Skip to content

Atelier

Cyber Storytelling: Communicating Risk to the Board and Beyond

Engage with Commvault’s Cyber Resilience Council and gain key insights into effective techniques for briefing the board of directors. Learn what questions to anticipate and how to translate deeplytechnical issues into business and operational terms.

Video thumbnail

Points clés à retenir

  • Business Language Matters 
    Cyber risk must be framed in business impact terms – not technical jargon – for boards to understand urgency. 
  • Boards Think in Risk 
    Directors respond best to discussions tied to financial loss, brand damage, and operational disruption. 
  • Clarity Over Complexity 
    CISOs should focus on likelihood, consequences, and mitigation using plain, accessible language. 
  • Real Incidents Resonate 
    High-profile ransomware cases boards visualize the cost of downtime and disruption. 
  • Cyber Is Enterprise-Wide 
    Cybersecurity is not an IT silo – it is a shared business risk. 
  • Tie Risk to P&L 
    Mapping cyber incidents to profit & loss areas  enable better governance and resource decisions. 

entreprises clientes font état d’une réduction des risques, d’une baisse des coûts et d’une amélioration de l’efficacité opérationnelle.

Communicating cyber risk to the board requires shifting from technical explanations to high-level business conversations. Instead of focusing on IT jargon, CISOs must translate cyber threats into tangible business outcomes – such as revenue loss, brand damage, regulatory exposure, and operational disruption – so board members understand the enterprise-wide impact.  

From Technical to Strategic 
Effective board communication requires shifting from technical explanations to business narratives. CISOs must explain cyber threats in terms of revenue loss, brand damage, regulatory exposure, and operational downtime. 

How Boards Evaluate Risk 
Board members are skilled at managing enterprise risk but often lack deep technical context. Clear explanations of attackers, targets, likelihood, and business impact them engage meaningfully. 

Highlighting Consequences and Blind Spots 
Strong cyber storytelling surfaces where risks exist, how they could materialize, and what mitigations are in place – reinforcing cybersecurity as a governance issue. 

Learning from Ransomware Events 
Real-world ransomware incidents provide relatable context, demonstrating how cyber events disrupt operations and financial performance. 

Aligning Cyber with Strategy 
Framing cybersecurity through operational and financial lenses empower boards to oversee risk and align cyber investments with business priorities. 

Solution

Activité continue

Automated cyber and disaster recovery to minimize disruption across all workloads.

En savoir plusabout Activité continue
Solution

Simplicité d’utilisation

Unified management and AI-enabled automation to reduce complexity and manual effort. 

En savoir plusabout Simplicité d’utilisation
Solution

Optimisation des coûts

Asset discovery and TCO analysis to help improve cost control across hybrid environments. 

En savoir plusabout Optimisation des coûts

Questions fréquemment posées:

Why should CISOs communicate cyber risk in business terms?

Boards evaluate risk through financial and operational lenses. Business-focused language clarifies consequences and supports informed decisions. 

What cyber information matters most to board members?

Who the attackers are, what they target, how likely incidents are, and the potential impact on P&L, brand, and operations. 

How can CISOs make cyber risks more relatable to the board?

By using real ransomware examples, quantifying downtime costs, and mapping risk to specific business units. 

Why is cybersecurity an enterprise-wide issue?

Cyber incidents affect supply chains, customers, compliance, and revenue – making shared responsibility essential. 

What should CISOs include when discussing mitigation?

Current controls, recovery plans, gaps, and readiness – explained in business language to build confidence. 

Transcription

Voir la Transcription

Veuillez visionner la vidéoicipour obtenir une transcription horodatée


Bonjour, bienvenue dans le podcast « Shift ».

I’m Melissa Hathaway and I’m joined ici by my friends, John Zangardi and Shawn Henry.

And we’re ici to talk about how do you communicate risks to the boardroom?

And we’re gonna talk about some very interesting cyber sticky stories.

Thank you so much for being ici and I’m looking forward to this conversation.

Que veulent entendre les conseils d’administration lors de leurs réunions ?

Qu’attendent-ils du RSSI et que souhaitent-ils savoir concernant les risques numériques ?

Vous savez, chaque fois que je pense à m’adresser au conseil d’administration,

je commence toujours par aborder les risques à un niveau global.

I think the board many times hears that tici’s a lot of issues.

Ils en parlent avec des amis au dîner.

They hear from other boards that they’re on that this is an issue, but they don’t
necessarily have the granular understanding and they don’t need the technical

.

I think they just need to understand who are the actors, what is it that they’re
exploitent et, surtout, quel en est l’impact.

Et s’ils parviennent à cerner tout cela,

alors ils pourront commencer à comprendre comment l’entreprise se prépare mieux, comment le RSSI
protège réellement l’entreprise pour atténuer les risques.

