How to brief Execs on Threat Landscape

Devin Shelley (Sr. Manager Information Security at O.C. Tanner)

SAINTCON 2025 · Day 1 · Main Track 1

Overview

In the current volatile cyber threat climate, effective communication between security professionals and executive leadership is paramount. Devin Shelley, Senior Manager of Information Security at O.C. Tanner, delivered a compelling talk at SAINTCON on the critical art of briefing executives on the threat landscape. This presentation underscored the necessity for security teams to transcend technical jargon and translate complex cyber risks into actionable business insights that resonate with the boardroom.

Watch on YouTube

Visual summary for How to brief Execs on Threat Landscape by Devin Shelley
Visual summary for How to brief Execs on Threat Landscape by Devin Shelley

Key moments

  1. 0:00 Introduction: Why executive cyber briefing matters
  2. 2:00 Cyber security as a boardroom issue; Return on Mitigation
  3. 4:00 Understanding executive mindset: risk, reputation, revenue
  4. 5:30 Common pitfalls: Avoid excessive jargon and acronyms
  5. 6:30 Introducing the 'Three C's' briefing framework
  6. 8:00 First C: Clarity – simplifying complex cyber threats
  7. 9:00 Second C: Context – aligning threats with business priorities

How to brief Execs on Threat Landscape

Speakers: Devin Shelley, Sr. Manager Information Security at O.C. Tanner

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=ZzxvR6JuM4E

Overview

In the current volatile cyber threat climate, effective communication between security professionals and executive leadership is paramount. Devin Shelley, Senior Manager of Information Security at O.C. Tanner, delivered a compelling talk at SAINTCON on the critical art of briefing executives on the threat landscape. This presentation underscored the necessity for security teams to transcend technical jargon and translate complex cyber risks into actionable business insights that resonate with the boardroom.

Shelley emphasized that cybersecurity is no longer merely an IT operational concern but a fundamental boardroom issue impacting reputation, compliance, and operational continuity. Executives, who are ultimately responsible for strategic decisions and resource allocation, require clear, concise, and business-oriented information to understand potential risks and make informed investments. The talk provides a structured approach and practical advice for security professionals to bridge this communication gap, fostering executive engagement and proactive decision-making.

The core message revolves around empowering security leaders to become educators and trusted advisors to their executive teams. By adopting tailored communication strategies, security professionals can ensure that their concerns are heard, understood, and acted upon, thereby strengthening the organization's overall security posture and securing the necessary budget and support for vital initiatives.

Background

▶ Watch: Introduction: Why executive cyber briefing matters (0:00)

The evolution of cybersecurity from a niche technical domain to a pervasive business risk has created a significant challenge: how to effectively communicate these complex threats to non-technical executives. Ten to fifteen years ago, it was rare to find a technically proficient individual on a company's board; today, this is increasingly common, yet a communication gap often persists. Executives inherently prioritize risk, reputation, and revenue, processing information through a strategic lens that often diverges from the granular, technical details favored by security teams. This disparity can lead to misallocated resources, underestimated risks, and a lack of executive buy-in for crucial security initiatives.

A common pitfall identified by Shelley is the use of excessive jargon and acronyms (e.g., RDP for Remote Desktop Protocol, CVE for Common Vulnerabilities and Exposures) that hinder effective communication and cause executives to disengage. Security professionals often fail to resonate with their audience by diving too deep into technical explanations, such as specific code levels or version numbers like Oracle 11c versus Oracle 18A, which hold little meaning for strategic decision-makers. The challenge, therefore, lies in translating highly technical threat data into clear, concise, and business-relevant insights.

Shelley introduced the concept of Return on Mitigation as a critical framework to address this challenge. This approach enables leaders to prioritize security investments based on an expected value, effectively communicating risk in business terms that align with executive priorities. By demonstrating the tangible value derived from security measures, such as detecting and blocking threats or maintaining compliance with contractual obligations, security professionals can justify budgets and unlock resources that might otherwise be withheld due to a perceived lack of immediate, quantifiable return. This shift from purely technical concerns to business impact forms the foundation for effective executive engagement.

Key Findings

▶ Watch: Understanding executive mindset: risk, reputation, revenue (4:00)

The central contribution of Shelley’s talk is the introduction of the Three C's briefing framework: Clarity, Context, and Confidence. This structured approach provides a robust methodology for security professionals to deliver impactful executive briefings on cybersecurity threats.

