Free Phishing Test

KSC does not add new responsibilities to the CISO, but rather changes his role in the organization. Building digital resilience is something that mature companies have been doing for a long time – many of them have implemented security procedures, appointed responsible people, and systematically conducted tailored and realistic phishing simulations or organized cybersecurity training before the amendment appeared.

It is not a new technical obligation that raises the profile of the CISO role today, but the responsibility that has fallen on the management board. Amendment to the KSC Act, implementing the NIS2 directive, makes management personally responsible for cybersecurity.

We talked about what this change looks like in practice in a webinar with Marcin Serafin – a digital law specialist and partner of Sterberg law firm – and Jerzy Muszyński, a legal advisor who runs his own law firm. The conversation was moderated by Maciej Kołtoński, thanks to which there was also a business perspective. And if you want to watch the entire recording, fill out the form on this page.

What actually changes KSC in the CISO position?

KSC changes the position of the CISO – from a person performing technical tasks to a management partner who is personally responsible for cybersecurity.

So far, security has been treated as the subject of the IT department. The amendment shifts this burden higher, to the very top of the organization: it is the management who approves the risk analysis, provides the budget and is responsible for its own training, and delegating tasks to IT does not relieve it of its responsibility.

As legal advisor Jerzy Muszyński emphasized during the webinar:

For the first time, in such a broader context, we can talk about the fact that […] the company’s management board is to be an active entity participating in the ongoing management of cybersecurity within the company’s structures.
Jerzy Muszyński, legal advisor at SECAWA

The board needs a CISO as a risk translator

The management board, which is personally responsible for cybersecurity, necessarily must have someone who understands the risk, can manage it and translates it into decisions. It is from this relationship that the new position of CISO comes from.

Marcin Serafin described this mechanism directly:

When our management board members have their duties in terms of regular training, making decisions, and supervising the entire system of thinking about cybersecurity, they inevitably start to have to use someone who will explain this reality to them. Who will actually support them, and not just replace them.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

In other words: The CISO ceases to be a contractor, and becomes an advisor on whose analysis the management bases its own decisions – and its own responsibility.

CISO becomes an integral part of business

KSC 2.0 ends treating cybersecurity as a separate world, separated from business. Today, systems, data and tools are already a business – not an addition to it.

I hope that the problem of many CISOs who were left to themselves will end: do your own thing, tinker with your devices, analyze your reports, but don’t disturb our business. This is something that has to end – because this business is all about software and all these tools.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

For organizations, this means that security is no longer an incidental expense, but a condition for business continuity.

Not everyone is happy with this “promotion”

The growing importance of the CISO comes at a price – close, demanding cooperation with the management board. Not every specialist dreams of explaining risk to managers and sitting at the decision-making table. “This is a kind of increase in the importance of the CISO role within the organization (…). The CISO as a partner for the management is not left alone.” – said Marcin Serafin during webinar about KSC.

The advantage, however, is this: CISO stops working in a vacuum. He gains the support of the management board, but in return he has to spend more time explaining what exactly the threats are and how to solve them.

Why is there no single, universal definition of the CISO role?

A CISO in one organization is not the same as a CISO in another – these roles can be extremely different. The KSC clarifies the duties, but does not impose a single model for filling this position.

A CISO in an organization is not [equal to] another CISO in another organization. These roles are indeed extremely different.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

The differences in the CISO role concern resources, independence and the right to make decisions – some act independently, others are dependent on the management at every step.

Implication for the decision maker: Before filling this role, the board must decide the scope of authority, budget and independence of the CISO.

What does KSC mean in practice – for the management board and for CISO

Real change occurs when the CISO gets access to the management board, a budget and the right to make decisions – not just a title.

In practice, this means three things:

for the management board: training, social-engineering tests and penetration testing, approving risk analysis and security budget is an obligation, not a gesture of good will,
for CISO: more time to translate the risk in the language of business than on the risk itself tools
for the organization: clear path, who receives the decision and who is responsible for it.

Summary

The new position of CISO comes from the responsibility that KSC has placed on the management board.

This is a change that both parties can benefit from:

There is one condition: the CISO role must be given resources, budget and the right to make decisions.

The entire conversation – with specific examples, implementation schedule and question session is available on request. Sign up and you will receive access to the webinar recording and a set of materials (presentation and UKSC/NIS2 validator).