Board members know what risk is, whether they’re in the financial services sector or
they’ve been dealing with risk their entire lives, they’re professionals.

And if you give it to them in that term, it’s a great way to store it to level set and
provide a framework for which tici can be much deeper conversations about how the

company’s getting better to secure the enterprise.

Je siège donc à plusieurs conseils d’administration et je pense que tout ce dont Shawn vient de parler est
tout à fait logique.

So the person who’s receiving it, what I really like is part of the audit and risk
, le RSSI intervienne lors de cette réunion et présente les éléments dont

Shawn’s talking about for the board to hear as part of that audit and risk committee
d’audit et des risques.

It’s really important that he covers the risks.

Il aborde les questions suivantes : quelle est la probabilité que cela se produise ?

bad thing happening and what’s the consequence, N’est-ce pas ?

En termes commerciaux simples, cela affecte-t-il notre marque, notre réputation ? Il doit également
expliquer à l’ensemble du conseil d’administration comment il pourrait gérer ces situations.

So generating an awareness for the board of the risks he’s dealing with in a language that
they understand because you can’t expect every board member to be an expert in IT.

N’est-ce pas ?

So tici are some blind spots and I think it’s the role of the CISO to start illuminating
en lumière.

Je siège à plusieurs conseils d’administration et j’interviens régulièrement devant de nombreux conseils.

Je considère toujours qu’il ne s’agit pas d’un problème informatique.

It’s an enterprise risk issue.

Et nous devons garder à l’esprit que toutes les entreprises sont des entreprises numériques.

Et comment allons-nous, quel est l’état de santé de l’entreprise aujourd’hui ?

Et en réfléchissant à ces termes clés du monde des affaires :

How do you actually communicate what’s at risk from a PNL perspective?

Et je pense que bon nombre de nos professionnels dans ce domaine considèrent cela comme un
technology issue and they’re not actually translating if this particular business critical

system goes down and it’s in this particular PNL, that’s going to cost us this amount of
d’argent par jour, sans vraiment traduire cela en termes métier.

Avez-vous constaté des réussites dans ce domaine, Shawn ?

I think that it’s become much easier in recent years.

Les ransomwares ont rendu cela

accessible à tout le monde.

On peut voir quand un rançongiciel frappe une entreprise en particulier, que celle-ci est à l’arrêt pendant
two days or two weeks or two months and what the cost of that is and that’s often

rendus publics.

We’ve seen some recent examples with Jaguar in the UK, domestically in the US, many, many
nombreuses autres entreprises qui ont été touchées de cette manière.

I think the CISO’s role is to enable the business.

On y parvient avant tout en la sécurisant,

but you’ve also got to ensure that you’re not restricting or constricting functions.

I think that when that risk that we’re describing ici is effectively communicated, then
qui font partie intégrante des opérations, en ont une bien meilleure

understanding and appreciation and they’re willing to make adjustments if they recognize
conscience des répercussions à long terme.

Sa quantification devient donc plus facile, car les données sont beaucoup plus répandues de nos jours.

Alors Shawn, laisse-moi ajouter quelque chose à cela.

Trust, it’s something that is hard to get, easy to lose, N’est-ce pas ?

Et dès qu’un incident survient, quand ce « ciseau » apparaît et commence à évoquer
about the bad thing and the risk, that’s too late.

Tici isn’t trust.

Trust is built up through interaction, N’est-ce pas ?

Wici he comes in, the board’s familiar with him, they know his or her approach, they’re
used to dealing with that person, they’ve seen the behavior that results from that.

Ainsi, quand ce problème survient – ce qui arrivera à tout le monde, car l’informatique
is ubiquitous, it is in every company everywici these days, you want to make sure that

tici’s an element of trust between the person talking to the board about risk and the
conseil lui-même.

Et dans tout cela, c’est le PDG qui est en dernier ressort responsable.

So even though I’m talking about this is something the CISO should do, the CEO is
la responsabilité en dernier ressort.

So, but it’s not just the CEO or the CISO or the CIO or the Chief Data Officer.

It’s a broad accountability.

So how do you get to that fluency that this is all about the business and it’s you’re
bringing in the Chief Privacy Officer you’re bringing in the IT organization, you’re

faites intervenir l’équipe chargée de la transformation numérique.

Le PDG peut alors traduire ces enjeux au conseil d’administration, et cela devient vraiment une question de responsabilité collective
plutôt que de responsabilité individuelle.

Je pense donc que

when you talk about accountability, tici has to be a human who owns accountability.

In this case, maybe it’s the CISO who owns it.

Mais cette responsabilité doit être représentée.

Et tous les membres de l’organisation doivent reconnaître et comprendre qu’il s’agit d’un travail d’équipe
et que chacun y joue un rôle.