  1. Clarity: This principle emphasizes simplifying complex cyber threats so executives can easily understand them without requiring deep technical expertise. Techniques include using analogies, visuals, and plain language, while strictly avoiding jargon and extensive technical explanations. The goal is to make the message accessible and impactful, enabling executives to quickly grasp the significance of threats and make informed decisions. For example, instead of stating a CVE score of "9," explain that it's a "fairly new vulnerability, seen exploited in the wild, and easily exploitable," detailing the potential impact.
  1. Context: This involves aligning cybersecurity threats with specific business priorities to demonstrate urgency. Threats should be framed in terms of their potential operational impact, compliance risks, and reputation damage. Providing real-world examples and scenarios that resonate with the executive audience helps them understand how a threat could directly affect organizational goals. This alignment is crucial for shifting executive priorities, potentially dedicating more resources or unlocking budget for necessary tools. Shelley noted that executives are not concerned with specific version numbers (e.g., Apache servers running version X.21 vs. X.13) but with the business risk associated with outdated or vulnerable systems.
  1. Confidence: The final 'C' is about demonstrating preparedness and control in the face of cyber threats. This involves presenting clear action plans, mitigation strategies, and readiness metrics. Metrics are vital for measuring the success of actions and fostering trust. Without quantifiable data, actions might be perceived as mere firefighting, making it difficult to secure further support. Confidence also means being prepared for difficult questions, acknowledging when an answer isn't immediately available, and committing to finding it, thereby building trust and demonstrating expertise.

Beyond the Three C's, Shelley highlighted the critical role of metrics in validating security efforts and securing budget. Examples include:

  • The number of vulnerabilities in the software stack, especially when tied to contractual obligations for remediation (e.g., fixing medium/high vulnerabilities within 30-60 days) and compliance certifications like SOC 2 or ISO.
  • Phishing simulation click rates: Quantifying the risk by demonstrating that a 10% click rate on an email sent to 800 employees means 80 potential introductions of malware or ransomware.
  • EDR (Endpoint Detection and Response) solution metrics: Showing how many items were detected and blocked, illustrating the Return on Mitigation.
  • SOC (Security Operations Center) performance: Demonstrating the value of a 24/7 in-house SOC by tracking the number of alerts handled (e.g., 10,000 alerts/month) and the mean time to resolve each alert (e.g., under two hours).

These findings collectively underscore that effective executive briefing is an educational process, a strategic imperative that requires translating technical prowess into business acumen.

Technical Deep Dive

▶ Watch: Common pitfalls: Avoid excessive jargon and acronyms (5:30)

While not a deep dive into exploit code or specific vulnerabilities, the "technical" aspect of Shelley's talk lies in the structured, systematic application of communication frameworks and tools to convey complex cybersecurity information. The Three C's framework (Clarity, Context, Confidence) serves as the architectural blueprint for these briefings.

Clarity in Practice:

Achieving clarity means de-emphasizing low-level technical specifics. Executives don't need to know the exact CVE-9 score of a vulnerability, but rather that it's a "fairly new, easily exploitable vulnerability seen in the wild" and the potential business impact. Analogies are powerful; Shelley even recounted drawing a cloud for the internet and a cookie with chocolate chips to explain web cookies and "evil jinx portals" (a simplified term for malicious sites) to a board. This level of simplification ensures the fundamental concept is understood without overwhelming the audience with intricate details. Avoiding acronyms or immediately explaining them (e.g., "RDP is Remote Desktop Protocol") is crucial.

Contextualizing Threats:

This involves linking technical threats to tangible business consequences. For instance, an unpatched vulnerability isn't just a technical debt; it's a potential breach that could lead to non-compliance with client contracts, jeopardizing business relationships and certifications like SOC 2 or ISO. A high phishing click rate isn't just a user training issue; it's a direct pathway for ransomware or data exfiltration, threatening operational continuity and revenue. Shelley highlighted that executives are often concerned about external events (e.g., a college they are alumni of being hit by ransomware) and security professionals must be prepared to connect these external incidents to internal risks. Tools like MITRE ATT&CK and NIST CSF can be leveraged to provide structured reporting frameworks, but their output must be translated into business language, not presented as raw technical data.

Building Confidence with Data:

Confidence is built on demonstrable control and preparedness, heavily relying on metrics.