Free webinar. How to approach the implementation of KSC sensibly: so as not to take on everything at once, but also to complete the duties on time.

In today’s dynamic world of cybersecurity, information security managers (CISOs) must stay up to date with changing threats and develop strategies to that will help them protect their organizations against attacks.

In this context, key performance indicators (KPIs) play an important role, allowing CISOs to monitor and evaluate the effectiveness of their activities. In this article, we will provide an introduction to metrics and KPIs in cybersecurity, discussing their role, the characteristics of good KPIs, how to select appropriate metrics, integration with the CISO roadmap, and the presentation and interpretation of results.

  

Cybersecurity Metrics and KPIs: Definitions and Differences

Cybersecurity metrics are numbers and data used to measure the level of IT security in an organization. They are crucial for monitoring and assessing the effectiveness of the applied protection measures.

KPIs (Key Performance Indicators) are key performance indicators that allow you to measure the organization’s achievements in cybersecurity. KPIs are used to monitor and evaluate the effectiveness of activities to achieve the organization’s strategic goals.

Role of KPIs and characteristics of good KPIs: CARE standard

KPIs are used to assess the effectiveness of cybersecurity activities, identify areas for improvement and make decisions about changes. Good KPIs should meet the criteria of the CARE standard, which specifies that the indicators should be:

15 key questions for CISOs:
Assess your company’s readiness for AI-powered attacks

Selecting the right KPIs for the organization: criteria for CISO

To get the most out of cybersecurity KPIs, a CISO must carefully select metrics that are relevant to his organization and its specific use cases. Choosing the right KPIs allows you to effectively evaluate results at the level of the entire organization, as well as detect areas that require attention. Below are the key aspects that a CISO should consider when defining cybersecurity metrics:

Taking into account the above criteria and the previously mentioned aspects related to the CARE criteria, the CISO should select KPIs that best reflect the priorities of his organization, its specificity and the expectations of the management board and stakeholders. Careful planning and thoughtful use of KPIs will allow for more effective cybersecurity management and achievement of the assumed goals.

Integration of KPIs with the CISO roadmap

Integrating KPIs into the CISO roadmap is crucial to effective cybersecurity management. By monitoring KPIs, the CISO can track the organization’s progress in achieving security goals, adjust action plans, and communicate results to stakeholders. Below are the steps a CISO should take to integrate KPIs into their roadmap:

  1. Define goals and priorities in cybersecurity – goals should be clear, measurable and consistent with the expectations of the management board and stakeholders,
  2. Develop an action plan based on selected KPIs – the plan should specify specific activities, responsibilities and implementation deadlines related to achieving the goals,
  3. Monitor progress and measure the effectiveness of activities – CISO should track KPI results, analyze differences between assumptions and actual results, and make adjustments if necessary,
  4. Implement internal communication – CISO should regularly inform management, employees and other stakeholders about KPI results to maintain commitment and understanding of cybersecurity activities,
  5. Review and update KPIs systematically – CISOs should regularly check that KPIs remain relevant and relevant to the organization’s goals, making changes as needed.
  6. Presentation and interpretation of KPIs for management and other stakeholders.

Effective presentation of KPIs to the management board and other stakeholders

CISO should present KPI results to management and other stakeholders in a clear and accessible way, taking into account the following principles:

Regular KPI monitoring and reporting

The CISO should regularly monitor and report KPI results – this is crucial to maintaining effective cybersecurity management. Regularly analyzing results allows CISOs to adapt strategies and actions, as well as keep management and other stakeholders engaged. Effective monitoring and reporting of KPI results will help:

By applying these practices, the CISO will be able to effectively monitor KPI results, provide valuable information to management and other stakeholders, and make informed decisions regarding cybersecurity management.

Summary

As cybersecurity becomes increasingly important to organizations, it is crucial to understand how to apply metrics and KPIs to monitor and evaluate the effectiveness of information security efforts. The main goal of cybersecurity is to ensure information security and maintain operational and business continuity, which emphasizes the need for cooperation between the IT department and other departments and stakeholders. This makes it possible to take into account the perspectives of all parties involved and select appropriate measures to achieve the maximum level of security.

