Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is presenting the annual information security strategy to the board of directors. The board expresses concern that information security initiatives are viewed as cost centers rather than value creators. Which of the following metrics would MOST effectively communicate the business value of information security?

  1. ANumber of security incidents detected and remediated.
  2. BReduction in cyber insurance premiums due to improved security posture.
  3. CPercentage of employees who completed security awareness training.
  4. DNumber of vulnerabilities identified in penetration tests.
Show answer & explanation

Correct answer: B. Reduction in cyber insurance premiums due to improved security posture.

Communicating a reduction in cyber insurance premiums directly demonstrates a tangible financial benefit and risk reduction, which resonates strongly with a board of directors focused on financial performance and risk management. This metric directly links security improvements to cost savings, showing clear business value.

Why the other options are wrong

  • A. This metric reflects operational efficiency but doesn't directly quantify financial value or business enablement.
  • C. This is a compliance or awareness metric, not one that directly communicates financial business value.
  • D. This metric indicates security testing activity but doesn't inherently show financial value or risk reduction to the board.

Measuring InfoSec Value

Quantifying and communicating the tangible benefits and return on investment (ROI) of information security initiatives to business stakeholders, especially leadership.

  • Translates security into business terms.
  • Justifies security investments.
  • Aligns security with enterprise objectives.

Memory trick: Speak the language of business: money and risk.

More Information Security Governance questions