When major news outlets report that yet another corporation has experienced a data breach, most of the focus gets placed on the dangers of these events for the consumer. That, of course, isn’t a bad thing, as customers need to know what they can do to stop themselves from being one of the nearly 24 million U.S. residents who experience identity theft each year.
However, there’s another story to be told about cybersecurity incidents, and that is the threats they pose to the affected organization. When a data breach occurs, your company pays a considerable price. In fact, it is said that the average organization spends $4.88 million to clean up the effects of a cybersecurity breach. On top of that, there’s no telling just how much a data breach will cost you in terms of network downtime, legal liability, and reputational damage, which can take time to recover from.
In July of 2023, the U.S. Securities Exchange Commission (SEC) adopted new rules requiring public companies to not only disclose material cybersecurity incidents but also publish details of their cybersecurity governance strategies on an ongoing annual basis. Under these new regulations, it has become clear that boards can no longer relegate cybersecurity and data privacy to mere IT issues. They have now become issues of internal controls and risk management for which boards must provide strategic oversight.
As of March 2024, Deloitte found that 69% of audit committees have ranked cybersecurity as one of their top three concerns, with 30% of them ranking it as the number one issue to tackle. Without the board’s deep involvement in cybersecurity issues, companies could end up in serious trouble.
The Need for More Cyber Proficiency on Corporate Boards
In their final ruling, the SEC declined to require boards to identify whether they have a cybersecurity professional. However, just because they no longer have to include that information in official reports doesn’t mean that having cyber-related skill sets on corporate boards isn’t important.
The fact that cyber threats are so common, yet 88% of S&P 500 companies don’t have anyone with such knowledge on their boards, underscores the need to fill the gap.
In simplest terms, a cyber risk is a business risk. You know well how much data breaches can affect an organization on a financial and operational level.
Having a cyber professional on the board of directors elevates the conversation from a purely technology-driven issue to one that affects all aspects of the organization.
It allows the board to recruit someone who not only has relevant professional experience in cybersecurity and risk management but also has the strategic mindset to integrate that knowledge with a broader understanding of business principles.
Therefore, the individual will have the necessary knowledge to educate the sitting board on cyber risks while also being able to bridge the communication gap with the Chief Information Security Officer (CISO) and other key technology personnel. In turn, the board will take a more comprehensive approach to cybersecurity that is reflective of the influence that the topic should have on strategic business decisions today.
How to Create a Robust Governance Strategy for Today’s Cybersecurity Threats
With the cybersecurity landscape always evolving, creating a comprehensive strategy for dealing with cybersecurity at the board level is crucial. Consider the following approaches to creating a framework that delivers results for your organization:
Establish Your Approach to Oversight
It’s important to establish exactly how the board will be involved in cybersecurity oversight. According to Deloitte’s study, 58% of boards currently leave it to the audit committee, and another 9% let the risk committee handle it. Your board may wish to establish a separate cybersecurity committee, but in either case, just ensure that the topic is discussed frequently and comprehensively.
Build the Right Team
Build a team of stakeholders that includes the Chief Information Officer and CISO, as well as representatives from your legal, finance, and IT departments. Giving a diverse team of executives a seat at the table when discussing cyber risk issues ensures that the board can analyze these matters from all angles and that strategic decisions are made with your entire cyber risk profile in mind.
Understand and Monitor Risks and Solutions
Your board should work to understand the organization’s key cyber risks (including those from third parties) and the risk controls in place to help manage them.
Make sure to get regular updates on how new SEC rules and other regulations are affecting the company and where the company currently stands with satisfying those requirements.
Additionally, senior management should ensure they can produce the metrics to show that these risk controls have been measurably effective in preventing data security incidents throughout the organization. These metrics will be key in meeting disclosure requirements and building trust with investors and other stakeholders.
Don’t Make the Same Mistakes Twice
The board should also fully understand the company’s incident response plan and any disclosure controls that the CISO has implemented. If your organization has already experienced a breach, ensure that the management team can detail what was learned in those situations and how controls have evolved because of those learnings. Remember that your team can also learn from mistakes other organizations have made.
Create a Culture of Continuous Learning
Board members should continually seek ways to learn about current and emerging cybersecurity threats and new mitigation tactics. Even if you have board members who possess a rich understanding of the topic, consider engaging outside professionals as well. Ensure that management has a plan for regular employee training and continues to highlight its importance from the top down.
No More Sitting on the Cybersecurity Sidelines
Today, simply being aware of your organization’s cyber risks is no longer enough. With new SEC disclosure rules in place, the board needs to take a more active and strategic approach to cybersecurity and data privacy oversight. The first step in doing so involves ensuring that the nomination committee considers cyber-focused aptitude when searching for new board members.
Boards must also develop a comprehensive governance strategy to identify, assess, and mitigate cyber threats. That should include building a diverse team of stakeholders, understanding key cyber risks and controls, and continually learning about cybersecurity threats and mitigation tactics. With an effective strategy and a mindset that prioritizes cybersecurity, boards can play a key role in reducing the company’s cyber risks.




