Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

One Identity: How CISOs Should Engage Boards on Security ROI

One Identity
06/16/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


As you know, right, over the last five years or so, as the interest rate climate has changed, the boards have become a lot more focused on the profitability of the business, the investment sort of profile of the business, not just pure growth. So they are looking at the investment and spend on things. And so I think the CISOs have to do this job of elevating themselves and put themselves in the shoes of the board members and engage them in the dialogue in the context of the ROI to the business for the things that they actually spend money on, right? You can pretty much read in press articles today, like the companies that are actually getting breached. And so I think the cost of a breach is one of the ways I think in terms of like the cost of a breach for organization can be hundreds of millions of dollars now. So when CISOs engage with the board, it's in terms of that kind of ROI, right? The investment in, hey, their identity governance framework that they actually are using or protecting their privileged accounts, right? It used to be that they could have a corporate firewall and they could be squishy in the middle and they still felt pretty good. Now with the cloud and the internet and post COVID, now their employees are distributed all over the world. So there is no such thing as a corporate firewall. Identity has become the security perimeter for these organizations. And the threats we are seeing like phishing attacks and ransomware and CISOs can focus on that rather than focusing on the technology piece and to sort of describe the attack vectors and the cost of not having protection in their environment. I think that's the level of conversation they need to be having at the board.

TL;DR

  • Boards now prioritize profitability and investment ROI over pure growth, requiring CISOs to justify security spending in business impact terms rather than technical features.
  • Breach costs can reach hundreds of millions of dollars, making cost avoidance a compelling framework for discussing investments in identity governance and privileged access management.
  • Identity has replaced the corporate firewall as the security perimeter due to cloud adoption and distributed workforces, fundamentally changing how organizations must approach security architecture.

Summary

This brief executive perspective addresses the evolving relationship between CISOs and corporate boards in the current economic climate. The speaker emphasizes that boards have shifted focus from pure growth to profitability and investment scrutiny over the past five years, driven by changing interest rate environments. CISOs must elevate their communication approach to engage boards in ROI-focused dialogue, framing security investments in terms of breach cost avoidance rather than technical capabilities. With breaches now costing organizations hundreds of millions of dollars, the conversation centers on quantifying the value of identity governance frameworks and privileged access protection. The fundamental shift from perimeter-based security to identity-centric security—accelerated by cloud adoption and distributed workforces—requires CISOs to articulate attack vectors and protection gaps in business impact terms rather than technical specifications.

Chapters

0:00 - Board Focus Shift
0:26 - CISO Communication Strategy
0:47 - Breach Cost Economics
1:11 - Identity as Perimeter

Key Quotes

0:26 "I think the CISOs have to do this job of elevating themselves and put themselves in the shoes of the board members and engage them in the dialogue in the context of the ROI to the business for the things that they actually spend money on ..."
0:53 "... the cost of a breach for organization can be hundreds of millions of dollars now ..."
1:26 "... there is no such thing as a corporate firewall. Identity has become the security perimeter for these organizations ..."

FAQ

Why do CISOs need to change how they communicate with boards?

Boards have shifted focus from pure growth to profitability and investment ROI over the past five years. CISOs must frame security investments in terms of breach cost avoidance and business impact rather than technical capabilities to align with board priorities and secure necessary funding.

How has the security perimeter changed for modern organizations?

The traditional corporate firewall perimeter has been eliminated by cloud adoption and distributed workforces. Identity has become the new security perimeter, requiring organizations to invest in identity governance frameworks and privileged access protection rather than relying on network-based defenses.


Categories:
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Executive Briefing
  • Identity & Access
  • Zero Trust
  • Security Operations
  • Compliance & Governance
  • CISO board communication
  • security ROI
  • breach cost economics
  • identity governance
  • privileged access management
  • zero trust architecture
  • cloud security perimeter
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: One Identity: How CISOs Should Engage Boards on Security ROI

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version