How to address the Board's lack of cybersecurity expertise
Sandika Daya
Non-exec director | Multi-award-winning IT GRC Senior Manager | Influential Woman in Tech | Wired4Women Trailblazer Finalist | Cybersecurity enthusiast | EDTX | Chartered CIO | Speaker | Mentor | C|CISO | CISA | CDPSE
What happens when a company is undergoing a digital transformation, implementing AI technologies to automate processes and personalise customer experiences, but the board lacks expertise in cybersecurity?
While the board may understand the potential benefits of AI, if they are not fully equipped to oversee the cybersecurity risks and governance issues arising from AI adoption, the board risks being unable to make informed decisions relating to cybersecurity.
?
Acknowledge the problem
Firstly, we need to acknowledge the problem. Present your concerns to the board and emphasize the potential consequences of a lack of cybersecurity expertise, such as financial losses, reputational damage, and regulatory penalties. This should be done in a way that highlights cybersecurity as a strategic business enabler rather than just an IT issue.
When you speak the Board's language in terms of their role in cybersecurity oversight in accordance with King IV and The Companies Act, you are more likely to get buy-in.
?
Address the problem
Next, we need to determine how the board will gain the missing cybersecurity experience. This can be done in a number of ways.
?
Management's role in ensuring the Board's effective monitoring of cybersecurity risks
Management should that they are providing the board with regular and comprehensive reports on cybersecurity risks and the company's efforts to mitigate them. Some of the ways to do this include:
By taking these actions, the company can ensure its board is equipped to provide effective oversight of cybersecurity risks, particularly in the context of its digital transformation and AI adoption.
OT Cyber Governance, Risk & Compliance Director | Board Member @ CSIR | Pr. Engineering leader @ ??
16 小时前Love your message here Sandika Daya ?? , we can go along way with following these steps. In my experience, table top excercises really help highlight the business impact and helps contextualise the controls required to manage and govern cyber risk . We can leverage these controls to gain competitive advantage and build trust, an opportunity that is often overlooked when managing cyber risk.
vCISO | Entrepreneur | Cybersecurity Advocate | Speaker | Cyber Workforce Developer | Trusted Adviser
1 周This is such a great article Sandika Daya, absolutely loved it. In my experience training and advising boards, I’ve often seen this disconnect play out firsthand. One of the biggest challenges from the management team side is the language we use. We’re presenting cyber issues in a way that we think is spot-on, but from their perspective, it's a technical snoozefest. Boards don’t want to dive into the nitty-gritty details or hear a soap opera storyline (like Santa Barbara). What they’re really asking is: What decision do you need from us, where's the data and how will it impact the business? If we don’t frame it in terms of the bottom line or the business implications, they lose interest—and let’s be honest, that’s probably why we get so little time in front of them! So as we educate them, we need to self-assess and change our approach.
Cybersecurity Leader | Appsec | GenAI (security) learner | Passionate about helping people.
1 周Great article addressing this. And very achievable ways to address that gap.