A Bonus Segment for Our CISOs—Reporting to the Board of Directors
Reporting to the CxOs or the board of directors is not easy but necessary. Several factors need to be considered when presenting to the board, including but not limited to:
- Strategy: How effectively does the CISO understand a company’s goals and strategic initiatives, and to what degree is cyber risk incorporated into wider board-level decision-making?
- Board ownership: To what degree does the board drive strategy and how effectively is it incorporated into risk management procedures at the board level?
- Financial resilience: Are cyber exposures quantified and included in a disaster recovery plan that has been stress-tested?
- Accountability of executives: How are executive duties for cyber-risk management organized, and how are executives held accountable?
- Assurance: How does the CISO ensure cyber risk has been adequately evaluated?
- Reporting: How is the board informed about a...