Notes:

  • Board Competency: Boards are increasingly expected to have at least one director with cybersecurity expertise. If not, they must have a clear process for accessing expert advice.
  • Oversight Structure:
    • Full Board vs. Committee: For smaller companies, the full board may oversee cyber risk. For larger/complex firms, a dedicated Risk Committee or a specific Cybersecurity Committee is recommended.
    • Reporting Cadence: The Board should receive regular updates (quarterly or semi-annually) on the cyber posture, including threat landscape, control effectiveness, and incident response readiness.
  • Incident Response Plan (IRP):
    • The Board must ensure the company has a tested IRP.
    • Tabletop Exercises: The Board should participate in or review the results of “war gaming” exercises to simulate a cyber attack and test decision-making under pressure.
    • Communication Plan: Protocols for internal and external communication (regulators, customers, media) during a breach.
  • Third-Party Risk: A significant portion of cyber breaches originate from vendors. The Board must ensure the company conducts due diligence on third-party vendors and monitors their security posture.
  • Post-Incident Review: After a breach, the Board must conduct a root-cause analysis to ensure lessons are learned and controls are updated to prevent recurrence.