The 15-Minute, 7-Slide Security Presentation for Your Board of DirectorsMay 29, 2017Help the board understand why cybersecurity is critical to the business. With recent highly publicized security breaches at large companies and organizations, boards of directors and C-level executives are beginning to recognize the importance of cybersecurity and risk.

In fact, Gartner estimates that by 2020, 100% of large enterprises will be asked to report to their board of directors on cybersecurity and technology risk at least annually. Security experts who have been trying to convey the importance of cybersecurity for a long time finally have the opportunity to and the responsibility of presenting key issues to the board.

Unfortunately, security and risk management leaders struggle to present this information to the board in a way that nontechnical executives will understand, and they may fail to get across the main points

“It’s critical that security and risk management leaders supply board-relevant and business-aligned content that is not hampered by overly technical references. “The key to a successful presentation is to ensure that it answers key questions about how cybersecurity can and will support the company’s main mission and business, relevant environmental factors and the extent to which material risks are being managed.

Most importantly, don’t allow the presentation to bog down in overly technical explanations, and ensure each point is high-level enough that the board will understand it, but detailed enough to give them a true picture.

Most importantly, don't allow the presentation to bog down in overly technical explanations, and ensure each point is high-level enough that the board will understand it, but detailed enough to give them a true picture.

Slide 1: Get startedSlide 1 is designed to be the call to attention slide. It needs to be sparse, and simply identify the topics you’ll cover in the following slides.

No details are necessary, but it should signal that the presentation will include information about business execution, strategy, external developments and risk position.

It's high level, and sets the scene for the board

Slides 2 – 6: Performance and contribution to business executionIt can be difficult for CISOs to demonstrate how security contributes to business performance. However, when presenting to the board, it is key to link (implicitly or explicitly) security and risk to business elements that the board members value.

Whatever version of these slides makes sense for your enterprise will enable you to highlight metrics and how the security team is contributing to the positive outcome.

However, you should also be prepared to explain potential problem areas and their implications

Bring more detailed documentation on how each metric was produced for any board member who asks.

Slides 3 through 6 should discuss how external events will affect security, an assessment of the existing risk position (this can change depending on acquisitions and other events) and the entire security strategy

Slide 7: The call to actionFinally, wrap up the presentation with a closing slide to reiterate the main points and any action items.

Summarize the points you’ve made, and be clear about anything you have requested. This is a good time to take questions, and thank the board for their time.