needed rest around the holidays and one week closer to the start of the 2020 sprint into a great year! As 2019 winds down, we hope that our Resolution Series can set priorities for the new year.
This week, our focus is on the Chief Security Officer (CSO), the person that the organization recognizes as being the most responsible for cybersecurity. For different organizations, alternative titles might be Chief Information Security Officer (CISO), Chief Technology Officer (CTO), or Chief Information Officer (CIO).
Let’s reflect on your experience as CSO in 2019 with respect to Board of Director meetings, budget discussions, and general organizational collaboration. Did you prepare for Board of Director meetings with updated heatmaps, threat and vulnerability reports, and a short list of things that you’ve implemented since the last Board meeting? How was that received? Was the Board engaged and enthusiastic about progress? Or were eyes glossing over and phones out within 3 minutes?
How were budgetary discussions this fall? When presenting your 2020 plan to the CFO, were you able to clearly convey your investments relative to risk reduced and get enthusiastic buy-in for your plan? Or did you get questioned as to why it seems that every single year, cybersecurity costs increase with no clear benefit?
How was dialogue and collaboration with your peers throughout the year? Did you have a robust partnership with the risk manager, perhaps frequently meeting over lunch and discussing how the fine-tuned insurance program would respond to major cyber losses that could happen to you? Or did you lament the week that you had to pull together a presentation, scrambling to talk to cyber insurance underwriters about your security program, all the while cursing under your breath about how insurance companies know nothing about cybersecurity and can’t be trusted?
If none of the above is true, you can chalk up 2019 to your best year ever from a cybersecurity leadership and recognition standpoint. Kudos to you! Keep it up.
On the other hand, if you are ending the year unfulfilled and despondent, our 2020 goal for you is to achieve more communication prowess and to ultimately be heard, recognized, and relevant.
Translating the technical complexities of cybersecurity to the business is challenging. Heat maps, threat reports, and vulnerability scans obscure the “so what?” Perceived as fearmongering, continually beating that drum about needing to do more is quickly losing favor. It’s time to elevate the conversation.
Where to start and what to do? Here’s the plan. Focus on understanding the financial side of cybersecurity and how to translate what you do to the daily cadence of the business. The easiest way to do that is to conduct a cybersecurity risk quantification exercise, so that you can speak in terms of the lifeblood of the enterprise – money!
Here’s a snapshot of how it works in practice:
All told, utilizing a cyber risk quantification methodology can provide this level of insight, drive more effective decisioning, and finally establish yourself among the C-level execs at the firm. That’s communication prowess for cybersecurity—an achievable 2020 resolution for CSOs.
Innovative Solution Helps Critical Infrastructure Organizations Understand Cyber-Physical Damage Risk and Offer Sustainable Coverage for Exposure
In this next part of the blog series on the connection between cybersecurity and insurance, we will provide a basic overview of how insurance policies are structured...