#GartnerSEC: Questions Your Board Will Ask About Security

#GartnerSEC: Questions Your Board Will Ask About Security

Speaking at the Gartner Security and Risk Management Summit in London, Gartner director analyst Sam Olyaei said that the topic of “questions on security and risk that you must be prepared to answer at your board meetings” was one of the most popular subjects.



He said that the company was getting around 100 enquires a year seven years ago on this subject, and now that number is over 700 a year. Pointing at Gartner research from 2016, which said that by 2020 “100% of large enterprises will be asked to report to their boards of directors on cybersecurity at least annually,” he said that we’re getting close to that number, as 2018 research showed that 91% of billion dollar companies had briefed the board on their cybersecurity program at least once in the last year.



Olyaei said that this shows the “cultural disconnect between security and the business” and that the business has “expectations for security and risk that we cannot manage.” Olyaei added that it is not enough to say that we are creating an impact, but security practitioners have to show evidence, data and examples of what they are doing.



Olyaei argued that most security leaders feel that the board is monitoring risk, and feel that the board understands the risks and monitors them on a regular basis, “but we find most board members are not that confident in their security leaders to manage risks on their behalf.” 



He said: “We feel that in a couple of years, your performance as security and risk leaders will be on demonstrating value at enterprise risk lev ..

Support the originator by clicking the read the rest link below.