Cybersecurity is a growing topic of discussion in Board meetings everywhere — given this fact, Board members need to be prepared to speak knowledgeably about their organization’s cybersecurity posture and programs. As businesses near the last quarter of the year and begin their planning processes, Boards must also be thinking about how to best prepare for 2019. Here are some factors that Boards must take into consideration:
Insight into Internal Security Performance
Security ratings provide key performance indicators of a company’s security operations, providing Board members transparency and visibility into an organization’s security posture. To effectively understand the impact of security programs and communicate changes to key decision makers, companies need tools that provide a quantified and comparative view of cybersecurity performance over time. A clear picture into a company’s security posture helps Boards assess the effectiveness of the internal security and risk programs that are already in place.
Benchmarking Security Performance to Industry Peers
While other corporate functions have embraced benchmarking as a way to compare performance, risk and security teams have been left in the dark. Traditional tools for network security are unable to compare security performance against industry averages and peers. By showing a company’s cybersecurity performance in relation to peers and actionable high level network performance metrics, organizations have been able to clearly demonstrate program improvements and advocate for increased cybersecurity resources.
The Importance of Managing Third-Party Risk
It’s important for Boards to prioritize the importance of third-party, or vendor, risk within your organization. Given that last year 56% of companies were affected by a third-party data breach, this is becoming absolutely critical. Businesses can partner with hundreds or even thousands of vendors that they engage with almost every day — if those companies possess sensitive information, it’s critical that their networks are readied for potential attacks as well. This is because hackers are now attacking larger organizations through these smaller vendors — they know that other, smaller organizations may not have the bandwidth to guard against these bad actors.