As cyber-attacks become more costly, disruptive, and a threat to businesses cybersecurity governance is quickly becoming a top boardroom priority. Some boards are introducing a new director’s competency of cybersecurity to their list of competencies, while others are using contractors and third-party service providers to bring cybersecurity expertise to the boardroom. Some boards are even using a controversial method: hiring hackers from red teams to test the company’s systems and determine what vulnerabilities they have.
However, for a lot of boards, there is a gap between their stated goals and the actions they take to meet the issues they have identified. Our research has shown that only 69% of board member have reported that they regularly interact with their CISOs. A large proportion of these board members interact with their CISOs when presenting to the board. These gaps must be addressed so that the boardroom can be able to have a dialogue and see cybersecurity risks.
To close the gap, it is essential to make cybersecurity a core component of every board’s meeting and to engage directors in meaningful discussions about the risks they are facing. This means changing the manner that discussions are conducted in the boardroom. For example, introducing a cybersecurity agenda item and pre-read materials to be used in meetings for more detailed discussions on cybersecurity issues. It is also necessary to make cybersecurity a priority for all board members and creating a security-focused company culture by setting the leadership from the top, rewarding of those who advocate for risk awareness and imposing consequences on the entire management team.
