“Said the CISO to the Board…”

Information security is a standard agenda item for most corporate Boards, and an area of focus that continues to get their attention. As it should. Fraudulent activity and security incidents are up more than 20% as workforce settings expanded and new work models took shape.

It’s not just a change in how employees work. It’s also a major shift in criminal activity. Security teams have gone from tracking bad characters to monitoring criminal enterprises, and from blocking breaches to managing every dimension of risks. There is no greater threat to the livelihood of a company than a breach in data security. Breaks in security efforts can put a business “out of business” overnight. And every Board member is well aware that’s a lot of liability and risks to manage.

That’s why they often say: “We want to hear from the CISO.”

They ask for an overview of the security strategy, a view of risks and indicators, and a brief on security governance. And every CISO will tell you there’s nothing brief about it.

The world of a CISO today looks a lot like a NASA command center with dashboards, indicators and a small army of resources deep in the trenches of multiple things on any given day. It’s monitoring, assessing, measuring, building, reviewing, testing, and reporting – all in a day’s work.

And it’s one of the toughest communication challenges in companies today.

Because if you’re the CISO, you have to figure out: What do they need to know?

Every CISO has presented to the Board this year. Some more successfully than others. And all CISOs are finding it’s becoming a significant part of their role. So, understanding how to communicate complexity in a clear and concise manner is an essential skill.

And that’s why we’ve helped hundreds of CISOs find the right approach and altitude with Boards.

The focus varies from one company to another, but we use these general guidelines to help CISOs cut through complexity and develop effective Board presentations.

Know your Board – The starting point is to gauge the current perspective of your Board members.  A review of backgrounds and involvement tells you where current inputs on security may be coming from. Do they sit on other Boards or are they currently leading a company with high risks? Most CISOs face a mix of perspectives with some Board members having a decent amount of insight and others having very little. Your content will need to focus on those who know the least as you can’t dismiss the perspective of anyone in the room. But you can leverage the insights and experiences of the more informed if you know their perspective in advance. This gives you a few supporters during the presentation and can identify the more informed questions that will come your way.

Understanding vs Knowledge –  Most CISOs approach their content with a desire to educate a group. And that leads to confusion, a boatload of details and information overload. Unintentionally, the CISO causes this by trying too hard to impart knowledge on a group. Boards don’t seek knowledge; they seek a high level of understanding. And there’s a difference. They want to understand enough about your priorities and strategies to trust that you have the knowledge to run a complex enterprise. But they aren’t seeking to become experts on security topics. So, tell them less about what you know and illustrate more about what you’re doing with that knowledge.

Outside-In View – The Board perspective will be influenced by the latest event or report that has hit the newsstand, other Boards or their colleagues. Leverage external events and security topics to align quickly to how a Board may be thinking and what they’re hearing as current priorities or shifts in the corporate environment. Relate those topics to your internal perspective. This helps them easily contrast the two and consider what may or may not be relevant as they engage with you.

Define What & Why – The hardest discipline to learn is staying away from HOW you deliver on things. They asked for overviews, but they really mean a broad view of what you’re doing and why you’re focused on those areas. They want very little of HOW your team literally does it. That’s too much detail. And it’s when their eyes glaze over. Boards don’t think confusion comes from their lack of understanding. They view it as your inability to be clear. Avoid talking over their heads because the response could knock you off your feet.

Illustrate with Examples – The only place for a little detail is in examples of programs or initiatives. These should be shared as stories or illustrations of a specific program that yielded impact or outcome. Think about these as stories and examples that a Board member might remember and repeat. The detail comes in the set-up and context, not the detail of how the solution was implemented.

Repetition and Structure – These presentations aren’t going away. Just ask the finance group! They’ve got the most experience keeping Boards informed. And they’ve learned to do so with a repeatable structure and high-level enterprise view. CISOs need to find a repeatable structure that allows them to present information in a consistent way. That’s the fastest way to engage and build trust with a Board.

