{"id":5898,"date":"2018-10-13T15:09:41","date_gmt":"2018-10-13T19:09:41","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=5898"},"modified":"2023-04-07T16:05:06","modified_gmt":"2023-04-07T20:05:06","slug":"talking-to-your-boss-about-cyber-security","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/talking-to-your-boss-about-cyber-security\/","title":{"rendered":"Re-Hashed: Talking to your Boss about Cyber Security &#8211; 5 Helpful Tips"},"content":{"rendered":"<h2>Learn to manage upwards and get your security needs met.<\/h2>\n<p>One of the hardest things IT workers deal with is talking to your boss about Cyber Security. Maybe you report to a manager, a director or even the C-Suite itself. Regardless, this can be a struggle owing to the fact your boss probably doesn\u2019t know, much less understand a lot of the concepts that you\u2019re discussing.<\/p>\n<p>Compounding things even more, their time is valuable, so you\u2019re going to need to manage upwards. You may have to make the pitch in just a few minutes, which can fluster some people. And while you may have a singular focus within your organization, your boss is likely juggling several.<span id=\"newline\"><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7374\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/09\/bigstock-Lock-Vector-Icon-On-White-Back-246867436-300x300.jpg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/09\/bigstock-Lock-Vector-Icon-On-White-Back-246867436-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/09\/bigstock-Lock-Vector-Icon-On-White-Back-246867436-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/09\/bigstock-Lock-Vector-Icon-On-White-Back-246867436-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/09\/bigstock-Lock-Vector-Icon-On-White-Back-246867436.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>Before you can even begin the conversation, here are some things you should be doing:<span id=\"newline\"><\/span><\/p>\n<ul>\n<li>Make sure you spend time rehearsing what you\u2019re going to say. I\u2019m not telling you to stand in front of a mirror like an idiot, but at least read over it several times and make sure you are familiar with it.<\/li>\n<li>Work on your elevator pitch. If you had 30 seconds to explain, what\u2019s the most concise way to do it? Doing this will help you determine what the most crucial elements of your pitch are.<\/li>\n<li>Make sure you bring data. Bosses don\u2019t want anecdotal evidence, they want numbers. Can we afford to take our systems offline that long? Is this a sunken cost? Will this disrupt other workflows? Data can help you answer those questions. Guesswork won\u2019t.<\/li>\n<\/ul>\n<p>Once you\u2019ve prepared to have the discussion with your boss about cyber security, it\u2019s also good to remember exactly what your objective is. For all intents and purposes, you\u2019re now becoming a salesman (or woman) and your goal is to get your boss to buy in to what you\u2019re selling. This isn\u2019t an ask, it\u2019s a negotiation. Don\u2019t come in hoping you\u2019re going to get his support, come in confident. This is a big deal. Then demonstrate why with proven facts and numbers.<\/p>\n<span style=\"--tl-form-height-m:140.667px;--tl-form-height-t:118.1042px;--tl-form-height-d:118.1042px;\" class=\"tl-placeholder-f-type-shortcode_12779 tl-preload-form\"><span><\/span><\/span>\n<p>Here are five more tips for talking to your boss about cybersecurity.<\/p>\n<h2>1.) Establish Some Basic Facts<\/h2>\n<p>As you start this conversation you\u2019re going to want to establish a few things right off the bat. Lay the foundation by citing a few proven facts about what you\u2019re asking for. Don\u2019t overdo it, but try to pick two or three impactful facts \u2013 things that relate to the industry you\u2019re in, or that pertain to competitors. Make sure your boss understands the implications of lagging security, which is what your organization could be opening itself up to if you don\u2019t act.<\/p>\n<p><strong>RELATED<\/strong>: <a href=\"https:\/\/www.thesslstore.com\/blog\/cyber-security-statistics\/\"><em>2023 Cyber Security Statistics<\/em><\/a><\/p>\n<h2>2.) Be ready to do a cost\/benefit analysis<\/h2>\n<p>Your boss and you have different objectives. Yours is cyber security-based. It&#8217;s your job to keep the network safe and your systems up and running, which requires both a reactive and proactive approach. Your boss, on the other hand, is likely more concerned with being profitable and growing the company. You\u2019re about to ask him to invest in something you need, so be ready to explain what the costs would be to do this, and what it might cost if you don\u2019t. Again, this is a good place to have data to back up your claim.