In today’s evolving threat landscape, corporate directors are increasingly asking for security performance updates from Chief Information Officer, Chief Information Security Officers, Chief Risk Officers, and other executives.
At Bitsight’s inaugural EXCHANGE forum last month, a panel of directors and executives from top global companies discussed the importance of Board involvement in mitigating cyber risk.
The panel was moderated by Suraj Srinivasan (Professor, Harvard Business School). The panelists included Ed Brandman (Chief Information Officer, KKR & Co.), Andy Brown (Board of Zscaler and Guidewire), Bijoy Sagar (Chief Digital and Technology Officer, Stryker) and Shelley Leibowitz (Board of AllianceBernstein and E*TRADE).
Panelists Ed Brandman, Andy Brown, Bijoy Sagar, Shelley Leibowitz, and Suraj Srinivasan discuss the Board’s role in cybersecurity at Bitsight’s inaugural EXCHANGE forum on October 10, 2018.
Here are some of the key takeaways from the discussion:
1) When it comes to cybersecurity, Board members need to completely understand the spectrum of risk for both their organization and industry.
It’s important for directors to understand the landscape around their company: its value and possible threats to that value, as well as company decisions, their residual risk, and the risk-mitigation techniques being employed. Understanding both qualitative and quantitative data allows organizations to look backward and forward; the cybersecurity audit committee should focus specifically on looking backward while the risk oversight committee focuses on what may happen. This helps create a comprehensive picture of risk both within and outside the organization. Companies, especially those that have a strong digital presence, must think about risks that may not seem obvious. As one executive said, “Think about the risks you may not be thinking about and expect the unexpected.”
2) While some Boards have a cybersecurity expert, most do not. Instead, the risk oversight committee should fulfill this role and facilitate discussions that provide the appropriate context around cyber risk.
The shortage of security professionals among Board members emphasizes the need for collective responsibility around cybersecurity and cyber risk. While most Boards do not have a designated cybersecurity expert, an increasing number are assigning this responsibility to the risk oversight committee. According to another executive, risk committees should be accountable for several cybersecurity-related areas: governance, policy, testing, transparency, and resource allocation.