A Cybersecurity Leader's Journey
Home > Computing and Information Technology > Computer security > A Cybersecurity Leader's Journey: Speaking the Language of the Board(Security, Audit and Leadership Series)
A Cybersecurity Leader's Journey: Speaking the Language of the Board(Security, Audit and Leadership Series)

A Cybersecurity Leader's Journey: Speaking the Language of the Board(Security, Audit and Leadership Series)


     0     
5
4
3
2
1



International Edition


X
About the Book

In today’s cybersecurity landscape, the role of a cybersecurity leader goes beyond technical expertise. Communicating cybersecurity risks and initiatives to executives and boards demands a unique blend of strategic insight and business language. A Cybersecurity Leader’s Journey: Speaking the Language of the Board takes readers on a transformative path from technical talk to business-savvy communication. Follow Nick, a newly appointed CISO, as he navigates the challenges of bridging the gap between complex cybersecurity concepts and the business-focused concerns of board members. Struggling to convey the impact of cybersecurity initiatives, Nick quickly realizes that his technical knowledge alone isn’t enough to gain the board’s trust. With guidance from a mentor, he learns how to address the board’s priorities, answer the critical question of “What’s in it for me?”, and deliver insights that resonate. This book offers more than just a narrative—it provides actionable takeaways for cybersecurity leaders and other professionals who want to master the art of strategic communication. Readers will discover how to close information asymmetry gaps, manage the affect heuristic, and develop a communication style that builds trust and fosters informed decision-making. Whether you’re a CISO, an aspiring CISO, or a technical expert aiming to improve your business communication, A Cybersecurity Leader’s Journey equips you with the skills to make cybersecurity not just a necessity but a valued component of business success as well. Step into Nick’s journey, gain insights from his challenges, and learn how to become the trusted advisor your board needs.

Table of Contents:
Chapter 1: The First Board Meeting Chapter 2: The Breach Chapter 3: Chat With The Ceo Chapter 4: Bridging The Gap Chapter 5: Overcoming Emotions Chapter 6: Trust Chapter 7: Business Language Chapter 8: One-On-One Meetings Chapter 9: Risk Chapter 10: Board Preparations Chapter 11: The Next Board Meeting Chapter 12: Wrap-Up Chapter 13: Epilogue

About the Author :
Edward Marchewka, DBA, MBA, MS, CISSP, CDPSE, PMP, CMQ/OE, LSSMBB Dr. Edward Marchewka is an industry-recognized executive, having been the 2022 CIO of the Year Finalist and 2015 CISO of the Year nominee, with more than two decades of experience in IT and information security. His background includes experiences from running his own computer support business to field service to Fortune 250 experience with Thermo Fisher Scientific. He ran information security for Chicago Public Schools, the 3rd largest school district in the country. His career started in the US Navy as an Electrician's Mate - Nuclear. Dr. Marchewka is active in the IT and information security community, having served the Chicago Infragard Members Alliance for over nine years. He has presented at dozens of events, including Camp IT Conferences, (ISC)2 Security Congress, ISACA, Secureworld, and Gartner’s Security and Risk Management Summit. He is an advisor for Colorado Technical University College of Security Studies and Prairie State Community College's IT Program. Dr. Marchewka holds a Doctorate in Business Administration from California Southern University and MBA and MS in Mathematics from Northern Illinois University. He earned a BA in Liberal Studies and a BS in Nuclear Engineering Technologies from Thomas Edison State College, NJ. He holds certificates in Nonprofit Management and Leadership from the Kellogg School of Management at Northwestern University and a certificate in Contract Management from the University of California-Irvine. Dr. Marchewka maintains several active IT, security, and professional certifications from (ISC)2, ASQ, ITIL, PMI, ISACA, SSGI, Microsoft, and CompTIA.

