{"id":2635,"date":"2019-06-05T13:04:12","date_gmt":"2019-06-05T13:04:12","guid":{"rendered":"http:\/\/www.blackopspartners.com\/?p=2635"},"modified":"2019-06-05T13:04:12","modified_gmt":"2019-06-05T13:04:12","slug":"what-corporate-boards-still-dont-understand-about-cyber-risk","status":"publish","type":"post","link":"https:\/\/blackopspartners.com\/what-corporate-boards-still-dont-understand-about-cyber-risk\/","title":{"rendered":"What corporate boards still don\u2019t understand about cyber risk"},"content":{"rendered":"\n

A recent study from the National Association of Corporate Directors highlights that one in five directors is dissatisfied with the quality of cyber-risk information that the board gets from management. Board members who felt their company was properly secured against a cyberattack fell to 37% in 2017 from 42% in 2016.<\/p>\n\n\n\n

One of the primary reasons for this drop in cybersecurity confidence is that most boards simply don\u2019t feel qualified enough to push their chief security officer for answers on what vulnerabilities their company faces and how they\u2019re protecting against today\u2019s attacks.\u00a0As a result, most board-level conversations are general in nature, such as, \u201cAre we spending on the right things?\u201d<\/p>\n\n\n\n

Cybersecurity needs to be a board-level discussion, and a vigorous one. Just consider the recent headlines illustrating the risks. FedEx and Maersk<\/a> each forecast $300 million in losses<\/a> tied to the NotPetya attack<\/a>. This year, it is estimated cybercrime will cost businesses more than $2 trillion\u2014a four-fold increase from 2015. And according to data from Juniper Research, the average cost of a data breach will exceed $150 million by 2020. The risks are not just financial, they could completely paralyze a business.<\/p>\n\n\n\n

So how can board members get their hands around the issue? One of the biggest problems boards face is that they simply don\u2019t have enough of an understanding of how attackers target companies and what the proper response should be. Security needs to be more than a series of patches or spending on security technology. Board members need to be able to understand their organizations\u2019 vulnerabilities in context with their security capabilities.<\/p>\n\n\n\n

There are a lot of resources available for board members to educate themselves on the security challenges their businesses face. A great place to start is the NACD\u2019s Director\u2019s Handbook on Cyber-Risk Oversight<\/a>, which lays out five principles creating the framework for a proactive means off addressing cyber risks. It\u2019s a practical guide including specific tips, templates, and resources for implementation.<\/p>\n\n\n\n

The board\u2019s enterprise risk management committee should also discuss the organization\u2019s cybersecurity risk and preparedness directly with the executive team. In these discussions, there are three important points to understand.<\/p>\n\n\n\n

First is what is being protected.<\/strong> Do we know what our assets are (IT devices, intellectual property, applications, etc.), especially in the autonomous, connected world we live in? How are we protecting those critical assets? How do we quantify cyber risk internally, and how is that tracked and benchmarked over time?<\/p>\n\n\n\n

Second is who might attack.<\/strong> What are the threats that are the most concerning, and how have those changed over time? What is the model we are using to think about insider threats? How about threats originating in our supply chain?<\/p>\n\n\n\n

Finally, discuss how the organization plans to defend against those attacks.<\/strong> Are we falling into the trap of assuming we can simply prevent every threat? What is our response strategy? Are we providing our security teams with the tools necessary to stop today\u2019s attackers? How are we making sure we aren\u2019t chasing the latest security and tech fad? What are our people and process challenges when it comes to security operations (burnout, training, knowledge management), and how are we managing them?<\/p>\n\n\n\n

Once they have an overview of the risks and a framework, board members will be better equipped to drill down to their companies\u2019 specific risks.<\/p>\n\n\n\n

The cost and impact of cyberattacks and data breaches has been well defined\u2014enough so that boards can no longer delegate the oversight of cybersecurity to the executive team. By understanding an organization\u2019s vulnerabilities and position within the broader attack landscape, board members can better address shortcomings and potentially start mitigating those risks for their companies.<\/p>\n\n\n\n

Read more at <\/em>Quartz<\/em><\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"

A recent study from the National Association of Corporate Directors highlights that one in five directors is dissatisfied with the quality of cyber-risk information that the board gets from management. Board members who felt their company was properly secured against a cyberattack fell to 37% in 2017 from 42% in 2016. One of the primary reasons […]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10],"tags":[],"acf":[],"_links":{"self":[{"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/posts\/2635"}],"collection":[{"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/comments?post=2635"}],"version-history":[{"count":0,"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/posts\/2635\/revisions"}],"wp:attachment":[{"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/media?parent=2635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/categories?post=2635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blackopspartners.com\/wp-json\/wp\/v2\/tags?post=2635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}