What Rules the Board?

What Rules the Board?

The World Economic Forum’s Global Risk Report 2021 lists cybersecurity failure as a top “clear and present danger” and critical global threat. Interestingly, the recent cyber-attack on JBS, the world’s largest meat processing company, illustrates that perfectly. Recognising this threat, the GFSC Cyber Security Rules and Guidance (the Rules) set out the risk-based requirements that Boards of Directors and organisations should consider and implement to mitigate against this significant risk.

These Rules indicate that the Board of Directors is responsible for ensuring that the Rules are followed. By "followed" the GFSC means that your organisation must have in place appropriate policies, procedures and controls to mitigate the risk posed by cybersecurity events. The regulator also requires that your organisation must be able to evidence that the Rules have been considered and implemented.

If the Rules seem daunting and overwhelming and you do not know where to start, we recommend that an organisation begins with a gap analysis against the Rules. This should be followed by a cyber risk assessment to identify and document their current risk profile, so that the Board can clearly see what the organisation's exposure to cyber risk is.

With this information in hand, a Board can help prioritise the work to reduce the gaps and/or to mitigate the risks. Getting to this point is critical, as it gives the Board an overview of the resources required to comply with the Rules by the deadline of 9th August 2021. With just more than two months remaining before the deadline, we recommend you assess where your organisation is on its journey to comply with the Rules.

Fortunately the Rules do state that the work involved is determined by the size, nature and complexity of your organisation. The journey to compliance is therefore different for each organisation, but the underlying principles remain the same.

If you need assistance to comply with the Rules or to simply assess where you are on the compliance journey, it’s not too late. Or if you just need to validate your position and then decide what to do for the best before the 9th August, we are independent cyber risk specialists and are here to help.

Please get in touch with us at [email protected] or via our website at www.centricalcyber.com.

要查看或添加评论,请登录

Kyan Frith的更多文章

  • The Hidden Costs of Bad Hires

    The Hidden Costs of Bad Hires

    ???A bad hire doesn’t just drain your resources—it can devastate your bottom line. No business owner wants that! You…

  • The Cyber Rules: Board of the Rules

    The Cyber Rules: Board of the Rules

    The GFSC Cyber Security Rules seek a pragmatic risk-based approach and if you have read the document, it may look a…

    1 条评论
  • Cyber Rules: Directors cut

    Cyber Rules: Directors cut

    Let's face it, cyber risk is everywhere. It's in your face on social media, on your news feeds, a topic in almost all…

  • New GFSC Cyber Rules: how to start

    New GFSC Cyber Rules: how to start

    It has been just over two month since the GFSC published the Cyber Security Rules & Guidance 2021. That means that…

  • Time to get your ducks in a row!

    Time to get your ducks in a row!

    The GFSC Cyber Security Rules seek a pragmatic risk-based approach and if you have read the document they may look a…

社区洞察

其他会员也浏览了