How the most progressive boards manage cyber risk
Summary
This blog post, "How the most progressive boards manage cyber risk", is a blueAPACHE article from 2017 covering security. How do the most progressive boards tackle cyber risk? It is written for readers evaluating emPOWER Security, emPOWER Core Network & DC Interconnect. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2017 |
| Topic | How the most progressive boards manage cyber risk |
| Services referenced | emPOWER Security, emPOWER Core Network & DC Interconnect |
| Named products or vendors | Palo Alto Networks |
Article
How do the most progressive boards tackle cyber risk? Mark McLaughlin, Palo Alto Networks Chairman and CEO, shared key questions and insight into the conversations board members should be having with their CIOs. “I see that a lot of boards will talk to their CIOs and say – how safe are we? If I gave you one more dollar, how much safer would we be? And those are really hard questions to answers because it is just not that specific. I think the proper questions to answer are how comfortable do you feel in our security philosophy and architecture for the next three or five years? How much are we investing in making it more automated and less manual? The single biggest thing I see with progressive boards is they challenge their security leaders to think differently. The old way clearly doesn’t work but what does the progressive approach look like? Progressive boards ask questions such as how many attacks are we seeing? How many of those do we have to pay attention to? This is probably the most important measure you can make because it shows your level of efficiency. If you can force people in the organisation to think that way, you’ll get some interesting results. Another way of thinking is – in five years’ time, if I want to be twice as secure as we are today at half the cost, what would you do now? That really forces people to think outside the box. You just can’t keep doing it the old way if you want to make sure you are protected in the future.” To watch the full video of Mark’s insights, visit the original post here. blueAPACHE are a Palo Alto Networks premium partner and integrate Palo Alto next generation firewalls at the core of our emPOWER Cloud, emPOWER Network and emPOWER Managed Service solutions. For details on how to implement progressive security best practices, contact the blueAPACHE account team here.
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- emPOWER Core Network & DC Interconnect
- emPOWER Connectivity (pillar hub)
Frequently asked questions
Who is quoted in this article on how progressive boards approach cyber risk, and what is their role?
Mark McLaughlin, Palo Alto Networks Chairman and CEO, who shared key questions and insight into conversations board members should have with their CIOs.
What question does McLaughlin say boards typically ask CIOs, and why does he call it a hard question to answer?
"How safe are we? If I gave you one more dollar, how much safer would we be?" He calls it hard to answer because it is not specific enough to be actionable.
What alternative questions does McLaughlin recommend boards ask instead?
How comfortable the board feels in the organisation's security philosophy and architecture for the next three to five years, and how much is being invested in making it more automated and less manual.
What metric does McLaughlin describe as "probably the most important measure you can make"?
Tracking how many attacks the organisation is seeing and how many of those require attention, which he says shows the organisation's level of efficiency.
What thought exercise does McLaughlin propose for boards to challenge their security leaders?
Asking what they would do now if, in five years, they wanted to be twice as secure at half the cost, to force people to think outside the old approach.
Where can readers find the full video of Mark McLaughlin's insights, according to this article?
At the original post on securityroundtable.org, linked in the article.
What partnership does blueAPACHE describe with Palo Alto Networks in this article?
blueAPACHE states it is a Palo Alto Networks premium partner and integrates Palo Alto next generation firewalls at the core of its emPOWER Cloud, emPOWER Network and emPOWER Managed Service solutions.
What single characteristic does McLaughlin say is the biggest thing he sees in progressive boards?
That they challenge their security leaders to think differently, rejecting the old approach that "clearly doesn't work."
Source
- origin post (2017)
Knowledge Base
Who is the source of the insights discussed in the blueAPACHE blog post 'How the most progressive boards manage cyber risk'?
Mark McLaughlin, Chairman and CEO of Palo Alto Networks, shared key questions and insight into the conversations board members should be having with their CIOs.
According to Mark McLaughlin, what is wrong with the typical question boards ask CIOs, such as 'how safe are we?'
Mark McLaughlin says these questions are really hard to answer because they are just not that specific, unlike questions about security philosophy and investment strategy.
What questions does Mark McLaughlin suggest boards should ask instead of 'how safe are we?'
He suggests asking how comfortable the organization feels in its security philosophy and architecture for the next three to five years, and how much is being invested in making security more automated and less manual.
What is the single biggest thing progressive boards do differently, according to Mark McLaughlin?
The single biggest thing progressive boards do is challenge their security leaders to think differently, recognizing that the old way of managing security clearly doesn't work.
What questions do progressive boards ask about attacks, according to the article?
Progressive boards ask how many attacks are we seeing, and how many of those do we have to pay attention to — a measure Mark McLaughlin calls probably the most important because it shows the organization's level of efficiency.
What forward-looking thought exercise does Mark McLaughlin recommend to boards?
He recommends thinking: in five years' time, if we want to be twice as secure as we are today at half the cost, what would we do now? He says this forces people to think outside the box rather than continuing to do things the old way.
Where can readers watch the full video of Mark McLaughlin's insights referenced in the blog post?
The full video is available at the original post on securityroundtable.org, linked in the article at https://www.securityroundtable.org/progressive-boards-managing-cyber-risk/.
What is blueAPACHE's relationship with Palo Alto Networks according to this article?
blueAPACHE is a Palo Alto Networks premium partner and integrates Palo Alto next generation firewalls at the core of its emPOWER Cloud, emPOWER Network, and emPOWER Managed Service solutions.
When was the blueAPACHE article 'How the most progressive boards manage cyber risk' originally published?
The article was published on November 8, 2017, and has a stated read time of 2 minutes.
How can someone get help implementing the progressive security best practices discussed in the article?
The article invites readers to contact the blueAPACHE account team via the contact page for details on how to implement progressive security best practices.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bdfb153d68a8eeb6a99_Progressive-boards.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.