Episode 18: The Board’s Role in Cybersecurity Decisions
Red Helix TV
0:00 / 0:00
Episode 18: The Board’s Role in Cybersecurity Decisions
3 просмотра · 4 дня назад
Red Helix TV
103 подписчика
3 просмотра · 4 дня назад
Why do boards struggle to make cybersecurity decisions? In this episode of Red Helix Cyber in Focus, Tom Exelby is joined by Graham Pottie, Associate vCISO and strategic security adviser, to explore the barriers preventing effective cybersecurity decision-making at board level.
They discuss board responsibility, cyber risk assessment, financial quantification, cybersecurity investment, and how security professionals can give boards the context they need to make informed decisions.
Key topics: cybersecurity governance, board-level cyber risk, risk assessment, cyber risk quantification, CISO strategy, CAF, NIST, and cybersecurity investment.
Chapters
00:00 Introduction
03:24 Why boards struggle with cybersecurity decisions
07:08 Quantifying cyber risk
09:53 Enabling board decision-making
11:14 Risk frameworks and assessment
12:22 Justifying cybersecurity investment
14:08 Building an ongoing board conversation
16:22 Identifying cybersecurity gaps
18:17 Creating a decision framework
20:52 Board champions and sponsors
22:10 Is cybersecurity overreacting?
23:18 The business case for cybersecurity
25:36 Balancing cyber risk and investment
28:00 The external threat landscape
30:14 Building cybersecurity awareness
33:30 Using risk assessment tools
36:25 Using frameworks to identify gaps
37:49 Communicating cyber risk financially
41:18 Cybersecurity champions at board level
43:20 Final thoughts
Resources
The UK Government Cyber Security Breaches Survey 2025/2026: https://www.gov.uk/government/statist...
Connect with Tom on LinkedIn: / tomexelby
Connect with Graham on LinkedIn: / graham-pottie-270178
Red Helix website: https://www.redhelix.com/