Questions Business Leaders Should Ask Themselves

PWC survey has found  that only thirty-six percent of board members have confidence in their company’s reporting on cyber security and while directors and senior management do not need to understand all the intricacies of cyber security, they do need to understand the business impact as well as the level of risks they are willing to accept. 
 
To do that effectively,  they need to ask themselves and the people whom they work with some searching questions.
 
Cyber crime is significantly increasing and it is time for the Board, directors and senior management to take more cyber security responsibility because if the organisation is hacked, they will be seen as responsible for the security breach. Cyber security should be a regular agenda item at Board meetings because directors need to gain an understanding of the cyber risks they are facing as an organisation and stay informed on a continual basis. 
 
Cyber security is a highly technical and specialised field, beyond the scope of most directors’ experience and  expertise. However, the role of the director is to ensure that their company is well prepared, has the right procedures in place and a high-quality leadership team that can respond quickly and effectively and that necessarily requires more than a basic understanding. 
 
  • The push towards digital transformation triggered by the coronavirus pandemic has only made companies’ task of protecting their data even more difficult. Recently, boards have been asking security professional for guidance on how to navigate a global pandemic with a workforce unaccustomed to working from home.
  • The rapid acceleration of digital transformation driven by the COVID disruption which has increased competition for talented, technically literate directors means getting knowledgeable talent to join the board has become harder.
  • A cyber attack will hit you when you least expect it and will probably occur in a way that you aren’t expecting. It is also important to recognise that the instigators of cyber attacks are typically sophisticated and well-organised criminals running lucrative businesses.

The key questions that directors should assure themselves they can answer in the event of a major breach. 

Is There A Comprehensive Cyber Security Strategy?    How confident are we that our company’s most important information is being properly managed and is safe from cyber threats? Do directors receive regular information from IT on who may be targeting our company, their methods and their motivations? 

How Are Cyber Attacks Detected And Responded To?     It’s great to know that all your business and customer information is secure but the board of directors would also want to know that there exists a plan of action whenever something gets compromised.  Without a doubt, data loss is seriously detrimental to any business and at times leads to its downfall also. That is why, the management would want to make sure that data backup and recovery plans are correctly put to place so that in case of an information breach, the business has the opportunity to fight back and thrive.
 
Are Accountabilities Clear?   Is there a defined process that identifies who does what when an incursion happens?  Have you confirmed that the business has escalation procedures in place and that these are up to date? How do you manage third-party cybersecurity risks    
 
Do You Have External Help You Can Call On When Attacked? Does the company’s commercial relationship with them guarantee timely access? Does your business have a war room environment ready to go when you are attacked? And do you understand what it can and can not do?
 
Can You Manage Reputational Damage?   Who Is The Public face of the business when you need to communicate a breach?   What is the company’s philosophy about paying a ransom if you are hit by a ransomware attack. What determines the decision to fight or pay?  
 
Does Your Organisation Have Cyber Insurance?    If yes, d do you understand the terms of coverage?  As a Board member, you need to understand the scope and details of the company’s cyber security insurance policy.  Part of an insurance plan is not just to insure your physical assets from a cyber threat. Ask your team if they have the tools and infrastructure that monitor your security parameters on regular if not real-time basis.
 
Cyber attacks are the new normal and the need for cyber  security is business critical. Business leaders have to be sure that they are looking at both the worst-case and best-case scenarios and are prepared to make some compromises to ensure a secure infrastructure.
 
PWC:       CPA Canada:       appknox:     Gartner:      AFR:     Tyler Cybersecurity:     
 
Symantec:         Which 50:      McKinsey:       ramsac
 
For advice and recommendations on your organisation's cyber security needs, contact Cyber Security Intelligence.
 
You Might Also Read: 
 
Get The Best Cyber Security Audits & Training In 2021:
 
« FBI Recover Ransom Paid To Pipeline Hackers
Beware Of Credentials Phishing »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

PortSwigger

PortSwigger

PortSwigger's Burp Suite is an integrated platform for performing security testing of web applications.

Astra Security

Astra Security

Astra's website security solution provides real-time protection against malware, hackers, SQLi, XSS, DDoS, LFI and RFI.

INCIBE-CERT

INCIBE-CERT

INCIBE-CERT is the reference security incident response center for citizens and private law entities in Spain

National Agency for Information & Communication Technologies (ANTIC) - Cameroon

National Agency for Information & Communication Technologies (ANTIC) - Cameroon

ANTIC is responsible for regulating the activities of electronic security and regulation of the Internet in Cameroon.

Information Network Security Agency (INSA) - Ethiopia

Information Network Security Agency (INSA) - Ethiopia

INSA's vision is to realize a globally competent National Cyber capability which plays a key role in protecting the national interests of Ethiopia.

Core Security

Core Security

Core Security provides threat-aware identity, access, authentication and vulnerability management solutions.

IQ Solutions

IQ Solutions

IQ Solutions is a Digital Integrator and an ICT Services Provider, focusing on innovative Cyber Secured ICT managed solutions tailored to the needs of the Maritime Industry.

IPN (ICT Research Platform Nederlands)

IPN (ICT Research Platform Nederlands)

IPN promotes academic research and education in the ICT field by building and maintaining a national community, and by developing policy to advance the field. Areas of focus include Cyber Security.

GreyCortex

GreyCortex

GreyCortex uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

Empiric

Empiric

Empiric is a multi-award winning technology and transformation recruitment agency specialising in data, digital, cloud and security.

Department of Justice - Office of Cybercrime (DOJ-OOC) - Philippines

Department of Justice - Office of Cybercrime (DOJ-OOC) - Philippines

The Office of Cybercrime within the Philippines Department of Justice is the Central Authority in all matters relating to international mutual assistance and extradition for cybercrime.

CYRail

CYRail

CYRail project will analyse threats targeting Railway infrastructures and develop innovative attack detection and alerting techniques.

Energia Ventures

Energia Ventures

Energia Ventures is a three-month intensive accelerator for entrepreneurs with an innovative business in the energy, smart grid, cleantech, and cybersecurity sectors.

Apura Cybersecurity Intelligence

Apura Cybersecurity Intelligence

Apura is a Brazilian company that develops advanced products and provides specialized services in information security and cyber defense.

DefectDojo

DefectDojo

DefectDojo is a DevSecOps and vulnerability management tool.

Cloud & More

Cloud & More

Tired of impersonal IT support? Experience the Cloud & More difference. We offer tailored IT services with a personal touch, ensuring your business technology runs smoothly.