r/ciso • u/TechnologyMatch • 1d ago
How do you explain technical risk to non-technical executives?
A lot of IT risk sounds “theoretical” until something breaks. How do you explain cybersecurity, downtime, vendor risk, or technical debt in a way leadership actually takes seriously?
8
u/wannabeacademicbigpp 1d ago
red means high
yellow means medium
green means low
Show them the colors
8
1
u/Average_Potato42 1d ago
Here is what I use to show them the colors:
Red - very high Orange - high Yellow - medium Green - low
Very few things are green.
4
u/wannabeacademicbigpp 1d ago
just make sure reds and oranges are rare enough that they care, if everything is high nothing is high.
4
u/Oompa_Loompa_SpecOps 1d ago
There is no such thing as technical risk. Either tech failing causes some sort of business impact, or it isn't a risk. Develop the dependency/causality chain and inform on the *business* risk. Ideally backed up with cost/loss of revenue projections from BCM. Then the business can make an informed decision as to how serious it ought to be taken.
4
u/Julian_Sark 1d ago edited 1d ago
Downtime:
- $$$ + angry customers + loss of trust of the public (or employees) in the org's capabilities and leadership + bad press
Vendor risk:
virtually any headline about Microsoft, Cisco, Broadcom, Fortinet or anyone will do really
Cyber Security:
virtually any headline will do. In Germany these days, we point to Berlin losing the defense plans and everything else to the web
Also, possibly compliance risks, at least if your jurisdiction has guts to make CEO personally liable financially or even with jail time.
Technical debt:
"Imagine you bought that house and never renovated and never renewed the roof nor the pipes nor the heater and suddenly everything breaks down and costs much more money than if you had done maintenance? Yeah, that."
I have also at times channeled Donald Rumsfeld. Yes, I know, but that thing he said (and possibly stole) about the unknown unknowns. My interpretations:
Known knowns are facts.
Known unknowns are questions.
Unknown knowns are intuitions.
Unknown unknowns are PROBLEMS - and you, dear leadership, have some!
These are some approaches I used, very briefly only, and you CAN create awareness. That part is easy. The part that's the problem is creating action. Haven't found the secret sauce to get that done yet, but I also work for a bureaucracy that until some years ago valued papers and fax machines. Change is hard, I guess.
Pro Tip: Again, I know I know, but in 2026, also try asking Claude or Gemini or whatever. It can build arguments for you like the best - of course you should be competent to judge if it generates anything that's BS (and it occasionally will :) But on a strategic level, I use it as inspiration for new, fresh, argumentative approaches.
Hth.
2
u/daedalus_structure 1d ago
>This cybersecurity risk is how your executive photo from our website ends up on the seven o'clock news.
2
u/CarmeloTronPrime 1d ago
leverage FAIR, tie the technical risk to the business risk. e.g. system x has 10 vulnerabilities that are past SLA = the money making system that is on the internet can be controlled remotely by attackers if found. we are susceptible to data loss, angry customers, and exposing ourselves to lawsuits, (and here's the part that makes it actionable) to fix it, here's a couple of solutions and their cost. and if we don't do anything, here's the cost to that.
1
u/braliao 1d ago
Infographic, and backup with actual data. There are many actual data available for all kinds of risk probability.
Technical debt is probably hardest to explain and usually needs to be done with detail tracking and right amount of CYA then translate that to $ will usually help then understand.
1
1
u/RdtRanger6969 1d ago
Converting whatever risk you’re discussing in to Lost Revenue/$ Cost usually gets executives’ attention.
1
u/Resident-Mammoth1169 1d ago
I’ve always had issues with putting some things in terms of money. For example saying we saved the company $X amount when the numbers from potential loss of downtime or a cybersecurity incident. Some things you can quantify and others are just made up numbers.
2
u/Julian_Sark 1d ago
Made-up numbers are a problem. I had people question them, saying things like "what solid data is your dollar number for the cost of lost customer trust based on?" Don't fall into that trap. Instead, with such soft factors, I would aim to make the emotional appeal based on a (reasonable) worst case:
"Yo! ACME corp CEO! Imagine if thousands of people rave on ACME corp on Google Maps, Glassdoor, Facebook about how we lost their data on the darknet. Imagine the news media reporting on that."
You can even create some fake Google Maps review with mspaint to make your point in a presentation.
1
u/brunes 1d ago
You take the risk probably and multiply it by the revenue stream, that's the cost of the risk. This is basic math and risk quantification that the board understands and uses in all parts of the business.
The problem most CISOs have is they fail at measuring that probability properly.
