Understanding the collaboration potential between the CRO and CISO
Shamane shares her observation of the conversations she had with various CROs about their interactions with the board: “They do not want us to be afraid of being contentious. In fact, they welcome an alternative view!” Part of this alternative view is to pivot your message from one of fear of threats to one the CRO can use to better inform their risk management framework/analysis/taxonomy.
CROs have observed that CISOs can use threatening language to scare the board of directors into a decision. However, from a behavioral and psychological perspective, fear only drives irrational decisions that do not pan out well in the long term.
One such CISO reported during a management meeting that cybercrime would be the third-largest industry in the world within a few years. The CISO did not support these claims with facts nor provide an analysis of the consequences. It’s then unsurprising that the...