As a board member, you are often asked ‘what is our cyber security posture?’.
So, we are going to help with answering your next question – ‘Where should I start when reviewing my company’s cyber security position?’.
Here are five points to help your board get their cyber security position understood.
1. Firstly, ensure you have the cyber basics in place;
- Basic awareness training, completed and repeated on a regular basis.
- Tailor awareness training for specialist groups; finance, software developers, front of house staff.
- Change the training content, to minimise complacency.
2. For specialist cyber security staff, ensure they are supported and listened to and set up a positive communication channel with them.
3. Develop a cyber risk policy with risk appetite statements clearly defined. Ask managers to ensure a cyber security strategy, policy suite and plan are defined.
- Establish metrics as part of your strategy,
- Quantitative or qualitative metric tracking can help reduce your cyber risk exposure.
4. Seek cyber assurance of your cyber security functions, an external view can help with the overall cyber security picture, Cyber Security Partners can help you with this.
5. Promote a positive cyber security culture
- People are your best line of defence,
- Avoid embarrassing people for their cyber security mistakes,
- People who make mistakes will become your cyber security champions of the future.
After doing all of the above many cyber risk stakeholders often have ‘just a few more queries to ask’, for example, how do you deal with new and emerging risks?
Below are new and current emerging risks
What is the use of artificial intelligence in your company?
- Know where and how artificial intelligence is used;
- Ask your product team, what artificial intelligence third-parties are they using,
- Who is using artificial intelligence to help them with their job communications.
Once you have all this information, you can then start to build an artificial intelligence risk profile and feedback into your overall cyber risk program. Then you can be confident in communicating what your cyber security posture is to the rest of the board, once you’ve set out and answered all the above questions.
