Top Banner
SESSION ID: #RSAC Terry Ragsdale Partnership with a CFO: On the Front Line of Cybersecurity GRC-T11 CFO LSQ Funding Group Dr. Christopher Pierson CSO and GC Viewpost @DrChrisPierson
23

Partnership with a CFO: On the Front Line of Cybersecurity

Apr 15, 2017

Download

Technology

Priyanka Aash
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Partnership with a CFO: On the Front Line of Cybersecurity

SESSION ID:

#RSAC

Terry Ragsdale

Partnership with a CFO:On the Front Line ofCybersecurity

GRC-T11

CFOLSQ Funding Group

Dr. Christopher PiersonCSO and GCViewpost@DrChrisPierson

Page 2: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Setting the Stage

2

Page 3: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Setting the Stage

3

Ernst & Young: Americas March 2014 CFO: need to know insights for CFOs

PwC's 2015 Annual Corporate Directors Survey

enRaged?enRaged?

Page 4: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Setting the Stage

4

Ernst & Young: Partnering for performance Part 3: the CFO and the CIO

Page 5: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Setting the Stage

5

4 Key Areas:Understanding DriversEducating PartnersCompelling ArgumentsGovernance & Team

Page 6: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Understanding Drivers

Page 7: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Understanding the Drivers

7

CFO Goals:Business OpportunitiesGenerate ProfitBusiness PredictabilityBoard & Investor RelationsFunding/Capital Raises

CSO/CISO Goals:Not in the NewsReduce Risk/Keep SafeBusiness Enabler

Page 8: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Understanding the Drivers

8

Execution:Trusting the NumbersMaking them Confess

Enablement:House in OrderFunding the Strategy

Development:Defining the StrategyTelling the Story

EY-CFO-need-to-know-Insights-for-CFOs

Page 9: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Understanding the Drivers

9

Risk ReductionFrequencySeverityLikelihood

Metrics to Illustrate

Customer Trust

Ignoring the 0.1% Risks

Page 10: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Educating Partners

Page 11: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Educating Partners: News

11

Cybersecurity Incidents:Your SectorNationwide

Risk Management Data

Risk Data from Insurers

Financial/GAAP PublicationsTarget CFO Testifying before Congress in 2015

Page 12: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Educating Partners: Technology

12

Focus on Consumer Tech

Focus on Impact not TechRisk not Security (directly)Bring back to Business

Transition to Company

Page 13: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Educating Partners: Board/Executives

13

Intense BoardAttention

Reputational ImpactDiffers

Credibility is aBusiness Value

SEC OversightShareholderDerivative SuitsKPMG: Connecting the dots: A proactive approach to cybersecurity oversight in the boardroom

Page 14: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Compelling Arguments

Page 15: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Compelling Arguments: What works?

15

Financial Arguments?Cost SavingsRisk Details

Security Studies/Risk Studies?Breach CostsCybercrime CostsLitigation Costs

Evidence of Current/Past Issues?Tied to Past Control Costs

Page 16: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Compelling Arguments: What works?

16

Tying Controls to Business Goals?

Shifting CapEx to OpEx (from Balance Sheet)?

Streamlining Efficiencies?

Current News?

Fear Mongering?

Page 17: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Compelling Arguments: What works?

17

Page 18: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Compelling Arguments: Hypothetical

18

MDM Management & Encryption

Average Cost of Data Breach in U.S. $154 yr./record

Average Number of Records on Devices – 1,000

Costs of Encryption and MDM per device is $250/yr. per device

Page 19: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Governance & Team

Page 20: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Governance & Team: Risks, Options

20

How do you Communicatethe Risk?

Tracking Results

Ensuring Controls andBudget Solve forMeaningful Business

Tie Business Wins toTeam Efforts

Page 21: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Now What? Application

Page 22: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Start Now Weeks & Months Ahead Within One YearCollecting NewsworthyArticles

Business Goals, Priorities, andOpportunities for Cyberthrough Business Evolution

Tie budget to true risks thathave surfaced recently –especially among competitors

Reviewing Consulting, Board,GAAP, NACD, and FinancialGuidance Materials(KPMG, EY, PwC, and Deloitte)

Review and Track MonetaryResearch (Ponemon, Gartner,Data Breach)

Transition budget from CapExto OpEx models wherepossible and show 3-5 yr. costsavings

Personal technologies to latchonto in terms of risk orbusiness advantage

Options for Enterprise RiskManagement partnerships orcommittees

Getting Board and ExecutiveManagement Interest andcreate business value

Research your CFO, Boardmembers, other Execs

Meet with the CFO when youdo not need anything

Seek financial learningopportunities; help CFO

Time to Apply!

22

Page 23: Partnership with a CFO: On the Front Line of Cybersecurity

#RSAC

Thanks & Contact

23

Dr. Christopher PiersonChief Security Officer & [email protected]

Terry RagsdaleChief Financial OfficerLSQ Funding [email protected]