Five actions to secure organisation networks and infrastructure

Measure success to drive board level buy-in

Measuring the success of your security is crucial to provide metrics to create a business case for investment. Security accreditation is one way to do it.

There’s a need to address the disconnect sometimes seen between security reporting and translating that into actionable business context and ROI. Security professionals need to improve communication with the board to get the budget they need, and especially communicate the ongoing, not just one-off benefits of cyber security spend.

“You have to have executive buy in for security,” says David Kosorok at DocuSign. “That doesn’t just mean approval of budgets. That means willingness to communicate to the company broadly.”

“For example, if a company’s IT or security department educates other users in the company about the warning signs for “phishing” cyber attacks (misspellings, poor grammar etc.) and the number of successful phishing attacks falls significantly, because fewer employees open suspicious-looking emails. This benefit of improved IT security is worth communicating to the board, David Kosorok says. The CEO may want to personally email the IT/security staff involved, thanking them for helping to keep the company secure”, he adds.

David Kosorok,

Dynamic Senior Director of Application and Product Security | DocuSign

You have to have executive buy in for security. That doesn’t just mean approval of budgets. That means willingness to communicate to the company broadly.

Next: Five actions to secure organisation networks and infrastructure

04. Resource security

Keep reading →

Share this page