Cybersecurity is one of the hotly debated subjects in board meetings. But many directors are unsure if they have sufficient technical skills to make a serious contribution. Such uncertainty is warranted. Cyber threats can develop rapidly, and the vocabulary related to them is frequently more suitable for IT organizations than for boardrooms.

You might be interested in: Disinformation Security

However, even though effective board oversight does not necessarily mean that board members should become cybersecurity specialists, it calls for their identification of the right questions to ask, and comprehension of the types of operational risks and assurance that administration is ready for any surprises.

Keep the Focus on Business Risk, Not Technical Issues

Boards should not be tempted to measure cybersecurity effectiveness only within the limits of technical metrics. While knowing the number of attacks that have been blocked or the number of vulnerabilities that have been eliminated is indeed informative, such approach only scratches the surface.

 Much more relevant questions have to do with how the cyber incidence may affect clients, business processes, finances, and the reputation of the company. Specifically, how long will crucial services be out of order after the attack? Which processes are the most vulnerable? How fast will the company be able to gain back its regular processes? Such issues relate to governance and now require regular public discussion.

Ask Questions That Drive Decisions

Non-technical directors create value by pushing the board to question preconceived ideas and demanding accountability. Questions like “Do we have an efficient incidence response plan?,” “How often does management report about cyber risk?” and “What useful conclusions do we have from previous incidents or simulations?” will normally produce a far more value-added discussion than any technical one.

It is also important to clarify if cybersecurity is taken into account at the very beginning of digital transformation projects, or if it is neglected until after the systems are being put into operation.

Seeking Cybersecurity as a Board Issue.

Nobody can totally get rid of cyber threats. Nevertheless, it depends on the board how ready the company is for that. It is critical to treat the cybersecurity problem not as an isolated technology issue but as a corporate risk issue. The best board members are not the ones who know all technical details about cybersecurity issues but those who instill the importance of maintaining the culture of resilience, making sure that all responsibilities are clearly assigned and that cybersecurity is closely aligned with the corporate strategy.

Leave a Reply

Your email address will not be published. Required fields are marked *

This field is required.

This field is required.