It’s also where we can help. We’ve developed a format and a storyline structure that has helped hundreds of CISOs define the right overview for their organization. And I bet we can help you!

We’re here when you need us.

 

Want a free 15-minute consultation with Sally to see how she can help you or your team prepare for these conversations? Book a call with her now!

Sally Williamson & Associates

Should I Get a Coach?

The timing has never been better for self-reflection, professional development and a little guidance through the uncharted times still ahead.

The last eighteen months were a test for all leaders, and many pulled it off well. But as companies reset and introduce hybrid work models, few leaders have the toolkit or the skill set to manage this way. And very few realize that the expectations of their leadership have reset as well.

Through company surveys and individual assessments, we’re seeing the trends and gaps emerge from the pandemic work styles. Efficiency came through, but so did a drop in impact and alignment with culture and overall inspiration from leaders. Many leaders are surprised to see that employees aren’t as attached to their teams or as aligned to their strategies. Many got too focused on the day-to-day detail and lost some momentum and focus on connecting the bigger picture for their teams.

The shortage of talent doesn’t help because while you may not talk to every employee every day, someone does. Through LinkedIn, social media and online ads, there are constant offers and opportunities put in front of employees to entice them to look around.

A recent survey by Pew Foundation showed that while 65% of employees were happy in their roles, up to 80% said they would consider another opportunity. It’s testing the waters. And it’s all a part of the reset we’re in now and will continue to be in for months to come. Most leaders are trying to juggle all of it.

So yes, the timing has never been better to engage with a coach.

Finding the right coach is an important part of the decision to hire one. As coaching has increased by more than 20% in the last year, there is some confusion about who to hire for what. When we start an engagement, we always ask if the leader had prior experience with a coach. And when they have worked with another coach, we ask them to rate the experience. The collective response is average, and that’s disappointing. It’s a signal that the leader didn’t get what they needed or didn’t take the time to leverage the engagement. A coaching experience should be one of the most valuable tools a leader gets, and that’s why it’s important to understand what you’re asking the coach to deliver.

The term “executive coach” has become a generic one and covers a lot of coaches who do very different things.  Some executive coaches are generalists, and they combine their experience with coaching certification that gives them a process for covering a broad range of topics.  The best ones have tailored their approach and can tell you how they plan to lead you through an engagement. Many coaches are aligned to companies, and they work with teams of leaders in support of business strategy more so than individual skills.

There are coaches who support sales, marketing, technology, finance and just about any function within a company. All are leveraging their experience to help you accelerate yours.

Communication coaching is distinctly different. Working on someone’s brand and influence within a company takes more than experience. An executive coach who has had experience leading a company and galvanizing employees can’t give you that skill. They can only give you that advice. And that may be what leads to disappointing results from an engagement.

To improve communication impact, you need someone who has experience AND expertise. You need more than advice. You need skills coaching and support to develop new habits and intentional choices that change the way you approach communication. It takes true expertise to work on body, voice and connection. And it takes proven tools to help you simplify your approach.

So, choose a coach wisely and determine if you’re looking for advice or skill development. Ask about both the experience of the coach and the deeper expertise in the area that you want to improve. Once you’ve found a coach with the right expertise and chemistry for you, you can get much more than an average experience.

In the year ahead, coaching can help you:

  • Consider your brand and how well you’re gaining visibility amidst company momentum and endless opportunity.
  • Evaluate your impact as a communicator and support your adjustment to a different way of leading a hybrid team.
  • Leverage the lifespan of a project by adding a compelling storyline and key soundbites that make the direction memorable and sustainable over a period of time.
  • Lead a young team to a high-performing team with expanded responsibilities and broader scope.

This year, it will be the difference in leaders who can shift from competent communicators to compelling ones.

It’s already an unprecedented year, and the expectations of leaders will continue to reset. You should take advantage of every opportunity offered to step up and speak out. And we’d like to help you succeed at it.

Call us when you need us!

Sally Williamson & Associates