
Mark Lamb at HighGround.io explains how to communicate the importance of cyber-security successfully to C-level executives
In the last few months, the world has witnessed regulators taking tough legal action against C-level executives after their organisations were impacted by security breaches.
First, we saw Joe Sullivan, the ex-CISO at Uber, being convicted in federal court over him concealing a breach of the company in 2016. Then, only weeks later, the Drizly CEO, James Cory Rellas, faced sanctions related to a customer data breach from 2020.
Both these incidents highlighted how law enforcement officials and governments are clamping down on cyber-negligence.
If an organisation holds sensitive consumer data, it has a duty to keep it secure. And when organisations don’t, they face the heavy hand of the law, with C-level executives coming directly in the firing line.
However, one of the biggest challenges with C-levels having a clear understanding on cyber is seeing it as a traditional business risk topic that needs to be assessed and managed in the same way as other business threats.
Today, the impact of attacks today are very business focused. Just like recessions, or corporate legal disputes, they hit the bottom line, put an organisation’s integrity at risk, and they can also erode customer trust in seconds.
As a result, business leaders must move away from treating cyber as a technical nuisance and move it up the agenda, so it is addressed in the same way as other business risks.
However, one of the biggest challenges with putting this in place is building strong communication bridges between IT teams and C-levels so the right information is disseminated between the parties.
When it comes to communicating on cyber-security to C-levels, less is often more. However, very few IT and security teams take this approach.
Instead, they overwhelm executives with information that is overly detailed, and that doesn’t give a clear and concise way to evaluate and understand the security posture of the business.
C-levels don’t need to know exactly what CVEs are patched against, or what firmware versions of products are running to keep the business secure. Nor do the need to know exactly what security products are being deployed and their headline features.
What they need to understand is how the critical business risk of cyber-security is being managed, what their organisation’s risk posture is, where it needs to be, and what plans and budgets are needed to get the business to where it needs to be to minimise risk and meet compliance requirements.
When it comes to talking to C-levels, IT and security teams need to focus on delivering information related to five key issues. These include:
By providing answers to these key questions, C-levels can easily understand how secure the business is, if more budgets are required to improve security, and if regulatory compliance requirements are being met.
However, one of the biggest challenges IT teams face when generating these security reports, is the speed at which C-levels often need the information. When the CEO wants to know about cybersecurity, they often need the information right away. They want to ability to access security data in real time, so they constantly have accurate and up to date information at their fingertips.
One of the best ways to counter this issue is through the deployment of tools which sit above security platforms and can then automatically generate reports around this data for C-levels.
These platforms integrate with security tools, providing a bird’s eye view on the organisation’s architecture, and they also have the ability to generate specific reports with the metrics that matter to the CFO, CEO or CTO, which significantly improves efficiency and allows C-levels to access security data when and where they need it, without having to wait on security teams pulling together the information they require.
The importance of cyber-security has never been greater to C-levels, but they don’t need to know the nuts and bolts of the organisation’s security implementations.
They simply need to know how well protected they are against attacks and if there are any weaknesses in the posture that could put them at risk. This information is enough for them to see how secure the business is and where budgets need to be allocated to make improvements.
By implementing tools that have the ability to generate this data when C-levels need it, this improves C-level cyber visibility, making security more accessible and relevant to them, while also preventing any unwelcome surprises from law enforcement or regulators in the future.
Mark Lamb is CEO of HighGround.io
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543