Embed cyber risk in strategic decisions
Many strategic decisions have a cyber risk component. For example, adopting new technologies to innovate or better enable and connect a remote workforce changes the company’s cyber risk profile.
Next steps:
- Give the chief information security officer (CISO) a seat at the table when addressing strategic decisions and the company’s plan.
- Get metrics on the effectiveness of employee training and awareness for cyber risks as well as the remediation efforts for those that do not comply or lack understanding of the risks.
- Ask others outside of the CISO, like business unit and other functional leaders, how they address cyber risk in their departments and key product and service offerings.
…read more in the report.
Understand the cyber risk management program
Boards want to know whether management is focusing on the right cyber risks, how management is addressing those risks and whether it’s enough. This starts with understanding the company’s cyber risk management program and cyber risk appetite.
Next steps:
- Understand the key cyber risks to the organization and how the executive team is managing these risks.
- Take a fresh look at the board’s cyber reporting and get consistent and holistic information to help the board make decisions.
- Understand significant new laws and regulations in the cyber/privacy areas and their impact on the business, and get updates on how the company is staying up to date with and meeting those requirements.
…read more in the report.
Rethink the board’s cyber oversight allocation
By now, all boards have allocated cyber risk oversight somewhere — either to a committee or the full board. But boards periodically should reassess their allocation to determine that it is effective.
Next steps:
- Reassess where cybersecurity oversight sits on your board and whether the board has cybersecurity skills/expertise, or has access to cybersecurity skills/expertise, to perform its oversight role.
- Evaluate how your board is continuing to get upskilled and educated on cybersecurity.
- Update the relevant charter with language that provides insight into the committee’s responsibility, under the direction of counsel.
…read more in the report.