Intelligent CISO Issue 06 | Page 73

develop a relationship with a board member that you can develop into a board mentor. This mentor can give you guidance on how to interact with the other board members. Some board members will be more technical than others, but don’t let that pull you back into your comfort zone of technical jargon. Use analogies business leaders can recognise to ensure you’re communicating in a way that is meaningful to all of them. I frequently use film and television analogies to convey key concepts; find the illustrations that work best for you. www.intelligentciso.com | Issue 06 To operate as an actual ‘chief’ you must spend time talking to line-of- business leaders to understand how your company truly operates. Now that you’ve laid the groundwork for a successful board presentation, what specific metrics should you report on? Keeping in mind that you have a finite amount of time to present and you don’t want to over-complicate the message, I suggest you focus on the following areas: • Report on the programme’s overall maturity using an industry-accepted framework (e.g. ISO 27001 or the NIST Cybersecurity Framework) to measure and track maturity and governance. Provide a high-level update to the board – for example, that the organisation is at 60% maturity based on the framework. 73