Intelligent CISO Issue 51 | Page 38

FEATURE
caused outages to find a recent headline as an example .
Then ask executives to evaluate and prioritise the most critical parts of the business – or the risks they would be willing to mitigate versus the risks they are willing to accept .
Ultimately by working closely with the C-suite , security professionals should aim to deliver an evolving programme that starts by addressing the highest probability and highest impact risks .
Business resiliency – strike the term ‘ disaster ’ from your vocabulary
One of the core issues when it comes to communicating technology concerns to a business audience is the use of appropriate vocabulary and the ability to communicate context . Tech-rich terminology will immediately switch off those that don ’ t understand it and ambiguous references that don ’ t adequately explain the impact to business or the everyday prevalence of security threats , will fall on deaf ears .
In terms of Disaster Recovery , the word ‘ disaster ’, for example , is often associated with low probability events such as a widespread outage due to an earthquake , flood or act of terrorism , and fails to adequately communicate the prevalence of data loss events .
In reality , however , most downtime is caused by mundane , everyday events such as hardware failure , human error , severe weather or power outages . This has become even more the case since the pandemic has driven widespread adoption of hybrid and home working . As employees work remotely in greater frequency , employee-based incidents are increasingly on the rise , wreaking havoc on IT environments .
By removing the word ‘ disaster ’ from conversations with senior management and discussing business resiliency in terms of high probability data loss events , CISOs are far more likely to grab the attention and focus of the C-suite .
Outline Business Continuity and business growth benefits
While it is important to outline and fully explain the risks around data
38 www . intelligentciso . com