White Paper
A CISO’s Guide to
Communicating Risk
The Business Value of Cybersecurity
An investigation confirms it: your
organization has been breached.
You know that on average, it takes 212 days before a breach
This paper details key angles of risk
is detected1. So you have to wonder: How long have we
been compromised? What will it take to recover? And communication for CISOs:
above all, how badly will it damage our reputation? Ť What executives need to understand
You consider what breach reparation and remediation about the threat landscape
entail. Confirming and containing the breach will be Ť How to educate leaders on the business
expensive, and you’ll need to answer on the cost. Your consequences of breaches
experts could spend hundreds of hours over many months Ť Essential elements of an executive
— maybe years — solving this crisis, diverting their efforts incident response
away from driving the business. Considering that the
Ť Why collaboration is key in a crisis
average data breach costs $18.5 million,2 your organization
will likely face a massive bill. And cleaning up the attack Ť How CISOs can introduce the “assume-
may be the smallest portion of that total. Fines and penalties breach” mindset to their C-suite peers
are more expensive than incident response, and the worst
fallout by far is reputational.3 Losing the trust of your
customers and the public has consequences that reach
further and last longer than the single cybersecurity threat
those companies that haven’t implemented fundamental
that started it all.
cybersecurity defenses and incident response processes,
Thankfully, this is just a hypothetical situation — but it’s the bad luck of encountering a dedicated adversary could
neither a rarity nor a worst-case scenario. ruin their business.
Organizations today are targeted constantly, and the Considering that a breach could occur in January, and you
threats increasingly come from trusted identities and might not find out until November, it’s clear that the only
credentials; of the breaches reported in 2021, 89% were sensible approach to cybersecurity is to assume you’ve
associated with legitimate users or devices4. And for been breached. By running your security operations center
(SOC) proactively, as if a breach has already occurred, you
1 IBM Security, Cost of a Data Breach Report 2021, p. 22
2 Cyber crime and FS: blocking the path of least resistance, Financier Worldwide
put yourself in a much better position to both detect and
3 Ibid. p. 58 protect against attacks.
4 2021 Data Breach Investigations Report, p. 18
[Link] 01
White Paper A CISO’s Guide to Communicating Risk
Embracing a “we’ve been Contending with today’s threat
breached” mentality landscape
One of the major challenges facing CISOs is the view, CISOs know intimately that cybersecurity threats continue
common among their executive peers, that cybersecurity to increase in their severity and sophistication. Since 2018,
is entirely a cost center. Not everyone sees that it enables the percentage of breaches caused by human error has
business or creates value. And even though many leaders hovered around 20% (17% in 2021).5 And given all of the
nominally understand the need for robust security, it often employee training and security awareness investment
takes an actual breach to get their attention — and by then, companies continue to make, this number is noteworthy.
it’s already too late. The C-suite relies on the CISO’s expertise for awareness of
today’s most challenging threats:
One of a CISO’s key roles is to help embed an “assume-
breach” mindset within the C-suite and the board, because Compromised insiders — users with authorized access to
security — or lack thereof — has critical ramifications. If a an organization’s data, whose credentials and assets have
new CFO joins an organization and makes a request, it’s been infected with malware and now serve unknowingly as
almost certain to be adopted; so how can CISOs establish a home base for criminal activity
similar credibility to get the executive leadership team on
Phishing — one of the most common methods for
board with a more proactive approach to risk, threats,
transferring malware onto a victim’s machine, this type of
and opportunities?
attack usually takes the form of fraudulent communications
that appear to be legitimate
Ransomware — the malware encrypts any files and
systems it infects, rendering them unusable — and
exfiltrating the data — until the organization pays the
The worst time to ransom to decrypt them
make an introduction Malicious insiders — employees or contractors with
is in a crisis.” trusted access credentials who set out to disrupt operations
or steal data, often in order to enrich themselves or
Steve Moore, Vice President and Chief intentionally harm their company
Security Strategist, Exabeam
Credential switching — a combination-type attack used
by threat actors wherein they hijack different accounts to
target different hosts, or hopscotch from stolen account to
stolen account in an attempt to infiltrate
Lateral movement — the ability for attackers to move
Moreover, what can be done to show that the CISO isn’t
progressively and incrementally through a network, eluding
just the bearer of bad news, but rather a recognized leader
commodity security controls that are designed to be
who drives business value? Now more than ever, the CISO
context aware
is critical to revenue, operations, employee engagement,
recruitment and retention, and business development — Data exfiltration — this occurs when data is copied,
and it’s time to change the narrative to reflect this new transferred, removed, or retrieved without permission, either
reality. by malware or by a malicious actor who may or may not
have authorized access
The “we’ve been breached” mindset is essential for
anticipating and preempting these threats — as well as the
new types of attack that will emerge in the future.
