Understanding cybersecurity challenges, organization, and reporting
Cybersecurity is a young and emerging profession. That is one reason why it is not fully understood or taken seriously by many C-level executives. While many CEOs and board members have extensive cross-functional experience in accounting, finance, marketing, or HR, few have much cybersecurity experience. As a result, cyber risks are not commonly understood in boardrooms. Many companies leave cybersecurity to the organization’s Chief Information Officer (CIO)/Chief Technology Officer (CTO), and cyber risk management is perceived as a cost confined to the IT department where it must compete for resources/budget against new initiatives for revenue generation, profit increase, customer acquisition, and so on.
A Chief Information Security Officer (CISO) who is responsible for the confidentiality, integrity, and availability of data often reports to a CIO or CTO. While this structure is common, it has proven...