
Secure & Simple · 2026-06-30 · 42 min
Key moments - from our scoring
Substance score
45 / 100
Five dimensions, 20 points each
Michelle Drolet, CEO of Towerwall, offers practical guidance for CISOs seeking to communicate cybersecurity strategy effectively to corporate boards. The core insight is that boards don't care about technical vulnerabilities or dashboards full of green checkmarks - they care about business impact, dollars-and-cents risk, and how security protects strategic initiatives. Drolet advocates for CISOs to frame cybersecurity as a business enabler rather than a cost center, highlighting how strong security programs directly support sales enablement (by passing customer security questionnaires), reduce liability exposure, and lower cyber insurance premiums. She recommends tabletop exercises with boards and C-suite executives to build threat awareness without overwhelming stakeholders with technical minutiae, maintaining a focus on salient metrics tied to compliance, vendor risk management, and business resilience. Drolet also emphasizes organizational positioning: CISOs should ideally report to the CFO or CEO rather than the CIO to gain true board credibility and independence in calling out security gaps. Most valuable for CISOs seeking to elevate their executive presence, security leaders wanting to reframe their programs' business value, and board members or audit committee chairs improving governance over cybersecurity risk.
CISOs should talk about business impact, dollars-and-cents consequences of incidents, and how they're building a program aligned with the organization's strategic goals. Focus on limiting blast radius and reputational/financial damage, not technical details like vulnerabilities or dashboards full of green checkmarks.
Metrics should be tied to ROI, compliance status, and strategic impact - such as third-party risk, access controls, critical data protection, blast radius, and sales impact. Present three salient points aligned to the organization's strategic plan rather than overwhelming the board with comprehensive program details.
Strong security programs enable sales by allowing the company to pass security questionnaires from prospects and customers. Without a solid incident response plan, disaster recovery plan, and documented security program, sales teams cannot answer customer security requirements and deals will be lost.
No, tabletop exercises typically run about an hour and occur outside formal board sessions. They serve as knowledge transfer to help board members understand threat scenarios like ransomware and insider threats before the actual board meeting, making those meetings more effective.
The CISO should report to the CFO or CEO (the president of the organization) rather than the CIO. This gives the CISO a real place at the table and independence to address security gaps without being constrained by loyalty to IT leadership's decisions.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode has a handful of useful practitioner points (security as sales enabler via prospect questionnaires, tabletop exercises outside board sessions, CISO reporting line argument) but the core thesis - speak business language, not tech - is repeated many times with little additive substance. Heavy on filler, affirmations, and 'does that make sense?' breaks that dilute the idea-per-minute rate.
how many of you all are answering questionnaires right now? That your salespeople are getting questionnaires from their prospects. And if you don't have a solid information security program plan... they're not gonna be able to make that sale
we do a lot of tabletop exercises with the c suite as well as boards now so that they understand the different elements of a threat
The central argument - CISOs should translate security into business/dollar terms for boards - is thoroughly conventional wisdom in cybersecurity circles, not a contrarian or first-principles take. The CISO-should-not-report-to-CIO point and the sales-enablement framing add mild freshness, but most positions are recycled industry consensus.
the board, we're talking dollars and cents from a catastrophe happening
it's not if, but when
Michelle Drolet is a genuine practitioner - CEO of a cybersecurity services firm with vCISO engagements and real client work - which gives her grounded credibility. However, she is a boutique firm operator rather than a CISO who has run security at scale inside a large enterprise, and the depth of insight reflects that positioning.
our CISO at Tower Wall was a customer for twenty four years before he joined us two years ago
we actually brought in four very, very senior consultants and helped build the whole entire program... we did it in nine months, and they got certified
There are a few concrete anchors - the $4.4M average ransom figure, the $13M exfiltration case over 100+ days, the 60% SMB failure rate post-ransomware, and the 180-question audit distilled to 12 - but most client examples are deliberately anonymised and the mechanisms behind key claims are not substantiated. Several specifics feel asserted rather than sourced.
the ransoms, the the average is $4,400,000
they exfiltrated $13,000,000 in thirty days because they had no idea
The host attempts follow-up drilling (e.g. pushing on how a CISO proves sufficient diligence before an incident, asking about vCISO-specific board dynamics) but frequently defaults to paraphrasing the guest's answer back as a restatement rather than a genuine probe. Soft confirmatory questions dominate and no claim is meaningfully challenged.
So what you're saying is that basically CISOs should somehow drive the agenda when it comes to cybersecurity rather than the boards
I'm just wondering, you know, if there is a way for a CISO to present to the board that you are really doing the maximum that you can
Computed from the transcript - who did the talking, and the words that came up most.