Everybody’s accountable and a significant breach or a significant incident is going to
des répercussions sur l’ensemble des membres de cette organisation.

So tici certainly is shared responsibility and liability.

Mais le RSSI, je pense qu’il faut une personne qui en assume la responsabilité,

who helps to provide the strategic direction, who’s responsible for ensuring that actions
soient prises et que cette stratégie soit mise en œuvre avec succès.

Mais il ne fait aucun doute qu’il s’agit d’une réponse de l’ensemble de l’entreprise, qui ne concerne pas seulement les dirigeants, mais chaque
single person in the organization, because they’re all users.

They’re all touching the keyboards, they’re all handling data, they’re all responsible for
l’alimentation des bases de données.

Chacun doit reconnaître et comprendre que :

que dans mon organisation, la sécurité passe avant tout.

We’re leaning in and everybody recognizes that a breach is going to have a catastrophic
sur l’ensemble du groupe.

So that’s well said.

Tici needs to be a single point of accountability.

The person who’s responsible that you go to, who’s coordinating the exercise.

But a lot of boards will have an executive session wici company members and the CEO will
pas présents.

And tici’ll be a discussion tici.

And sometimes wici

les conseils d’administration manquent d’expertise, c’est dans le domaine de la cybersécurité, dans le domaine informatique.

And I think it’s important that boards also have that expertise on the board.

And I say this sarcastically and don’t take it as bad, going to an NACD course on cyber
ne fait pas d’un membre du conseil d’administration un expert dans ce domaine particulier.

I think it’s really helpful for a board to have someone tici that when something happens,

and they’re in executive session, that tici’s someone on the board who is in the company
wici tici may be a little breakage of trust who can do that translation and bring it to

the board in a way that’s more understandable or help them frame the questions they’re
posent.

Oui, donc si je devais résumer cela, il faut désigner un membre du conseil d’administration pour vous
aider, et peut-être aussi, en collaboration avec le PDG, pour jouer le rôle de traducteur au sein de la réunion et réaffirmer

wici they all have a fiduciary responsibility on protecting the company.

And that’s the key word fiduciary responsibility.

Alors, franchement, pourquoi ne pas avoir un ancien RSSI, un ancien DSI ou quelqu’un de ce genre
au sein de votre conseil d’administration pour vous aider à réfléchir à ces questions lors des séances à huis clos ?

Tout à fait d’accord.

D’accord.

Donc, quand on commence à réfléchir à tout ça, j’essaie toujours, quand je veux cerner la
what’s going on, it’s the it’s the what’s happening.

On know, we’ve got

on a été victimes d’une demande de rançon.

The so what, we’re completely offline and it’s costing us a lot of money per hour per day
.

And as you said, Shawn, tici’s a number of examples wici we’re watching companies who
have been offline now for almost three months and can’t support, they’re not paying their

suppliers, they’re not paying, they’re not selling their product, et cetera.

And then it’s the now what, now what do we have to do about, how do we get in this
sortir ? »

Pourriez-vous donc commencer par nous parler de certains indicateurs

that you’re finding useful of communicating that.

For me, it’s sort of the legacy, legacy, hardware and hardware and and software that’s
ne sont plus pris en charge et qui sont 100 % vulnérables 100 % du temps.

Mais quels sont les indicateurs que vous trouvez utiles, Shawn ?

Je pense donc que um when you’re providing metrics, the purpose of the CISO providing
metrics is just, I believe, to show the board that tici’s progress being made in the

sécurité globale de l’organisation.

Ainsi, si le mois dernier

mois, nous avions X vulnérabilités non corrigées,

We’ve narrowed that gap this month and we’re demonstrating why it’s happening.

And if it’s not happening then tici needs to be questions asked.

Les indicateurs doivent donc être mesurables et utiles pour démontrer
that tici’s growth in the program.

Je pense à des éléments tels que la capacité de l’entreprise à détecter les attaques.

C’est vrai.

On have to have visibility into what’s happening.

So ici’s what we’re able to detect.

La rapidité de réaction.

Quel est le délai nécessaire pour réagir, remédier au problème ou en atténuer les effets après la détection ?

Réussissons-nous à réduire ce délai ?

We’ve learned through AI and a bunch of other attack vectors that the inability to quickly
ce délai entraîne une violation de sécurité.

Cela arrive régulièrement.

We’ve seen adversaries that have been on networks for months or years undetected.

Voici quelques-uns de ces indicateurs.

Cette question de vulnérabilité est cruciale.

I really appreciate when you said, something that’s a legacy, it’s not supported anymore,
sans correctifs, 100 % vulnérable, 100 % du temps.

Est-ce que cela nous convient ?

Car si c’est le cas,

That’s gross negligence if tici is a breach.