In addition, it is worth remembering that increasing safety often introduces difficulties that may arouse resistance among employees. Therefore, it is important to analyze risk and take into account the risk appetite of decision-makers, which allows for a balance between the need for protection and the functioning of the company.

It’s worth focusing on Quick Wins!

It is worth focusing on the so-called Quick Wins, i.e. areas that, at low cost and organizational effort, will allow you to secure those parts of the enterprise that are exposed to the greatest risk. A particularly important element here isemployee security awareness and their resistance to attacks, as well asdeveloping a security culture in the organization.

Introducing practical training based on simulations, aimed at increasing employee awareness and skills in cybersecurity, is an effective solution. Thanks to this, in addition to increasing the level of protection, you can alsocollect hard datathat will be used to create and monitor KPIs. This type of indicators will allow assessment of employees’ progress and the effectiveness of undertaken actions.

Check out how with Secawa you can start Practical Anti-Phishing Training for employees, which will allow you to measure your employees’ resistance to cyberattacks – without complicated implementations and the involvement of your specialists.

Increase security awareness with Practical Anti-Phishing Training

Today, information security is a key element of every company’s operations. To ensure effective management and protection of information, organizations create positions such as CISO and CSO. What are the differences between these two roles and what are their main responsibilities?

CISO vs CSO – duties and responsibilities

CISO (Chief Information Security Officer) and CSO (Chief Security Officer) are two managerial positions responsible for various aspects of security in the organization. Although their responsibilities may overlap, the differences between them are important.

CISO

The CISO mainly focuses on information security in the organization. This includes protecting data, systems, networks and other IT resources from threats such as hacker attacks, data leaks, system failures, data loss and other cybersecurity events.

The main responsibilities of a CISO include:

  1. Developing and implementing information security strategies and policies.
  2. Conducting and supervising security audits.
  3. Risk analysis and information security risk management.
  4. Monitoring and analyzing information security incidents.
  5. Create and maintain emergency plans and incident response procedures.
  6. Training employees in information security and increasing awareness of cybersecurity threats and best practices.
  7. Cooperation with other departments to secure processes and data on which they operate.
  8. Ensure compliance with legal regulations and industry standards regarding information security.
  9. Cybersecurity budget management.
  10. Reporting to the management board on the security of IT systems.
  

15 key questions for CISOs:
Assess your company’s readiness for AI-powered attacks

CSO

The CSO is responsible for broadly understood security in the organization, including both physical security and cybersecurity. As such, a CSO can manage all aspects of security, including protection of assets, employees, customers, partners and information assets.

The main responsibilities of a CSO include:

  1. Developing and implementing overall security strategies for the organization.
  2. Coordinating activities related to physical security, such as facility security, access control systems and crisis management measures.
  3. Conducting and supervising security audits.
  4. Collaborate with IT and CISO to implement cybersecurity policies and procedures.
  5. Collaborate with other departments to secure infrastructure, assets and staff.
  6. Monitoring and assessing threats and implementing countermeasures.
  7. Create and maintain emergency plans and incident response procedures.
  8. Ensure compliance with safety regulations and standards.
  9. Coordinating other activities related to the protection of personal data and privacy.
  10. Managing the security budget and reporting to the management board on the organization’s security status.

Summary

In summary, a CISO focuses primarily on information security and cybersecurity, while a CSO has broader responsibilitiesthat include both physical security and cybersecurity. In some organizations, these positions may be closely related or even combined into one (CISO/CSO), but in larger organizations they are usually separate roles.

Remember the biggest threats

One of the most important areas of responsibility of both CISOs and CSOs is proper education of employees, which will effectively raise their awareness of threats and improve their resistance to cyberattacks and manipulations.

With the help of Practical Anti-Phishing Training – education based on realistic simulations of cyberattacks, micro-training in the event of a mishap and measurable effects – you can strengthen your employees’ cybersecurity while tracking clear KPIs, with which you will be able to measure and report the effectiveness of your activities.

Read the next article in our series: Key Performance Indicators (KPIs) in Cybersecurity: An Introduction for CISOs. We focus on KPIs in cybersecurity. We describe what criteria to follow and how to implement them so that they provide real value from the perspective of the CISO and other stakeholders.

Key Performance Indicators (KPIs) in Cybersecurity:
Introduction for CISOs