In this Secure and Simple Podcast episode, host Dejan Kosutic (Advisera) interviews Michelle Drolet, CEO and founder of Towerwall, about communicating cybersecurity to corporate boards. Drolet says boards often don’t know what questions to ask, so CISOs should drive the agenda by focusing on incident impact, business risk, and alignment to strategic initiatives rather than vulnerabilities or technical tools. She recommends concise, ROI- and compliance-oriented metrics tied to dollars-and-cents outcomes, limiting “blast radius,” and protecting critical data, while avoiding overly detailed dashboards. She emphasizes having a cybersecurity advocate on the board, running interactive tabletop exercises, addressing cyber as a business enabler affecting sales, insurance, and vendor risk, and using frameworks and regulations as measurable KPIs. The discussion also covers AI adoption with guardrails, CISO reporting lines, and future pressures like quantum planning.
Transcribed and scored by The B2B Podcast Index.
1 - > Dejan Kosutic: Welcome to Secure and Simple Podcast. In this 2 - > podcast, we demystify cybersecurity governance 3 - > compliance with various standards and regulations and 4 - > other topics that are of interest for consultants, CISOs 5 - > and other cybersecurity professionals. Hello, I'm Dejan 6 - > Kosutic, the CEO at Advisera and the host of Secure and Simple 7 - > Podcast. Today, my guest is Michelle Drolet, and she is the 8 - > CEO and the founder of Towerwall, a cybersecurity 9 - > company.
And she's the author of numerous articles in the Forbes, 10 - > SC World, CSO, and others, and she recently published an 11 - > article called Six Tips for Talking More Effectively to 12 - > Corporate Boards. 13 - > So in today's podcast, you'll learn how CISOs should 14 - > communicate with their boards. So welcome to the show, 15 - > Michelle. 16 - > Michelle Drolet: Nice to be here.
Thank you so much. 17 - > Dejan Kosutic: Great to have you here. So tell me, what are kind 18 - > of, let's say, key questions that CISOs can expect from to be 19 - > asked actually by the board? 20 - > Michelle Drolet: So a lot of times the board doesn't know 21 - > what the questions are.
Right? So as CISOs or ISOs, we need to 22 - > walk in there and be able to not talk vulnerabilities, but really 23 - > talk about impact on what could happen inside of an incident. 24 - > And it's not if, but when, and how to help them understand that 25 - > you're actually building a program based on their strategic 26 - > initiatives. 27 - > Dejan Kosutic: Okay.
So, what you're saying is that basically 28 - > CISOs should somehow drive the agenda when it comes to 29 - > cybersecurity rather than the boards. 30 - > Michelle Drolet: Absolutely. Absolutely. Having an advocate 31 - > on the board is really important too.
But coming in and not 32 - > having this huge dashboard that has all these green check marks 33 - > and things like that is not it's it's gonna put everybody to 34 - > sleep. So having key metrics on, you know, what's happening 35 - > across the board, no pun intended, to to help them 36 - > understand that, you know, the board, we're talking dollars and 37 - > cents from a catastrophe happening, and so not just, you 38 - > know, vulnerabilities. 39 - > Does that make sense? 40 - > Dejan Kosutic: Yeah.
Definitely. And you mentioned that CISOs 41 - > should, let's say, paint the picture that they are building a 42 - > security program to the board. So how do you actually do this? 43 - > Michelle Drolet: So the metrics are are based on ROI.
Right? 44 - > It's not just going in and saying, I need a SIEM or I need 45 - > a SASE product. They don't they don't care. It's how are you 46 - > going to limit the blast radius by actually putting repeatable 47 - > processes and a program in place to actually then show that if 48 - > something bad were to happen, it's going to limit what the 49 - > impact is gonna have from a reputational perspective, from a 50 - > dollar and cents perspective.
51 - > And, hey, by the way, now your board is being held accountable 52 - > as well. So, you know, going in and having that, saying, here's 53 - > where our data is. Here's who has access to the data. Because 54 - > what we always say as CISOs, as ISOs, you're all stewards of the 55 - > data, but you're not owners of the data.
56 - > So helping them understand that so that everybody is held 57 - > accountable and that the programs are put in place. 58 - > Dejan Kosutic: And if we can, you know, drill a little bit 59 - > deeper into into, you know, building a security program. So 60 - > does this mean that CISOs should basically explain what are all 61 - > the elements of this program or should they focus only on the on 62 - > the matrix and dollars and cents? Or or what is the best 63 - > way to do it?
64 - > Michelle Drolet: So we look at what are the strategic goals in 65 - > the organization and then build a program around that. I don't 66 - > think that boards care about the details of the program. They 67 - > really care about how you are protecting their information. 68 - > The customer information, the vendor risk profile, vendor risk 69 - > management, all of those types of things.
If you can go and 70 - > say, these are some of the salient points that we're doing, 71 - > but not getting into the minutiae and the detail. 72 - > Because then the CFO is gonna be on his phone or the CEO is gonna 73 - > think about lunch. Right? So we don't wanna shut them down.
