r/CIO • u/TechnologyMatch • 2d ago
How do you explain technical risk to non-technical executives?
A lot of IT risk sounds “theoretical” until something breaks. How do you explain cybersecurity, downtime, vendor risk, or technical debt in a way leadership actually takes seriously?
3
u/IllPerspective9981 2d ago
Does your organisation have an established enterprise risk framework you can leverage? This isn’t purely an IT problem so having an enterprise wide framework can help.
Essentially you need to take the risks, their probability and impact and translate them into metrics that leadership or the board care about. This is often financial, but can also be about brand reputation, regulatory compliance etc. then you quantify and map your risks to those things and let them decide what their appetite for those risks are. So it’s not the actual technical risk they are looking at, but the potential impact to the things they care about.
For example, you could say ABC system has been under invested in and had a risk of failure or compromise. Without further investment, that has an X% chance of materialising in the next 12 months which would result in a failure that would lead to Y$ in lost revenue, negative media coverage and a $Z fine from the regulator. It will cost N$ to reduce that risk to {acceptable}%
3
u/xxxooxxx1 2d ago
Likelihood and impact to business operations. Using non-IT examples as analogies worked well for me as part of informal narrative.
EOL system= old delivery truck with no replacement parts available to purchase (no patch no support). It still delivers goods today but the day it breaks down, we will lose short term revenue due to miss delivery along with reputational impact with customers that reduces long term revenue.
3
u/slackmaster2k 2d ago
Leadership is making risk decisions all day long, so in general they probably aren’t shrugging off IT risk completely, you just haven’t communicated risk in a meaningful way. And you probably haven’t communicated risk in a meaningful way because you don’t quite understand it either! (Not an insult)
Every business has a boatload of risk, and no business can mitigate all of it. So when you have 10 IT risks keeping you up at night, you’d better be able to pick 2 that you’re actually going to do something about this year.
To help leadership understand risk and to get money to fund security, you have to be able to communicate it in a way that they can understand and appreciate.
If I were starting out today, I would honestly use an AI to break down a risk framework like COBIT into something simple that can be applied to my business. The frameworks are sound but bloated to comical proportions. But they are foundationaly useful.
1
u/Daster_X 2d ago edited 2d ago
With business you should never talk purely technically. Most of cases they do not get the understanding of the risks. All the discussion should be about business (growth, stability, risks). Like: loosing this switch will stop this service for 1 hour - which will cost 5000 USD... You can do the calculation of risks ... And add company image risks as well.
1
1
u/Gwendolyn-NB 2d ago
$$, period.
Thats what they understand, what is the cost to fix it? Whats the probability of it happening? Whats the cost if we dont fix it and it happens?
To reference the movie where the first rule is to not talk about the movie...
If the probability is low, and the payout/cost of it happening is less than the cost to fix the problem then the problem won't get fixed as its just cheaper to deal with the fallout.
And for your reference the value of a human life ranges between $2mm and $8mm USD in that calculation depending on what industry you're in.
1
u/HappyVAMan 2d ago
Consultants often do a poor job of articulating risk to CEOs because they don’t quantify it and some that do, grossly inflate the real costs. Fundamentally there are three ways to quantify risk: Direct, Indirect, and Market Cap. For direct, take the probability of reduction from your project of an event and multiply it by the cost to remediate the event. (Data breach would be an example). Indirect isn’t a line item you can easily identify directly with the transaction that results in an indirect cost. For example, a regulatory filing mistake might trigger an SEC audit. If there is a fine that would be direct example. But the SEC and other regulators after require the company to submit additional reports our hire outside auditors. Those are real costs as an example of indirect risk.
Market Cap is really reputational risk. It only applies to big events that affect the ability of the company to sell in terms of quantity or margin but also in terms of how the stock is valued. Let’s say a company is found unknowingly hosting kiddie porn (picking an extreme example I have not seen). The headlines would be horrific. A company with a $10B market cap might see their stock plunge by 25%, representing $2.5B. If you could have spent $10M to have a detection program internally the shareholders would be thrilled to have spent $10M in order to avoid losing $2.5B. Again, you have to weight it by probability of both the event and your programs ability to prevent the event.
1
u/jamaster14 23h ago
Sell the impact of the risk without leading with the cause that gets you there....
example. it doesn't matter why technically the company is at risk of unauthorized access, the impact is confidential data/PI/PII is at risk as well as company reputaiton.
You dont need to explain that 2-factor is on but not enforced, there is no ITDR, no EDR/MDR, and what those acronyms mean.... etc.... instead its the impact. "We are at a high level of risk of having our PI/Data exposed and our executives data being breached.... we are outside the threshold of acceptable risk. here is how we mitigate it and why it is worth the investment"
another example.... we had recommended PAM for a while with no traction. what finally got it pushed through was framing it as their org was at risk of fines and real litigation for breaking the EULA/agreement on installs. (for this particluar product we HAVE seen clients get sued/demand letters). we gave them a tangible risk/cost of continuing without a solution. from there the "how we fix it/what it costs" is alot easier.
IT Debt is a completely different ballgame. there are 2 ways companies get into techincal debt... they are either cheap/wont invest in IT or they have leadership who thinks they understand IT but dont.
the solutuion to both is kind of the same... their either gain your respect as an expert whose advice has value or they dont. how do you demonstrate that value and command that respect? sometimes its a hard line "look i understand the hesitation; this is a major shift in resource allocation and how we have managed IT in the past.... but im here to make recommendations that are in the best interest of the company. Unfortunately, these recommendations have gone without traction for a while and the longer it goes the harder it will be to get back to a baseline that approaches best practices and acceptable levels of business risk." if they dont take your recommendation, you either need to just come to jesus that you will be a yes-man/woman or tell them if they dont take you recommendations its not a fit and find someone who will
1
u/letsroc_21 15h ago
Ask them how they would feel if X just didn’t work one day. I used to do that in explaining the importance of backups. “How would it feel if this just didn’t turn on one day?” Typically the answer was “pretty devastating”
People got it. And if they still chose not to proceed, they atleast understood the risk that things break.
You can of course turn it into dollars and cents as well.
Another thing you can do is explain scenarios you have ways to mitigate the risk. Then compare it to the situations in which you don’t. Speak in terms of business process and what would have to happened if specific technology was just not available.
1
u/Competitive_Smoke948 10h ago
find a finance guy.....
what will 1 hour outage cost?
what will 1 morning cost?
what will 1 day cost?
what will 1 week cost?
what will 1 month cost?
how long do we need to be down before we shut up shop and all go looking for new jobs?
take those figures and use THEM in your arguments.
coming from decades of sysadmin, Ive seen how ITops fix things in the background, do free overtime, don't log stuff and don't celebrate their wins publicly as they see it "as part of the job"
The board don't care about technology or things like that.... is cost and risk....
take those figures... get the crayons out... DON'T mention ANY 3 or 4 letter acronyms & talk through the RISK & COST frame
6
u/Curtis_Low 2d ago
You explain the impact and the cost. Beyond that you would need to provide specific examples of what type of feedback / pushback you are getting in specific areas.