Skip to content

Cybersecurity Influence Starts With Explaining Risk Clearly

Cybersecurity leaders can have the right technical answer and still fail to influence business decisions when they cannot translate cyber risk into language executives understand, trust and act on.

Cybersecurity has spent decades getting better at finding problems. The industry has built increasingly sophisticated tools for detecting threats, identifying vulnerabilities, measuring risk and telling organizations what they should do next.

But there is a problem no dashboard or detection engine can solve: The people who need to act on that information have to understand it first.

That was the central theme of the latest episode of CYBR.Minded, where host Dr. Dustin Sachs spoke with Heather Antoinetti, founder and CEO of AH-HA Marketing, Inc., about the gap between cybersecurity expertise and organizational influence.

Full Episode:

Translating what Matters with Heather Antonetti
Why cybersecurity influence depends on trust, storytelling, visibility, and overcoming imposter syndrome to earn stakeholder buy-in.

It is a gap with real consequences. Security teams can produce perfectly accurate findings, warnings and recommendations and still watch executives underfund the risk, misunderstand its urgency or prioritize something else. As Sachs put it at the beginning of the conversation, technical expertise has to travel through “trust, interpretation, language, status, and attention” before it can influence a decision.

The implication is bigger than simply telling CISOs they need better presentation skills.

Communication itself is part of cybersecurity risk management.

Your work does not speak for itself

Antoinetti took aim early at one of the most persistent assumptions among technical professionals: If the work is good enough, it will speak for itself. It doesn't.

“Nobody's work stands on its own anymore,” Antoinetti said. If professionals cannot explain what they have accomplished in terms other people understand, their expertise may never travel much farther than the person who received their report. That limits not only their personal visibility, but the organization's ability to recognize and act on what they know.

The problem becomes particularly acute when deeply technical security teams communicate with executives.

Technical professionals spend enormous amounts of time understanding how something happened. Naturally, when they finally solve the problem, they want to explain the details.

The executive sitting across the table may want something entirely different.

Antoinetti offered a deliberately simple alternative: Tell the executive what was broken, that it has been fixed and why it is unlikely to happen again. Diving immediately into the technical mechanics can cause the listener to disengage before the security professional ever reaches the information that matters to the decision.

That does not mean dumbing down cybersecurity. It means understanding the audience. A CISO briefing a board does not have the same communication objective as an engineer briefing another engineer. If the person controlling budgets, priorities or business trade-offs cannot understand the security signal, having the technically correct answer accomplishes surprisingly little.

As Sachs noted, that makes failed translation more than a branding or communications problem. It becomes an operating risk: The organization may fail to address a legitimate security problem because the people responsible for making the decision never understood that it was a problem in the first place.

The quiet professional has a cybersecurity problem

But translating technical information is only part of the challenge. Before experts can influence an organization, they have to be willing to make their expertise visible.

That brought Sachs and Antoinetti into a discussion about imposter syndrome and the tendency of accomplished professionals to continually minimize their own authority.

They write the dissertation. Publish the research. Build the product. Solve the problem. Then they barely talk about it. Antoinetti said people struggling with imposter syndrome often continue collecting credentials and accomplishments because they believe they need one more piece of proof before they have earned the right to be considered an authority.

“People are always trying to collect more receipts and more proof,” she said.

The irony is that many have already reached the level of expertise they are chasing. Antoinetti said she often sees people achieve that status months before they recognize it themselves.

For cybersecurity, that matters beyond career development. Organizations need knowledgeable people to influence decisions. An expert who stays invisible because talking about their accomplishments feels like bragging can leave that influence to someone who may know considerably less but is much more comfortable occupying the room.

Influence doesn't require becoming a LinkedIn personality

That creates another uncomfortable question: How do security professionals become more visible without turning themselves into personal-branding machines?

Antoinetti draws a distinction between self-promotion and becoming a resource.

Influence, in her view, comes from demonstrating that you know something useful and are willing to help others with it. For professionals interested in educating people, supporting peers and strengthening the cybersecurity community, visibility can be a means of creating those connections rather than simply accumulating attention.

And LinkedIn posts are hardly the only way to do it.

A security professional who hates social media might mentor someone. Someone else might excel in one-on-one conversations. Others can speak at conferences, publish research, participate in communities or start podcasts. There is no single formula.

“Influence and community are very, very interconnected concepts,” Antoinetti said.

That framing is important because cybersecurity has traditionally celebrated the quiet expert: Do excellent work, keep your head down and assume the people who matter will notice. Sometimes they won't.

And sometimes taking the risk of becoming more visible has an extraordinarily asymmetric payoff. Antoinetti suggested thinking about it almost like a cybersecurity risk calculation: What happens if you ask for the opportunity, customer, investment or platform and receive a no?

Your ego gets bruised. What happens if the answer is yes? “Literally everything could change,” she said.

Cyber risk needs a story people can remember

For CISOs and other security leaders, Antoinetti's practical recommendation is to get better at storytelling. Not storytelling as marketing theater. Storytelling as translation.

Cybersecurity routinely asks executives to comprehend risks that are abstract, technical or difficult to quantify. Rather than explaining every technical component of a DDoS attack, for example, a security leader can explain what happens to the business if critical systems become unavailable.

That gives the audience something concrete to understand. Antoinetti recommended Made to Stick by Chip Heath and Dan Heath as a useful resource for learning frameworks that turn complicated or difficult-to-grasp concepts into stories and visuals people can remember.

The objective isn't to make cyber risk sound nicer. It's to make risk understandable enough that somebody does something about it.

That changes how CISOs brief boards, frame trade-offs, earn trust and communicate with the teams expected to implement security controls.

Cybersecurity should rethink the language it uses

Antoinetti's closing point may be the most consequential. Asked where cybersecurity needs to slow down and think more carefully, she pointed to language itself.

The industry routinely communicates through commands and conflict:

You must do this. You have to do that. Adversaries. Cyberwar. Firefighting.

That vocabulary may feel natural inside security because practitioners have used it for years. But Antoinetti questioned whether it supports the outcome cybersecurity actually wants.

Security ultimately needs partnerships. It needs people across organizations to participate in protecting systems and data. And it needs users to embrace technology safely rather than view security as the department constantly telling them what they cannot do.

Changing the language could change how those people perceive security — and potentially increase adoption of the behaviors and controls security teams have been struggling to encourage.

That brings the conversation back to the assumption at its center. The technically correct answer does not automatically win. Cybersecurity influence depends on whether people hear the signal, understand it, trust the person delivering it and recognize what they are supposed to do next. Tools matter. Controls matter. Data matters.

But if the expertise behind them cannot survive the journey from the security team to the people making the decision, organizations can still get the risk wrong.

That makes communication much more than presentation polish – it makes communication part of the control environment itself.

HOU.SEC.CON CTA

Latest