We 74 - > want to engage them. And so by engaging, it's actually getting 75 - > them to be part of the program. 76 - > Right? And so we do a lot of tabletop exercises with the c 77 - > suite as well as boards now so that they understand the 78 - > different elements of a threat, of a ransomware attack, of 79 - > insider threats, all of those types of things that they don't 80 - > understand.
And if you can bring that knowledge to them, you know 81 - > what? That's half the battle. 82 - > Dejan Kosutic: But these kind of exercises, are they actually 83 - > part of the, really, the board session, or or this is done 84 - > something that is outside of the the formal board session? 85 - > Michelle Drolet: It's typically outside the board session, and 86 - > they run about an hour.
And it just it just makes a lot of 87 - > sense. And it's it's it's scenario, but it's also really 88 - > about knowledge transfer so that this when you go into that board 89 - > meeting, that they're understanding what's what's 90 - > going on and what they need to pay attention to. 91 - > Dejan Kosutic: Yeah. If that makes sense.
The meetings are 92 - > there much smoother if if they have some kind of a a pre 93 - > knowledge already. And you mentioned that disengagement is 94 - > really important. So from your experience, what kind of, let's 95 - > say, facts or what kind of, let's say, discussions are 96 - > engaging for a CEO or a CFO? 97 - > And, I mean, what kind of things the CISOs should should really 98 - > focus on?
99 - > Michelle Drolet: So when when we're doing these board 100 - > exercises and the c suite exercises, it's really coming in 101 - > and doing, you know, what are some of the threats that are out 102 - > there? What what type of data does your organization have that 103 - > needs to be protected? And then going through some scenarios, 104 - > like a ransomware attack or an insider threat or different 105 - > things like that. So it's scenario based.
So then it's 106 - > very, very interactive, and it really helps them get an idea of 107 - > what you're trying to accomplish. 108 - > And it can go back to that dollar and cents and, you know, 109 - > just risk and risk mitigation, if that makes sense. 110 - > Dejan Kosutic: And and what you're saying is that even 111 - > though these are cybersecurity topics, right, the ransomwares 112 - > and and all these, they're still interested in in if you actually 113 - > present them as kind of what scenarios, if I understood well.
114 - > Michelle Drolet: Absolutely. And and it's very engaging, and 115 - > there's a lot of good conversation during the session 116 - > as well as after the session. It's it's really, really good. 117 - > Dejan Kosutic: You mentioned also that the CISOs should have 118 - > I mean, the boards should have someone as as an advocate of of 119 - > cybersecurity as part of the board.
So who is typically this 120 - > person? I mean, what is the pro the best profile of the person 121 - > who can who could be an advocate on on the board? 122 - > Michelle Drolet: It would be someone like your audience, 123 - > actually, somebody that sat in the CISO position or ISO 124 - > position or CIO position, you know, that has had security 125 - > reporting to them. Right?
Mhmm. So that that they can they can 126 - > help the other members of the board really understand that 127 - > cybersecurity or information security isn't a cost center. 128 - > It's not a cost center. 129 - > And if it's thought of as a cost center, it's never gonna be 130 - > taken seriously.
And so it really needs the information 131 - > security or cybersecurity team or CISO needs to really come in 132 - > and help them understand that, you know, if they don't have a 133 - > good, strong information security program, you know, the 134 - > the liability to the organization, the threats, the 135 - > exposure, they could be down not just for a couple days, but 136 - > weeks or months and out of business, reputational damage, 137 - > all of those types of things. 138 - > Dejan Kosutic: Okay.
But, I mean, still, most companies are 139 - > still considering, you know, the cyber as a cost center. Right? 140 - > How do you actually then make a case that this is something 141 - > more? 142 - > And do you actually go in this direction resilience, or are you 143 - > making some, let's say, other arguments 144 - > that positions the cyber.
145 - > Michelle Drolet: So resilience is is perfect also to business 146 - > performance. 147 - > Right? So looking at, you know, if we don't do this, this could 148 - > happen. Or if we don't do this, from a regulatory and compliance 149 - > perspective, you know, we like CMMC, for instance, right now.
150 - > Yep. I mean, you you can't do work with the government unless 151 - > you are CMMC certified. 152 - > So there is business impact to that. And so being able to to 153 - > sell that not just as a checkoff box, but actually make it 154 - > programmatic so that they understand that you're 155 - > mitigating risk and and business exposure across the board.
156 - > Dejan Kosutic: So on one hand, there is the resilience. On the 157 - > other hand, there is a compliance. But you also 158 - > mentioned business performance, if I understood well. 159 - > So how could actually cybersecurity improve a business 160 - > performance?
I don't know. Sales, profitability, margins, 161 - > these kind of things. 162 - > Michelle Drolet: That's that's a great question. So you think 163 - > about, again, it's not a cost center.
How many of you all are 164 - > answering questionnaires right now? That your salespeople are 165 - > getting questionnaires from their prospects. And if you 166 - > don't have a solid information security program plan and can 167 - > answer that you have an incident response plan, a disaster 168 - > recovery plan, a name it, you know, that that you're not gonna 169 - > be able to, answer that questionnaire, and they're not 170 - > gonna be able to make that sale. 171 - > Well, that has impact, and now it's gonna have impact on the 172 - > CEO.
It's gonna have impact on the CFO. And so having that 173 - > strong information security program with those repeatable 174 - > processes now, again, goes back into business, not just a cost 175 - > center. Does that make sense? 176 - > Dejan Kosutic: Yeah.
And are you saying that CISOs should bay 177 - > basically build their security program based on on expected, 178 - > let's say, requirements from future customers? 179 - > Michelle Drolet: I it I don't know if it would be a 100% that, 180 - > because there's a lot of aspects, right, from the people, 181 - > the processes, the policies, and the the partnerships. Right? 182 - > Mhmm.
But they do need to think about or you do need to think 183 - > about, what are the elements and making sure that everything if 184 - > you come in and get audited by one of those clients, that 185 - > you're gonna be able to show. And so we're actually hired 186 - > every once in a while to come in and go in and audit those those 187 - > questionnaires and say, okay. 188 - > Show me. We just did it for a a very, large bank, and we audited 189 - > them for a a financial institution.
And and we took out 190 - > of a 180 questions, we took 12 and said, okay. Show us how 191 - > you're doing this stuff. 192 - > So, you know, just thinking about that. And then also, you 193 - > you add that vendor risk management component too, and 194 - > the insurance component.
So doing all the different things 195 - > and building out your programs and being able to show, it's 196 - > gonna keep your cyber insurance premiums lower too. 197 - > Dejan Kosutic: Lower. Yeah. Mhmm.
Mhmm. Now if, let's say, a 198 - > CISO wants to kind of, anticipate what are the business 199 - > needs, how then should CISO be, let's say, positioned in the 200 - > organization to to actually better understand what is the 201 - > business strategy? 202 - > So how would that work? 203 - > Michelle Drolet: So my my thought forever is that the CISO 204 - > does not report to the CIO, but in a true and I need to say this 205 - > cautiously.
But in an organization where the CISO 206 - > reports to either the CFO or really realistically the CEO or 207 - > the president of the organization, then they have a 208 - > real place at the table, and information security or 209 - > cybersecurity is is taken very seriously. Because sometimes if 210 - > you're reporting to the the CIO, it's hard to call their baby 211 - > ugly, so to speak. So different things can happen, and so your 212 - > hands get tied. 213 - > Dejan Kosutic: Yep.
You mentioned also the board 214 - > accountability. I assume that you're mentioning this from a 215 - > cyber perspective. So, how can actually CISOs enable boards to 216 - > understand their cyber obligations in a better way? 217 - > Michelle Drolet: I think it goes back to that awareness 218 - > component.
219 - > Alright. And doing those those tabletop exercises and helping 220 - > them understand, providing, you know, articles and going and 221 - > just having a place at the table, not on a annual basis, 222 - > but at every board meeting. Right? You need to be there at 223 - > every board meeting, and it could be just a five minute 224 - > conversation.
But tips and tricks and things that are 225 - > happening out in real world and then what's happening inside 226 - > your organization. 227 - > And it's not about technology, but, again, it goes back to 228 - > business risk. And if you don't get this or get that budget, 229 - > it's gonna have impact from a sales perspective as well as a 230 - > liability perspective. 231 - > Dejan Kosutic: Now let's speak a little bit about matrix.
232 - > Obviously, this is what the boards are always obsessed 233 - > about. So in your view, what what are the best matrix CISOs 234 - > should present, okay, on one hand to the board, but also to 235 - > to other executives in the company? 236 - > Michelle Drolet: So I think the matrix is tied to compliant 237 - > like, compliance matrix. Mhmm.
Also, dollars and cents when 238 - > you're talking about strategic impact or or board impact. And 239 - > so what if if you don't do something I'm gonna give an 240 - > example. So our CISO at Tower Wall was a customer for twenty 241 - > four years before he joined us two years ago. 242 - > And what he says to our clients now is that we don't want to 243 - > have something that just shows all of this stuff, you know, 244 - > from, again, from that people, from the policy, from the 245 - > processes, from the partnerships.
It's three three 246 - > salient points. Okay? So we're doing this. We're doing that.
247 - > We're doing this, and it's tied into our strategic plan. And 248 - > that's different for everybody. But if you can do that he said 249 - > he actually had that, and he took it away and didn't show it 250 - > at one of the his board meetings. And the CFO said, 251 - > where is it?
So if anybody wants to see that, we can we can show 252 - > it at some point. 253 - > Dejan Kosutic: Okay. Can you give some, let's say, different 254 - > examples? Of course, without any company names, but let's say 255 - > different examples of what kind of matrix can work for, let's 256 - > say, one type of a company and what, let's say, other matrix, 257 - > the security matrix can work for a different type of a company.
258 - > Michelle Drolet: So it could it could be on third party third 259 - > party risk. It could be on access. It could be on critical 260 - > data. 261 - > It could be on the matrix of of sales impact.
There's a whole 262 - > bunch of different things. The blast radius. You know, 263 - > protecting that critical data. I had somebody the other day say, 264 - > we don't know where all our critical data is, so we just try 265 - > to protect everything, and that doesn't necessarily work.
266 - > Dejan Kosutic: Yeah. It's too too ambitious. 267 - > Michelle Drolet: Did that answer your question? 268 - > Dejan Kosutic: Yes.
And and they usually I mean, when when you 269 - > show this kind of a matrix, do they usually show them in in in 270 - > a in a monetary a in terms or are using some other KPIs as 271 - > well? 272 - > Michelle Drolet: It it could be monetary terms. It could be 273 - > other KPIs as well. So, again, that blast radius.
And it's not 274 - > vulnerabilities because they don't care about 275 - > vulnerabilities. 276 - > What they care about is that connection into the strategic 277 - > strategic initiatives. And if there's certain specific 278 - > elements of that strategic plan that they can tie into to say, 279 - > we're gonna do these three things Mhmm. To protect this, 280 - > say, IP or whatever it is, then that's gonna help the business 281 - > grow and thrive.
282 - > Dejan Kosutic: Great. Now, how should I mean, obviously, board 283 - > members can ask various questions. And I assume that 284 - > board members are asking, you know, questions like, are we 285 - > secure? Now how should, you know, CISOs handle this kind of 286 - > a situation, this kind of a, well, generic question?
287 - > Michelle Drolet: So the answer to that would be or secure as 288 - > your your budget provide or fight. But, no, that was tongue 289 - > in cheek. I apologize. But, really, it's it's about 290 - > repeatable processes.
So when a board member asks, you know, are 291 - > we secure? 292 - > You know, with all the challenges and all the threats 293 - > that are out there, you know, it's nobody's a 100% secure. 294 - > There's phishing. Right?
There's vishing. There's smishing. 295 - > There's, you know, links that people are clicking on. 296 - > You know, that user awareness is a big component because we want 297 - > our our team members to be, you know, part of our information 298 - > security team.
Right? They're the they're our first defense, 299 - > but you can't stop necessarily people from clicking. And now 300 - > with AI and the bad actors getting way badder and way more 301 - > sophisticated, that happens more frequently than not. And and now 302 - > the ransoms, the the average is $4,400,000.
303 - > That's average. Yeah. So when they ask, are we secure? It's 304 - > like we're as secure as I possibly can make us with the 305 - > budget that we have.
306 - > And so, you know, thinking about that, I go back and and say that 307 - > to them because you can't protect everything. We recently 308 - > had a client, and I don't understand why they did it, but 309 - > they were moving to the cloud. And they had an MDR solution on 310 - > prem, so they had everything being monitored on their servers 311 - > on prem as well as in the cloud. And for some reason, they 312 - > decided to remove the MDR solution from the servers on 313 - > prem and just in the cloud.
And somebody clicked on somebody 314 - > something, and a bad actor got in there. 315 - > And they sat there for it was over a hundred days and watched 316 - > how the CEO communicated with the CFO, and the CFO 317 - > communicated with accounting. And they exfiltrated $13,000,000 318 - > in thirty days because they had no idea. 319 - > Dejan Kosutic: So what you're saying is not if, but when.
320 - > Right? It's not I mean, I mean, incidents will happen. 321 - > Right? And, I mean, from that perspective, how can actually 322 - > CISO ensure the boards that what is being done is actually being 323 - > done enough, especially from the perspective of, let's one day an 324 - > incident will happen.
So how do you actually then say that you 325 - > were diligent enough with your security before the incident 326 - > happened? 327 - > Michelle Drolet: So one of the things we always say is that, 328 - > you know, if somebody if the bad actor really wants to target an 329 - > organization, they're gonna target that organization. But if 330 - > it's kind of a pray and spray type thing, if we can lock our 331 - > doors and lock our windows and maybe shut the shutters so that 332 - > when the bad actors are knocking or trying to pry open the door, 333 - > it's not easy.
They'll go to the next house. And so if you can do 334 - > that, that limits the the target or the access. Right? 335 - > But that's not gonna stop from an absolute targeted attack 336 - > where they're going out and they're doing the research on 337 - > the CEO or the CFO or, you know, an accounting person that they 338 - > know potentially could get to click on something or even an IT 339 - > person that, you know, has admin rights and now they're in.
So it 340 - > just all always depends on what the organization's doing. And so 341 - > just do your due diligence and try to lock things down as much 342 - > as possible. Put guardrails. 343 - > Dejan Kosutic: I agree with you.
You know, the I'm just 344 - > wondering, you know, if there is a way for a CISO to present to 345 - > the board that you are really doing the maximum that you can. 346 - > Right? Because, I mean, if if the board is reasonable, they 347 - > will say, okay. You can't have a 100% security.
348 - > This is not possible. But are you doing the best you can, or 349 - > is there some, let's say, room for improvement? This is, you 350 - > know, what I'm wondering. If if the CISO can present this effort 351 - > and how to present this effort to to to the board.
352 - > Michelle Drolet: So there's always room for improvement, and 353 - > there's always more budget needed. Needed. Yep. And so when 354 - > we think about that, we don't wanna we don't wanna sell on 355 - > scare tactics, but we do wanna sell on risk based security.
And 356 - > so if we can do that, that's gonna go a long way. 357 - > That if we don't do this, this could have this impact. And and 358 - > that's not selling fear, uncertainty, and doubt, but 359 - > selling, you know, true impact to the business. And that's what 360 - > you need to do is if you don't do these things.
And, again, 361 - > it's not it's not the widget that they care about. It's the 362 - > protection of the data or the assets or the people or your 363 - > customer list. 364 - > Dejan Kosutic: Okay. Makes sense.
Now you mentioned also 365 - > CMSE, but there are other security frameworks out there 366 - > like NIST Cybersecurity Framework, ISO 27,001, and so 367 - > on. So should the CISO really present any of these to the 368 - > board, or is this kind of irrelevant for the board level? 369 - > Michelle Drolet: I personally think that regulatory 370 - > requirements are the CISOs friend. Right?
Because you have 371 - > to I mean, with GLBA, for example, higher ed right now, 372 - > they're getting audited by the federal government. And if you 373 - > are not GLBA ready and something were to happen, there's huge 374 - > fines attached to that. So if we can utilize those regulatory 375 - > requirements or compliance requirements, but not just as a 376 - > checkoff box, but truly as a measurable metrics, just like 377 - > what we were talking about to show you don't need to get into, 378 - > you know, the minutiae of what is in CMMC.
379 - > But to talk about that we are CMMC compliant or we are GLBA 380 - > compliant or we're PCI compliant or, you know, GDPR compliant, 381 - > now all these states have all these privacy regulations like 382 - > CCPA in California. I'm in Massachusetts. MIPSA is coming 383 - > out. And so that's gonna be, you know, a privacy and security 384 - > regulation that is it's gonna go up against GDPR.
Yeah. 385 - > So there's a lot there there. Mhmm. But to utilize that to 386 - > their strength, not just as a checkoff box.
387 - > Dejan Kosutic: Yeah. And to utilize them as as you were 388 - > saying as a KPI kind of. Right? The level of compliance for each 389 - > of those.
Yeah. Okay. We touched upon a little bit of on AI and 390 - > but how what do you think how is AI changing the job of the CISO, 391 - > especially when it comes to communication with the board? 392 - > Michelle Drolet: With AI, and I just I just read an article 393 - > actually, and it's it it stated that if we do not embrace AI and 394 - > agentic AI and all of those different things, it's going to 395 - > be like email back in the nineties where the CEO said, I 396 - > don't need email.
I don't need email. And those people are not 397 - > in business any longer. So Yep. We have to embrace AI, but we 398 - > need to embrace it with guardrails on it.
And we need to 399 - > have the use cases, and the board needs to understand what 400 - > those use cases are, instead of just we have some clients right 401 - > now that are just saying the board and the c suite are 402 - > saying, we wanna use AI. Just go do it. And it's like, okay. You 403 - > know, as as stewards of the data, the CISOs and the ISOs and 404 - > the CIOs actually, you know, need to understand, you know, 405 - > where that where that data is, who has access to the data, and 406 - > then what is AI doing.
407 - > Because we know AI lies, and it will it will change. I just 408 - > listened to a a presentation on quantum computing and AI, and 409 - > just the the changes that that's gonna have across the board, but 410 - > that's a whole different topic. 411 - > Dejan Kosutic: And, I mean, yeah, it's interesting this I 412 - > mean, really to handle AI in in a responsible way and try and 413 - > make AI trustworthy, companies will have to introduce 414 - > Michelle Drolet: I don't think it's ever trustworthy.
Sorry? I 415 - > said I don't think it's ever quite trustworthy. 416 - > Dejan Kosutic: Yeah. Right now, not, but I hope that we will be 417 - > able to drive AI towards trustworthiness, so to say.
And 418 - > if if I mean, obviously, CISOs will have an important role, as 419 - > you were said, as as data stewards there. But do you think 420 - > that CISOs should be actually the main person in charge who 421 - > should who should actually drive this AI governance effort, or 422 - > should they only be the part of the team to actually drive AI 423 - > governance? 424 - > Michelle Drolet: I think that CISOs have a definite place at 425 - > the table. I think risk and compliance, if the company has a 426 - > risk and compliance team, I think that they need a place at 427 - > the table as well.
And then the, the CEO, CFO, HR, all all of the 428 - > the folks that are going to be utilizing it in their team, they 429 - > need to, to really think about what are the use cases, but what 430 - > are the guardrails and the access and and what AI tool is 431 - > being utilized. Right? So it's Claude or Copilot or ChatGPT or 432 - > AgenTic, you know, AI. 433 - > It's it's all all the different things, and they're all 434 - > leapfrogging each other right now.
And what we don't wanna do 435 - > is be the voice of no because then people are going to figure 436 - > out how to use, and then they're not gonna go and and utilize it 437 - > with the guardrails across the board. So, yes, the CISO and ISO 438 - > definitely needs to have a voice of what can be utilized and what 439 - > can be accessed. 440 - > Dejan Kosutic: Yeah. So, again, security as enabler.
Right? Not 441 - > as as a disabler. 442 - > Michelle Drolet: Yeah. Right.
Exactly. 443 - > Dejan Kosutic: Definitely. And, I mean, obviously, the CISO CISO 444 - > role is is changing a lot. And and okay.
445 - > As we discussed, it goes also in this direction of enabling more 446 - > secure AI. But how do you see actually I mean, you're you're 447 - > long in this business. How do you see that CISOs role has 448 - > changed in the last, I don't know, ten or twenty years? So 449 - > what kind of major changes have happened in the CISO role during 450 - > this period?
451 - > Michelle Drolet: So I think what I have seen in the past, yeah, 452 - > ten, fifteen, twenty years is that the CISO, you all have a 453 - > place at the table way more than you ever have had before. The 454 - > impact to the business that if an information security program 455 - > is not in place can be detrimental. Right? 4,400,000 456 - > may be small to some of your organizations, but in others, in 457 - > SMB, somebody gets hit with a ransomware attack.
Six months 458 - > later, sixty percent of them are out of business. 459 - > So that's serious stuff. So, you know, having having seen the 460 - > CISO actually have a place in a conversation and being in that 461 - > boardroom, is is huge. And, you know, bringing in an 462 - > organization like a tower wall to actually present to the 463 - > board.
I'm actually presenting to one of our clients' boards. 464 - > We did a pen test for them, and then they had a risk assessment 465 - > done. 466 - > So I'm combining all that and doing just a five minute quick 467 - > presentation on impact, the vulnerabilities, but very, very 468 - > high level, and, you know, what they need to pay attention to. 469 - > And if you could do that on a quarterly basis or a monthly 470 - > basis, if that's when the board meeting is, you know what?
471 - > They'll be way more informed, and you will have a way bigger 472 - > budget. 473 - > Dejan Kosutic: Yeah. I mean, what I also noticed is is that 474 - > people are now much better understand what security is and 475 - > actually are willing to to have someone from the security team 476 - > or the CISO actually as part of the senior management, which is 477 - > great. And looking into the future, okay, beyond this, what 478 - > we spoke about AI, what do you think will change in the future 479 - > when it comes to the role of of CISO?
480 - > Michelle Drolet: So we used to be able to go and say, we're 481 - > doing a three and five year plan. You can't do that now, 482 - > especially with quantum. I mean, I was in a presentation, like I 483 - > said, and the CSO, the CIO all need to start doing their 484 - > quantum plans. They said they needed to start doing the 485 - > planning by 2027, 2028 because it's gonna start rolling out in 486 - > 2030.
And so it's everything's moving so fast that, you know, 487 - > trying to keep up with the technology, the the policy 488 - > changes, the regulatory requirements, those are those 489 - > are tough things. 490 - > So surrounding yourself with knowledgeable people and getting 491 - > outside of your four walls is really, really important. Having 492 - > conversations, walking the hall. Yeah.
Think the CISOs that walk 493 - > the hall and really understand so that they're invited to all 494 - > conversations and not have doors shut are going to be the most 495 - > successful. 496 - > Dejan Kosutic: Yeah. I agree with you. Yeah.
And by the way, 497 - > did a podcast episode about Quantum a couple of episodes 498 - > ago. And basically, yeah, 2,030 is kind of the latest prediction 499 - > for Quantum to become effective. 500 - > But actually, it could happen even a year earlier. So it's 501 - > very close.