  • Vulnerability Management: Instead of just reporting raw vulnerability counts, tie them to contractual obligations. "We have X high-severity vulnerabilities, and our contracts with key clients require remediation within 30-60 days. Failure to meet this could result in Y financial penalties or loss of Z business."
  • Security Operations Efficiency: For a SOC, metrics like "mean time to detect (MTTD)" and "mean time to respond (MTTR)" are vital. Shelley gave an example of a SOC handling "10,000 alerts a month" with a resolution time "under two hours," demonstrating efficiency and proactive threat neutralization. The Return on Mitigation framework becomes critical here. If an EDR solution "detected and blocked 100 items," that directly translates to prevented incidents and avoided costs.
  • Security Awareness: Phishing simulation click rates (e.g., "10% click rate on 800 emails means 80 chances for malware") directly quantify human risk and the need for ongoing training or technical controls.
  • Risk Quantification: While not explicitly a technical tool, the "likelihood and impact" matrix (a 4x4 or 5x5 grid) is a visual tool executives love. It allows for quick understanding of risk levels (e.g., "likelihood is a one but the risk is a three – that's still high"). Some vendors even offer services to quantify these risks into potential dollar losses, providing a concrete financial context for security investments.

Furthermore, Shelley stressed the importance of being aware of current events. Executives often bring questions from their personal news feeds, such as new vulnerabilities (e.g., an "F5 vulnerability") or emerging topics like AI and its implications for enterprise risk management. Security professionals must be agile, prepared to "shift gears" and address these concerns, even if they deviate from the planned agenda. This requires constant vigilance through RSS feeds, podcasts, and daily news consumption.

Demo / Proof of Concept

▶ Watch: First C: Clarity – simplifying complex cyber threats (8:00)

Shelley did not conduct a live software demo in the traditional sense, but he presented a compelling hypothetical scenario that served as an excellent proof of concept for his Three C's briefing framework and the broader principles of executive engagement.

The scenario involved a CISO facing an urgent demand for information after executives learned that a college they were alumni of had been hit by ransomware. With less than a day's notice before a board meeting, the CISO had to prepare a comprehensive brief not only on ransomware in general but also on the specifics of the college's incident, including whether the ransom was likely to be paid.

Crucially, the hypothetical CISO was "prepared," having kept up with news and understanding the nuances of ransomware. They then applied the Three C's framework:

  • Clarity: Explaining ransomware's impact in plain language.
  • Context: Framing the college's incident in terms of its relevance to the company's own potential risks, reputation, and operational continuity, resonating with the executives' personal connection to the college.
  • Confidence: Presenting the company's existing preparedness and potential mitigation plans, demonstrating control.

The success of this brief was evident in the outcome: the board, now thoroughly engaged and understanding the tangible threat, took the CISO's recommendation to perform a ransomware tabletop exercise. This exercise was scheduled for the following week and included not just security personnel but also "every VP in the company," indicating significant executive buy-in and a shift in organizational priority.

The scenario continued to demonstrate the value of this proactive engagement. Hypothectically, a week after the tabletop, a VP reported finding a suspicious file named decrypt_instructions.txt in a shared department folder. This file, a trace of a failed ransomware launch, indicated that while the attack didn't fully execute, it left behind critical evidence. The CISO's earlier briefing and the subsequent tabletop exercise had empowered the VP to recognize a potential threat and report it, showcasing how executive education can transform employees into active security participants. This fictional example powerfully illustrated how effective communication can lead to tangible security improvements and a more vigilant organizational culture.

Defensive Implications

▶ Watch: Second C: Context – aligning threats with business priorities (9:00)

The insights from Shelley's talk offer crucial defensive implications for both security professionals and the organizations they protect. The primary takeaway is that robust technical defenses are insufficient without equally robust communication strategies to secure executive understanding and support.

For Security Professionals:

  1. Master the Three C's Framework: Implement Clarity, Context, and Confidence in all executive communications. This means simplifying complex threats, aligning them with business priorities (risk, reputation, revenue, compliance), and demonstrating preparedness with data-driven metrics.
  2. Become an Educator and Translator: View your role as educating executives. Translate technical jargon (e.g., CVE-9, Oracle 11c) into digestible business impact. Use analogies, visuals, and real-world examples that resonate with their strategic perspective.
  3. Prioritize Business Impact over Technical Detail: When discussing threats, focus on operational disruption, financial loss, compliance failures (SOC 2, ISO), and reputational damage. This is the language executives understand and respond to.
  4. Develop and Utilize Actionable Metrics: Move beyond raw data. Present metrics like Return on Mitigation for EDR solutions, phishing click rates, vulnerability counts tied to contractual obligations, and SOC efficiency (MTTD/MTTR, alerts handled per month/FTE). These metrics quantify risk and justify security investments.
  5. Stay Hyper-Aware of Current Events: Monitor news feeds, podcasts, and industry reports (e.g., F5 vulnerability, AI in enterprise risk management). Executives will ask about what they see in the news, and being prepared to address these questions demonstrates expertise and builds trust.
  6. Prepare for Tough Questions: Anticipate questions like "Are we exposed?" and "What's our risk level?" Have multi-faceted answers ready, covering both internal and external data. Be prepared to explain the impact of remediation steps on production.
  7. Foster Trust and Be Honest: It's acceptable not to have all the answers. Acknowledge when you don't know something and commit to finding the information. This transparency builds trust, demonstrating that you are a reliable partner.
  8. Provide Clear Calls to Action: Conclude briefings with strategic actions. Offer clear choices, explaining the differences between mitigation (cheaper, short-term fix) and remediation (longer, permanent solution) and their respective business implications.
  9. Leverage Tools and Templates: Utilize dashboards, reporting frameworks like MITRE ATT&CK and NIST CSF, and reusable templates to maintain consistency and professionalism in communications.

For Organizations and Executives:

  1. Recognize Cybersecurity as a Boardroom Imperative: Understand that cybersecurity is a strategic business concern, not just an IT problem. Allocate adequate time and attention to security briefings.
  2. Engage Proactively: Participate in activities like ransomware tabletop exercises with key leadership (VPs, C-suite). This direct engagement builds understanding and preparedness across the organization.
  3. Support Security Budget and Initiatives: Understand that security investments, while often appearing as "cost centers," provide critical Return on Mitigation by preventing costly incidents, maintaining compliance, and protecting reputation.
  4. Foster an Open Communication Channel: Encourage security professionals to speak openly about risks and challenges, creating an environment where concerns are heard and addressed without fear of technical misinterpretation.
  5. Value Expertise and Education: Recognize that security professionals are crucial educators. Empower them to translate complex threats into business terms, enabling more informed and strategic decision-making at the highest levels.

By implementing these defensive implications, organizations can move beyond reactive security measures to a proactive, strategically aligned posture, ensuring that cybersecurity is integrated into the core fabric of business operations.

Key Takeaways

  • The Three C's Framework is Essential: Effective executive briefings hinge on Clarity (simplifying complex threats), Context (aligning threats with business priorities), and Confidence (demonstrating preparedness with metrics).
  • Translate Technical Jargon into Business Language: Security professionals must act as educators, converting technical details like CVE scores or server versions into discussions of operational impact, financial risk, compliance failures, and reputational damage to resonate with executive priorities.
  • Data-Driven Metrics are Crucial for Buy-In: Utilize quantifiable metrics such as Return on Mitigation (e.g., EDR detections, SOC efficiency), phishing click rates, and vulnerability counts tied to contractual obligations to justify security investments and unlock budget.
  • Proactive Engagement and Preparedness are Paramount: Staying informed on current events (news, vulnerabilities like F5, AI implications) and being prepared for diverse, unexpected executive questions demonstrates expertise and builds trust.
  • Security is a Shared Organizational Responsibility: Effective communication, as demonstrated by the ransomware tabletop exercise scenario, transforms executive understanding into active participation, empowering all levels of leadership to contribute to the organization's security posture.
  • Budget Approval Requires Demonstrating Value: Security is often a cost center, making it critical to articulate the tangible value of security investments in preventing losses and protecting the business, using frameworks like Return on Mitigation and risk quantification.

About the Speaker(s)

Devin Shelley is a seasoned cybersecurity professional currently serving as the Senior Manager of Information Security at O.C. Tanner, where he has been for nine years. Beyond his corporate role, Shelley brings a wealth of experience from his 24-year military career, having retired in 2020. During the last eight years of his military service, he led a defensive cyber operations team, honing his skills in safeguarding critical systems. This talk marks his third presentation at SAINTCON, demonstrating his commitment to sharing knowledge within the security community. Shelley is also dedicated to charitable work, providing security awareness training to assisted living homes and VA centers through his personal business website, debcysecurity.com. He is available for contact on LinkedIn.

All talks from SAINTCON 2025