The workplace and the workforce will continue to evolve
too, changing and expanding the attack surface. We have
already witnessed the shift to distributed work and
5 Verizon, 2021 Data Breach Investigations Report, p. 16
[Link] 02
White Paper A CISO’s Guide to Communicating Risk
the transition to cloud environments. Employees can now Loss of opportunity
sign into their workspaces from anywhere, on any device.
In a breach, 38% of an organization’s financial losses7 are
And companies are facilitating this by moving more of their
lost business opportunities, and they come in a variety
operations — and data — to the cloud. CISOs and SOCs
of forms. Customer turnover can increase. Lost revenue
must be vigilant of every person, device, and cloud; each is
can limit investment potential — or damaged value and
a potential point of attack.6
reputation can drive up the investment it takes to attract and
The business impacts of a breach acquire opportunities.
It’s part of a CISO’s job to be aware of the risks and costs While it may seem negative to raise awareness of
associated with a data breach — but what about the rest these risks, it’s essential to remember that the role and
of the senior leadership team? In some cases, it’s difficult contributions of the CISO are fundamentally positive,
for executives to comprehend both the short-term and proactive, and forward-looking. An assume-breach
long-term ramifications. Given CISOs’ expertise, they have mindset is not about existing in a heightened state of
an opportunity to step in to educate key stakeholders and anxiety or panic; it’s about maintaining focus on business
protect the business. It’s important to ensure that the entire productivity, profitability, and long-term value. And one
C-suite realizes what they could lose in a serious security of the top benefits a CISO brings to the table is a sense of
event. confidence; preparedness is fundamental to peace of mind.
Loss of continuity
A bad breach could hold business-critical data and
systems hostage, disrupt them, or destroy them, making
basic operations impossible. The publicized ransomware The million-dollar question that every
attacks of 2021, and the distributed denial-of-service single board member will ask a CISO at
attack on Microsoft illustrate the complexity and fallout of
some point in their career is ‘how secure
serious attacks.
are we?’ And so how do you actually
Loss of revenue measure that to be able to tell that story?”
Leaders need to be aware of the massive financial impacts
Tyler Farrar, Chief Information Security
that result from a breach. It’s not just the costs of retrieving Officer, Exabeam
data, or investing hours to rectify the situation, or losing
profits as vital systems remain offline. It could include
paying reparations to victims and fines to regulators.
Loss of service Of course, that confidence only comes with buy-in across
There’s an entire ecosystem of internal and external the executive level. Leaders must take action, not only to
stakeholders that depend on the products and services invest in the best possible security systems, processes, and
an organization provides — and that includes employees, response strategy, but also to adopt and implement them
partners, contractors, and customers. A cyberattack across the organization.
will impact all of these groups; executives need to know
what their contractual obligations are and how they’ll be A coordinated executive is an
penalized for failing to meet them. effective defense
Loss of reputation One of the most powerful ways of both mitigating risks
pre-breach and minimizing damage post-breach is to
A breach will impact an organization’s revenue and
implement an executive incident response plan. This means
profitability even when it is contained, operations resume,
that multiple positions and portfolios across the senior
and service is restored. The deficit of public trust that
leadership team need to recognize the indispensable role
results from a breach represents a significant long-term
they play in preventing and managing crises. Moreover,
risk.
they must be accountable to the board, investors, and
customers in meeting these responsibilities.
6 The State of DevOps Report, p. 1
7 IBM Security, Cost of a Data Breach Report 2021, p. 16
[Link] 03
White Paper A CISO’s Guide to Communicating Risk
To establish these expectations and responsibilities, CISOs Security touches every part of the organization, which is
need to proactively connect with executives one-on-one, why emphasizing an ethic of shared responsibility across
demonstrating how to work collaboratively to manage risk. the C-suite helps establish a coordinated executive
approach.
Most importantly, CISOs must accurately report the state
of the organization’s security, but they can also help the
C-suite see how security is a business enabler.