Vous saviez qu’il était vulnérable et vous avez choisi de ne rien faire pour y remédier ; il a été exploité
et cela a entraîné ces conséquences.

That’s not good.

So I want the board to be comfortable that tici’s progress being made.

To John’s point, if you’ve got people that are pure business people, don’t have any
experience from a security perspective, they’re really relying on the trust of the CISO.

That in and of itself, I don’t think is appropriate.

Il faudrait disposer d’une personne dotée d’une certaine expertise, capable de faire valoir son point de vue de manière constructive et
professionnelle.

But you’ve got to you’ve got to demonstrate we’re growing and we’re more secure.

So I’d like to add everything we is fantastic.

Je voudrais ajouter une chose à cela.

Et je pense que cela touche en quelque sorte à la formation.

Et vous m’avez entendu parler de l’aviation bien trop souvent.

Mais dans l’aviation, quand on part en mission et qu’on a un mauvais vol ou un incident, on procède à une analyse immédiate (« hot wash »).

On

revenez en arrière et examinez la cause profonde de ce qui s’est passé.

Et ça peut être une raison technique, ou d’autres raisons.

But I think it’s important that when that bad thing happens that the board be brought in
et qu’on lui explique ce qui s’est passé.

Voici pourquoi cela s’est produit.

Voici comment nous nous en sommes sortis.

Voici les conséquences que nous avons subies : perte de chiffre d’affaires, atteinte à
notre réputation, ou quoi que ce soit d’autre.

Et la raison, c’est que,

nous le savons tous, c’est qu’on apprend davantage de ses erreurs que de ses succès.

So I’m not making light of it, but I think that’s an important addition as part of
la formation et la sensibilisation de votre conseil d’administration.

J’aime donc toujours utiliser des exemples et des études de cas réels, et l’histoire qui m’a le plus marqué ces
dernières semaines, c’est le braquage du Louvre.

So we lose, you know, $10 million in jewelry or maybe it was even more than that, N’est-ce pas ?

Et donc, le Louvre

utilisait du matériel et des logiciels non pris en charge dans l’ensemble du musée, et il en était conscient.

Et les mots de passe étaient « Louvre » puis « Thales », qui était l’entreprise censée
assurer la sécurité du site.

Donc 100 % vulnérable, 100 % du temps, avec un mot de passe facile à deviner, et boum, les bijoux ont disparu
.

Avez-vous d’autres anecdotes marquantes de ce genre que vous pourriez
citer en exemple ?

On can

les rendre anonymes, en disant par exemple : « C’était une mauvaise journée, c’était grave et embarrassant. »

Le mot de passe, c’était « Louvre » ?

It was I’m writing this up this week.

I didn’t know that.

It’s going to be in my newsletter this week.

I don’t think I have anything quite that embarrassing.

I’m sorry.

But, you know, I’ll come back to what I was talking about earlier.

On know, what do you learn from things?

And I’ve had the privilege of watching a lot of cyber incidents over my career while in
gouvernement.

Et, vous savez,

While you’re in DOD and something bad happens if you’re selling to them, Cyber Command is
s’immiscer fortement dans votre vie.

The way you should handle it, because it’s important that you handle it, is a matter of
transparence et à dire : « Voilà les erreurs que j’ai commises. »

I’d hate to be able to say to CyberComm, well, our password was the Louvre, but you need
to be able to go in tici.

The consequences are very high when you’re selling to the government that

le Cyber Command émettra un ordre de mission.

That’s basically a rip and replace and all the components, the services will begin
supprimés.

So it’s very important to be open kimono when you’re dealing with those sorts of people.

Et je pense que cela s’applique également aux clients.

If you go back and you look at SolarWinds, which everybody knows it’s entered our
vocabulaire courant, et que l’on examine la manière dont elle a été gérée et comment les choses se sont déroulées,

tici’s a lot of

things in tici that went wrong and I’m not going to get into that but if you were to look
at the company’s revenue from the day that happened until now they’re still alive they’re

une entreprise qui fonctionne : son chiffre d’affaires a augmenté car elle a pris les mesures nécessaires – aussi difficiles
soient-elles et malgré les nombreux faux pas commis – pour s’améliorer, et le produit se vend même si « SolarWinds »

soit généralement perçue comme une notion peu flatteuse.

Let’s pull that thread just for a moment on product security because a lot of the products

companies don’t necessarily think of themselves as security companies.

Elles n’ont donc peut-être pas investi dans la sécurité dudit produit.

And so we’re seeing this one to many of, I’m going to go after a product, compromise the
, puis j’atteins de nombreux autres clients qui comptaient vraiment

depending upon them to do the right thing of invest in security, ensure that it’s a
produit de qualité, veiller à ce qu’il bénéficie de mises à jour, etc.

