I used the risk-acceptance process instead. Those seats weren’t luxuries. They were how we implemented the control or supported it.
If the seat wasn’t there, someone had to sign that we were accepting the risk.
The first year I put additional people in the annual budget, the answer was no.
Over the next few months, I got those employees. I didn’t wait for the next annual review.
The CFO’s response came back. I later learned it was the usual response:
"Global IT Security's annual budget must remain at or under last year's budget. Request for additional personnel denied."
I started with a very lean cybersecurity team.
The company was doing about $6B in revenue. Three of us in corporate cybersecurity.
It took about a year before my boss finally gave me the department budget to manage.
one of the reasons i like being a retired ciso is that i don't have to listen to security vendors talk about their "single pane of glass" solutions any more
"No, and if I said yes then you should fire me."
Silence lingered. Then an approving nod. Others around the table seemed to agree.
That was my first Board meeting. They got tougher after that.
All that preparation and rehearsal, and the deck never left slide 1. It was conversational.
Our VP of Internal Audit had warned me about one guy. Very technical. On our Board. Full-time C-suite at a global media company.
"Can you guarantee that we won't get hacked?"
My mind raced. Everything the team did. The clichés. Weakest link. An attacker can get it wrong over and over. You’re wrong once, you’re toast.
I answered from my gut.
A voice towards the front and the left interrupted me. Not rudely, but firmly.
"Michael, if you don't mind... we all did the pre-read so we're familiar with what's in your deck. Instead we have a few questions for you."
I walked into the room. The CEO. CEOs of other companies who served on the Board.
I had pictured myself standing at the front. There was a chair for me towards the back.
"Have a seat," somebody said.
The deck sat on slide 1: my name and title. Four slides behind it. Two months of work.
I had rehearsed those 15 minutes a hundred times. I sized up the room. They looked ready. I started to introduce myself.
After two months of prep, it was the day.
I took the elevator to the executive floor, the top floor of the Corp HQ building. I was ushered to a chair outside the conference room and told they would invite me in when I was up.
After countless dry runs, I felt ready.
What started as 12 pages for 15 minutes was cut to 5 slides. They went out a week early in the Board pre-read.
I was ready.
I had over two months to prepare my first Board presentation.
I built org charts. Listed the team’s accomplishments. Named the key risks and how we were managing them.
Working with my leadership team, I had a solid deck. I ran it past our VP of Internal Audit, Marketing, and the CIO.
A lot of the energy went to changing colors, and to killing the spider charts. He didn’t like them.