"As CEO I was ultimately responsible for what happened on my watch"
Cybersecurity is no longer just the responsibility of the IT department. Boards of Directors have the ultimate role to ensure their organizations are identifying and mitigating key cybersecurity risks.
However only 39% of Boards and Executive Management Teams have a comprehensive understanding of information security to fully evaluate cyber risks and preventive measures, according to a recent study by EY.
The National Association of he National Association of Corporate Directors (NACD), Director’s Handbook on Cyber-Risk Oversight outlines five principles that all corporate boards should consider “as they seek to enhance their oversight of cyber risks.”
The challenge for Boards is how do they ensure they are asking the right questions of management? How do they know they have the right focus, strategy and investment in protecting their critical assets? How well prepared is their company when something goes wrong?
"As CEO I was ultimately responsible for what happened on my watch"
“Cybersecurity risks pose grave threats to our investors, our capital markets, and our country”
“Today we are announcing that, after extensive discussions, the board and Gregg Steinhafel have decided that now is the right time for new leadership at Target”
“In essence, the Board should consider cybersecurity as a managerial issue, not just a technical one”
Cybersecurity Strategy Assessment
Provides the Board with an independent assessment of the company’s cybersecurity strategy and the investments made to protect the company from cybersecurity risks. Understand where improvements are needed in people, process and/or technology. A short time-boxed assessment designed to deliver high value insights to Board members.
Cybersecurity Executive Awareness Training
In-person or virtual cybersecurity awareness training for Board members focused on how to protect the company from cybersecurity risks. Includes guidance on key considerations for the Board, how to evaluate the organization’s security program, and how to prepare for a security incident.
Cybersecurity Breach Simulation
An interactive session with key Board members to rehearse and practice the real-time decision-making needed in a breach incident. Adapted to follow the company’s specific incident response plans. Board members will gain a better understanding of their role in responding to a cybersecurity breach when (not if) it happens.
Cybersecurity Mentoring
Ongoing support and mentoring to key Board members to help them identify, understand and evaluate the company’s cybersecurity program. Helps Board members keep up-to-date with key cybersecurity issues and trends and be able to make appropriate queries of management.