Alors, comment raconter l’histoire d’

quand un produit a perdu son intégrité et que l’on sait ce que l’on attend de l’entreprise, comment présenter cette situation au conseil d’administration alors
how do you tell that story to the board I don’t have the power of them of the purse.

Je pense donc que you mentioned solar winds and NotPetya shows another one.

Tici have been more recent ones wici the product has been breached.

Je pense que c’est l’un des risques et que le RSSI doit en exposer clairement les implications au conseil d’administration.

Je pense que cela soulève également

un aspect intéressant concernant la continuité des opérations.

And it’s not just wici are we vulnerable?

Because we’re all vulnerable somewici.

Wici are we vulnerable?

Qui nous prend pour cible ?

Pourquoi nous prend-il pour cible ?

Quelles en sont les conséquences ?

Si l’une de ces situations se produit, ou si elles se produisent toutes, comment s’en remettre ?

À quoi ressemble notre résilience ?

And what is our plan to ensure that we’re able to rebuild the enterprise, regain trust?

À quoi cela ressemble-t-il ?

Et cela doit constituer un élément essentiel des communications du RSSI au conseil d’administration.

Toute entreprise est susceptible d’être confrontée à un incident.

Il peut s’agir de quelque chose d’aussi simple qu’un ordinateur portable égaré.

It might be something like we saw with Jaguar wici the entire enterprise is down for
months at a time and they’re losing hundreds of millions or billions of dollars.

What does the company’s response look like?

Who’s responsible?

Comment communiquez-vous à ce sujet ?

D’un point de vue technique, comment faites-vous appel à

des organisations externes et des partenaires pour vous aider à y parvenir ?

It’s another important piece to give the board some level of comfort that we as a company
dispose du meilleur plan possible.

La première chose que nous voulons faire, c’est nous assurer que tout est sécurisé.

When tici is a problem, we need to make sure we have a plan in place to rectify it.

That’s kind of the 360 security because you can’t have resiliency without security, you
can’t have security without resiliency.

Bien dit.

Et je pense que la résilience est un

piece ici that we should talk a little bit about.

I’ve written many articles about software monoculture and creating a dependency on one
fournisseur de logiciels.

Names aren’t going to be mentioned.

If you’re thoughtful, you want to make sure that you’ve created some sort of redundancy to
garantir votre résilience.

So these matters are pretty complicated in terms of how they’re laid out.

I wouldn’t expect many boards to be able to walk through these issues, but I think it’s
important qu’un RSSI fasse preuve d’une transparence suffisante,

CIO to be transparent enough to explain the precautions they’ve taken, how they’ve laid
out the infrastructure to ensure that they’ve thought about different contingencies that

pourraient se produire.

And they’re not too reliant on one source for their software.

Oui, la continuité d’activité, la reprise après sinistre… J’aime les appeler « catastrophes numériques ».

Et le défi réside dans le fait que, même si j’étais chargé de la sécurité, c’est quelqu’un
d’autre qui est responsable de la restauration et de la remise en service de l’ensemble du système.

Cela met donc en évidence la question suivante : comment dois-je me préparer, ou comment dois-je élaborer ces scénarios et organiser
des exercices sur table impliquant le conseil d’administration ?

I know, Shawn you’ve run multiple exercises.

Yeah, I think we’ve done exercises with kind of the line people, CISO and the CISO’s team,
mais aussi plus largement avec l’ensemble de la direction, et enfin avec le conseil d’administration.

I think these things, it’s most important is awareness and getting them to understand.

And then from a practical level, trying to determine who’s responsible for what.

I can tell you I’ve been in these exercises.

I’ve led some of them.

L’un de ceux qui m’ont le plus marqué et qui a eu le plus d’impact pour moi – et cela remonte à assez longtemps,
probablement huit ou dix ans –, c’est lorsque je me suis entretenu avec une grande institution financière et que le

COO of that organization was in the room and tici were

20 ou 30 personnes dans la salle : le RSSI ainsi que de nombreux techniciens, le DSI et le directeur technique.

Lorsque nous avons présenté le scénario d’attaque fictif et les événements qui avaient en réalité affecté la
plateforme de trading de cette institution financière, je me souviens que le directeur des opérations a regardé au bout de

table en direction du RSSI : « Est-ce que cela pourrait vraiment arriver ? »

En désignant la présentation PowerPoint, il a demandé : « Est-ce que cela pourrait vraiment arriver ? »

Et le RSSI a acquiescé.

Il était sous le choc.

Puis nous avons examiné

Bon, alors, à quoi ressemble la réponse ?

well, oh, Mary’s responsible for that.

Mary’s actually on vacation this week.

Who’s her backup?

That’s Dave.

Dave doesn’t work at the company anymore.

