Notes:
- Board Competency:Â Boards are increasingly expected to have at least one director with cybersecurity expertise. If not, they must have a clear process for accessing expert advice.
- Oversight Structure:
- Full Board vs. Committee:Â For smaller companies, the full board may oversee cyber risk. For larger/complex firms, a dedicated Risk Committee or a specific Cybersecurity Committee is recommended.
- Reporting Cadence:Â The Board should receive regular updates (quarterly or semi-annually) on the cyber posture, including threat landscape, control effectiveness, and incident response readiness.
- Incident Response Plan (IRP):
- The Board must ensure the company has a tested IRP.
- Tabletop Exercises:Â The Board should participate in or review the results of “war gaming” exercises to simulate a cyber attack and test decision-making under pressure.
- Communication Plan:Â Protocols for internal and external communication (regulators, customers, media) during a breach.
- Third-Party Risk:Â A significant portion of cyber breaches originate from vendors. The Board must ensure the company conducts due diligence on third-party vendors and monitors their security posture.
- Post-Incident Review:Â After a breach, the Board must conduct a root-cause analysis to ensure lessons are learned and controls are updated to prevent recurrence.