19 articles in the Board & Executive Governance track of the Deep Trust Governance Series.
Risk reporting that has stopped reflecting reality is a more common governance condition than most practitioners acknowledge. The indicators are subtle: metrics that have…
The risk appetite statement was developed over three months. It involved the board, the executive team, the CISO, and the CRO. It was approved at the highest governance l…
The slide deck is the governance product that the security and privacy functions deliver to leadership. It is curated, organized, and designed to communicate effectively…
The CISO presented the quarterly security report to the board. The report was accurate in every particular: the metrics were correctly calculated, the risk ratings were d…
The CISO's quarterly report to the board contained forty-three slides. It covered vulnerabilities patched, phishing simulations completed, security awareness training com…
The security dashboard presents: 94,000 vulnerabilities remediated this quarter. 2,847 phishing emails blocked. 99.3 percent of systems with current endpoint protection.
This is not a claim that your data is fabricated or your team is incompetent. It is a claim about the nature of risk measurement. Risk is the product of likelihood and im…
Enterprise governance programs assign accountability with confidence. Risk owners are named. Control owners are documented. The RACI is populated and reviewed.
The governance program had a perfect audit record. No significant findings in four consecutive external audits. Internal audit consistently rated the security program as…
Governance frameworks are excellent tools for the governance problems they were designed to solve. NIST CSF provides structure for cybersecurity risk management.
The governance program had been in place for four years. It had passed external audits. It had received favorable board assessments. The maturity scores had improved cons…
Risk accumulates in the space between reporting cycles. Not catastrophically — not in events that are unmistakable at the time. It accumulates through the incremental dec…
Board discussions of strategic risk are substantive. The risk that a competitor deploys AI capabilities faster than the organization. The risk that regulatory change affe…
The board assigned risk ownership for cyber risk to the CISO. The CISO assigned ownership of specific risks to business unit leaders. Business unit leaders assigned opera…
The governance framework covered the organization at its current scale. The risk committee structure, the control ownership model, and the reporting mechanisms were desig…
The incident started at 11:47pm on a Wednesday. The security operations team detected it at 12:14am. By 12:30am they needed a decision: contain the affected systems and a…
Board risk reporting shows trends: improvement in coverage percentages, reduction in open findings, increase in training completion rates. These are activity trends.
Board risk reporting is built around compliance metrics and audit outcomes: controls in place, assessments completed, findings remediated. What it is not built around is…
Boards receive reports that describe what the security and privacy organization has done: incidents responded to, controls implemented, assessments completed, training de…