J’ai trouvé ça incroyable, mais c’est le genre de choses qui ressortent quand on fait ce
exercises, and especially for a board to go through an exercise wici they can actually

see all of the cascading implications and how tici are so many moving parts.

Et cela les aide vraiment à comprendre, à apporter leur soutien

et de fournir des ressources, ainsi que de prendre conscience de l’importance de tout cela, je pense, et c’est ce que cela apporte.

We talked earlier about it’s a whole team sport.

Well, the board’s part of the team because at the end of the day they have the same
objectif que tous les membres de l’entreprise : ils veulent que l’entreprise réussisse et réponde aux attentes de ses

clients.

Je pense donc que ces exercices sont importants et qu’ils apportent une grande valeur ajoutée à l’ensemble du processus
we’re talking about.

So I agree and we’ve all heard of the learning curve.

La première fois qu’un événement se produit ne devrait pas être la véritable

thing, N’est-ce pas ?

Because of everything you’re saying, wici’s Dave?

Il a démissionné.

Wici’s Mary?

It’s her day off.

Au fur et à mesure que vous menez un exercice de simulation et que vous passez ces éléments en revue, les gens se familiarisent avec les différents
familiar with the moving parts and how they’re supposed to deal with that.

Et les imprévus donnent lieu à des questions intéressantes.

That’s why people practice things to learn from it and become more proficient.

On want to be somewhat proficient before

qu’un incident survienne.

Je recommande donc vivement de ne pas se contenter d’un seul exercice, mais d’organiser des exercices réguliers qui, en quelque sorte, permettent
know, lift everyone’s boat to the same level.

Développer cette mémoire musculaire est vraiment important, etc.

I think that that is essential, but it’s also starting to get that when you have a bad
day, it’s not just the people who are going to restore the systems, the people who need to

sécuriser les systèmes.

Tici has to be an entire communication strategy.

And thought through of who’s gonna be the spokesperson, how is my press or media team
operating, wici’s my legal, internal counsel, outside counsel, how do I start to think

à cette gestion de crise, si l’on peut dire, Shawn.

Oui, tout à fait, et un exercice sur table est un excellent moyen d’y parvenir.

Identifiez les personnes concernées bien à l’avance.

On don’t wanna start thumbing through numbers and figuring people out while you’re
est déjà débordé par la situation.

On want to be prepared well in advance.

This is an area also wici you start talking about governance and compliance and
regulations, N’est-ce pas ?

Dans le cadre du processus de communication, vous devez avant tout dialoguer avec
vos clients, bien sûr.

On want to talk to all your partners.

On want to talk to your employees.

And in many cases, you’re going to have to talk to regulators and that then you’re to have
to bring your general counsel in to participate in that because tici’s some significant

potential liability issues tici.

Tout cela peut être anticipé.

It’s not going to be 100%.

It’s not going to be perfect.

Mais cela vous permettra d’acquérir une familiarité suffisante et un certain niveau de confiance.

It’s going to establish the relationships with these outside folks so that when something
bad happens, and it will happen, depends on what degree it happens, you’ll be able to

réagir.

Je peux vous dire que ceux qui sont le mieux préparés parviennent à surmonter ces situations avec succès.

Et ceux qui sont mal préparés vont échouer lamentablement.

Well, and it’s visible if you haven’t practiced it and you’re the CEO who what I would
attends dans de nombreux cas, devra s’adresser à ses principaux clients pour leur exposer la situation.

This needs to be done thoughtfully and as if you’re a professional.

Donc, se contenter de répondre sans s’être préparé vous met dans une situation délicate.

And I think it’s very apparent from how that’s portrayed.

It will also do damage to the company’s reputation and brand.

Donc, donner l’impression d’être préparé,

with some degree of polish and that you’re in charge, I think, is something that you need
transmettre ici.

And you don’t get tici without everything that Shawn just talked about.

Oui, j’ai animé un atelier pour un établissement de santé : il ne durait que deux heures et était
divisé en blocs de 30 minutes.

À la fin,

the CEO was like, my adrenaline was up, my heart rate’s at 140, and thank God this is only
exercice. »

Tout simplement parce que, si vous l’organisez correctement, le niveau de stress est le même que si c’était
vraiment un jour réel, et un mauvais jour.

Eh bien, nous avons tous les trois travaillé au sein du gouvernement, et nous avons tous les trois dû aller voir notre
supérieur, qui était probablement un haut responsable politique, pour lui annoncer de mauvaises nouvelles.

It’s not easy.

It just isn’t.

Mais il faut arracher le pansement d’un coup sec.

On got to do it.

Yeah, so in the government, we would say it’s a bottom line up front.

Commencez par l’essentiel : commencez tous vos messages au conseil d’administration par l’essentiel.

I’m ici to tell you about A, B, and C.

And today, I’m gonna tell you how sick our organization is, because we have this many
de systèmes hérités qui gèrent notre cœur de métier.

