7 cyber security questions for boards

32
Cyber security questions for boards 7 ???????

Upload: paul-mcgillicuddy

Post on 21-Apr-2017

25.333 views

Category:

Business


0 download

TRANSCRIPT

Page 1: 7 cyber security questions for boards

Cyber security questions for boards7

???????

Page 2: 7 cyber security questions for boards

risk oversight is a

function of the full

Board…yet

NACD  DIRECTOR’S  HANDBOOK  SERIES  2014  EDITION  

Page 3: 7 cyber security questions for boards

Did you know 50% OF BOARDS

SEE Cyber Security AS AN I.T. ISSUE?

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 4: 7 cyber security questions for boards

That means 50% Are doing

it wrong

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 5: 7 cyber security questions for boards

full Board

involved in

cyber risks =25%

Good

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 6: 7 cyber security questions for boards

no Board

INVOLVEMENT in

cyber risks =30%

Bad

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 7: 7 cyber security questions for boards

26% OF BOARDS SAY CISO or CSO

makes a presentation to the Board once

a year

UGLY

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 8: 7 cyber security questions for boards

28% SAY their security

leaders make no

presentations at all.

UGLIER

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 9: 7 cyber security questions for boards

What about 3rd Party vendors?

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 10: 7 cyber security questions for boards

23% do not evaluate 3rd parties - that number is

probably much higher

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 12: 7 cyber security questions for boards

only 50% of EMPLOYEES RECEIVE

PERIODIC cyber TRAINING

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

Page 13: 7 cyber security questions for boards

PWC:  US  cybersecurity:  Progress  stalled,  Key  findings  from  the  2015  US  State  of  Cybercrime  Survey

only 50% of EMPLOYEES

RECEIVE Initial cyber

TRAINING

Page 14: 7 cyber security questions for boards

Cyber Security’s biggest obstacle?

Cyberedge Group 2016 report

Page 15: 7 cyber security questions for boards

Low security awareness among

employeesCyberedge Group 2016 report

Page 16: 7 cyber security questions for boards

So here are the 7

questions

Page 17: 7 cyber security questions for boards

How are key business processes

affected by different types of

cyber attacks?

(i.e. Ransom ware, Denial of service,

Data breach, etc)

1

Page 18: 7 cyber security questions for boards

Leads to discussion on what type of

cyber security we have and why

1

Page 19: 7 cyber security questions for boards

Is our physical

security adequate & is

it congruent with our

cyber security?

2

Page 20: 7 cyber security questions for boards

the two are

interrelated

NACD  DIRECTOR’S  HANDBOOK  SERIES  2014  EDITION  

2

Page 21: 7 cyber security questions for boards

who are our 3rd party

vendors?

3

Page 22: 7 cyber security questions for boards

and what risks do

they pose?

3

Page 23: 7 cyber security questions for boards

who is responsible for

cyber security

training?

4

Page 24: 7 cyber security questions for boards

HR, IT, CISO, etc?

4

Page 25: 7 cyber security questions for boards

Have officers and

directors received

cyber security /

information assurance

training?

5

Page 31: 7 cyber security questions for boards

Cyber security questions for boards71. How are key business processes affected by different types of cyber attacks?

2. Is our physical security congruent with our cyber security?

3. who are our third party vendors?

4. who is responsible for cyber security training?

5. have officers and directors received cyber security training?

6. How do we vet our administrators?

7. Who does the ciso report to?

www.paulmcgillicuddy.com