Board Level Cyber Risk Management Standard Needed

Calls for company boards to be active governance partners in “collaborative cyber defence” have been made in the Advanced Cyber Security Center's (ACSC)   effective practice report, “Leveraging Board Governance for Cybersecurity, The CISO / CIO Perspective." The report urges boards and their directors to adopt a dynamic understanding of their organisation’s cybersecurity responsibilities and to maintain regular direct access to CISOs and risk officers in conjunction with CIOs and other executives.


Importantly, the report seeks to create an initial benchmark and method of evaluation for the evolving role of corporate boards in cybersecurity governance, initially through the perspective of Chief Information Security Officers (CISOs), Chief Security Officers (CSOs) and Chief Information Officers (CIOs), the primary networks supported by the nonprofit, member-based Advanced Cyber Security Center (ACSC).


P{rimary recommendations of the report are:


The board’s strategic risk role: In most cases, the board partnership with management is still “at an early stage” or “maturing” phase in its ability to provide strategic guidance and help guide management’s strategic risk judgments.


Building board cyber expertise: Because most boards do not yet have sufficient expertise in technology or cybersecurity to serve as strategic thought partners on cyber risk, they should recruit board members with broad digital/technology expertise, develop an annual curriculum of cyber briefings, provide ongoing training, and use third-party assessments.


Aligning the board role and corporate structures: CISOs and CIOs should present jointly at board meetings to provide a holistic view of digital strategies and security.  Boards as a whole should review cybersecurity more consistently as a business risk; the risk or audit committee should be used for more frequent (at least quarterly) cyber reviews.


Overseeing cybersecurity and digital transformation budgets: Boards should present digital transformation budgets as a whole, with cybersecurity investments as an element of overall IT-related decisions about where to invest in growth and security.


Developing cyber risk metrics and measurement: Boards should prioritise and support senior management’s development of a new generation of outcome-based cyber risk management frameworks, and in the meantime, executives should use only a few operational metrics with boards.


The full report can be seen here

more news

SEC Releases Guide To Combat Cybersecurity Threats


The Securities and Exchange Commission has released a guide to best practices to combat cybersecurity infractions, data loss and privacy breaches.

read more

FBI Fires Off A $3.5 Billion Cybercrime Warning


America's FBI has released the Internet Crime Complaint Center (IC3) "2019 Internet Crime Report." which shows that in on year the number of cybercrime complaints from individuals and business organizations reached a staggering 467,361. The total cost £2.7 billion.

read more

Fake Coronavirus Emails Contains Malware


Fear of the coronavirus infection is being leveraged by cybercriminals for their malicious activities, new research shows. Criminals disguised malware as documents proporting to be for educational purposes.

read more

Phishing Lures Still Affecting Organisations


A cybersecurity survey carried out by Proofpoint discovered that 90 percent of global organisations were targeted with BEC and spear phishing attacks in 2019, reflecting cybercriminals’ continued focus on compromising individual end users. Seventy-eight percent also reported that security awareness training activities resulted in measurable reductions in phishing susceptibility.

read more