Cybersecurity is a top risk for corporate directors to understand and navigate. The implications of cyber events for a company are many and growing: instantly damaged reputations that erode years of credibility and trust with customers and investors, impaired profitability from customer attrition and increased operating costs, lost intellectual property, fines and litigation, and harm to a company’s people and culture.
Consequences for companies can be significant. Cybersecurity incidents may result in material impact for shareholders. With the new U.S. SEC cybersecurity rules going into effect, investor awareness is on the rise. According to Cheryl Gustitus, Chief Strategy Officer at Glass Lewis, “investors will be looking even more closely at companies’ risk management, strategy, and governance practices on this critically important issue.”
How can security leaders help their boards perform effective cybersecurity oversight? According to a recent survey of U.S. directors, improving cybersecurity and data privacy is one of the top priorities for boards in 2023 and 2024. At the same time, 38% of directors identify cyber risk and data security as the issue most challenging to fulfilling their oversight responsibilities. 47% are engaging in director education programs to prepare for proposed regulatory requirements surrounding cybersecurity disclosures.
A strong, collaborative, and informed relationship between the Chief Information Security Officer (CISO) and the Board of Directors is essential for maintaining a robust cybersecurity program and ensuring that cybersecurity is integrated into the organization's corporate governance.
Steps to Improving the CISO/Board Relationship and Driving Effective Cybersecurity Governance
The relationship between the CISO and the Board of Directors is crucial in driving an effective cybersecurity program and overall corporate governance. This relationship should be characterized by communication, collaboration, and mutual understanding.
Here's a description of the key elements that should exist in this relationship:
- Regular Communication: The CISO should maintain open and regular communication with the Board. This includes providing updates on the organization's cybersecurity posture, emerging threats, and the status of ongoing security initiatives. The frequency of communication may vary, but quarterly or semi-annual presentations are common.
- Educational Engagement: The CISO should provide or help facilitate educational sessions to the Board to ensure that the directors have a fundamental understanding of cybersecurity risks, the potential impact on the organization, and the measures being taken to mitigate these risks. This education can be particularly important because many board members may not have a technical background.
- Risk Reporting: The CISO should present cybersecurity risks in the context of business risks. This helps the Board understand how cybersecurity vulnerabilities can impact the organization's reputation, financial stability, and compliance with regulations. Risk assessments, metrics, and key performance indicators (KPIs) should be used to illustrate the potential impact.
- Alignment with Business Goals: The CISO should align the cybersecurity strategy with the organization's overall business objectives. This ensures that security measures support, rather than hinder, the company's growth and strategic initiatives.
- Cybersecurity Governance Framework: Establish a cybersecurity governance framework that outlines the roles and responsibilities of the CISO, management, and the Board. This framework should define how cybersecurity decisions are made, who approves cybersecurity budgets, and how incident response plans are activated.
- Budget and Resource Allocation: The Board should be actively involved in approving cybersecurity budgets and resource allocations. They need to understand the financial requirements of maintaining effective cybersecurity and ensure that the necessary resources are available. CISOs should be able to justify current and new spend with metrics and outcomes, not by resorting to fear tactics.
- Incident Response Planning: The CISO should work closely with the Board to develop and regularly test incident response plans. Boards should be active participants in tabletop exercises. In the event of a security incident, the Board should be aware of the roles they play in managing and overseeing the response.
- Regulatory Compliance: The CISO should keep the Board informed about evolving cybersecurity regulations and ensure the organization remains in compliance. This includes discussing potential legal and financial implications of non-compliance.
- Vendor and Third-Party Risk Management: The CISO should have a strategic and operational approach to managing and reducing risks associated with third-party vendors and service providers. The Board should be aware of these risks and aware of how the organization is addressing and reducing risk from these partners.
- Cybersecurity Culture and Awareness: Promote a cybersecurity culture throughout the organization. The Board should set an example by participating in security training and awareness programs, emphasizing the importance of security from the top down. The Board should consider adopting metrics to hold management accountable for cybersecurity performance.
- Transparency and Accountability: Both the CISO and the Board should hold each other accountable. The CISO should be transparent about the organization's security posture, and the Board should provide guidance and support.
- Continuous Improvement: The relationship should be characterized by a commitment to continuous improvement. Regularly assess the effectiveness of the cybersecurity program, learn from incidents and mistakes, and adjust strategies as necessary.