7

A CISO’s Playbook for Security Comms (with Jeffrey Brown)

Veteran CISO Jeffrey Brown shares a practical security communications playbook - BLUF, metrics with a job, and a non-judgmental report-button culture that changes behavior.

Listen on Apple Podcasts buttonListen on Spotify buttonWatch on Youtube button
Show Notes

Security leaders don’t need more slides - they need messages that move budgets, influence behavior, and reduce risk. In this episode, host Eliot Baker sits down with CISO and author ⁠⁠Jeffrey Brown⁠⁠ to unpack a practical security communications playbook: metrics with a job, and how to build a report-button culture without blame.

‍

Read full cybersecurity communications guide here.

‍

What you’ll learn in this episode:

  • How to use Bottom Line Up-Front (BLUF) to get faster decisions from executives and the board - and when not to.
  • Turning “security talk” into business outcomes: mapping risk to revenue, resilience, and cost.
  • Metrics that matter: designing KPIs that show behavior change, not just completion rates.
  • Building a non-judgmental reporting culture (and why “Report > Don’t Click” works).
  • Instant feedback loops: faster reinforcement without punishment in phishing drills.
  • Story-first, stat-supported narratives that land across technical and non-technical audiences.
  • Practical cadences and mediums: what to send to execs, managers, and the whole org and how often.
  • Using analogies (brakes & airbags) to make layered defense memorable and actionable.

    ‍

‍Timestamps:

  • (00:00) Introduction and Guest Introduction
  • (01:25) Jeffrey Brown's Background and Career Path
  • (03:22) The Importance of Communication in Cybersecurity
  • (06:10) Effective Cyber Awareness Strategies
  • (09:12) Challenges and Solutions in Cybersecurity Training
  • (25:48) The New Mandate for Security Leaders
  • (26:47) Effective Communication Strategies
  • (30:14) Building Influence and Relationships
  • (34:11) Crisis Communication and Incident Response
  • (39:34) Engaging with the Board and Continuous Improvement

‍

Resources:

‍

Host links:

Full Conversation Breakdown

In this episode of All Things Human Risk Management, host Eliot Baker sits down with veteran CISO and author Jeffrey W. Brown to unpack a practical playbook for communicating security so it actually influences behavior, budgets, and board decisions.

‍

The new mandate for security leaders

Security is a business issue and CISOs must communicate across every audience - from admins to the board. Keep messages at the right altitude for who’s in the room.

“Connect at the level your audience needs - resist the tech deep-dive.”

‍

BLUF to boardroom

Lead with the decision/request, then the why. BLUF shortens exec conversations and speeds outcomes.

“Put the bottom line up front - sometimes that’s all they need.”

‍

Make risk real (in business terms)

Boards understand risk - credit, market, operational. Frame cyber as operational risk with concrete impact (e.g., dollars per minute if a claims system is down).

“Translate ‘patch CVE’ into ‘avoid fines and downtime in system X.’”

‍

People don’t buy airbags - they buy cars

Use simple metaphors to explain layered controls (brakes = prevention, airbags = mitigation, recalls = incident response). It’s memorable and non-technical.  

“Metaphors make security relatable and sticky.”

‍

Culture as a control

Psychological safety beats punishment. Reward the right behavior and make reporting a social norm (even trophies or recognition).  

“Job well done isn’t deleting the phish - it’s reporting it.”

‍

Reporting > Don’t Click (and instant feedback)

Design communications that build a report-button habit and close the loop fast with user feedback on real threats.  

“Reinforce the behavior in the moment it happens.”

‍

Relevance and repetition

Send messages that match actual risks (tie to IR data) and repeat core points 7-14 times to make them stick.  

“Simple, repeatable, relevant beats one big October blast.”

‍

Channels, cadence, and clarity

Use visuals and concise language; mix depth for mixed audiences but avoid unnecessary detail.

“Right message, right medium, right amount.”

‍

Feedback is a gift

Close the loop with short surveys and qualitative input; perception is reality, use it to refine.

“Bad feedback beats no feedback - iterate the message.”

‍

Crisis communication that holds up

Have a tested IR plan, speak only to facts, and avoid speculation under pressure.  

“Tabletop before the breach; in the breach, stick to verifiable facts.”

‍

Metrics with a job

Ditch vanity counts (“5B blocks”). Give each metric a purpose: tell progress, drive behavior, or inform a decision - paired with a narrative.  

“If you can’t answer ‘so what?,’ it’s the wrong metric or the wrong story.”

‍

Takeaways you can implement this quarter

  • Ship a one-page BLUF template for exec updates and board decks.
  • Launch a Report > Don’t Click micro-campaign with recognition for reporters; add instant feedback on real-threat reports.  
  • Add the car safety analogy to all-hands and manager briefings to explain layered defense.
  • Tie awareness topics to current incidents (IR → comms loop) and repeat key behaviors throughout the year.
  • Replace vanity KPIs with behavioral ones (verification/reporting rate, time-to-report) and pair each with a short story.
Transcript
See Hoxhunt in action

Drastically improve your security awareness & phishing training metrics while automating the training lifecycle.