Review :
"A Cyber Security Leader's Journey, Speaking the Language of the Board", by Dr. Edward Marchewka, was a quick and enjoyable read. More importantly, it highlighted the importance of understanding the Governance, Risk Management and Compliance (GRC) context for the work of the CISO. It resonated with my experience as a board member and General Counsel. Questions such as “What does this mean for our bottom line?” and “How does this impact our ability to ship more products?” should be expected and prepared for, with specific answers rather than generalities. This book helps CISOs with that preparation, with practical examples and an honest sharing of what must be the author's experiences repackaged as stories, enabling a mindset shift for the aspiring CISO and an understanding of the importance of understanding your audience, so that questions such as “We need to understand the impact on our business operations. Can you provide a clearer picture?” can be answered with confidence and clarity. The Checklists and Discussion Prompts are GOLD that should be mined by CISOs and their teams. A great book for a workshop or weekend reflection - Son-U Michael Paik, an experienced GC and risk management executive, with over twenty-five years designing, building and managing Governance, Risk Management & Compliance (GRC) systems Dr. Edward Marchewka's "A Cybersecurity Leader's Journey: Speaking the Language of the Board" is a transformative guide for cybersecurity leaders. The book masterfully combines storytelling with practical strategies, following Nick's journey from a technically skilled CISO to a trusted strategic partner. Marchewka's emphasis on understanding the audience, using relatable analogies, and presenting risk in clear, business-relevant terms is both insightful and practical. The book's focus on continuous learning and adaptation, along with its real-world examples, makes it an invaluable resource for anyone looking to improve their communication with executive leadership. Whether you're a seasoned CISO or new to the role, this book offers the tools and insights needed to effectively convey the importance of cybersecurity in a way that resonates with business leaders. - Gary Craven, P.Ag., FCMC, ITCP, Partner, Paradigm Consulting Group A Cybersecurity Leader’s Journey trades dry frameworks for a narrative that feels surprisingly relevant for those of us who have ever sat nervously in front of a board. By casting its lessons through the story of Nick, a first-time CISO at a medicaldevice supplier, the book drives home the reality that most directors don’t care about CVEs and packet captures; they care about keeping products flowing and patients alive. Nick’s early stumbles show how easy it is to lose your audience when you speak in technical jargon. The guidance he receives—tailoring messages to individual board members, translating risks into revenue or patientsafety impacts, and maintaining a calm cadence during crises—is spoton for healthcare environments where supplychain disruptions have lifeordeath implications. The real value lies in the practical checklists. It offers step-by-step advice on building metrics dashboards, rehearsing board presentations, and scoring risk in ways that make sense to non- technologists. His insistence on understanding information asymmetry and the “what’s in it for me?” mindset helps turn board meetings from dreaded monologues into constructive dialogues. The sections on risk scoring and board preparation provide templates that can be easily adapted to HIPAA or HITRUST reporting regimes. The story does veer toward optimism at times, Nick’s transformation from deerinheadlights to trusted advisor happens faster than it you would in a real-world bureaucracy, and seasoned CISOs might find some concepts familiar. - Keith Duemling, Chief Information Security Officer “A Cybersecurity Leader’s Journey: Speaking the Language of the Board” by Edward Marchewka follows the fictional story of Nick, a newly appointed Chief Information Security Officer (CISO), as he learns to shift from technical communications to strategic, business aligned dialogue with company leadership. Nick’s technical acumen is without question but his providing the board of directors relevant business information is the challenge. Nick’s initial meeting with MedTech Parts’ board of directors as the new CISO is ineffective in his ability to convey cybersecurity concepts in business terms to which the board members can relate. Author Dr. Marchewka interjects board members with differing perspectives including the chief financial officer, chief operations officer, medical officer, and chief executive officer. Each of these different corporate roles have specific viewpoints relative to business functions and cybersecurity expectations. At the meetings end, Nick recognizes his