Questions Business Leaders Should Ask Themselves

PWC survey has found  that only thirty-six percent of board members have confidence in their company’s reporting on cyber security and while directors and senior management do not need to understand all the intricacies of cyber security, they do need to understand the business impact as well as the level of risks they are willing to accept. 
 
To do that effectively,  they need to ask themselves and the people whom they work with some searching questions.
 
Cyber crime is significantly increasing and it is time for the Board, directors and senior management to take more cyber security responsibility because if the organisation is hacked, they will be seen as responsible for the security breach. Cyber security should be a regular agenda item at Board meetings because directors need to gain an understanding of the cyber risks they are facing as an organisation and stay informed on a continual basis. 
 
Cyber security is a highly technical and specialised field, beyond the scope of most directors’ experience and  expertise. However, the role of the director is to ensure that their company is well prepared, has the right procedures in place and a high-quality leadership team that can respond quickly and effectively and that necessarily requires more than a basic understanding. 
 
  • The push towards digital transformation triggered by the coronavirus pandemic has only made companies’ task of protecting their data even more difficult. Recently, boards have been asking security professional for guidance on how to navigate a global pandemic with a workforce unaccustomed to working from home.
  • The rapid acceleration of digital transformation driven by the COVID disruption which has increased competition for talented, technically literate directors means getting knowledgeable talent to join the board has become harder.
  • A cyber attack will hit you when you least expect it and will probably occur in a way that you aren’t expecting. It is also important to recognise that the instigators of cyber attacks are typically sophisticated and well-organised criminals running lucrative businesses.

The key questions that directors should assure themselves they can answer in the event of a major breach. 

Is There A Comprehensive Cyber Security Strategy?    How confident are we that our company’s most important information is being properly managed and is safe from cyber threats? Do directors receive regular information from IT on who may be targeting our company, their methods and their motivations? 

How Are Cyber Attacks Detected And Responded To?     It’s great to know that all your business and customer information is secure but the board of directors would also want to know that there exists a plan of action whenever something gets compromised.  Without a doubt, data loss is seriously detrimental to any business and at times leads to its downfall also. That is why, the management would want to make sure that data backup and recovery plans are correctly put to place so that in case of an information breach, the business has the opportunity to fight back and thrive.
 
Are Accountabilities Clear?   Is there a defined process that identifies who does what when an incursion happens?  Have you confirmed that the business has escalation procedures in place and that these are up to date? How do you manage third-party cybersecurity risks    
 
Do You Have External Help You Can Call On When Attacked? Does the company’s commercial relationship with them guarantee timely access? Does your business have a war room environment ready to go when you are attacked? And do you understand what it can and can not do?
 
Can You Manage Reputational Damage?   Who Is The Public face of the business when you need to communicate a breach?   What is the company’s philosophy about paying a ransom if you are hit by a ransomware attack. What determines the decision to fight or pay?  
 
Does Your Organisation Have Cyber Insurance?    If yes, d do you understand the terms of coverage?  As a Board member, you need to understand the scope and details of the company’s cyber security insurance policy.  Part of an insurance plan is not just to insure your physical assets from a cyber threat. Ask your team if they have the tools and infrastructure that monitor your security parameters on regular if not real-time basis.
 
Cyber attacks are the new normal and the need for cyber  security is business critical. Business leaders have to be sure that they are looking at both the worst-case and best-case scenarios and are prepared to make some compromises to ensure a secure infrastructure.
 
PWC:       CPA Canada:       appknox:     Gartner:      AFR:     Tyler Cybersecurity:     
 
Symantec:         Which 50:      McKinsey:       ramsac
 
For advice and recommendations on your organisation's cyber security needs, contact Cyber Security Intelligence.
 
You Might Also Read: 
 
Get The Best Cyber Security Audits & Training In 2021:
 
« FBI Recover Ransom Paid To Pipeline Hackers
Beware Of Credentials Phishing »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Government Communications Headquarters (GCHQ) - UK

Government Communications Headquarters (GCHQ) - UK

GCHQ defends Government systems from cyber threat, provide support to the Armed Forces and strive to keep the public safe, in real life and online.

K&D Insurance Brokers

K&D Insurance Brokers

K&D provide insurance for all sectors of industry and commerce including cyber risk cover.

MailXaminer

MailXaminer

MailXaminer is an advance and powerful email investigation platform that scans digital data, performs analysis, reports on findings and preserves them in a court validated format.

CYSEC SA

CYSEC SA

Cysec is equipped to deliver agile security solutions for the most challenging IT infrastructures around the world.

Neovera

Neovera

Neovera is a trusted provider of managed services including cyber security and enterprise cloud solutions, committed to delivering results through the innovative use of scalable enterprise-grade tech.

ProcessUnity

ProcessUnity

ProcessUnity is a leading provider of Third-Party Risk Management software, helping companies remediate risks posed by third-party service providers.

Swiss It Security Group

Swiss It Security Group

Swiss It Security Group offers clients complete IT security concepts based on innovative solutions and technology, with a focus on protection, detection and defence.

GoTo

GoTo

At GoTo we help people and businesses to connect and collaborate simply and securely – from anywhere. We’re the trusted partner for companies of all sizes.

Concorde Technology Group

Concorde Technology Group

Concorde Technology Group is one of the UK’s leading IT support and services providers, delivering cost-effective and innovative IT solutions to businesses across the country.

FluidOne

FluidOne

FluidOne are an award-winning Connected Cloud Solutions provider. We design tailored solutions to help customers and partners digitally transform their IT and communications.

CloudCoCo

CloudCoCo

CloudCoCo help UK businesses of all sizes and industries succeed by providing enterprise-grade technology at small-business prices.

Seven AI

Seven AI

Seven AI develops cyber security software designed to identify online threats.

Softsource vBridge

Softsource vBridge

Softsource vBridge are an ICT systems integrator providing specialist technology solutions, professional services, technical expertise and data centre services.

Aryon Security

Aryon Security

Aryon Security is redefining cloud security with the ability to enforce cloud strategy with confidence, enabling organizations to prevent risks before they emerge.

CyberTee

CyberTee

CyberTee is an Alliance designed for and by independent cybersecurity professionals to address the talent shortage.

Stingrai Inc.

Stingrai Inc.

Stingrai helps companies prevent breaches by simulating real-world attacks through penetration testing.