With Cybersecurity Month well underway, find out how CEO’s can support their organisation’s cybersecurity readiness.
By: Phil Gladwell
News, info & events

A common misconception is that cybersecurity is solely about making your system impenetrable to hacking attempts and nothing else. The truth is no system is 100% bulletproof. Cybersecurity is also about managing risks and keeping them at bay.
Prevention instead of cure. Being one step ahead and planning for cyberattacks is one of the best ways to ensure that attempted breaches can be stopped in their tracks and, if the worst should happen, your organisation can respond to attacks more efficiently.
Here are ten key questions CEO’s should be asking about their cybersecurity readiness:
1. What are you actively doing to prevent cyber attacks?
This may involve evaluating your security, and the protections and policies that are currently in place. This will enable you to identify where the gaps are and address what’s missing.
2. What roles do senior leaders and board members play in managing cyber risk?
Do you participate in drills that allow key players to determine how they would respond to a cyberattack? Key authority figures need to be involved with cybersecurity even if it is not their forte – for example, if they don’t belong to the IT department.
3. Do you have cyber risk insurance? If so, what does it cover and exclude?
Cyber-liability policies are important because if a hacker gains access to your system and steals confidential data of your customers, the financial consequences of an individual suit or class action against your organisation would be crippling. (Read Are you covered for cyber fraud?)
4. How do you manage third party cyber risks, such as vendors and other third parties in your supply chain?
When dealing with any part of your supply chain you need to consider what information and/or data you are providing them with, how sensitive is that data, and what kind of access do you give to your vendors?
5. Do you engage in basic “cyber hygiene”?
This means being aware of all the devices connected to your networks and what is running on these networks. You need to know who has administrative permissions to change, bypass or override the system, and then reduce that number to only those who absolutely need it.
6. Are your employees appropriately educated to recognise and understand cyber threats?
Ian Kennedy-Compston, founder of EnterpriseRed said: “The biggest threat we see affecting businesses in every sector is a lack of real understanding of a company’s IT vulnerabilities and inadequate or ineffective training of employees. This puts any business at significant risk, from either error or malice of anyone in a company or its supply chain, or the determined efforts of cybercriminals.” If employees know how to be more savvy online, they will work in a more cyber aware and secure way and businesses will be better protected.
7. How protected are you from new threats?
You should have a clear idea of how well protected against new vulnerabilities your organisation is. Part of your efforts should involve threat monitoring. You may also want to consider penetration testing to assess the security of your network and systems, and to address any weaknesses.
8. How exposed to risk are you?
Cybersecurity risk is usually defined in terms of exposure. How exposed is your company to the risk of attacks and breaches? Many attacks or incidents are initiated using information that exists outside of an organisation’s firewall. Understanding the information that is available outside of your system and identifying these risks is crucial.
9. When and how do you engage with law enforcement after a breach?
You need to be aware of the legislation in place and what you need to do if you suffer a breach, and how quickly you need to act to avoid penalties.
10. After a breach, when and how do you inform your customers?
Maintaining the support and trust of your customers’ is imperative to your organisation’s reputation. You need to have a plan in place regarding what you will tell them, and how and when you will tell them, should you suffer a breach.