I think that a leader’s
Collaboration starts with the CISO calling real role in a company
their shots and saying, ‘Look, this is who I is to be someone who
am; this is the value I’m going to bring, and
this is what I need from you. This is how I breaks down barriers to
expect to operate. And this is what a execution.”
world-class organization looks like.’”
Tyler Farrar, Chief Information Security
Steve Moore, Vice President and Chief Officer, Exabeam
Security Strategist, Exabeam
CFO
CEO Working with a CFO, a CISO can help uncover cost-saving
Around 68% of business executives don’t allow security opportunities in the short, middle, and long term. CFOs
measures that slow down a company’s progress8. Yet, the face massive budgetary considerations related to digital
CEO’s prioritization of cybersecurity sets the tone for the transformation, and the CISO can contextualize the value
executive team. of immediate infrastructure investments in minimizing
future losses, both through a reduction in the incidence
When they invite the CISO to the table to share of breaches and a more efficient incident response when
cybersecurity expertise, it sets the stage for strategic they do occur. The average cost of data breaches at
collaboration on preventing and containing cyberattacks. organizations with robust incident response planning and
Honesty and transparency are assets in communications testing was $3.25 million in 2021, compared to $5.71 million
with a CEO. They may want reassurance that the business for organizations that lacked these capabilities. That’s a
has been breach-proofed, but they need to hear the truth: difference of $2.46 million, or 54.9% — and those savings
depend on a CISO’s expertise9.
Ť No business system can be optimized without the right
resources; the CISO should articulate what’s absent, and CIO
what might happen without it There can be a sense of conflict between CIOs and CISOs
Ť While the SOC is building, or has built, the best because it’s not always clear where one portfolio ends
possible defense, it’s up to the CISO to contextualize and the other begins. But in truth, these areas of overlap
its importance to other business units — and then the are opportunities for partnership and collaboration.
organization’s leaders must drive adoption Leaders should apply shared expertise toward patching
infrastructure, onboarding cloud apps, and establishing
detailed topologies of the technology stack in the event an
incident does occur.
8 5 Reasons DevOps And Security Need To Work Together, Forbes
9
IBM Security, Cost of a Data Breach Report 2021, p. 25
[Link] 04
White Paper A CISO’s Guide to Communicating Risk
A significant portion of IT involves security, but the CISO is ineffective, accompanied by loss in the form of wasted
needs to frame this function as fundamentally business- hours and low productivity. That means building powerful
first — something that supports operational efficiency defense capabilities will tangibly assist CHROs in their
and customer experience. There’s also an opportunity mission to recruit and retain top talent and build a thriving
for conversations with the CIO about building and culture.
adopting the strongest modern security processes when
In addition, a robust and intelligent security apparatus
implementing cloud infrastructure.
can supply the insights HR teams need to support internal
CRO investigations. Demonstrate how powerful threat mitigation
empowers HR, and the CHRO becomes another executive
Sales and revenue leaders may not always realize it, but
ally.
they have a vested interest in powerful cybersecurity. A
breach has a major impact on the value of a company, CTO/CPO/CIO
with implications for customer retention, lead generation,
Technology leaders prioritize the procurement,
customer privacy, and closing sales.
development, and deployment of new solutions; this means
The CISO needs to help revenue-focused peers see security should be top of mind for these decision makers,
how data security impacts sales activity. What security and they have a proactive role to play in an executive
concerns are sales teams hearing from leads and prospects incident response program.
in the field — and are those concerns affecting the pipeline?
The CISO can help to ensure they consider all angles on
A CRO that understands the overall value of industry-
the security of new solutions by emphasizing the need for
leading cyber defenses becomes a powerful supporter for
DevSecOps: embedding security at every stage of the
future threat prevention initiatives.
development lifecycle, architecture, and Cloud and on-
CMO premises infrastructures.
Along with supporting growth, the CMO is invested in the Through the CISO’s expertise, the CTO/CPO/CIO gains
reputation and value of the brand, making cybersecurity a deeper understanding of the best-in-class systems
threats a major concern in their role. Since breaches have and processes in cybersecurity, and how those will
a tremendous reputational impact, the public relations best position the organization. Investing in security by
apparatus of any organization must be deeply involved in implementing automation, adding 2 factor authentication,
incident response strategy. This is essential to protecting developing or procuring apps, and expanding IT
both the brand and the investments in it, since reputational management can make a massive impact. In 2021,
damage can confound the market and decimate the organizations with intelligent security solutions, powered
return on an organization’s working spend. However, the by AI or machine learning, saw an average cost of $2.90
close relationship between security and PR presents an million for a data breach, compared to $6.71 million for
opportunity for CISOs and their CMO peers to mutually those that hadn’t, representing a difference of 80%.10
benefit by championing security modernization.
