I need to create a business case for phishing risk and demonstrate true business impact? I need this for a board presentation and any data, information/charts, links, vendors (with tentative costs) will be useful... please share
You need to be a member of CISO Platform to add comments!
Replies
A simple phish on leaders before you meeting and presenting results will be an eye opener :-).
Propose how the entire solution can be built using open source (go phish is one of them) with minimum investment and can be enhanced in-house to meet org specific needs.
Include a slide on tentative timeline for rollout and asks.
You can simulate the Phishing exercise and present the statistics to the management. I think that statistic along with the list of internal threats due to Human behavior shall do the trick.
Another effective way to build a usecase would be to conduct a phishing simulation within your organisation (target everybody that has capability to send and receive email outside the company). The results will talk for themselves to ensure right investments are supported around strengthening user awareness, procedural and technical controls. Phishing simulation is a very inexpensive way to build a strong usecase
In case you do not have strong detection then it is likely that your org may already have witnessed a phishing attack/data loss. A compromise assessment will establish it and provide a very strong and dirty usecase to channel the right investments