As cybersecurity moves to the forefront in the realm of risk management and regulatory compliance, boards of directors must be more engaged than ever in overseeing all things cybersecurity.

Board oversight of cybersecurity is so important, in fact, that it was one of the headlining topics presented at a recent Federal Reserve Bank of Boston conference centered around cybersecurity. No longer can the board simply rubberstamp a bank’s cybersecurity practices. Directors must be actively involved in a way they never before have been.

“The issue has really been accelerating on the board agenda because of the number of data breaches, the reliance on digital assets and information and the interconnectedness of the system. Today a cyberattack could present an existential threat to the organization, so it’s really become a top tier issue on board agendas, and it’s not going away,” said Stephanie Zierten, associate counsel with the Boston Fed.

That means directors must ensure and monitor reporting systems, they must ask the right questions about the bank’s cybersecurity practices, and they must oversee the creation of a worst-case scenario plan in the event that the bank falls victim to any of the myriad and multiplying cyber threats lurking in the vast wilds of the Internet.

Regulators have turned up the focus on bank boards, too. If 2014 was the year of the data breach, then 2015 was the year of the data breach lawsuit, and financial institutions entrusted with safeguarding their customers’ personal and financial information must consider cybersecurity as part of a holistic view of enterprise risk management – not as something that’s strictly the domain of IT experts.

“The board certainly has a responsibility to understand the risks with the business that it’s in, and cybersecurity is a business problem that affects them. The products and services they’re offering, a lot of those are technology-based and the risks associated with those are great,” said Gerald R. Gagne, a member of the firm Wolf & Co.

Talking The Talk

As important as cybersecurity may be, though, getting the board better involved in oversight can be difficult for many community financial institutions. Consider your typical, small-town New England community bank. Its board of directors is likely comprised largely of well-respected local business owners, and though they may be experts in their own particular kingdoms, IT probably isn’t one of them.

Moreover, the language of cybersecurity can be intimidating.

“Cybersecurity is an inherently technical discipline and boards are increasingly being asked to monitor and oversee cybersecurity as an enterprise-wide risk, so they need to essentially become competent enough on the issue to ask informed questions and know whether the answers are satisfactory,” Zierten said.

Those who work with banks on cybersecurity issues say that’s beginning to change and that tech-savvy people are increasingly in demand on bank boards.

“One of the things that we try to help our banks do is look for individuals who might have IT experience or cybersecurity experience or risk management experience to participate on their boards,” said Viviana Campanaro, the director of security and compliance at the IT service company All Covered.

Sometimes, she said, banks will get one or two directors involved in the bank’s information technology or cybersecurity subcommittee.

Banks that don’t have that expertise on their boards make work busy for Campanaro and her colleagues.

“That’s where we find most of our work being done right now,” she said. “I deliver a high-level training for board members that brings it down to earth, and explain to them what they can do as a board member to protect their bank. We’ve found that that has a lot of positive impact.”

She also said that bankers are increasingly asking vendors like All Covered to help them with the reporting process, so they can better present those issues to their boards of directors.

In addition to outside training, there exists an ever-growing wealth of cybersecurity guidance for financial institutions and their directors. For instance, Gagne points to the Federal Financial Institutions Examination Council’s Cybersecurity Assessment Tool, which lays down a blueprint for how a bank’s management and directors should evaluate their own risk profile and manage its risk in this area.

“I think the board needs to understand that it’s a business problem, not an IT problem,” he said. “That’s one of the big hurdles in the board’s thinking, is making sure they understand this is a problem related to their business. When they’re entering new lines of business, they should be thinking about the risks associated with cybersecurity.”

Cybersecurity Moves To The Top Of Board Agendas

by Laura Alix time to read: 3 min
0