Boards Need To Step Up Or Risk Cybersecurity Fines

Protecting companies against the threat of cyber attacks used to be something that the IT department would be tasked with. Leaving tech to the tech experts seemed to make perfect sense. So long as the Board had appointed the right people for their job, many Board members felt their work was done, aside perhaps from hearing the occasional update from the IT department manager. 

What would be the point of interfering in matters that may be outside of their areas of expertise, after all? Let tech deal with tech, to free the Board up for more pressing matters.

The Daily Threat Of Cyber Attacks

But now, cyber attacks are not distant threats that happen to other organisations; they’re a daily reality, and no company is safe, regardless of their industry or size. A survey by the UK Government revealed that in 2022, 39% of UK businesses identified a cyber-attack. Out of the organisations who had reported attacks, 31% of businesses and 26% of charities estimated they were attacked at least once a week.

Fines - Insult To Injury Or Just Desserts?

On top of the sheer number of attacks, the costs to businesses can be staggering.  According to CISCO, data breaches are likely to cost, on average, 20% of a company’s turnover. There is also the high likelihood of businesses being hit with a substantial fine. Insult to injury? Perhaps, but when a Board has failed to take adequate preventative measures to safeguard their customer data, a fine may be viewed as appropriate punishment. A vital lesson in standing up and taking responsibility.

What Can The Board Do? 

If the recent £4.4m fine imposed on Interserve by the ICO has taught companies anything, it should be that understanding cybersecurity risks and investing in all the right technology is simply not enough to protect themselves from receiving a hefty fine. 

Like many firms, Interserve wasn’t ignorant to the real threat of an attack, nor was it reluctant to put the right tech in place. Where they failed was monitoring that tech and taking action when suspicious activity was flagged. They fell at the final hurdle and that cost them - big time.

Remaining resilient to the ever-evolving threats of cyber-attack requires a robust strategy driven by the Board that is constantly maintained and monitored. To put it simply, firms without watertight cyber resilience strategies are risking everything.

What is certain is that more eye-watering fines will continue to hit the headlines. 

There is a tendency for Boards to think that once they’ve invested in cybersecurity tech, they’ve done their job. This is a dangerous assumption. The vital part in a successful cyber strategy, which is still missing in all too many companies, is a security operations centre (SOC) service - experts who know how to monitor the tech, interpret the data and what to do when an alert is flagged.
 
Having all the tools but lacking a SOC service is only going halfway to protecting your organisation - which, in today’s cyber threat environment, isn’t nearly far enough. A SOC service provided by a trustworthy and reliable supplier means the difference between resilience and total vulnerability.”

Delivering Competitive Advantage

The Financial Times published the results of a survey by MIT Sloan and Proofpoint, a California cybersecurity company, which showed that Board members’ biggest fears on encountering a cyber attack, were data being made public, reputational damage and revenue loss

All these fears are well-founded, but what about the potentially devastating effects of being fined? Not to mention the cost of cyber insurance after a fine has been imposed. And then there’s losing out to competitors - many organisations are now refusing to work with partners who do not have a SOC service in place, as it means their data is vulnerable.

We have customers who came to us because they knew their cyber-attack resilience was weak and it was causing them to lose sleep. Having a SOC service in place gives Board members enormous reassurance that they’re doing everything they can to mitigate an attack - and can prove it if the ICO ever does come knocking.

Rob Demain is CEO & Founder of e2e-assure

You Might Also Read: 

How Do You Solve A Problem Like The Cyber Security Skills Gap?:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« US Strategy Will Allow Hacking Criminal & Foreign Networks 
Choose the best web application firewall for you »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

UCD Centre for Cybersecurity and Cybercrime Investigation

UCD Centre for Cybersecurity and Cybercrime Investigation

UCD Centre for Cybersecurity and Cybercrime Investigation is Europe's leading centre for research & education in cybersecurity, cybercrime and digital forensics.

CERT Polska

CERT Polska

CERT Polska is the first Polish computer emergency response team and operates within the structures of NASK (Research and Academic Computer Network) research institute.

PFP Cybersecurity

PFP Cybersecurity

PFP provides a SaaS solution for life-cycle protection based on our IoT security platform and power usage analytics.

Deltagon

Deltagon

Deltagon develops information security solutions to protect companies’ confidential information in e-communication and e-services.

AGAT Software

AGAT Software

AGAT Software is an innovative security provider specializing in external access authentication and data protection solutions.

Radiflow

Radiflow

Radiflow is a leading provider of cyber security solutions for critical infrastructure networks (i.e. SCADA), such as power utilities, oil & gas, water and others.

Sasa Software

Sasa Software

Sasa Software is a cybersecurity software developer specializing in the prevention of file-based network attacks.

TechVets

TechVets

TechVets is a non-for-profit helping UK veterans and service leavers retrain into Cyber Security and Technology jobs.

Cyber Range Malaysia

Cyber Range Malaysia

With Cyber Range Malaysia organizations can train their security professionals in empirically valid cyber war-gaming scenarios necessary to develop IT staff skills and instincts for defensive action.

BIO-key

BIO-key

BIO-key is a pioneer and innovator, we are recognized as a leading developer of fingerprint biometric authentication and security solutions.

Bolster

Bolster

Bolster (formerly RedMarlin) is an AI-based cyber-security platform designed to detect phishing and fraudulent sites in real-time.

TAG Cyber

TAG Cyber

TAG Cyber's mission is to provide world-class cyber security research, advisory, and consulting services to enterprise security teams around the world.

Business Resilience International Management (BRIM)

Business Resilience International Management (BRIM)

Business Resilience International Management (BRIM) is engaged by law enforcement in the UK and overseas to advise on establishing and developing Cyber Resilience Centres (CRCs) for business.

In Fidem

In Fidem

In Fidem specializes in information security management, with a bold approach that views cybersecurity as a springboard to organizational transformation rather than a barrier to innovation.

Altospam

Altospam

Altospam is a full service corporate email protection, integrating multiple security levels for your emails.

Cyber Unicorns

Cyber Unicorns

Cyber Unicorns is a cyber security consultancy created to help drive cyber security outcomes in the small to medium-sized business space.