Frame security discussions in internal currency beyond dollars, such as reputation, service availability, and trade secrets. The CISO can also face SEC enforcement and criminal proceedings, which adds personal risk to the individual side of that currency.
How a security professional frames a risk finding shapes whether leadership acts on it. The most motivating frame often isn’t financial, because every organization weighs risk in a different unit of value. The better you match your message to that unit, the more likely leadership will act on your recommendation. The framing is even more useful when applied to the individual on the other side of the conversation, not just the organization.
Organizational Internal Currency
The “internal currency” framing comes from David Hoelzer’s post How to Present Audit Findings Effectively. As David pointed out, “putting audit reports and risk assessments in terms of dollars and cents is the most motivating context for management” in most organizations. He also explained that money isn’t the only internal currency you can refer to.
For instance, you might be able to engage your audience by framing the discussion in terms such as:
- The company’s reputation
- Service availability
- Organizational culture clash
- Protection of trade secrets
In theory, risks related to these factors can ultimately be described in terms of financial expenses. However, sometimes when aiming to frame security discussions in financial terms, people make up numbers or use meaningless calculations.
You might not have enough data for monetary computations and might be tempted to make hopeful, but possibly incorrect assumptions. Rather than give up and begin talking about security as if its importance is widely acknowledged, consider other forms of internal currency that might resonate with your audience.
Individual Internal Currency
I’d like to take a somewhat Machiavellian perspective on this matter, very possibly diverting from the road map charted in David’s post. (So don’t blame him if the following rubs you the wrong way.)
Remember that companies don’t make decisions. Instead, individuals working for companies make decisions. As the result, consider which form of internal currency is most relevant to the person with whom you’re interacting. Though the person operates within a company that pursues certain, usually financial goals, they might have more immediate concerns related to avoiding:
- Looking bad in front of their manager when a data breach occurs
- Being fired or demoted as a scapegoat
- Spending time away from their family dealing with a drawn-out security incident
- Being known as the person on whose watch a major security issue came up
- Having to ask for funds beyond the budget allocated to security spending
- Losing support for their favorite security product roll-out project
- Being blamed for being the one who failed a compliance audit
- Losing respect of their peers due to weak security posture
Keep these subjective concerns in mind when preparing to discuss your information security findings, recommendations or requests.
The chief information security officer can face personal legal consequences for incident-related decisions. In October 2023, the SEC filed fraud charges against SolarWinds and its CISO Timothy Brown for allegedly misleading investors about cybersecurity practices. A year earlier, a federal jury convicted former Uber chief security officer Joseph Sullivan of obstruction and misprision of a felony for his handling of a 2016 breach. Since December 2023, public companies must disclose material cybersecurity incidents under Item 1.05 of Form 8-K, and each filing makes public what the CISO knew about an incident and when.
Important Reminder
The goal of accounting for internal currency isn’t to distort findings or manipulate the organization or the person into making bad decisions. Rather, it’s a technique that helps capture the attention of the audience in the context within which the security program exists. Your discussion still needs to be based on accurate observations, factual information and, whenever possible, empirical data.
In the perfect world, we’d have all the data we need to calculate the best outcome congruent with the organization’s strategic goals. In the meantime, recognize that internal currency can take other forms than money and might differ across individuals within the company.