No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Risk

What Every Board Member Should Know About Cybersecurity

by Ron Warren
December 15, 2014
in Risk
What Every Board Member Should Know About Cybersecurity

Is your company prepared for a cyber attack? This is a question that every director should be asking, and management should be providing regular updates to the Board on its level of preparedness. Cyber attacks are running rampant, and no company is exempt from an attack. If your company thinks so, then brace yourselves for a rude awakening.

Cyber attacks can cause serious damage to a company’s reputation, which says nothing of the financial impact that accompanies such an event. According to the National Association of Corporate Directors, if companies and governments are unable to effectively combat cyber threats, between $9 and $21 trillion of global economic value creation could be at risk.

Due to the growing volume and sophistication of cyber attacks, cybersecurity is an issue that every Board should be actively grappling with in order to mitigate the pitfalls associated with a breach. For companies and Boards, it is not the time or place for complacency when it comes to cybersecurity. Just because a company is small doesn’t mean that it is insulated against an attack.

In fact, hackers are nondiscriminatory, targeting large and small business alike. In a 2013 study conducted by Verizon’s RISK Team, 92 percent of cyber attacks by volume were perpetrated by people outside of the organization, whereas only 14 percent were conducted by insiders.

Outside Cyber Attack Perpetrators:

  • Organized crime – 55 percent
  • State-affiliated actors – 21 percent
  • Activists – 2 percent
  • Former employees – 1 percent

One of the greatest security threats facing businesses today is phishing. Seemingly innocent and trustworthy email messages masquerading as legitimate communications are causing employees at all levels of an organization to fall prey to phishing schemes. Why? Because they are relatively easy to execute and usually work. Top executives are not exempt either and are usually targets of more sophisticated and complex phishing scams.

Addressing cybersecurity should be a top priority for Boards and senior management. Companies would be well advised to solicit advice from both internal and external advisors. Internal advisors should be multi-departmental and include communications, legal, IT and risk management. Boards need to consider appointing a member well-versed in cybersecurity whose focus should be on understanding and developing strategies to manage cybersecurity risks and vulnerabilities.

Some companies have created a separate risk committee, while others utilize the audit committee to oversee this extremely important issue. The question remains as to whether risk oversight should be a function of the entire Board or handled in committee.

Before implementing an enterprise-wide cybersecurity plan, companies should do their homework and do the following:

  • Conduct appropriate due diligence on any company they do business with,
  • Develop a comprehensive cybersecurity policy for both the company and third-party providers,
  • Develop an incident response plan,
  • Develop a business continuity plan,
  • Periodically review insurance policies to determine if the company is adequately protected,
  • Conduct cybersecurity training programs for all employees,
  • Conduct regular audits of cybersecurity effectiveness and
  • Develop or update the crisis communications plan.

Currently, SEC regulations require that public companies assess and disclose any significant security risks. In the event of a breach, many state and federal laws also require companies to disclose the nature and scope of the breach to investors and affected individuals. This means that companies may face legal risks, as well as regulatory liabilities.

Cybersecurity needs to be a main topic on every Board’s agenda, and senior management should review its status and risk assessment at each meeting. In today’s society, it is not the time for management and the Board to put their heads in the sand and hope nothing happens. This issue deserves regular and ongoing discussions at the Board and senior management level. Only then can a healthy respect for cybersecurity be cultivated throughout the company.

Resources:

http://www.nacdonline.org/cyber
http://www.verizonenterprise.com/DBIR/
http://www.pwc.com/us/en/corporate-governance/publications/directors-and-it/risk.jhtml
http://blogs.law.harvard.edu/corpgov/2014/11/05/the-risky-business-of-cybersecurity/
https://forms.thawte.com/websurveys/servlet/ActionMultiplexer?Action_ID=ACT2000&WSD_mode=3&WSD_surveyInfoID=2351&toc=GLLSX-2351-04-26&brand=04&country=26&cid=A9CC4D30A054B9A0
https://na.theiia.org/special-promotion/PublicDocuments/GRC-Cybersecurity-Research-Report.pdf
http://www.blankrome.com/index.cfm?contentID=37&itemID=3309
http://www.blankrome.com/index.cfm?contentID=37&itemID=3146
http://www.citadeldirectorsinstitute.com/wp-content/uploads/board-oversight-cybersecurity-risks.pdf
http://www.theiia.org/bookstore/product/cyber-security-what-the-board-of-directors-needs-to-ask-download-pdf-1852.cfm
http://www.networkworld.com/article/2458975/security0/homeland-security-wants-corporate-board-of-directors-more-involved-in-cyber-security.html
http://www.smithlaw.com/newsletter-74.html


Previous Post

Employee Views of Leaders’ Personal Conduct Drives Perceptions of Their Ethical Leadership, ERC Study Says

Next Post

Top 10 Cybersecurity Predictions for 2015

Ron Warren

Ron Warren

Ron Warren is a senior communications professional with over 20 years of diversified experience in all forms of communications including investor relations, corporate communications, public relations, HR communications, marketing communications, advertising, writing, editing, project management, change management, and strategic planning. He is experienced in large, well established and start-up publicly held companies with multicultural audiences. His skill set includes excellent day-to-day, hands-on communications experience and operations management with an emphasis on creating operating efficiencies to impact company bottom-line success. Warren is a creative self-starter, team player, problem solver who works well under pressure and has proven project management and writing skills to meet any communications challenge. Warren possesses wide range of experience including strategy development, online content, publications, print production, interactive projects, executive speechwriting and executive presentations. Warren is a dedicated, highly accomplished communications professional with a strong background in strategic planning. He is recognized for providing creative, innovative, and enthusiastic leadership in a team environment.   Warren is currently a Senior Advisor with Labrador Regulated Information Transparency.

Related Posts

parliament

Coming Soon to the UK: Sweeping Corporate Criminal Liability Reforms?

by Peters and Peters
March 28, 2023

UK legislators have proposed major amendments to the Economic Crime and Corporate Transparency Bill currently passing through Parliament. If adopted,...

wind turbines

What Companies Around the Globe Need to Know About EU Sustainability Reporting

by John Peiserich
March 28, 2023

By the beginning of next year, large companies in the EU or that do a substantive amount of business in...

amsterdam

At a Gathering of Compliance Practitioners, No Shortage of Food for Thought

by Mary Shirley
March 28, 2023

Last week, about 300 ethics and compliance professionals descended upon Amsterdam’s Hotel Okura to participate in SCCE’s European Compliance &...

documents

Meeting Accounting Standards in an Uncertain Economy

by Tom Zauli
March 28, 2023

After a Covid-related grace period, new contract accounting standards — ASC 606 — are in effect for both public and...

Next Post
Top 10 Cybersecurity Predictions for 2015

Top 10 Cybersecurity Predictions for 2015

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Code of Conduct Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT