Cybersecurity Ecosystem Show · 2026-08-20 · 34 min
Key moments - from our scoring
Substance score
49 / 100
Five dimensions, 20 points each
Chris brings three decades of cybersecurity experience - including roles at the SEC, GE Capital, and Worldwide Technologies - to solving a critical governance gap: most boards lack visibility into how cyber risk materially impacts business operations and financial condition. Working with roughly 25,000 corporate directors through the NACD and serving as chair of the NASDAQ Center for Board Excellence's AI and Cyber Insights Council, Chris has identified that approximately 70% of board members don't grasp how threat landscape changes, AI adoption, and post-quantum computing affect strategic growth and financial exposure. The core problem is structural: CISOs typically operate in isolation with minimal board contact (often just a 20-minute annual audit committee briefing), while boards remain disconnected from cyber dynamics. Chris advocates for establishing enterprise risk management committees that integrate cybersecurity with M&A, supply chain, finance, HR, legal, and operational functions - creating visibility that allows CISOs to align budgets to actual business threats. Rather than traditional frameworks like FAIR or NIST maturity scoring alone, Chris champions annual loss expectancy analysis borrowed from insurance markets, which quantifies residual cyber exposure by industry peer group and specific loss categories (ransomware, business interruption, wire fraud, IP theft). This approach helps boards understand not just the risk dollar amount, but where capital should actually be deployed and how much insurance to purchase, creating a feedback loop that demonstrates de-risking over time.
Roughly 70% of board members across NACD's community are still not in tune with how the threat landscape, AI adoption, and post-quantum computing materially impact business operations and financial condition.
CISOs may have only a 20-minute briefing with the audit committee once a year, or quarterly in highly regulated environments, which is insufficient given the compressed time-to-attack with AI (now measured in minutes rather than months).
Annual loss expectancy analysis, borrowed from insurance industry pricing models, quantifies residual cyber exposure by industry peer group and specific loss categories (ransomware, business interruption, wire fraud, IP theft), then informs where capital should be deployed - going beyond traditional maturity scoring to substantiate potential losses based on actual industry dynamics.
An enterprise risk management committee should include heads of M&A, finance (CFO), HR, legal, compliance, chief risk officer, and technology/CISO, with a documented charter defining roles, responsibilities, frequency of meetings, and alignment to frameworks like COSO.
Start by identifying key business pillars and appointing individuals responsible for each (finance, M&A, HR, legal, compliance, manufacturing operations), create a charter defining roles and risk priorities specific to your industry (uptime for manufacturing, data privacy for healthcare), and map those risks to cyber investment decisions.
Our reviewer’s read on each dimension, with quotes from the episode.
There are some useful, practitioner-grounded frameworks - especially the annual loss expectancy / actuarial approach to cyber risk quantification - but the episode is heavily diluted by generalities, platitudes, and transitional throat-clearing. The ratio of novel claims to filler is moderate at best.
When I was a ciso, the reconnaissance period would take like three or four months and then I would see some type of infiltration on the network. And then you contain now with AI that's being compressed to minutes.
We look at, uh, wire transfer, fraud, business interruption, and somewhere loss of intellectual property. These are all very distinct categories of risk that are used by the insurance markets.
The insurance-actuarial framing for cyber risk and the GAAP analogy for standardized board reporting are genuinely fresh angles, but the bulk of the episode recycles well-worn ideas: CISO isolation, culture from the top, enterprise risk committees, and maturity frameworks.
we always say, you know, the ultimate arbitur for any type of risk domain, whether it be hurricane risk or flood insurance, flood risk or a fire, is the insurance markets.
there's accounting principles like gaap. We understand profit and loss. We have interest rates that we have to line to. We need a very similar approach to reporting on cyber threats, including now with AI.
Chris has genuine, multi-sector practitioner credentials - global CISO at GE Capital, four years as a senior policy advisor at the SEC, three years embedded with major insurance carriers - making him a real operator rather than a pure thought leader, though the conversation rarely pushes him to his depth.
I was a global chief information security officer at GE Capital. I spent four years at the securities Exchange Commission as a senior policy advisor to both chairs of the SEC during that tenure.
I spent about three years in the insurance industry working with some of the largest brokers and carriers here in New York to evaluate different methods and capabilities around sizing the overall exposure
A handful of concrete data points appear - the 70% board survey figure, the 20-minute annual audit briefing, the six-to-eight-hour vs. minutes assessment comparison - but most dollar figures are explicitly labelled as made-up examples, and named case studies or named companies with outcomes are absent.
roughly 70% of our board members are still not in tune with the deep tactical dynamic
The CISO may have a 20 minute briefing with the audit committee once a year, or in highly regulated environments, they may be more of a touch point on a quarterly basis.
The host moves topics forward adequately and lands one decent probing question on why cyber risk quantification adoption remains low, but the interview is marred by repeated sycophantic affirmations, no substantive pushback on any claim, and an awkward mid-interview self-promotion of the host's own employer.
Super cool. Thanks for the, thanks for the context setting.
Wow. Yeah, well said.
Computed from the transcript - who did the talking, and the words that came up most.
Christopher Hetner has seen the board conversation from every seat: building New York City data centers in the nineties, running global information security at GE Capital, advising two chairs of the SEC as senior policy advisor, and three years inside the insurance industry learning how brokers and carriers actually price cyber exposure. Today he is Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors and its roughly 25,000 members, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. In this conversation, Chris and Taylor dig into the numbers behind the board disconnect: roughly 70 percent of directors are still not in tune with how cyber and AI materially impact the business, many CISOs get 20 minutes with the audit committee once a year, and AI has compressed attack reconnaissance from months to minutes. Chris lays out the fix layer by layer. Build an enterprise risk management structure even when no regulator requires it, with a charter, a risk register, and the heads of the business in the room.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to the show. I got Chris here today. Hey Chris.
Speaker B: Hey Taylor. Good to see you.
Speaker A: Good to see you as well. I'm looking forward to our conversation. We, uh, we, we talked a couple weeks ago about this conversation and Chris uh, has a, uh, wealth of experience. He's currently, I'll let him share a little bit more about what he's been up to as we, as we talk. But right now he's a chief, uh, cyber advisor at Worldwide Technologies. He's involved in a bunch of other organizations and has a, ah, kind of a rich history in technology and cybersecurity. So I really look forward to our conversation. Chris, let's just jump. So one of the main topics that I was, that you shared with me that you're, you know, you, you've been involved with a lot is around working with boards and really as it relates to cybersecurity board reporting, um, and building those relationships and whatnot. So I imagine you've seen thousands of board decks, uh, or been involved in, you know, many conversations. I'm just curious, kind of open us up for, what are you seeing right now as ah, on the frontline, you know, kind of educating boards and. Yeah, tell me about some of your experience in that space.
Speaker B: Yeah, uh, no, it's a great, great question. And you know, uh, to your point, um, I am on the front line with the boardroom community. So I serve as the national association of Corporate Directors Cyber Risk Advisor. We support a community of roughly 25,000 members. I'm also the chair of the AI and Cyber Insights Council for the NASDAQ center for Board Excellence. So I would say the last seven years I spent about 60% of my time advising corporate directors, CEO level general counsel. I have close to 30 years experience in cyber technology. I built data centers in New York City back in the 90s. I was a global chief information security officer at GE Capital. I spent four years at the securities Exchange Commission as a senior policy advisor to both chairs of the SEC during that tenure. So really the focal point here is treating technology and digital, digital exposure as an enterprise risk. And these risks are materially impacting, uh, the company's ability to operate and run their business, impacting their financial condition. Many of these ransomware attacks, if we think about business, ah, interruption, loss of intellectual property, these are real dollars and cents. Pick the currency and the pound.
Speaker A: Right.
Speaker B: It's materially impacting the balance sheet of these companies. And so the objective with our platform at the NACD now with Worldwide Technology is to advance technology into the boardroom through that lens. Right. This is a business issue. This can materially impact your operational condition. By the way, you also have legal, fiduciary, regulatory responsibilities as well. And there's also financial cost. And so what we see, uh, across our community is, you know, a lot of our board members, they're very sophisticated, right? They've, they're former CF, CFOs, former general councils, former CEOs, running multi billion dollar companies. But, uh, they're uh, acclimated and adjusted more towards a business lens.
Speaker A: Right.
Speaker B: They're not necessarily into the zeros and ones in the bits and bytes and cybers. What we've done is we've launched over the past several years a capability that brings that business focus. And so that when we have the conversation in the boardroom, instead of delivering a tactical dive and look, you may be fortunate to have one or two board members that have a tech background. And that's great.
Speaker A: Right.
Speaker B: We encourage that. But the goal is to provide the entirety of the board with visibility.
Speaker A: Right.
Speaker B: And that's what we call proper governance.
Speaker A: Right.
Speaker B: It shouldn't be pigeonholed to a specific individual. It should be the entirety of the board, really engage on this topic and then properly govern and pull the triggers and pull the levers across your organization in order to manage this risk accordingly.
Speaker A: Super cool. Thanks for the, thanks for the context setting. Chris. In the background. I'm curious, I'd love to dive into the how. Right. How you demonstrate, uh, and quantify that risk to the board. I'm curious, what are the problems you see in organizations, uh, that don't have that alignment. Right. Where kind of the before and after. Let's talk about the before. Before you go through this transformation or maybe before. Yeah. The work you've done or, or kind of the outcomes you've seen, um, which we'll get to. But tell me about like, what's the before. What are the. What is the relationship maybe with the CISO on the board or the CIO on the board? What does it look like? And what sort of problems do you see that, that you're trying to address?
Speaker B: Yeah, it's a great question. You know, I would say based on our recent surveys through the NACD community and um, obviously my engagement with the NASDAQ center for Board Excellence, I'd say roughly 70% of our board members are still not in tune with the deep tactical dynamic in terms of how the threat landscape or how AI, uh, now we're talking about post quant computing can materially impact their business and the boardroom community is being pressured to adopt advanced technology such as artificial intelligence. And how do we automate processes, how do we drive go to market efficiency? And so we're still seeing a disconnect between the inner workings of tech, including cyber, and its relationship to the board and how these levers and these capabilities align to strategy in terms of growth, to different markets out aligns to managing your financial condition in terms of exposure. And so we're trying to pull this kind of shift in a very methodical way.
Speaker A: Right.
Speaker B: But it's a major ship that we're moving into a position where we're contextualizing the cyber dynamic, the supply chain dynamic, the AI dynamic. Now we're talking about post quantum to a level that resonates with the board. And short of having a bench of technology experts that could really dive in, unfortunately we're seeing very limited touch points between the CISO and the board. It ranges from this individual. The CISO may have a 20 minute briefing with the audit committee once a year, or in highly regulated environments, they may be more of a touch point on a quarterly basis. And now with the shift, with adoption of artificial intelligence, advanced computing power, obviously we have the whole geopolitical dynamic. We're still operating in a modality in terms of governing and managing this risk based on the threats we've seen 20 years ago. So we need to evolve, particularly as we see the compression between the time to attack. When I was a ciso, the reconnaissance period would take like three or four months and then I would see some type of infiltration on the network. And then you contain now with AI that's being compressed to minutes. Right. And so how do we govern that capability at the top of the house, including enterprise risk management, to address this ongoing dynamic that's going to be increasingly becoming more complex but more efficient in terms of executing these types of attacks.
Speaker A: Super helpful. That's very interesting. Um, I'm curious, you mentioned something earlier around translating maybe the business impacts of cybersecurity. And I know I'd love to talk about like, you know, quantifying risk and maybe we can segue into that. Uh, but I'd also love to understand like what do you see as maybe some best practices for what should be reported to the board, a lot of our guests on this show, and even, you know, uh, throughout my career I've noticed, you know, some people take angles of, I mean there's also different angles. Obviously there's a regulatory for highly regulated, you know, reporting on exam findings or uh, audit findings or success rates There and then there's, you know, everything from, uh, getting deals done. Right. I know, like a lot of organizations have, you know, cyber security is a big, a big part of. We had one guest on the show that, you know, they have an AI native. They're an AI native company. Right. So cyber security is involved in like every deal. Right. From a security standpoint. So I'm just curious, uh, yeah. How do you, how do you. Yeah. What are some of those things you look at as far as what to report to the board as it relates to business impacts? Because there could be a lot. And then I'd love to get into maybe even the ROI or quantifying side as well.
Speaker B: Yeah. So the way I typically examine an organization is really, you know, top down, bottom up, left to right, laterally. And what I mean by that is, you know, let's look at the board construct. Right. Do you have a technology committee? Do you have a, uh, committee focused on cyber AI? And if you're in the business of advancing technology, reliant on the supply chain, integrating AI, and you see that as a strategic value, you know, we try to examine that governance construct at the top of the house to make sure that there's focus right there needs to be focused, there needs to be some level of touch point. Look, if they don't have the expert expertise within the boardroom, there are plenty of external experts. Like I. I engage roughly a dozen or so boards on an annual basis where I'll be pulled in, I'll sit with the board, engage with the ciso, examine their metrics and provide, you know, critical feedback. And it's helpful because I can serve as that interpretive layer. The second layer is really that lateral dynamic where there must be some level of integration of technology as part of enterprise risk management. And if you're a complex organization that runs globally and you don't have that enterprise risk management layer, what happens is the CISO tends to operate within isolation, has lack of visibility across the entirety of the enterprise. And, you know, I'm more slanted towards highly regulated institutions because I spent, you know, 25 years on wall Street. But outside of the highly regulated institutions, the. Our view, in my view, is that that enterprise risk management layer is lacking. And So I encourage CEOs and boards and CISOs to create an enterprise risk management structure where you have folks from operational risk, perhaps you have your traditional operations function, hr, legal compliance, finance, and plugging in the technology as part of that enterprise risk management function now allows this function to have that visibility on a Broad basis so that when they're presenting to the board and they're aligning cybersecurity budget it actually aligns to true enterprise risk. But without that layer Taylor, unfortunately you know you can spend hundreds of millions of dollars on cybersecurity but without that layer, CISO tends to operate in their own island and has very limited visibility in terms of the contours of the business to make sure that you're de risking that business appropriately.
Speaker A: Interesting. I'd love to go a little bit deeper in that. Can you tell me a little bit more about the enterprise risk side? Like uh, yeah. What if you were advising a board and or a ah, CISO in a non highly regulated industry that doesn't have that. What are the steps should they take to establish that and get or get ingrained, you know, you know or at least. Yeah. What are your thoughts on that?
Speaker B: Yeah, so yeah, I've done this repeatedly within financial services so we had no choice because we had the regulatory mandate. But if you're non regulated and uh, you don't have that enterprise risk management structure, start to identify those key pillars. You know who's in charge of M and A, Is there an individual responsible for finance? Of course there's a cfo. Is there a chief risk officer, somebody that's responsible for HR legal compliance and having those individuals part of the enterprise risk management committee and then defining it through a well documented charter. What are the roles, responsibilities and create a risk register like what's most important to me as a company. If I'm in healthcare and I possess and manage significant amount of healthcare information, personal health, healthcare data, then that's probably going to be a priority for me. In terms of privacy. If you're in the manufacturing business, operational uptime is going to be critical. So having folks that are responsible for the manufacturing floors in the factories part of that discussion. So that you as a CISO and a CIO have visibility into those components that run your business and so defining that through a ah, well defined charter, having roles, responsibilities, defining the frequency what top risks are being identified and then having an alignment in a framework in place such as COSO coast actually has a incredible framework that allows for defining enterprise risk management as well as a plugin for cybersecurity. So once you have that enterprise risk view in terms of understanding the contours and dynamics of the business now I could start to think about so based on these top end threats I have, I'll make up the number $200 million right to spend on cybersecurity I know business interruption downtime is going to be a significant cost. I know because I have my folks from the privacy team that personal data is particularly critical and can represent material amount of fines and regulatory pressure. I know that, um, we work with our finance team and they move and transact tens of millions of dollars a day. So wire transfer fraud is going to be critical. So again, it's allowing that integration, net visibility into all these risk domains so that the CISO now has the budget aligned with those top threats, aligned with business impact, and more importantly, having that engagement collectively in the board. It shouldn't be the CISO in isolation reporting to the board. It should be the CISO in tandem with the heads of business, in tandem with the cfo, with the chief risk officer. That this is represented as more of a broader view versus a tech issue.
Speaker A: Super interesting. I love that. Uh, uh, yeah, that's. It's fascinating to. It sounds like the opportunity to not only others understand other business risk factors, but kind of get ingrained in this overarching. Yeah, obviously, enterprise risk committee is the way to get a seat at the table. I'm hearing you correctly from the CISO side. Tell me about what happens if they don't have that right. If they're, hey, if there is no enterprise risk, you know, uh, committee or there is no chief risk officer and, you know, this, the CISOs over here in the. And the, you know, not having this, you know, kind of overarching committee, is it. Hey, you, you should, you know. Uh, yeah. What kind of problems do you see when CISOs are trying to work when they don't have that kind of structure in place?
Speaker B: The primary issue is lack of visibility into the, the motion of the business. For instance, if you're a business that you're growing, you're expected to grow 20% year over year.
Speaker A: Right.
Speaker B: And your growth strategy is through acquisition. So I'm going to go buy companies and piece them together. If the CISO doesn't have visibility into that M and A activity, then what happens is it becomes highly distributed and difficult to manage. So data breaches occur. You acquire an asset that's been compromised. Right. And it's integrated into your networks, becomes more of a reactive position we are seeking to go towards is more what we call left a boom, more proactive. And so, uh, and then of course, you know, I mentioned before, it's the budget allocation. I mean, again, you could throw hundreds of millions of dollars at cybersecurity, but with that visibility into the, you know, the dynamics of your Business where, what markets are you growing to? What types of technology are you integrating into the business? Where are your suppliers? Right. The supply chain exposure, like, without that visibility, again, you know, you could be sitting on hundreds of millions of dollars and still an unprotected enterprise. And so, and I would argue, and we see this a lot during our work with boards, members and enterprise risk using, you know, advanced insights and analytics, particularly around, um, loss ratios. We see the inflated budgets. Right. And the opportunity to reallocate capital in areas that are mo more important to you as a business. And so having that, um, that view is, is just going to have a level of success for you as a ciso. And unfortunately, like I said, if, if you don't have that visibility, that seat at, you're essentially operating in isolation. And that is not best practice at all.
Speaker A: Yeah, thanks for sharing. That makes a lot of sense. And even, um, yeah, I think as a part of the enterprise, risk makes a ton of sense. And I've heard, you know, other CISOs and other folks on the show talk a lot about the idea of ultimately like, you know, building relationships with their peers, understanding what their priorities are, and then figuring out how to leverage, you know, our. How to integrate the priorities. Right. But I love that obviously focus on like risk. Tell me about. So, uh, let's. Actually, I'd love to finish the, the thread on, on risk and tell me about how you quantify risk. I know like, there's obviously fair out there. There's lots, uh, of different, uh, kind of methodologies and ways. But how do you connect? Here's all the, you know, here's all the business units, here's all the potential risks. Here is the, you know, the financial, you know, here, here's a financial impact, I presume. How do you, how do you calculate that? What, what, you know, and then maybe in that, the way you see it, how is that different from others? Right? How are you like, hey, you know what? I think our model or our approach. Yeah, I'd love to hear kind of your approach to it.
Speaker B: Yeah. Well, first and foremost, it's having the visibility, right. In terms of the dynamics of your business. It's, you know, what's the revenue? Where is the revenue source from? Is it international? Is it domestic? What countries are you operating in? What types of data do you possess? Is it phi, is it pii, is it PCI data? Um, are you heavily reliant on intellectual property?
Speaker A: Right.
Speaker B: Tied to, let's say, the latest and greatest cancer treatment drug?
Speaker A: Right.
Speaker B: If you're in a Big Pharma business. So really understanding the dynamics of the business and then incorporating that, uh, as part of your program to make sure that you have the right budget allocation to those areas that are most risky. I spent about three years in the insurance industry working with some of the largest brokers and carriers here in New York to evaluate different methods and capabilities around sizing the overall exposure at the enterprise level based on specific categories of risk. So we at the NACD have, uh, selected an approach that advances a capability that aligns to how the insurance markets price cyber exposure. It's called annual loss expectancy analysis and it, uh, leverages a significant amount of industry benchmarks. We get very specific to your peer group because, you know, we have to bring context to the risk. Big Pharma is going to look different than a hospital. The insurance industries is going to look different than, let's say, a capital markets business running a trading platform. So really getting specific to those peers and extracting where those losses are most likely to occur. Manufacturing, their biggest exposure is business interruption, your inability to produce products, banking, financial services. It could be loss of personal identifiable information, account data. But if you're running a trading platform that transacts, let's say, $10 million a day in equities trading, then availability is going to be important, including integrity. So we align a lot of our insights in terms of how the losses are likely to occur based on actuarial data, an actuarial approach, and we inform that outcome, um, aligned to specific categories of risk. So we look at, uh, wire transfer, fraud, business interruption, and somewhere loss of intellectual property. These are all very distinct categories of risk that are used by the insurance markets. And we always say, you know, the ultimate arbitur for any type of risk domain, whether it be hurricane risk or flood insurance, flood risk or a fire, is the insurance markets. And I've been engaged with Lloyds and some of the largest CEOs in the brokering space as well as the carrier space to kind of condition myself and our platform within the boardroom community to understand how these dynamics are happening and how we can be more effective in our boardroom. So actually we've selected an approach for our members at the nacd. It's on our website that has this type of capability. We look at supply chain exposure, we evaluate AI risk now. And once the understanding of the dynamics of the business is incorporated into the platform, then we're able to say, okay, so based on your condition, your peer group, based on your maturity level.
Speaker A: Right.
Speaker B: And we take kind of an agnostic approach. Like we could evaluate any maturity framework under the sun, whether it be nist, ISO, mitre. And then based on your capability to manage that risk, then we have the residual exposure. We help them think through what, what, what's the right level of insurance you should have. And then the balance is okay. So based on this residual exposure, I'll make up the number. You know, $200 million in an unjust cyber risk, here are the most likely categories that they're going to manifest. It could be ransomware. You have exposure around intellectual property theft, you have exposure on business interruption because you may not have immutable backups to recover, right from a type of denial service attack or a ransomware attack. And then from there we help to inform where to invest. And this is where we differentiate in our approach. So you know, traditional models like FAIR and all these other concepts, um, project a potential loss. But we go a step further, we actually substantiate that loss based on your specific industry group and based on dynamics of the company. But we also help to inform based on your exposure, here's where you should deploy capital, you should improve mfa, you should expand your endpoint detection capability, deploy immutable backups right across these various systems. And as we trend this over time, ideally the company should be realizing and de risking of the exposure. Now the reverse could happen, right? We can have a zero day exploit that we're all exposed to and suddenly we might see increase in risk. If you decide to expand as a business as a different regions, right into different countries that maybe have geopolitical exposure, your risk may increase. But that's a really a decision point and an articulation of how these threats are going to manifest to the business, resonates to the board, resonates to the cfo, the CEO, enterprise risk. And it's incumbent upon the board of directors and the C suite to make a determination as to how much risk we will accept. Can we transfer some of this risk using some type of vehicle, whether it be insurance or other vehicles. And then based on the residual exposure, I've got $200 million in capital deployed towards cyber. Where do we deploy that and prioritize it. And this continues to repeat month over month, quarter over quarter. And it's been a very successful approach. We have testimonials, uh, from board members say hey, we love this approach. It goes beyond the maturity scoring, right? Uh, goes beyond the deep technical operational metrics such as patching penetration. And you know, now at the age of these advanced frontier AI models, like I would Argue that we probably have to have more frequent reporting to the board, maybe weekly. Right. Particularly as you see platforms like Methos and all these other different platforms that, uh, are running exploitations in a very efficient way. Like, if I'm just waiting for my annual update from the ciso, like, those days are over.
Speaker A: Right.
Speaker B: Like, we have to shift that whole dynamic.
Speaker A: Wow. Yeah, well said. And I think that I'd love to get into some, if we have time, some quantum computing and even AI and talk a little bit more about that before we get there. I would love to hear first, I think, hearing from the board that they love this form of reporting or they're way more bought in. So powerful. Right. I think that's like the. The aha moment of like, oh, wow, the board actually wants this. Right. And Right. This is. This is, uh, something that, you know, I think, uh, yeah. That, uh, obviously speaks to the effectiveness of it. I'm curious, what other impacts do you see? Obviously a board being like, wow, this is super helpful. Yeah. Just tell me about some of the other impacts of being able to quantify the risk, um, and have some sort of dollar associated with it. Yeah. Any other, Any other outcomes you found from, uh, from it?
Speaker B: Yeah, I mean, the feedback we receive is. It's a language that we understand.
Speaker A: Right.
Speaker B: It's a, uh, I don't have to be fearful that I don't understand what's being reported. Right. And so we see more engagement around the entirety of the board, and we actually see, uh, efficient alignment of capital. There's a lot of frustration in the audit committee that, you know, the CISO may have asked for 20 million in capital last quarter. Now we need another 10. Where is that capital being deployed? And so helping to align that budget to business risk and optimization is also a big benefit. So we just, you know, again, we're trying to knock down every board at a time to make sure that we have a consistent approach. And, yeah, one could argue, like, you know, if you sit on three publicly traded boards, probably have three different cyber risk metrics.
Speaker A: Right.
Speaker B: Juxtapose that to, you know, reading a financial statement. You know, there's. There's accounting principles like gaap. We understand profit and loss. We have interest rates that we have to line to. We need a very similar approach to reporting on cyber threats, including now with AI.
Speaker A: So, so interesting. And, uh, and I think most audience knows this, but my day job is I work for head of marketing for Reveal Security, and we have our own cyber risk quantification model that we use mostly work we actually work a lot in highly regulated industries, mostly mid market companies though. And uh, yeah, uh, that's small to mid market banks, credit unions, things like that. And I've seen the impact of it firsthand. So like I'm definitely, I'm a believer in risk, cyber risk quantification. But if you look at the stats, you'll actually see that, you know, I mean, I don't know how much it is in the enterprise, maybe enterprises has adopted it more, uh, but in general, you know, you know, it's not low, low double digits. Right. Where, uh, from the research I've seen on organizations actually adopting cyber risk quantification, I'm curious your thoughts on that and where. And you just said it just a second ago. You know, if, if you sit on three boards, you could have three different metrics. Why hasn't there been, you know. Uh, yeah, why hasn't adoption of, you know, cyber risk quantification, uh, you know, been more prevalent? And you know, maybe I'm generalizing obviously for the whole economy, but um, yeah, I'd be curious your thoughts even in enterprise or highly regulated industries.
Speaker B: Uh, yeah, look, we view cybersecurity risk quantification as a component of the entirety of the engagement with the board. It's more than just quantifying the risk. It's expressing the risk to business impact, original impact. It's not just putting a dollar sign. And then of course it's through remediation efforts. Part of the problem that we have in the industry, just putting the quantification risk aside, is the CISO community are very tactical, right? And they're getting thrusted into the boardroom from the data centers, or they're getting thrusted into the boardroom from the engineering team without having a deep understanding of the business, without having the relationships. And that's a, that's a core problem that we see, particularly as we see a disconnect and the default for the deep technical CISO is to rely on the metrics that they're most comfortable with. Use operational metrics, patching penetration, meantime to detect and respond, you know, phishing, penetration testing, all important metrics. Right. But they belong in the society, in the security operations center and data center. So the, the, the ability to translate that into more of a business friendly approach is where we have a challenge, where we have to create standardization and more of a professionalization of the CISO community so that we have that, you know, that discipline, that structure in place so that we have that, you know, connected tissue with enterprise risk. And the board and that's what we're building towards. We're building towards that within our community, within the Cyber Future foundation where I serve as an advisor. Obviously we're advancing that uh, capability across the NECD with my role at Worldwide Technology. We have an advanced technology executive core capability where all these same principles we've been talking about is core to our capabilities. And again, more importantly, short of, you know, just expressing, here's your exposure, here's your risk, instead of walking away from the problem, let's lean into the problem and let's start building. Let's start re engineering. Like a lot of these AI, uh models that are, uh, identifying vulnerabilities. They're vulnerabilities that have been dated for almost decades. And the reason why certain systems are unpatched because if you patch or change based on these legacy systems, you'll break a business process. And so, you know, how do we think about re engineering for the future? And some of this is going to require significant uplift in terms of investments. And we're not even talking about post quantum computing. PQC is going to kind of flip everything on its head. So now I've got to, you know, survey all of my assets. Uh, right. I have to understand and prioritize those assets to understand the encryption embedded within my organization supply chain. What's our ability to swap out the encryption. And these are not trivial tasks and these are going to cost companies hundreds of millions of dollars to pursue.
Speaker A: Thanks for sharing. Curious. Is there anything else besides, I mean. Yeah, thank you for taking me through your process. Uh, fascinating. And I think the, that work is super important mostly, uh, because I feel like, I mean like, like really any job. The, you have your job, right. And you have your responsibility. But also you have the responsibility understanding what the rest of the organization is doing and the mission of the company and the, what we, how we serve folks and how we make money and yeah, you have to have also that job too of figuring out all that out and how do you integrate, you know, what you do and support what you do? Is there anything else besides like tying risk to business outcomes and then you know, de risking that which is, which is like obviously the is awesome. Is there anything else you tie to? As far as I know, you know, some CISOs like to report on, you know, um, supporting, you know, new innovations and uh, being a part of those other areas. Do you? Yeah. How do you, when you report to the board, is there anything else you include? Yeah. In that area, outside of the, the risk aspects, I would Say it's, it's
Speaker B: really comes down to culture.
Speaker A: Right.
Speaker B: Uh, the, the culture. Setting the tone from the top, from the CEO level. I know it sounds cliche, but, you know, having the CEO, a handful of board members, express the importance of maintaining proper cyber hygiene as part of the ongoing motion of your business and leading by example, the CEO, you know, has, uh, is using his personal email. Right. To, to transact business and not best practice. You're not setting the right tone from the top. So really having that culture in place and having the CEO divine webinars with your employees in town halls expressing the importance of maintaining, you know, areas such as, you know, proper hygiene, you know, look out for phishing emails and potential frauds. That, that really goes such a long way.
Speaker A: Love that. Super great. Well, only have a couple minutes left. I love two small topics, but I would love maybe uh, what should CISOs be reporting to the board or, or uh, thinking about or preparing. Right. To report to the board around AI and post quantum. I'd love it. Just your thoughts on, you know, high level. Um, uh, both of those, both of those small topics.
Speaker B: Yeah, that deserves another few sessions.
Speaker A: Yeah.
Speaker B: Regarding AI is that there's really two dynamics. The adoption of AI by the company to automate process from an agentic capability and realizing that these agents are no different than employees. You know, replace human with agents. There's human error and we're going to have agent error. How do you monitor for that agent? Well, you have to have human in the loop, obviously. But the way to truly manage that agent is to have an agentic monitoring capability. So we're going to see this agentic to agentic dynamic in terms of protection. And then of course the adoption of AI from an adversarial perspective is creating and compressing the timeline for, for executing an attack more effectively. But then on the other side, you can use AI secure, uh, your environment. You know, I work with companies that. I'll just give you an example. My assessment report 10 years ago, it might take an analyst six to eight hours to produce, analyze and produce it, socialize it. I have a couple of companies that can do within minutes.
Speaker A: Right.
Speaker B: Ah. And so utilizing AI to your advantage to defend the enterprise, that's. That's a whole different ballgame. Like at this point we really need to have the conversations now as the Q days on its way. I'm fortunate to work with some incredible folks from the National Security Agency, some of the top leaders, cryptographers, and you know, obviously we do engagement with the intelligence community with the Department of War, government agencies, but really pushing this upstream and out to critical infrastructure, whether it be banks, telecom or power companies. And starting to have that conversation at the top of the house because it's going to require capital, it's going to require material shift and so performing post quantum computing readiness assessments, understanding your exposure, how much it's going to cost you. Right in terms of that lift and then what's that timeline to get there? I would start now.
Speaker A: Thanks Chris. Super interesting, a great conversation. I know we're up on time here. I love um. Yeah, thank you for everything you shared and super interesting insights around uh yeah ultimately building trust with the board, getting more buy in getting ultimately um, yeah our security programs to be successful. How can folks connect with you online this way?
Speaker B: The connected fees on LinkedIn. So I'll share with you my profile as we released this uh, this talk and feel free to hit me up. I'd love to meet different people and love to help the community. Really passionate about this. Thanks for your time.
Speaker A: Thanks Christopher, really appreciate it and thanks everyone for listening. We'll see you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.