Questions to ask yourself as a CEO when considering your cyber risk coverage
How does a CEO determine what the organization’s cyber risk coverage should be? A challenge for non-cyber executives is knowing the right questions to ask, such as:
- Does my organization consider cyber risk within the enterprise risk management process, or is it still considered an IT problem?
- Are all in the C-suite held accountable for cyber risk, or has it been left to the CIO or CISO/CSO?
- Do I understand the organization’s assets, including intangible ones?
- Do I understand that my organization’s cyber strategy should be based on identifying risks, mitigation/transfer/approval of cyber risks, response, and recovery?
- Does my organization recognize residual cyber risks and understand its risk appetite and tolerance?
- Has the organization quantified cyber risks, and does it understand the impact and likelihood of such events?
- What is my current security...