Et voici ce que nous devons faire pour y remédier.

And this is wici I need your support.

And never leave, especially when you’re briefing Congress, never leave without your ask.

On have to have the bottom line up front and then what you want from them.

Je veux votre soutien.

J’ai besoin d’argent.

Nous avons besoin de plus de personnel.

On’re 100 percent right.

But this is wici the trust comes in.

If the board trusts the CSO because, she’s been up front with them previously, they’ve
déjà traversé un incident ensemble.

She’s got, you know, command of the room, if you will, tici is going to be that sense of
responsiveness and they’re going to be much more willing to provide the ask

without a lot of questions, not that they shouldn’t ask questions, but when tici’s a
level of trust, the program’s been built such that it just makes free flow of information

beaucoup, beaucoup plus facilement.

Nos régulateurs nous ont donc essentiellement dit que nous devions disposer de stratégies, de politiques,
d’un système de responsabilité et d’un financement adéquat pour la cybersécurité et la résilience numérique de notre entreprise.

And the board is supposed to have a regular cadence of meetings and show that they’re um
de sa responsabilité fiduciaire.

17 % of the organizations say that they’re not ready for a bad day.

And a lot of boards are still only doing this once a year, or they’ve delegated it to a
comité sans y associer l’ensemble du conseil.

Quel est votre point de vue à ce sujet ?

Je suis d’accord pour dire qu’il s’agit là de l’un des risques les plus importants, voire du risque le plus
important, pour toute organisation, car l’ensemble de son activité repose sur

environnement numérique.

So ticifore, as part of ERM, it’s got to be something that’s

accorder une grande attention.

Chaque conseil d’administration est un peu différent, chaque entreprise est un peu différente ; le niveau de
familiarité et d’expertise varie d’un cas à l’autre.

So tici’s not really one size fits all, but I would air on the side of more is better
vaut trop que pas assez » compte tenu de l’importance de cette question.

I don’t have an issue with a particular committee, the audit committee, as an example
le comité d’audit, soit l’entité responsable et que le président de ce comité

being almost matrix to the CISO wici the CISO has a direct line to pick up the phone and
go over and talk to the audit committee chair if tici’s a problem.

Mais je pense sincèrement que l’ensemble du conseil d’administration doit avoir une bonne appréciation et une bonne compréhension
de la situation, ce qui nécessite des communications plus fréquentes.

So I’m like you, I’m not wedded to the audit committee, but I do think that’s a logical
.

Et cela dépend vraiment de la manière dont l’entreprise souhaite gérer cette question.

So tici’s no formula per se, but.

I guess tici is a formula in that it should be connected to somehow in the board.

Mais nous devons vraiment comprendre que le monde ne devient pas moins risqué en matière de cybersécurité.

It’s really getting more risky.

And we can go into all the reasons why, but they should be apparent because they’re in the
presque tous les jours.

So you can’t put your head in.

On can’t bury your head in the sand like an ostrich.

On have to really start going, ok it is happening.

I’m seeing it happen.

It’s probably happened to one of your friends in business.

Comment suis-je préparé ?

Tout commence donc par poser des questions simples au conseil d’administration.

Que faisons-nous quand cela arrive ?

Et il faut lancer le processus.

That’s the first thing you have to do to begin getting prepared.

I’d add something else too.

As part of this whole trust thing, I don’t think the CISO should always be just responsive
aux questions du conseil d’administration.

Je pense que le RSSI doit être proactif.

Par exemple,

we’ve been talking about AI as a significant risk.

It’s a new arrow in the quiver of the adversaries.

It would be great for the CISO to be proactive and come to the board and say, hey, you’ve
sans doute déjà entendu parler.

Let me tell you what we’re doing ici.

Cela contribue à instaurer la confiance en montrant que les RSSI sont attentifs.

On know, hey, I know we’re we’re building a new factory over in in India.

Here’s some thoughts and concerns about this from

mon point de vue en tant que RSSI.

Here’s the types of things we should be thinking about.

Je pense qu’en étant proactif, on fait preuve de vigilance, on démontre ses compétences et on
renforce la confiance.

Et je pense que cela permet vraiment au RSSI de contribuer au bon fonctionnement de l’entreprise.

So Shawn I never thought about what you’re just saying and I love it.

Et le directeur financier est, de la même manière, lié au président du comité d’audit.

If tici’s a problem coming up wici

hey we’re going to have problems paying around the paychecks or some financial issue,
tici’s a reach out to the auditor.

Une relation de confiance s’est établie entre ces deux personnes.

Tici’s no reason.

Tici’s no good reason why a sizzle should not be doing something similar.

Soyez proactif dans vos communications.

On know, I look at it as also what what questions should the board be asking?