communications shortcomings and enlists the mentorship of seasoned CISO, Kathy to help him. With Kath’s guidance, Nick successfully bridges the gap between technical details and business priorities through effective communication. He prioritizes clarity over complexity, ensuring that cybersecurity information is understandable for board members. Nick interacts with each board member in one-on-one meetings to better understand their cybersecurity concerns and most importantly, build their trust in him as the CISO. Based on these meetings, Nick tailors his communications to address the specific concerns of each board member, making his presentations more relevant and impactful. As Nick’s communications with the board improves, he presents an updated cybersecurity strategy, focusing on its business impacts. He highlights how cybersecurity initiatives support business goals, operational continuity, and financial health. He uses specific examples, such as preventing a phishing attack, and demonstrating the effectiveness of their cybersecurity measures. Nick connects cybersecurity investments to cost savings, showing a potential loss of $2 million avoided through proactive measures. Nick improves risk communications by using clear metrics and visual aids to convey complex data. He defines risk metrics in understandable terms and employs visual tools like heat maps and graphs. Combining quantitative data with qualitative assessments provides a comprehensive and relatable view of risks. Highlighting preventive measures taken to mitigate risks reassures the board of the effectiveness of cybersecurity efforts. Nick’s plans for his cybersecurity strategy going forward is a personal commitment to ongoing learning and relationship-building to enhance cybersecurity leadership. He plans to stay updated on cybersecurity trends and engage in professional development opportunities. Continuing regular one-on-one meetings with board members will help address their evolving concerns and maintain trust. And integrating cybersecurity with business strategy positions it as a value driver rather than a cost center. What sets this book apart is its narrative approach. Rather than delivering dry theory, it humanizes the leadership journey through relatable scenarios: failed board presentations, crisis response, emotional dynamics, and learning through mentorship. These moments are not only engaging but also serve as case studies that illustrate key principles like bridging information asymmetry, managing the affect heuristic, and developing a business-aligned communication style. At the end of each chapter, Dr. Marchewka includes Key Takeaways and Discussion Prompts, which adds to the book’s value as a reference. As I started reading this book, I felt as though Dr. Marchewka attended some of my own early meetings with boards of directors and executive management. Initially, I was as ineffective as Nick and could still see the blank stares as I tried to convey detailed and overly complex technical information. I only wish I had A Cybersecurity Leader’s Journey: Speaking the Language of the Board then. I highly recommend this book for CISOs in their efforts to be more effective communicators. - Ron Baklarz – C|CISO, CISSP, CISM, CISA, NAS- IAM/IEM (Retired) A Cybersecurity Leader’s Journey trades dry frameworks for a narrative that feels surprisingly relevant for those of us who have ever sat nervously in front of a board. By casting its lessons through the story of Nick, a first-time CISO at a medicaldevice supplier, the book drives home the reality that most directors don’t care about CVEs and packet captures; they care about keeping products flowing and patients alive. Nick’s early stumbles show how easy it is to lose your audience when you speak in technical jargon. The guidance he receives—tailoring messages to individual board members, translating risks into revenue or patientsafety impacts, and maintaining a calm cadence during crises—is spoton for healthcare environments where supplychain disruptions have lifeordeath implications. The real value lies in the practical checklists. It offers step-by-step advice on building metrics dashboards, rehearsing board presentations, and scoring risk in ways that make sense to non- technologists. His insistence on understanding information asymmetry and the “what’s in it for me?” mindset helps turn board meetings from dreaded monologues into constructive dialogues. The sections on risk scoring and board preparation provide templates that can be easily adapted to HIPAA or HITRUST reporting regimes. The story does veer toward optimism at times, Nick’s transformation from deerinheadlights to trusted advisor happens faster than it you would in a real-world bureaucracy, and seasoned CISOs might find some concepts familiar. - Keith Duemling, Chief Information Security Officer


