CISOs need to be thinking about their answers to critical questions the CEO is likely to pose. CISOs should be able to easily demonstrate how cybersecurity initiatives and projects are in fact reducing risk, shrinking the attack surface of the organization and aligning the security program with the firm’s overall risk profile. The key to being able to speak to the board is to base their program on a business-focused model. Questions like this are sure to arise as corporate leadership attempts to understand the risk associated with a cyberattack.”]
Source: https://www.govinfosecurity.com/8-tough-questions-every-ciso-should-be-ready-to-answer-a-10357