That’s not, that’s just in general.

Connaissons-nous réellement tous nos systèmes critiques pour l’entreprise ?

Avons-nous une visibilité sur toutes les identités humaines et non humaines ?

Et sommes-nous prêts pour la prochaine vague d’identités avec les agents ?

Comprenons-nous réellement tous les comptes privilégiés et analysons-nous réellement le dark
web à la recherche, par exemple, de nos identifiants et autres éléments de ce type ?

If you, us, we can’t answer those questions to the board, that is a red flag in my mind of
that we don’t have the capabilities that we need to have.

We’re not really prepared for that, for, you know, uh being resilient business.

Plus tôt dans la conversation, j’ai mentionné qu’il pourrait être utile pour un conseil d’administration de compter
parmi ses membres une personne ayant une expérience en informatique et en cybersécurité.

And a practical example, I’m on a board of a company and they were changing their HR
, une transition qui, comme tout le monde le sait, comporte toujours des risques.

Mais nous avions été informés.

Mais c’est moi, au sein du conseil d’administration, qui ai vraiment permis de cerner le risque, car je posais des questions
en m’appuyant sur mon expérience de la migration de ces systèmes

which was really helpful for the board to understand wici things were.

Et d’ailleurs, cela a été très utile pour le PDG, car il n’était pas issu du milieu informatique.

Cela a donc vraiment mis en avant le risque, et la discussion approfondie qui s’en est suivie – du type « je comprends
that’s a risk and ici’s how I’m managing it, is an important discussion for the boards to

lorsqu’ils procèdent à des changements dans leur système ou même lorsqu’ils cherchent à comprendre leurs systèmes critiques.

So the CISO needs to understand that they’re briefing

aux personnes chargées de la supervision de l’entreprise.

Il doit leur expliquer quels sont les risques réels pour l’activité et les risques d’entreprise,
puis les présenter en termes commerciaux.

And they need to actually discuss the plan and advocate for what they’re gonna need from
la part des membres de son conseil d’administration.

That’s absolutely true.

And I have dealt with many boards and I’ve dealt with many CISOs.

Et je sais que parfois, les RSSI sont réticents à le faire parce que

leur supérieur hiérarchique est peut-être présent à la réunion et qu’ils ne souhaitent pas fournir
toutes les informations qu’ils devraient communiquer, car le conseil d’administration a une responsabilité fiduciaire et

il doit avoir une vision globale des risques encourus.

But they’re reluctant to do it and I would suggest to CISOs that again professionally done
de manière professionnelle et appropriée ; cela demande parfois du courage, et vous devrez peut-être

break a little glass, but I think that you’ve got to do that and if you’re in a situation
wici you feel you cannot provide legitimate authorized information that the board is is

required or should hear, if you’re not in a situation wici that environment is conducive
à cela, vous devez chercher un autre emploi.

It’s hard.

Pour vous raconter une anecdote personnelle, sans entrer dans les détails, en tant que DSI ministériel,

I have a lot of component CIOs and tici was an issue at one of the components wici the
DSI de cette composante avait peur de s’adresser à ses supérieurs.

Je l’ai fait.

It shouldn’t be like that.

On need to do it.

Et une fois que j’ai parlé à la direction, on pouvait lire la surprise sur leurs visages, mais
ils ont aussi compris qu’il fallait bien faire quelque chose.

So you’re right, it’s hard to break glass, but you need to do it.

Je l’ai fait avec respect.

Je l’ai fait simplement.

Et nous nous sommes attelés à régler le problème.

I think I’ve told many board directors that when you’re sitting at the table, you need to
créer un environnement propice à une discussion ouverte.

Si, en tant qu’administrateur, vous êtes assis là à essayer de prendre quelqu’un en flagrant délit et
que vous créez un climat qui restreint le libre dialogue, vous êtes un problème.

On’re creating issues for that board.

L’ambiance doit être propice.

Il doit être collaboratif.

And again, we all want the same objective, N’est-ce pas ?

Nous voulons que l’entreprise réussisse.

We want to minimize risk, we want to delight our clients.

That’s what we should be doing as a company.

Le conseil d’administration a une responsabilité de supervision.

Le RSSI a une responsabilité d’exécution.

But together, you’ve got to create an environment that allows that to happen.

And if you are not creating that environment as a board director, you need to go somewici
ailleurs.

Mais nous devons communiquer sur les risques et les atténuer.

Exactement.

and together we’re the team.

Et nous devons le faire de manière « délicieuse », parce que j’aime ce mot.

« Ravissant ».

Eh bien, ça a été un vrai plaisir de discuter avec vous deux, John et Shawn, merci.

Et voilà, c’est la fin de notre podcast SHIFT.

I’m Melissa Hathaway, and this was Communicating Cyber Risk in the Boardroom.