What does the Boardroom need to know about Cybersecurity?
This Photo by Unknown Author is licensed under CC BY-NC

What does the Boardroom need to know about Cybersecurity?

Ever since the "Year of the Breach" there has been a flood of interest in the question about boardroom knowledge of cybersecurity and the posture of the enterprise with respect to it. The CISO of Target resigned as a result of a breach, but responsibility lies higher in the organization. The buck no longer stops with the technical leadership.

More than five years ago, the New York Stock Exchange Governance Services commissioned a survey of directors of public companies. Two-thirds of the directors lacked confidence in the enterprises ability to properly secure itself. This was despite the fact that nearly one-half of board meetings were addressing cyber security issues. The directors had clearly shifted the responsibility on the CEO of the organization. Years later, major risk insurance providers have placed cybersecurity issues in the list of top concerns for their clients. As recently as last summer, Forbes presented an article about, "Compliance Is Not Security: Why You Need Cybersecurity Chops In The Boardroom."

In forming a center on the Marquette University campus to deal with academic and community needs for knowledge and skills in cybersecurity, we chose the name, the Center for Cyber Security Awareness and Cyber Defense. The intent was to emphasize the need for all to be aware and the need for all to prepare defenses. Our cyber security awareness event two years ago emphasized that cybersecurity was everybody's job. Last year we emphasized educating all in the knowledge and skills that are required.

The world is full of companies marketing technical solutions and their consultancy, but the Directors on the board are lead by the Chief Executive Officer who is to be ultimately responsible for making managerial decisions. Where are the CEOs who are exerting leadership? I see that there are three kinds of postures for CEO's who have taken meaningful action:

  1. Those who "got it" and led the discussion inside their enterprise and the Boardroom
  2. Those who after observing the risk to the enterprise and themselves "did it"
  3. Those who were breached or had a near-miss, but experienced the threat inside their organization and "recovered."

Do you have a story to tell about an enlightened CEO who got it, or one who just did it, or who recovered?

Not every CEO has yet responded to the threats. The community needs to compile the stories and share them so that we can collectively reduce the risk.

Wayne P.

Comprehensive IT/ICS/OT Cybersecurity Evangelist

5 年

Incidents and breaches shall continue indefinitely unless & until our paradigm shifts.

回复
Brian Kunick

Advising organizations on managing risk, effectively

5 年

Cybersecurity representation at the Board is still inadequate.? At Digital Assurance Advisors we have focused our practice to provide Cyber Advisory to the Board to address this need as threat actors will not wait one or two election cycles until the Board ramps up.? H.R. 1731?https://www.govtrack.us/congress/bills/116/hr1731/text stresses the importance to align with a qualified entity at the highest level to secure your organization.? Rick Howard? Christopher Kolenda, Ph.D.? Greg Duckert?

回复
Steb Scheele

We manage your IT. You focus on the business.

5 年

With the cost of attacks/downtime easily extending into the millions for many organizations, C-Suite executives must take heed.? You can take a look at an article I wrote regarding the top threats businesses will face in 2020 here: https://www.dhirubhai.net/pulse/organization-under-siege-how-managed-service-provider-steb-scheele/?trackingId=HTZSXegWQAGnyOkZUxWUbw%3D%3D

要查看或添加评论,请登录

Tom Kaczmarek的更多文章

  • What everybody Needs to Know

    What everybody Needs to Know

    I was recently prompted (by my daughter, Teresa Janusz) to think about the needs of Finance students to learn more…

    1 条评论
  • Spotlight on Project Management

    Spotlight on Project Management

    Experience is a great teacher My practical experience in research and development plus the feedback that I have…

  • Spotlight on Project Management

    Spotlight on Project Management

    My practical experience in research and development plus the feedback that I have received from successful alumni…

    1 条评论
  • Enabling Career Change

    Enabling Career Change

    On Wednesday, May 4 at 5:00 PM we are holding a special celebration and Open House. Five years ago we received a S-STEM…

  • I'm excited

    I'm excited

    I am always excited to see students demonstrate leadership. Recently I announced a cyber competition to students in the…

    1 条评论
  • Remote Work

    Remote Work

    Today I received an email from Tech Target that included this teaser-line: "There are many questions around re-opening…

  • The "secret sauce" in digital transformation

    The "secret sauce" in digital transformation

    Not too surprisingly..

  • Serving the profession

    Serving the profession

    I am truly grateful for the interest I have seen in our professional MS degree program. It is serving the computing…

    2 条评论
  • Ethics Belongs in Data Governance

    Ethics Belongs in Data Governance

    Recently I attended the 4th annual Ethics of Big Data that was sponsored by our Center for Cyber Security Awareness and…

    2 条评论
  • What?

    What?

    Report on High Demand Skills Today, I ran across an article about The Most In-Demand Hard and Soft Skills of 2019. With…

社区洞察

其他会员也浏览了