WorkNest

Blog

Getting Board Buy-in on Cybersecurity

A look at the cyber problems facing boards & CISOs. Packed with real-life examples useful tips for security managers & smart tactics every board can adopt.

Background Image

As any seasoned cyber security professional will tell you, good security only works when it’s embedded as culture within an organisation – and that must come from the top. But sometimes, the top doesn’t want to know. Even with recent events highlighting the vital importance of cyber security and the average cost of a breach reaching an eye-watering £3 million, many organisations still struggle to get security on the boardroom agenda. This leads to critical levels of under-investment, leaving organisations wide open to cyber attack. Let’s look at the problems in more detail.

Let’s start with the obvious: some boards don’t have a CISO. Not having a CISO means boards are likely to be simply unaware of the very real operational risks to the business that poor cyber security presents. Unaware, that is, until it’s too late: over half of medium and large businesses have suffered a cyber security breach or attack in the last 12 months. Without a board member literally bringing it to the table, it’s going to be an uphill struggle for any security manager to get cyber on the agenda. Even boards who want a CISO might struggle to get one thanks to the security skills gap.

Those boards who do have a CISO, and so have hopefully invested in cyber security in some degree, still face the challenges of making their security investment truly effective in the real-world. This requires the CISO to have the full trust of the board and the resources to move and react quickly. Effective controls can only come from understanding hackers’ motives and abilities, as well as fully analysing the risks of internal threats.

Security service providers can even make matters worse by trading on fear, uncertainty and doubt (something we at Bulletproof work hard to avoid). This only serves to muddy the waters for organisations trying to manage their cyber risk profile as it obscures threats and confuses priorities, which ultimately – and not to mention ironically – can leave businesses less secure.

Source: https://nominetcyber.com/major-global-study-of-senior-cyber-security-professionals-reveals-increasing-pressure-workload-and-budgetary-deficits

Having outlined the problems, the common theme running through these problems is clear to see: lack of knowledge. Boards don’t have a CISO because they don’t know they need one. CISOs don’t always invest wisely because they aren’t given the resources they need to uncover the real threat profile. In our experience, even organisations who have invested wisely in cyber security often lack the capability to detect a hack. To put it more succinctly, board-level investment doesn't include cyber, or cyber controls aren’t effective despite investment, because of a lack of knowledge.

Common security myths

To demonstrate the problem in action, we have some real-life examples from Oliver Pinson-Roxburgh, our Co-founder and from Nicky Whiting, our Head of Consulting. These are all real and repeated scenarios they’ve encountered during the course of their security careers when trying to educate a board on the importance of security.

Talk to an expert

Share your challenge with us and we’ll help you find the right level of support for your business.

Your certified partner

Proven standards, trusted expertise, complete peace of mind

Award logo 1
Award logo 2
Award logo 3
Award logo 4
Award logo 5
Award logo 6
Award logo 7
Worknest logo
© 2020-2026 WorkNest. All rights reserved. (888) 243-3110