It will happen very pretty soon. Okay. You mentioned 502 - > that you work also as fractional CISO to other companies, if I 503 - > understood well, right? 504 - > Michelle Drolet: Yes.
vCISO. Exactly. 505 - > Dejan Kosutic: So do you see or better to ask, is it harder to 506 - > be a vCISO and basically work as a CISO from the outside rather 507 - > than working as opposed to someone who is a full time CISO 508 - > from the inside. So do you see that there is a kind of harder 509 - > to do as an outsider?
510 - > Michelle Drolet: The answer to that is depends. So we are 511 - > virtual CISO to a retail a a retail chain. And they have a 512 - > very solid IT director at the organization. But he needed, you 513 - > know, that overlay of information security.
And so 514 - > they didn't need a full time person. 515 - > And so coming in, you know, fifteen or twenty hours a week, 516 - > sometimes it's just ten or ten a week, a month, and putting 517 - > together a project plan and saying, okay. These are the 518 - > things that we're gonna do. These are the trainings that 519 - > we're gonna do and really walk alongside him is has been really 520 - > beneficial.
We also go and sit on the outside of a CISO 521 - > themselves. So we actually we had a a client that started a 522 - > new position, and he didn't realize when he started the 523 - > position that they needed to get ISO certified. 524 - > They had a contract. They were contractually obligated to get 525 - > ISO certified.
They had had, like like, twelve to eighteen 526 - > months. But he got there, and they had six months to get it 527 - > done. And he called, he said, Michelle, we don't have 528 - > anything. 529 - > What are we gonna do?
So we actually brought in four very, 530 - > very senior consultants and helped build the whole entire 531 - > program. And while we didn't do it in six months, we did it in 532 - > nine months, and they got certified. And now they're going 533 - > on their fifth year, and they don't need us anymore. So we 534 - > came in for the first two years, really walked and ran alongside 535 - > of them.
536 - > And so that makes a big difference. But having a trusted 537 - > adviser from the outside is so important because my team or 538 - > other organizations, you know, see, you know, that that 539 - > crowdsourcing, you know, what's happening. And that really helps 540 - > our customers really stay ahead from a threat landscape 541 - > perspective. Did that answer your question?
542 - > Dejan Kosutic: Yes. Yes. Okay. So, obviously, this has pros and 543 - > cons.
Right? 544 - > And okay. When you're a VCSO, is there something else when you 545 - > have to communicate to the company's board? Or, basically, 546 - > all the things that we already mentioned during the interview 547 - > are valid also for vCISOs?
548 - > Michelle Drolet: It's it's all the same for vCISOs or CISOs. 549 - > The communication doesn't change. And the boards the 550 - > boards still need that information, but at a very high 551 - > level. 552 - > Dejan Kosutic: So let's wrap up the call.
And what would be your 553 - > top suggestions for for CISOs? How should they handle the 554 - > board? How how should they handle the communication with 555 - > the board? 556 - > Michelle Drolet: So simplify, be realistic, you know, provide 557 - > really good data, and then, you know, tie it to business 558 - > performance and, you know, keep the guardrails on and help them 559 - > stay informed.
560 - > Dejan Kosutic: Great. So thanks for these insights, Michelle. 561 - > It's it's been a pleasure talking to you. 562 - > Michelle Drolet: Thank you very much.
This is awesome. 563 - > Dejan Kosutic: Thanks again, Michelle. And and thanks 564 - > everyone for listening or watching this podcast and see 565 - > you again in two weeks time in our new episode of Secure and 566 - > Simple Podcast. Thanks for making it this far in today's 567 - > episode of Secure and Simple Podcast.
Here's some useful info 568 - > for consultants and other professionals who do 569 - > cybersecurity governance and compliance for a living. On 570 - > Advisera website you can check out various tools that can help 571 - > your business. 572 - > For example, Conformio software enables you to streamline and 573 - > scale ISO 27,001 implementation and maintenance for your 574 - > clients. White label documentation toolkits for NIS2, 575 - > DORA, ISO 27,001 and other ISO standards enable you to create 576 - > all the required documents for your clients.
Accredited Lead 577 - > auditor and Lead implementer courses for various standards 578 - > and frameworks enable you to show your expertise to potential 579 - > clients. And the learning management system called Company 580 - > Training Academy with numerous videos for NIS2, DORA, ISO 581 - > 27,001 and other frameworks enable you to organize training 582 - > and awareness programs for your clients workforce. Check out the 583 - > links in the description below for more information.
584 - > If you like this podcast, please give it a thumbs up, it helps us 585 - > with better ranking and I would also appreciate if you share it 586 - > with your colleagues. That's it for today, stay safe!
Other episodes covering the same guests and topics, from across The B2B Podcast Index.