7 board cyber security questions

33
Cyber security questions for boards 7 ???????

Transcript of 7 board cyber security questions

Page 1: 7 board cyber security questions

Cyber security questions for boards7

???????

Page 2: 7 board cyber security questions

risk oversight is a

function of the full

Board…yet

NACD  DIRECTOR’S  HANDBOOK  SERIES  2014  EDITION  

Page 3: 7 board cyber security questions

Did you know 50% OF BOARDS

SEE Cyber Security AS AN I.T. ISSUE?

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 4: 7 board cyber security questions

That means 50% Are doing

it wrong

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 5: 7 board cyber security questions

full Board

involved in

cyber risks =25%

Good

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 6: 7 board cyber security questions

no Board

INVOLVEMENT in

cyber risks =30%

Bad

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 7: 7 board cyber security questions

26% OF BOARDS SAY CISO or CSO

makes a presentation to the Board once

a year

UGLY

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 8: 7 board cyber security questions

28% SAY their security

leaders make no

presentations at all.

UGLIER

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 9: 7 board cyber security questions

What about 3rd Party vendors?

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 10: 7 board cyber security questions

23% do not evaluate 3rd parties - that number is

probably much higher

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 12: 7 board cyber security questions

only 50% of EMPLOYEES RECEIVE

PERIODIC cyber TRAINING

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 13: 7 board cyber security questions

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

only 50% of EMPLOYEES

RECEIVE Initial cyber

TRAINING

Page 14: 7 board cyber security questions

Cyber Security’s biggest obstacle?

Cyberedge Group 2016 report

Page 15: 7 board cyber security questions

Low security awareness among

employeesCyberedge Group 2016 report

Page 16: 7 board cyber security questions

So here are the 7

questions

Page 17: 7 board cyber security questions

How are key business processes

affected by different types of

cyber attacks?

(i.e. Ransom ware, Denial of service,

Data breach, etc)

1

Page 18: 7 board cyber security questions

Leads to discussion on what type of

cyber security we have and why

1

Page 19: 7 board cyber security questions

Is our physical

security adequate & is

it congruent with our

cyber security?

2

Page 20: 7 board cyber security questions

the two are

interrelated

NACD  DIRECTOR’S  HANDBOOK  SERIES  2014  EDITION  

2

Page 21: 7 board cyber security questions

who are our 3rd party

vendors?

3

Page 22: 7 board cyber security questions

and what risks do

they pose?

3

Page 23: 7 board cyber security questions

who is responsible for

cyber security

training?

4

Page 24: 7 board cyber security questions

HR, IT, CISO, etc?

4

Page 25: 7 board cyber security questions

Have officers and

directors received

cyber security /

information assurance

training?

5

Page 31: 7 board cyber security questions

Cyber security questions for boards71. How are key business processes affected by different types of cyber attacks?

2. Is our physical security congruent with our cyber security?

3. who are our third party vendors?

4. who is responsible for cyber security training?

5. have officers and directors received cyber security training?

6. How do we vet our administrators?

7. Who does the ciso report to?

www.paulmcgillicuddy.com