The Boardroom Gap: How to Close the Gap Between Board Priorities and Actions

As cyber attacks become more costly, disruptive, and a threat for businesses cybersecurity governance is fast becoming a top priority for boardrooms. Some boards are adding a new director competency of cybersecurity expertise to their rosters, while others are turning to contractors and third-party service providers to bring cyber risk expertise into the boardroom. Some boards are employing an approach that is controversial: hiring hackers on red teams to test their systems and determine the areas where they’re vulnerable.

There is a gap between the goals boards declare and what they do to meet these goals. Our research has revealed that only 69% of board members report they regularly interact with their CISOs and a large percentage of them only communicate with their CISOs during board presentations. These gaps must be eliminated to ensure that the boardroom has enough visibility and dialogue regarding cybersecurity risks.

To close the cybersecurity gap, it is essential to ensure that cybersecurity is an integral part of every board’s agenda and involve directors in meaningful discussions regarding the risks they are facing. This means changing the way that the conversation takes place in the boardroom. For example, introducing the topic of cybersecurity on the agenda and pre-read material to be used in meetings for deeper discussions on cybersecurity issues. It is also crucial to make cybersecurity a priority for the board and develop an environment of security-conscious business through the tone of voice that comes from the top and rewards for those who speak up about the risks.

https://greatboardroom.com/

댓글 남기기

이메일은 공개되지 않습니다. 필수 입력창은 * 로 표시되어 있습니다