What not to do in the boardroom
As a result of the increase in global rules and legislation, cyber-risk management increasingly is part of the board’s agenda.
Cybersecurity is complex. There is a plethora of expertise, guidelines, standards, requirements, and vulnerabilities, among other matters. However, there is a growing emphasis on avoiding extra complexity and ensuring that cyber-risk management contributes to the enhancement of current company structures by acting as an integrated part of established processes, rather than in opposition to them. This requires a common understanding of the impact of cyber risk on company goals and good communication between business executives, the CISO, and the board.
The CISO’s role is to make sure the board understands the threats cyber poses to the business and should have a place on almost every board agenda. A key question for CISOs to ask themselves before every board presentation is: Are we overcomplicating things...