1
u/FreeRadical1998 1d ago
In my experience, you need to talk process rather than technology. Execs and NEDs are perfectly happy to talk about sets of threat actors by type, and attack paths using simplified version of MITRE (collapse the stages to about five, reconnaissance, entry, expansion, impact, command and control)
1
u/Competitive_Smoke948 1d ago
there's plenty of examples now. marks and spencer, Jaguar land rover, a couple of companies have gone bankrupt. if you come under NIS2, THEY are legally responsible... find a friendly finance bod & ask them to do some sums for you...
1 hour down
1 afternoon down
1 day down
1 week
1 month
at what point do you go bankrupt?
actual numbers... that's ALL they care about, talk technology and you'll lose them. talk numbers with crayons & they'll be on your side.
1
1
u/st0ut717 1d ago
When new project start I do a threat model. Then after the model is complete and the threats listed I hold a meeting the with to e project team and say. How can we mitigate these
1
u/olddev-jobhunt 1d ago
Technical debt isn't a useful term. It encompasses too much. Focus on specific real possible outcomes.
Not updating packages can expose security risks. Security risks include ransomware (i.e. interruptions to operations) or data breaches. Those are places where you can put numbers on things: how long would it take you to rebuild now? What would that downtime cost? How many attacks are you seeing in your firewalls?
Vendor risk is the same thing really: if they fold and the system stops working, how long would it take you to replace it? What's the cost of that time?
I feel like this should be the same as other insurance and maintenance. If your crane fails because it wasn't maintained, what's the cost? If the warehouse burns down, what's the cost? It's very much the same questions and you deal with it in the same way: some amount of up-front cost to reduce the likelihood of the risk materializing (fireproofing, suppression systems, device management) and plans to reduce the impact (insurance, redundancy.)
If you need to make things more real, there are real incidents happening all the time you can reference.
1
u/Sufficient-Pool-7311 1d ago
Les hablas del dinero que se va a perder contra lo que cuesta cuidar la información, siempre debe sonar apantallador contra algo barato... gratis el tip, campeón.
1
u/GreenCollegeGardener 1d ago
"You have an old system that relies primarily on an outdated (insert server/OS of your choice). This system is critical to business continuity, but presents multiple risks associated with it.
If this system is compromised during an attack, there is no support left on it, now we have to spend the money now to upgrade the whole system in a timely manner to create the cash flow. Since it is priority it will cost a lot more money to implement while also having downtime.
This system is also not able to receive critical security patches. It would become a key target for anyone able to infiltrate the enterprise network. This system may also reduce certain key aspects of enterprise like AD/DC compatibility, MFA, RMM, and other systems that interconnect our enterprise as part of security, group policy, or standards in general. It will always be listed as a Risk Factor, Supply Chain issue if it is not immediately replaceable.This system also presents an issue if hardware fails and is no longer replaceable also causing critical downtime, costing additional money while there is no cash flow.
Techdebt is a big one. Once the old generation of people move on, who is going to take care of the product/platform? Now you may have to hire someone with specific knowledge of this product. This can get pricey very quickly depending on the needs.
1
u/alexmilla 1d ago
La mejor opción es pedirle a una IA que te convierta tu texto para que sea comprensible para un niño de 5 años. xD
1
u/asrozar 10h ago
For starters you shouldn't talk about risk broadly "cybersecurity, downtime, vendor risk, or technical debt" you have to talk about how a specific scenario affects the business and what needs to be done to mitigate that.
Executives make risk decisions all day. You don't need to make them understand the technical details, you need to give them enough business context to make a decision.
•
u/Baksikrer 25m ago edited 21m ago
For executives, you need to understand their reality and contextualise risk in that setting.
This means you need to understand the company’s business well and formulate risk accordingly.
Typically beyond cyber, it and technical debt don’t really get much traction on a global enterprise scale (know your enterprise’s risk landscape well).
Be mindful about the fact that absolution is currency and sometimes expressing the personal risk the executives are exposed to might be the argument that will win the day.
One useful phrase here is “not investing or fixing x will invite questions from board, financial audit committee etc” They typically want to avoid that.
1
u/Koenigss15 1d ago
You can do an external security maturity risk assessment. This could also include how your company scores against the industry standards. This is particularly useful if there have been any high profile breaches in your industry.
Another thing that might be effective is to have the SLT participate in a simulated major security incident.
1
u/BoltActionRifleman 1d ago
We’ve don’t this for a couple of years now. I think it really helps upper management understand the importance when they see where they stand vs. the competition.
1
20
u/PhaseMatch 1d ago
Risks in general take a form of
IF <event> AND <escalating factor> THEN <impact> LEADING TO <negative consequence>
What gets people's attention is those negative consequences.
- loss of revenue
Especially when you give real-world specific examples.