General Counsel/Risk Officer
CHRO Privacy and security regulations are complex, and
The decision makers in charge of human resources are compliance is non-negotiable. Costly audits, penalties,
important stakeholders in an executive incident response and litigation can follow from a serious security incident,
strategy. They strive to measure, monitor, and maintain and research has found that compliance failure was the top
positive employee and contractor sentiment, in addition to factor amplifying the total cost of a breach.
providing context on employees when necessary. These
An organization’s head counsel is on the hook to prove
become much more difficult after a data breach.
that appropriate action was taken to protect stakeholders’
An insecure workplace erodes trust, lowers morale, and data before, during, and after the breach. They play a key
diminishes a culture of excellence. And a lackluster culture role in establishing attorney-client privilege for response
communications, as well as when engaging outside help,
and should review internal and external statements.
9 IBM Security, Cost of a Data Breach Report 2021, p. 25
[Link] 05
White Paper A CISO’s Guide to Communicating Risk
By working with these executives, showing them which process that can immediately be launched along with the
security systems are in place, and flagging opportunities right communications and messaging.
to introduce additional measures, CISOs can enlist them as
An assume-breach mindset keeps your organization
advocates for further cybersecurity training, process, and
prepared to mobilize in a practical and methodical way,
investment.
without confusion and panic. As a CISO, you can model
this by practicing self-awareness, servant leadership, and
candor. Be transparent about what’s happening, and be
a willing collaborator. Above all, have empathy for your
colleagues and employees.
It’s that constant engagement and tying
it to their objectives, and how they align The assume-breach mindset is also
to the overall business objectives, that one of action
should be shared amongst every single
If there’s been a security incident, it’s incumbent upon
C-level executive.”
the CISO’s team to find the compromise in your systems.
But first, and hopefully long before a breach takes place,
Steve Moore, Vice President and Chief
Security Strategist, Exabeam you must find the compromise with your executive peers.
That opens the door to collaborate on an effective threat
mitigation strategy. It will reduce costs for the organization,
increase happiness and job satisfaction for employees,
build trust within your partner ecosystem and customer
True leadership in times of crisis community, and differentiate you from the competition.
Eventually, a serious security incident or breach will An assume-breach mindset is essential, considering
happen, which is precisely why the CISO has to build undetected data breaches happen every day, but
connections and relationships across the C-suite. A CISOs need to take it a step further — and act. By raising
coordinated executive strategy not only includes having awareness, proactively planning, and introducing intelligent
explicit responsibilities and expectations for each senior security technologies, they make powerful contributions
role, but an effective, comprehensive, and repeatable to the wider success and long-term resiliency of the entire
organization.
10
IBM Security, Cost of a Data Breach Report 2021, p. 7
Exabeam, the Exabeam logo, Exabeam Fusion, Smart Timelines, Security Operations Platform, and XDR Alliance are service marks,
trademarks or registered marks of Exabeam, Inc. in the United States and other countries. All other brand names, product names, or
trademarks belong to their respective owners. © 2021 Exabeam, Inc. All rights reserved.
About Exabeam Exabeam provides the following benefits:
Industry-leading behavioral analytics and automation to
As the leading Next-gen SIEM and XDR, the Exabeam detect and respond to threats overlooked by other tools
Fusion SOC Platform is a modern, modular, and cloud-
delivered solution for SIEM and XDR. Exabeam delivers Ť 51% reduction in the time it takes to detect, triage,
advanced security analytics, automated threat detection investigate, and respond to threats
and incident response (TDIR) with a use case-based Ť 83% of analysts report triaging twice as many alerts than
approach focused on delivering outcomes. with their legacy SIEM
For more information, visit [Link]. Ť 92% of customers report value in week one
Ť Advanced SOC capabilities with threat-centric, use-
case packages
Want to learn more about Exabeam? Get a demo today.
[Link] 06
Exabeam-Guide-A-CISOs-Guide | 02/09/22