This post is contributed by guest blogger Michael Duffy, a member of Bitsight's Board of Directors.
With the growth in the number and sophistication of cyber threats and the daily reports of security breaches, cyber risk is high on the list of the most significant risks that organizations face. In fact, according to Lloyds Risk Index 2013, cyber risk is now the third biggest concern of CEOs and their senior executives, following high taxation and loss of customers. These threats and the potential risks call for a rethinking of the right way to approach managing cyber risk in the context of enterprise risk management (ERM).
Organizations have traditionally included cyber risk in the context of the IT risk management pillar under the domain of the CIO. IT risk management has always focused on security risk but also is responsible for the risks associated with the key areas of internal operations such as IT controls, availability, disaster recovery and performance.
But due to the dramatic increase in sophisticated corporate cyber attacks, including the emergence of state sponsored cyber terrorism, companies need to step back and think about cyber risks in terms of not just IT risk but also the broader context of ERM. Cyber risks, which are based on threats and attacks outside of the enterprise, now need to be measured, monitored and reported on separately as they can have serious implications for the business across ERM categories like strategic risk or reputational risk. By elevating the reporting of cyber risk in the context of ERM, senior business leaders will have better visibility into the true risks faced by the business.