Best Sellers


Product Details
  • ISBN-13: 9781032980539
  • Publisher: Taylor & Francis Ltd
  • Publisher Imprint: CRC Press
  • Height: 234 mm
  • No of Pages: 94
  • Sub Title: Speaking the Language of the Board
  • Width: 156 mm
  • ISBN-10: 1032980532
  • Publisher Date: 29 Apr 2025
  • Binding: Hardback
  • Language: English
  • Series Title: Security, Audit and Leadership Series
  • Weight: 360 gr


Similar Products

Add Photo
Add Photo

Customer Reviews

REVIEWS      0     
Click Here To Be The First to Review this Product
A Cybersecurity Leader's Journey: Speaking the Language of the Board(Security, Audit and Leadership Series)
Taylor & Francis Ltd -
A Cybersecurity Leader's Journey: Speaking the Language of the Board(Security, Audit and Leadership Series)
Writing guidlines
We want to publish your review, so please:
  • keep your review on the product. Review's that defame author's character will be rejected.
  • Keep your review focused on the product.
  • Avoid writing about customer service. contact us instead if you have issue requiring immediate attention.
  • Refrain from mentioning competitors or the specific price you paid for the product.
  • Do not include any personally identifiable information, such as full names.

A Cybersecurity Leader's Journey: Speaking the Language of the Board(Security, Audit and Leadership Series)

Required fields are marked with *

Review Title*
Review
    Add Photo Add up to 6 photos
    Would you recommend this product to a friend?
    Tag this Book Read more
    Does your review contain spoilers?
    What type of reader best describes you?
    I agree to the terms & conditions
    You may receive emails regarding this submission. Any emails will include the ability to opt-out of future communications.

    CUSTOMER RATINGS AND REVIEWS AND QUESTIONS AND ANSWERS TERMS OF USE

    These Terms of Use govern your conduct associated with the Customer Ratings and Reviews and/or Questions and Answers service offered by Bookswagon (the "CRR Service").


    By submitting any content to Bookswagon, you guarantee that:
    • You are the sole author and owner of the intellectual property rights in the content;
    • All "moral rights" that you may have in such content have been voluntarily waived by you;
    • All content that you post is accurate;
    • You are at least 13 years old;
    • Use of the content you supply does not violate these Terms of Use and will not cause injury to any person or entity.
    You further agree that you may not submit any content:
    • That is known by you to be false, inaccurate or misleading;
    • That infringes any third party's copyright, patent, trademark, trade secret or other proprietary rights or rights of publicity or privacy;
    • That violates any law, statute, ordinance or regulation (including, but not limited to, those governing, consumer protection, unfair competition, anti-discrimination or false advertising);
    • That is, or may reasonably be considered to be, defamatory, libelous, hateful, racially or religiously biased or offensive, unlawfully threatening or unlawfully harassing to any individual, partnership or corporation;
    • For which you were compensated or granted any consideration by any unapproved third party;
    • That includes any information that references other websites, addresses, email addresses, contact information or phone numbers;
    • That contains any computer viruses, worms or other potentially damaging computer programs or files.
    You agree to indemnify and hold Bookswagon (and its officers, directors, agents, subsidiaries, joint ventures, employees and third-party service providers, including but not limited to Bazaarvoice, Inc.), harmless from all claims, demands, and damages (actual and consequential) of every kind and nature, known and unknown including reasonable attorneys' fees, arising out of a breach of your representations and warranties set forth above, or your violation of any law or the rights of a third party.


    For any content that you submit, you grant Bookswagon a perpetual, irrevocable, royalty-free, transferable right and license to use, copy, modify, delete in its entirety, adapt, publish, translate, create derivative works from and/or sell, transfer, and/or distribute such content and/or incorporate such content into any form, medium or technology throughout the world without compensation to you. Additionally,  Bookswagon may transfer or share any personal information that you submit with its third-party service providers, including but not limited to Bazaarvoice, Inc. in accordance with  Privacy Policy


    All content that you submit may be used at Bookswagon's sole discretion. Bookswagon reserves the right to change, condense, withhold publication, remove or delete any content on Bookswagon's website that Bookswagon deems, in its sole discretion, to violate the content guidelines or any other provision of these Terms of Use.  Bookswagon does not guarantee that you will have any recourse through Bookswagon to edit or delete any content you have submitted. Ratings and written comments are generally posted within two to four business days. However, Bookswagon reserves the right to remove or to refuse to post any submission to the extent authorized by law. You acknowledge that you, not Bookswagon, are responsible for the contents of your submission. None of the content that you submit shall be subject to any obligation of confidence on the part of Bookswagon, its agents, subsidiaries, affiliates, partners or third party service providers (including but not limited to Bazaarvoice, Inc.)and their respective directors, officers and employees.

    Accept

    Fresh on the Shelf


    Inspired by your browsing history


    Your review has been submitted!

    You've already reviewed this product!