Cyberattacks have increased significantly in recent years, bringing vital conversations about cybersecurity into the Boardroom. As Board oversight of cybersecurity has increased, Board members — even those without technical expertise — have had to become rapidly acquainted with IT risk and security concepts. In the past few years, frameworks and best practices have emerged to help these Boards get a grip on their organization’s cybersecurity posture.
However, while there are many lists of what Boards of Directors need to ask about cybersecurity, the more important thing might be what they’re not asking. Each organization has a unique risk profile — when Board members rely too heavily on predetermined frameworks and cyber security risk assessment checklists, they risk passing over the most urgent risks.
What Are Board Members Missing? The Dangers of Bike-Shedding
When there is incongruity between the extent of the Board’s cybersecurity knowledge and the level of decision-making authority they hold, that’s a recipe for bike-shedding.
Bike-shedding occurs when a team spends an unnecessary amount of time on trivial details, neglecting the big picture. It usually happens because the most important issues are so complex that teams focus instead on simpler, more solvable problems. The term originates from the story of a committee that approved flawed plans for a nuclear power plant because they wasted time discussing details about the plant’s bike shed.
[Learn about the core elements of risk-based reporting.]
Here’s an example: let’s say that a Board of Directors has learned about a recent ransomware attack on a competitor. Each Board member has a decent understanding of how ransomware works and how dangerous it can be, and in the next Board meeting they discuss different ways their organization might be targeted, possible ransomware prevention initiatives, and whether or not the company’s firewall and detection tools are sufficient. After discussing and voting on those details, they quickly run through the rest of the cybersecurity agenda items.
Meanwhile, there are several much more pressing cybersecurity threats facing the organization, none of which get adequate attention from the Board. Malware prevention, while important, is receiving a too-large share of resources because it’s more visible and easier to get a handle on than these other issues. The Board has gotten hung-up on one tactical detail, rather than assessing their organization’s cybersecurity strategy as a whole. This is bike-shedding in action.
Here are some cybersecurity issues that might need more attention from the Board of Directors at your organization, and tips for addressing them.
Third-Party Risk
Rather than coming directly through an organization’s systems, many cyber attacks originate in the systems of third parties. Third-party data breaches are among the most expensive, so a solid understanding of supply-chain risk is essential for many enterprises.
Regulators are increasingly targeting third-party risk. Wide-reaching laws like GDPR and industry-specific regulations like the New York Department of Financial Services (NYDFS) Cybersecurity Regulation and NERC CIP-013 in the utilities industry provide specific requirements for managing third-party risk.
But third-party risk is complex. When an organization has hundreds or thousands of third parties with access to sensitive data and systems, keeping the company secure becomes extremely complex.