Search
Close this search box.
Search
Close this search box.

CEOs, Boards Must Prioritize Cybersecurity and Risk

What’s the big deal around cyber risk? A data breach will immediately cause a free fall in stock price, taint the brand and call into question the competency of board and C-level leadership.

Much of my time is spent advising CEOs and boards of directors on board composition, and I’m always amazed how so many boards are simply having the wrong conversation. The primary focus and responsibility of a board is governance, and broken down to its essence, governance is all about risk awareness and mitigation.

Sure, boards can (and should) talk about strategy, director independence, board culture, board diversity, board succession, board education, board attendance and the like—all important issues. Committee structures, public policy, procedure refinement, media relations, constituency management, capital allocation and deployment are all great and worthy topics. However, these issues as important as they are, rarely do they pose immediate extinction level threats.

The hot topics at board meetings these days are very heavily skewed toward what I refer to as the double Ds of diversity and digital. Again, worthy topics which clearly need to be addressed, but neither of these issues pose an immediate threat of putting an enterprise out of business in the near-term.

“A data breach will immediately cause a free fall in stock price, taint the brand, call into question the competency of board and C-level leadership, and will result in a guaranteed class action law suit.”

Most boards simply have easy, expected, and often pedestrian conversations – they don’t have the necessary and hard conversations. Average boards do easy well. Great boards do hard well. I often tell boards they can either do hard, or hard will do them. The former is a much better alternative than the latter.

So, what skill gaps are most prevalent in the board room? Almost universally, the glaring blind spot for boards are in the arenas of cybersecurity and risk. These are the two very large elephants in the room, these are the hard issue, these are the issues that can put even the most successful company out of business.

What’s the big deal around cyber risk you ask? For starters, a data breach will immediately cause a free fall in stock price, taint the brand, call into question the competency of board and C-level leadership, and will result in a guaranteed class action law suit. Those are just the obvious outcomes of data breach. Further fall-out from a breach could result in content or IP being held for ransom, confidential and embarrassing information being leaked to the media, systems being shut down, employees or customers being harmed due to exposure of personal information, physical (site security) vulnerabilities being exposed or exploited and the list goes on.

When it comes to physical risk, if the phrases, corporate negligence, wrongful death and corporate manslaughter don’t put the fear of God into you then I’m not sure what will.

Boards should not be lulled into a false sense of security because the company has hired a chief information security officer or a chief risk officer. This is a step in the right direction, but the best boards are expanding to have director seats representing cyber security and risk, as well as forming formal committees to oversee governance issues related matters with regard to cyber and risk.

The reality is when it comes to cybersecurity and risk, it’s not a matter of if, but when and how catastrophic? Boards that do not take the prudent and proper steps in these two areas will leave the company exposed and will pay a very heavy price down the road.


MORE LIKE THIS

  • Get the CEO Briefing

    Sign up today to get weekly access to the latest issues affecting CEOs in every industry
  • upcoming events

    Roundtable

    Strategic Planning Workshop

    1:00 - 5:00 pm

    Over 70% of Executives Surveyed Agree: Many Strategic Planning Efforts Lack Systematic Approach Tips for Enhancing Your Strategic Planning Process

    Executives expressed frustration with their current strategic planning process. Issues include:

    1. Lack of systematic approach (70%)
    2. Laundry lists without prioritization (68%)
    3. Decisions based on personalities rather than facts and information (65%)

     

    Steve Rutan and Denise Harrison have put together an afternoon workshop that will provide the tools you need to address these concerns.  They have worked with hundreds of executives to develop a systematic approach that will enable your team to make better decisions during strategic planning.  Steve and Denise will walk you through exercises for prioritizing your lists and steps that will reset and reinvigorate your process.  This will be a hands-on workshop that will enable you to think about your business as you use the tools that are being presented.  If you are ready for a Strategic Planning tune-up, select this workshop in your registration form.  The additional fee of $695 will be added to your total.

    To sign up, select this option in your registration form. Additional fee of $695 will be added to your total.

    New York, NY: ​​​Chief Executive's Corporate Citizenship Awards 2017

    Women in Leadership Seminar and Peer Discussion

    2:00 - 5:00 pm

    Female leaders face the same issues all leaders do, but they often face additional challenges too. In this peer session, we will facilitate a discussion of best practices and how to overcome common barriers to help women leaders be more effective within and outside their organizations. 

    Limited space available.

    To sign up, select this option in your registration form. Additional fee of $495 will be added to your total.

    Golf Outing

    10:30 - 5:00 pm
    General’s Retreat at Hermitage Golf Course
    Sponsored by UBS

    General’s Retreat, built in 1986 with architect Gary Roger Baird, has been voted the “Best Golf Course in Nashville” and is a “must play” when visiting the Nashville, Tennessee area. With the beautiful setting along the Cumberland River, golfers of all capabilities will thoroughly enjoy the golf, scenery and hospitality.

    The golf outing fee includes transportation to and from the hotel, greens/cart fees, use of practice facilities, and boxed lunch. The bus will leave the hotel at 10:30 am for a noon shotgun start and return to the hotel after the cocktail reception following the completion of the round.

    To sign up, select this option in your registration form. Additional fee of $295 will be added to your total.