Episode 199: Translating Cyber Risk into Business Decisions
In episode 199 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Chris Painter, Chair of the Risk Committee and Board Member at the Center for Internet Security® (CIS®). Together, they discuss how chief information security officers (CISOs) can support the work of translating cyber risk into business decisions by Boards.
Here are some highlights from our episode:
- 00:50. Introductions to Chris
- 01:36. The single biggest translation error Chris has seen CISOs make
- 07:38. Cyber risk quantification: An opportunity to go beyond translation for Boards
- 09:25. How ransomware changed Boards' understanding of cyber risks' business impact
- 10:45. The value of tabletop exercises (TTX) and other simulations in creating shared language
- 13:26. Recommendations on how to make the most of a TTX
- 18:37. Risk modeling and how artificial intelligence (AI) complicates probability estimations
- 21:51. "Pressure" (2026) as an illustration of making good, not 100% accurate, estimations
- 22:58. How growing public awareness of cyber is reshaping CISOs' conversations with Boards
- 25:55. The importance of walking Boards through risk mitigation steps with AI as an example
- 29:31. A recommendation for how CISOs can learn what directors care about
- 30:15. From "wizardry" to familiarity: An ongoing generational shift around cyber
Resources
- Episode 183: The Role of CISO in Supporting Risk Translation
- Episode 187: The Role of a CISO as a Strategic Storyteller
- Episode 192: How Leaders Balance Expertise and Communication
- How Risk Quantification Tests Your Reasonable Cyber Defense
- CIS RAM (Risk Assessment Method)
- Leveraging Generative Artificial Intelligence for Tabletop Exercise Development
- CIS Controls v8.1 Incident Response Policy Template
- You Have a Cybersecurity Incident. Now What?
- Prompt Injections: The Inherent Threat to Generative AI
- "Pressure" | Official Website | 29 May 2026
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.