<\/p>\n<p><strong>RELATED<\/strong>: <a href=\"https:\/\/www.thesslstore.com\/blog\/cyber-attacks-third-greatest-threat-world\/\"><em>Cyber attacks are the third biggest threat facing mankind<\/em><\/a><\/p>\n<h2>3.) Bring up Compliance<\/h2>\n<p>Depending on where you\u2019re located, there are rules and regulations you must abide by. Whether its HIPAA, PCI DSS or the upcoming GDPR, nobody wants to get slapped with fines and other penalties for not being compliant. Make sure your boss is aware of what your organization\u2019s responsibilities are and what impact failing to follow them would bring. Afterwards, you may want to document that you informed your boss of the regulations and rules that the company might run afoul of. Just send a quick email to your boss, recapping your conversation. That way if heads roll because of compliance issues, your butt will be covered.<\/p>\n<p><strong>RELATED<\/strong>: <a href=\"https:\/\/www.thesslstore.com\/blog\/cybersecurity-compliance-statistics\/\"><em>10 Cybersecurity Compliance Statistics That Show Why You Must Up Your Cybersecurity Game<\/em><\/a><\/p>\n<h2>4.) Identify the biggest gaps in your security<\/h2>\n<p>Ideally, you should be running regular scans and penetration tests on your digital infrastructure. This will help inform you where the biggest vulnerabilities are. Take this information and categorize it by order of severity. This will help inform your boss about where the fire is and what it would take to put it out. Remember, you may not get everything you ask for. So prioritizing the gaps in terms of severity can make sure you get the most critical things taken care of.<\/p>\n<p>RELATED: <a href=\"https:\/\/www.thesslstore.com\/blog\/cyber-risk-assessment\/\"><em>How to Perform a Risk Assessment<\/em><\/a><\/p>\n<h2>5.) Make sure your boss can effectively explain things to his boss<\/h2>\n<p>This may not apply to some of you\u00a0&#8211; you may be pitching your ideas directly to the C-Suite or the Board. In which case, I\u2019ve done all I can for you. But oftentimes, your boss may not be the decision-maker. Your boss may need to take it to their boss to get approval. Remember that elevator pitch we discussed earlier? That\u2019s a good guide in terms of identifying the key information your boss needs to take away. Try not to use too much technical jargon, focus on benefits and costs and make sure you have at least one or two important statistics or facts that they can internalize and repeat. Also, don\u2019t be afraid to repeat yourself occasionally. Repetition, when done tactfully, really drives home a point.<\/p>\n<p>RELATED: <a href=\"https:\/\/www.thesslstore.com\/blog\/1-out-of-every-101-emails-malicious\/\"><em>1 out of every 101 emails is malicious<\/em><\/a><\/p>\n<h2>Wrapping up<\/h2>\n<p>It\u2019s easy to overlook IT and the rest of the people who do the behind-the-scenes work on your systems and infrastructure. That\u2019s largely owed to the fact that other people have no idea what you\u2019re doing, much less talking about. But it\u2019s important that your superiors understand what a critical component of their business you are. You are literally all that stands between your organization and a breach or attack. According to the National Cyber Security Alliance, 60% of SMBs that are the victim of a cyber-attack go out of business within six months of the incident. Larger companies tend to fare a little better, <a href=\"https:\/\/www.thesslstore.com\/blog\/2013-target-data-breach-settled\/\">but they do take a hit to their reputations<\/a> and are oftentimes fined or penalized.<\/p>\n<p>Your boss needs to understand the stakes. And you\u2019re just the person to explain it to them.<\/p>\n<p><em>As always, leave any comments or questions below&#8230;<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7276\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" width=\"1559\" height=\"407\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w\" sizes=\"auto, (max-width: 1559px) 100vw, 1559px\" \/><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Learn to manage upwards and get your security needs met. One of the hardest things IT workers deal with is talking to your boss about Cyber Security. Maybe you report&#8230;<\/p>\n","protected":false},"author":6,"featured_media":5899,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[6254],"class_list":["post-5898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-cyber","post-with-tags"],"views":17823,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/02\/iStock-917742994.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=5898"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5898\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/5899"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=5898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=5898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=5898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}