Combatting Cybergeddon with cyber governance in 10 steps

The accelerating worldwide trend of digitisation represents a key business opportunity for European organisations, but also brings with it key business risks. With recent cyber attacks increasing concerns on what the risk experts see as a wider lack of focus on risk governance in cyber security, how can companies in Europe meet their obligations under EU regulations?

Cybersecurity is a matter of corporate governance which is high on the list for today’s European risk managers. This aspect of cybersecurity, however, has not been fully explored by European legislation. Joint with the European Confederation of Institutes of Internal Auditing (ECIIA), we recently set up a working group of risk managers and internal auditors to provide guidance on the governance of cyber risk.

Our report, entitled At the junction of corporate governance and cybersecurity, contains 10 recommendations for a cyber governance model that will benefit European organisations in managing their exposures to cyber risks. We will be covering this report in detail at our Seminar in October, but here is the outline of the 10 steps:

  1. Transparency and regulation
    There is a trend toward more transparency and regulation over cyber security. The implementation of the two new European Union laws impacting cybersecurity, the Network and Information Security Directive and GDPR, will reinforce the obligations for organisations.

     
  2. Governance framework
    With cybersecurity becoming a matter of corporate governance, the right governance framework is crucial to an efficient management of cyber risks.

     
  3. Challenge management
    With a strong cyber risk management framework in place, organisations should manage the challenges and opportunities of digitisation in a holistic way and ensure effective management of cyber risk across the organisation.

     
  4. OECD principles
    The OECD developed eight principles for digital security risk management:

     

 

    • Awareness
    • Responsibility
    • rights and obligations
    • co-operation
    • risk assessment
    • security measures
    • innovation
    • preparedness, resilience and continuity.

 

These are applicable to the private sector and describe all the aspects to be considered to manage cyber risks effectively. We will be joined by a guest speaker from the OECD at our Seminar later this year for more insight.
 

  1. Three Lines of Defence
    A cyber risk governance framework should be based on the Three Lines of Defence model to define the role of each function, including that of the Risk Committee and the Audit Committee.

     

  2. Risk Committee
    Risk Managers should coordinate the Risk Committee which will present selected mitigation plans, including investments in cyber security and insurance coverage solutions, to the Board of Directors.

     
  3. Governance focus groups
    Organisations should create a “Cyber Risk Governance Group”, reporting to the Risk Committee and chaired by the Risk Manager. The aim for this group is to determine the cyber risk exposure, expressed financially, and establish the possible mitigation plans. The group should cooperate with Internal Auditors to avoid silos.

Share with others

Subscribe to our newsletter

* indicates required
Interests

By subscribing to our newsletter, you agree that we may process your information in accordance with our Privacy policy.

You can change your mind at any time by clicking the unsubscribe link in the footer of any email you receive from us, or by contacting us at enquiries@ferma.eu.

We use MailChimp as our marketing platform. By subscribing to our newsletter, you acknowledge that your information will be transferred to MailChimp for processing. Learn more about MailChimp’s privacy practices here.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.