Latest news
This gap indicates that boards have a lack of understanding of how all business operations are supported by computer systems and digital data and how risks in these areas can undermine operations.

Less than two-thirds of the respondents' organizations have full-time personnel in key roles for privacy and security (CISO/CSO, CPO, CRO) in a manner that is consistent with internationally accepted best practices and standards. The degree to which these roles are filled varies by industry and region.
Survey results in the report confirms the belief among security experts that, overall, the financial sector has better security and governance practices than other industry sectors.
The financial sector shows the greatest degree of board attention to critical issues related to cyber risk management, while the energy/utilities and industrials sectors reveal a lack of board attention to critical issues such as vendor management, computer and information security and IT operations.
More than half, 57 percent, of respondents are not analyzing the adequacy of cyber insurance coverage or undertaking key activities related to cyber-risk management to help them manage reputational and financial risks associated with the theft of confidential and proprietary data and security breaches.
Although boards across geographical regions are consistent in not reviewing cyber-insurance coverage, a very high percentage of respondents from critical-infrastructure sectors, such as the energy/utilities and IT/telecom sectors, indicate that close to 80 percent of their boards of directors do not review insurance for cyber-related risks.
Although Europe leads globally in privacy regulations and enforcement, only 3 percent of the respondents indicate that their organizations have CPOs. The U.S. generally believes it is the global leader in security, but the survey results indicate that North American boards lag behind European and Asian boards in undertaking key activities associated with privacy and security governance such as regular reviews involving annual budgets, roles and responsibilities, and top-level policies.
A positive sign from the survey is the importance that boards are placing on IT and security/risk expertise in board recruitment as respondents ranked it very important or more important. Risk and security expertise was even more encouraging with 64 percent of the respondents indicating that it was very important or important.
Improvements are also occurring at the organizational level in the increased number of organizations with Board Risk Committees and cross-organizational teams that manage privacy and security risks within the organization.
Jody Westby, CEO of Global Risk & Adjunct Distinguished Fellow, Carnegie Mellon CyLab, said: "Cyber criminals today are sophisticated; they are getting inside corporate systems and stealing confidential and proprietary data. It is imperative that boards and executives take appropriate governance steps to protect their organizations' computer systems and information. This involves undertaking key-oversight activities, obtaining independent cyber-risk expertise, recruiting board members with cyber risk and governance expertise, and reviewing cyber-insurance coverage. These are the basics; critical infrastructures have a higher duty of care. Boards that fail to step up their cyber risk management are placing their organizations at risk and could be breaching their fiduciary duty to protect the assets of the corporation, which includes digital assets.


Spotlight

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






