---
title: [Video] FAIRCON18 Panel Explains How to Bridge the Gap Between CISO and CRO
description: CISO Omar Khawaja and CRO Dennis Cronin from Highmark Health got into details on how they tag team cyber risk reporting.
---

[The FAIR Institute Blog ](https://www.fairinstitute.org/blog)

# [[Video] FAIRCON18 Panel Explains How to Bridge the Gap Between CISO and CRO](https://www.fairinstitute.org/blog/video-faircon18-panel-explains-how-to-bridge-the-gap-between-ciso-and-cro)

 Written by [Jeff B. Copeland](https://www.fairinstitute.org/blog/author/jeff-b-copeland) | Nov 13, 2018 3:53:17 PM

As the [FAIR model](https://www.fairinstitute.org/what-is-fair) and risk quantification brings cyber risk management in line with the rest of enterprise risk management, the roles of CISO and CRO also pull closer together. A panel discussion at the recent [2018 FAIR Conference](https://www.fairinstitute.org/blog/topic/fair-conference-2018) showed a cooperative CISO/CRO relationship in action – Omar Khawaja, CISO at Highmark Health and Dennis Cronin, CRO at Highmark got into details on how they tag team cyber risk reporting, with input from moderator Amjed Saffarini, CEO, [CyberVista](https://www.fairinstitute.org/blog/fair-institute-partners-with-cybervista-for-board-director-education) and Mary Ann Blair, CISO, Carnegie Mellon University, the host for FAIRCON18.

Watch the panel discussion [Bridging the Gap between the CISO and the CIRO](https://link.fairinstitute.org/discussion/308/panel-discussion-bridging-the-gap-between-the-ciso-the-cro#latest) (FAIR Institute membership required. [Join the Institute now.)](https://www.fairinstitute.org/get-involved)

Some tips from the discussion, especially for CISOs:

- Make sure to align methodologies for cyber risk management with the ERM program.
- Develop a direct reporting relationship by CISO and CRO with the audit committee of the board.
- Reach out to senior executives and develop relationships so they enjoy hearing from you. For instance, Omar recently held meetings with executives to discuss their personal online safety.
- “Make sure we are part of the operational fabric of the organization,” Omar says. “We would much rather the business reach out to us and say, ‘We’re doing this [initiative], can you help us do it safely?‘”
- Keep infosec and risk staffs in constant contact.
- Let everyone know that cybersecurity has high level support from the C-suite and the board.

[Watch the CISO & CRO panel discussion now](https://link.fairinstitute.org/discussion/308/panel-discussion-bridging-the-gap-between-the-ciso-the-cro#latest).

**Related: **

[More about events at FAIRCON18](https://www.fairinstitute.org/blog/topic/fair-conference-2018)

[Read an interview with Omar Khawaja ](https://www.fairinstitute.org/blog/meet-a-member-omar-khawaja-introducing-fair-to-highmark-health)

[View full post](https://www.fairinstitute.org/blog/video-faircon18-panel-explains-how-to-bridge-the-gap-between-ciso-and-cro)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Jeff B. Copeland"
  },
  "dateModified" : "2018-11-14T03:27:54.137Z",
  "datePublished" : "2018-11-13T15:53:17Z",
  "headline" : "[Video] FAIRCON18 Panel Explains How to Bridge the Gap Between CISO and CRO",
  "image" : {
    "@type" : "ImageObject",
    "height" : 401,
    "url" : "https://cdn2.hubspot.net/hubfs/1616664/Omar%20Khawaja%20CISO%20Hightmark%20Dennis%20Cronin%20CRO%20Highmark%20FAIRCON18%20Panel%20Discussion%203.png",
    "width" : 600
  },
  "mainEntityOfPage" : "https://www.fairinstitute.org/blog/video-faircon18-panel-explains-how-to-bridge-the-gap-between-ciso-and-cro",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "FAIR Institute Blog"
  }
}
```