Board Concerns About Cyber Security Billy Kinuthia
Our Focus Areas For Today Cyber Risks of Augmented Reality Zero-day Initiatives (ZDIs) Malware Analysis Advanced Persistent Threats Reverse-code Engineering “Of Course, you can’t get that technical with the Board… (This is the mistake some people make!)”
Recent Cyber Attacks
Impact of Cyber Attacks and why Boards Should be Concerned As seen from the attacks it boils down to key impacts including : Financial Loss/ Fraud Loss of Customer Confidence Reputational damage Regulatory sanctions Litigations Leaked trade secrets
Why Boards should be involved Increasing cyber threat landscape The Board is responsible for steering the organization in the right direction The tone at the top will influence how the rest of the organization behave (organizational culture) The Board sets expectations for Management Litigation – Lawsuits by shareholders against the Board
Challenges in obtaining Board’s buy-in Deeply technical subject that is new to most Professionals serving in Boards Most companies don’t consider Cyber risks as strategic risk The board doesn’t understand the risks and impact of cyber security Failure to articulate the ROI of investments in securing the enterprise. Lack of adequate regulation around cybersecurity
Getting the Board on-board Be clear and concise (Use simple language and avoid technical jargons and acronyms) Articulate business impact, risk, mitigations and plans Clearly identify and describe anything that requires Board action or consideration Do not surprise Senior Management (C-Suite Team). brief them in advance before taking anything to Board Train people from board level to become security aware.
Q & A