Speaking the board’s language
When the board of directors fails to interact with critical risks, including cyber risk, to the same extent they engage with rewards and opportunities, this is referred to as board risk blindness. This certainly can be avoided if the CISO employs a proper communication strategy.
An aware and involved CEO and board of directors seek updates on cyber risk, do not treat it as a simple and small IT problem, and entrust their CISO with a cyber-risk management strategy and roadmap. The CEO and the board need to feel confident that, in the event of a breach, appropriate measures are part of the business continuity plan and disaster response plan to minimize the damage to consumers in particular and the firm in general.
Although cybersecurity has been increasingly declared a high-priority issue for many board directors (72 percent of the AICD survey respondents indicate it as so), it is interesting to note that most boards indicate they still have...