Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementCybersecurity News

CISOs struggle to articulate business impacts of cyber risks

By Security Staff
security-executive-freepik1170x658v7.jpg

Image by pressphoto via Freepik

October 25, 2022

A new survey from FTI Consulting reveals the heightened pressure felt by chief information security officers (CISOs) as company boards and leadership seek to improve oversight of cyber risks in the face of growing regulatory, investor and media scrutiny.


With CISOs required to regularly present to their boards, they now face the challenge of articulating cybersecurity risks and opportunities to an engaged audience, according to CISO: Communications Redefined, Navigating the Journey from Control Room to Boardroom report by FTI Consulting’s Cybersecurity & Data Privacy Communications practice. The survey was conducted between June and July 2022, representing 165 CISOs and those in charge of information and cybersecurity, representing U.S. companies with $4.4 trillion in aggregated revenues and employing over 528,000 people.


Among CISOs surveyed, 85% said that the prominence of cybersecurity on the Board’s agenda has increased over the last 12 months, with 79% feeling heightened scrutiny from senior leadership. The lack of executive leadership understanding CISOs’ roles (55%) prevents CISOs from articulating critical priorities, with 53% saying their cybersecurity priorities are not completely aligned with their organizations’ C-suite leadership.


Despite this increased prominence, most CISOs (58%) surveyed revealed their struggle to articulate technical information and effectively communicate cyber risk in a manner that the Board and senior leadership can understand. Ultimately, a disconnect between the CISO and Board and leadership priorities may negatively impact an organization’s ability to effectively prepare and respond to a cyber incident.


Other key survey findings include:

  • With mounting pressure, 82% of CISOs claim that they feel the need to positively exaggerate their role to their Board.
  • Even as cybersecurity awareness grows, 58% of CISOs struggle to communicate technical language to their boards, and 63% feel that their concerns are not aligned with senior leadership priorities, potentially leaving companies exposed to a possible incident or regulatory sanction.
  • While 88% of CISOs surveyed have experienced a cyber incident in the last 12 months, 46% of the respondents claim these incidents were not mitigated quickly and continue to struggle to rebuild trust and confidence among leadership following the incident.
  • 52% of CISOs claim that managing communications with internal and external stakeholders is the biggest challenge when responding to an incident, and 63% believe that their cyber concerns are not fully aligned with senior leadership’s priorities and could leave companies exposed to a possible incident or regulatory sanction.


While 66% of CISOs feel that their senior leadership struggles to understand the CISO’s role, over half state that they struggle to communicate technical language in a way their board members can comprehend. In response to those results, FTI Consulting asked if respondents would benefit from communications training, and 91% said communications coaching would positively impact their role.


This research explores the communications challenges facing CISOs and those in charge of information security. It illuminates the struggles of CISOs and information security leaders to more clearly communicate — internally and externally — their role, leadership and management of cybersecurity.


Joseph Carson, chief security scientist and Advisory CISO at Delinea, says, “CISOs must invest time listening to their executive Board and business peers to learn how they measure their organization’s success. Our role within cybersecurity is not to simply put technology in place for the sake of security but to put technology in place that contributes to business success — while ensuring cyber risks are either reduced or eliminated.” 


According to Carson, the CISO must become the bridge between the Board and the IT security team to ensure that a business-first approach is made with each and every security decision. “How does implementing a security strategy help your business, the executive team, your business peers and your employees be successful in their tasks and goals? In the past, security was typically enforced on the business, typically creating a negative experience and slowing down employees trying to achieve their goals,” Carson adds. “The CISO needs to make security a fundamental core to the business, and employees must never be afraid to speak out when they see something suspicious. Promote a culture where employees are never afraid to ask for advice or report suspicious activity, even if it was the result of something they clicked on. The earlier an employee reports something, the lower the potential impact and cost to the business it will have.”

KEYWORDS: board of directors c-suite Chief Information Security Officer (CISO) cyber security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Man on laptop

Healthcare Executives Face a New Era of Personal Risk

Police lights

Security Team Member Dies in Standoff with Dallas Police

Man walking with briefcase

The Rising Tide of Executive Protection: Corporations Ramp Up Security in an Era of Heightened Threats

Stadium

Physical Security in Global Arenas: How AI Improves Security at Scale

Four people in suits

Mexico Security Crisis: Never Waste a Crisis

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

April 15, 2026

How AI is Closing the Decision Gap in Leading GSOCs

Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.

April 21, 2026

The Blind Spot in Enterprise Security: Managing Workforce Risk Post-Hire

Organizations continuously monitor their networks and systems for risk, yet the people with legitimate access are often the least monitored part of the model. Discover a Workforce Risk Intelligence Framework that adds a dedicated layer focused on workforce risk.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders

Related Articles

  • Taxes, Cyber Security Climb to Top of Global Business Risks

    See More
  • Man in suit looking out window at city

    41% of organizations struggle to find and retain cyber professionals

    See More
  • report on desk

    Digital-first economy introduces unforeseen risks for 89% of CISOs

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing