July 24, 2014 By Rick M Robinson 2 min read

Cyber security threats aren’t just for security specialists anymore. Today, cyber security is drawing attention from the very top, with one recent study finding that it has now become the number-one concern of corporate boards.

The reasons for this board-level concern are not hard to understand. Enterprises can be — and many already have been — badly shaken by cyber security breaches. However, the more important thing to know about the boardroom’s interest in cyber security is that it can be highly effective for building a framework with better security. One thing we have learned about cyber security is that it needs to be built in, not bolted on as an afterthought — and support from the boardroom helps.

Topping the Worry List: Cyber Security Threats

As reported by FierceCIO, cyber security has now come front and center in corporate boardrooms. A recent study by FTI Consulting titled “Law in the Boardroom in 2014” surveyed nearly 500 board members and general counsel. The study found that cyber security threats have taken over the top spot in the lists of worries by both board members and general counsel, displacing concern over succession and leadership transitions.

Cyber security threats have drawn this much attention because they are so costly — and growing costlier by the year. Regulators, the media, customers and markets all show scant mercy to organizations that have suffered major security breaches, especially if consumers’ sensitive data has been exposed. The FTI study cites the Ponemon Institute’s estimate that the average cost of security breaches went up 30 percent in the past year alone.

Building Security With Focus From the Top

Given the costs of cyber security breaches, the heightened boardroom interest in security is no surprise. But the good news for everyone — except black-hat hackers — is that leadership from the boardroom can have a real, crucial effect in building better security.

In their new e-book “Staying Ahead in the Cyber Security Game,” security experts Erik van Ommeren, Martin Borrett and Marinus Kuivenhoven said that until recently, security was treated largely as an afterthought. Now, however, hard experience is teaching organizations “to consider security as an essential element of how products and services are designed and delivered, how business processes within an organization are structured and how both customer and confidential data and information are stored and protected,” according to the e-book.

Security at the Heart

Even more fundamentally, the authors write, our hard-won security experience has taught us that security must be built into the systems architecture from the outset. In the e-book, a chief security officer of a research institute states, “Security must be at the heart of systems.”

At first glance, this sounds like an impossible ideal; after all, enterprises must work with systems that already exist. But these systems are in constant development, and the practical goal is to improve security with all-new builds and upgrades, gradually bringing the security of the whole system to a higher level.

What is needed above all is the ongoing, focused attention on cyber security that is now dominating the boardroom. This makes now the ideal moment to take charge in building the secure networks of trust that enterprises need to thrive in the information age.

More from CISO

CISO vs. CEO: Making a case for cybersecurity investments

4 min read - Ask CISOs why they think there is a cyber skills shortage in their organization, what keeps them up at night or what the most important issue facing the industry is — at some point, even if not the first response, they will bring up budgets.For example, at RSA Conference 2024, a roundtable discussion about issues facing the cybersecurity industry, one CISO stated bluntly that budgets — or lack thereof — are the biggest problem. At a time when everything is…

Making smart cybersecurity spending decisions in 2025

4 min read - December is a month of numbers, from holiday countdowns to RSVPs for parties. But for business leaders, the most important numbers this month are the budget numbers for 2025. With cybersecurity a top focus for many businesses in 2025, it is likely to be a top-line item on many budgets heading into the New Year.Gartner expects that cybersecurity spending is expected to increase 15% in 2025, from $183.9 billion to $212 billion. Security services lead the way for the segment…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today