Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Note To The C-Suite: It’s Time To Stop Avoiding Cyber Risk Governance
Articles

Note To The C-Suite: It’s Time To Stop Avoiding Cyber Risk Governance

ISBuzz TeamBy ISBuzz TeamApril 11, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The significant threat cyber attacks represent to commerce and infrastructure is intensifying calls for government to “encourage” companies and agencies to act more responsibly. Pending actions, which include a presidential executive order, bills in the U.S. Congress, and legislation in 35 state governments, call for standardized cyber risk reporting and management based on a de facto standard, namely the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework (CSF). What is driving all this activity?

The recent revelation of two massive Yahoo breaches raised the bar for the scale and awareness of devastating cyber attacks. The $350 million drop in the valuation of the company’s acquisition by Verizon made it clear that technology alone won’t overcome a lack of management and board commitment to protect an enterprise from cyber risk. Ripple effects of the Yahoo breach and multiple breaches of U.S. government agencies has led to widespread calls for more and better oversight of cyber risk on a par with oversight of financial risk, and it is rapidly elevating the importance of cyber risk governance (CRG).

In the last two years, a broad understanding has emerged: cyber risk is no longer a problem that IT should grapple with alone. While IT professionals have worked hard to build moats around their organizations using millions of dollars’ worth of external perimeter defense technologies, the truth is that most breaches don’t result from technology failures. Leaving the problem to IT without executive oversight has resulted in spending 80% of cybersecurity budgets to protect the perimeter, while only 20% of breaches result from failed technology, according to Zeus Kerravala, principal analyst at ZK Research.

Mitigating risk that cyber attacks pose to enterprises requires a widespread awareness that the right mix of people, policies and process, paired with technology, is necessary. Cybersecurity should be a team sport; it involves the CIO and CISO, of course, but other critical functions each have important roles to play in enhancing cyber resilience, including Internal Audit, General Counsel, Risk Management, Human Resources, and Procurement.

If cybersecurity is a team sport, what key steps can team members take to implement effective CRG?

  • CIOs and CISOs should acknowledge that their efforts must be augmented with a broad culture of awareness and action, and they must be willing to deliver information that matters and is comprehensible to non-technical team members.
  • Internal Auditors should devise understandable internal control systems for managing cyber risk that foster collaboration across the enterprise.
  • General Counsel should insist on cyber risk management processes that do more to decrease liability for the company, its management, and its board.
  • Risk Management needs to fully embrace cyber risk as an equal enterprise-wide source of risk and insist that it be treated equally as important as other sources of risk.
  • Human Resources must work hand in hand with IT and Security to (a) ensure that every employee learns how to avoid introducing risk into the organization’s networks, and (b) ensure that only necessary employees are given appropriate access to critical data.
  • Procurement should begin evaluating the risk that doing business with an insecure vendor represents, improve its vetting processes, and incorporate cyber risk into the evaluation process.

The failures that breaches characterize are a direct result of people, policies and process that are not aligned with a security-minded IT team. Cultures must change, boards and C-suites must adjust, and CRG needs to be considered an integral business function.

Improving cyber risk governance has been discussed in the past, but it’s now on the front burner as the best way to focus on effective management of cyber risk and to orchestrate organization-wide risk mitigation efforts. It’s become a topic in most boardrooms as directors accept cyber risk oversight as part of their fiduciary duties and look for objective ways to evaluate and monitor their organization’s cybersecurity.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}