There’s no doubt that organizations understand the value of implementing strong cybersecurity programs and encouraging their third parties to do the same. As data breaches continue worldwide, 63% of those breaches are caused through a third party vendor, according to Soha Systems’ Third Party Advisory Group. As such, Boards of Directors realize the need to have security and risk practitioners such as Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) provide their expertise and guidance. In today’s landscape, cyber risks are at the front of Boards’ minds. This is why it is critical that security practitioners be in the room.
Here are three ways that security practitioners can get involved with Boards and help formulate a strong security program.
1. Stay up-to-date with current events and facilitate company alignment.
Major global breach events are taking place almost weekly and Boards want to know if their own organizations are at risk. It’s a security practitioner’s job to stay up-to-date with these events and understand how they could affect their business. For example, with the recent WannaCry or NotPetya/GoldenEye ransomware attacks, it is critical to know if either your organization or one of your third or fourth party vendors is affected. The Board of Directors needs to know how any event such as this can affect daily operations and revenue.
2. Regularly provide updates on an existing security program and measures.
It’s important for the Board to be regularly updated on your organization’s security posture in terms that they can understand and relate directly back to business value. Providing this visibility shows the Board the importance and effectiveness of a strong security program. This ensures that an organization’s security team and Board are aligned in terms of allocating resources and budget for any cybersecurity practices that are a priority.