---
title: Boards focus on cyber-risk regularly, but only 1 in 7 have deep security knowledge
description: Boards focus on cyber-risk regularly, but only 1 in 7 have deep security knowledge
image: https://businessinsights.bitdefender.com/hubfs/rsz_conference-room-768441_960_720-1.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security)

 By [**Razvan Muresan**](https://businessinsights.bitdefender.com/author/razvan-muresan) / Feb 13, 2017

# Boards focus on cyber-risk regularly, but only 1 in 7 have deep security knowledge

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge&utm_medium=social&utm_source=facebook)

Nearly 90 percent of directors at public companies say their board discusses cyber-risk regularly, yet only 14 percent of boards have in-depth knowledge of cyber-risks, according to a survey by the National Association of Corporate Directors ([NACD](https://www.nacdonline.org/Cyber)), cited by [Internal Auditor](https://iaonline.theiia.org/2017/Pages/Principles-of-Cyber-Oversight.aspx?utm_postdate=01/26/17).

Almost 60 percent of respondents reported that they find it challenging to oversee cyber risk. For 51 percent of publicly listed companies, cyber-risk oversight falls on the audit committee, but 96% of directors surveyed say the full board takes on the big picture risks that could impact their company's strategic direction.

The most common board cyber-risk oversight practices are reviewing the company's approach to protecting its most critical assets (77 percent) and reviewing the technical infrastructure used to protect those assets (74 percent).

"The cyber-threat picture continues to become more challenging with nation-state attacks against both public and private sectors,” authors of the study say. “Industry needs to demonstrate leadership in promoting enhanced cyber defense.”

In case of a breach, NACD recommends directors and management focus on the following areas of concern:

- What data, and how much data, are we willing to lose or have compromised?

Discussions of risk-tolerance will help identify the level of cyber-risk the organization is willing to accept. A key step is distinguishing between mission-critical assets and data that is less essential.

- How should our cyber-risk mitigation investments be allocated among basic and advanced defenses?

When considering how to address more sophisticated threats, management should focus most on sophisticated defenses designed to protect the company’s most critical data. While most organizations would agree with this, research from the Armed Forces Communications and Electronics Association (AFCEA) indicates companies typically apply security measures equally for all data and functions. The same AFCEA study, cited by NACD, notes that protecting low-impact systems and data from sophisticated threats could require greater investment than warranted. For those lower-priority assets, organizations should consider accepting more security risk than for higher-priority assets, as the costs of defense will likely exceed the benefits. Boards should encourage management to frame cybersecurity investments in terms of ROI, and to reassess ROI regularly, as the costs of protection and the company’s asset priorities will change over time.

- What options are available to assist us in transferring certain cyber risks?

Organizations of all industries and sizes have access to end-to-end solutions that can help mitigate and transfer some cyber-risk. Beyond coverage for financial loss, these tools can help mitigate risk of property damage and bodily injury resulting from a cyber breach. Some solutions also include access to proactive tools, employee training, IT security and expert response services, to add another layer of protection and expertise. The inclusion of these value-added services proves even further the importance of moving cybersecurity outside of the IT department into enterprise-wide risk and strategy discussions at both management and board levels. When choosing a cyber-insurance partner, it is important for an organization to choose a carrier with the breadth of global capabilities, expertise, market experience, and capacity for innovation that best fits the organization’s needs.

- How should we assess the impact of cyber events?

Conducting a proper impact assessment can be challenging given the number of factors involved. To take just one example, publicity about data breaches can substantially complicate risk evaluation. Employees, customers, suppliers, investors, the press, the public and government agencies may see little difference between a comparatively small breach and a large, dangerous one. As a result, damage to reputation and share price may not correspond directly to the size or severity of the event. The board should seek assurances that management has carefully thought through these implications in devising their priorities for cyber-risk management.

 

**Here is a list of questions boards can ask management once a cyber breach is found:**

1. How did we learn about the breach? Were we notified by an outside agency, or was the breach found internally?
2. What do we believe was stolen?
3. What has been affected by the breach?
4. Have any of our operations been compromised?
5. Is our crisis response plan in action, and is it working as planned?
6. Is the breach considered “material information” requiring prompt disclosure and, if so, is our legal team prepared for such notifications? Who else should be notified about this breach?
7. What steps is the response team taking to ensure the breach is under control and the hacker no longer has access to our internal network?
8. Do we believe the hacker was an internal or external actor?
9. What weaknesses in our system allowed it to occur (and why)?
10. What steps can we take to make sure this type of breach does not happen again, and what efforts can we make to mitigate any losses caused by the breach?

[![continuous sec](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/4beaf4e4-1af1-4ccb-860d-ae3057c97900.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/4beaf4e4-1af1-4ccb-860d-ae3057c97900)

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/fortune-100-boards-cio?hsLang=en-us>

### [A third of Fortune 100 boards have a director who is a CIO](https://businessinsights.bitdefender.com/fortune-100-boards-cio?hsLang=en-us)

<https://businessinsights.bitdefender.com/information-security-spending-market?hsLang=en-us>

### [Information Security Spending To Reach the $80-Billion-a-Year Threshold in 2016. IT Outsourcing and DLP, Main Drivers](https://businessinsights.bitdefender.com/information-security-spending-market?hsLang=en-us)

<https://businessinsights.bitdefender.com/small-gains-big-wins-when-facing-cyber-threats-a-swift-response-could-save-your-company?hsLang=en-us>

### [Small Gains, Big Wins – When Facing Cyber Threats, a Swift Response Could Save Your Company](https://businessinsights.bitdefender.com/small-gains-big-wins-when-facing-cyber-threats-a-swift-response-could-save-your-company?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Razvan Muresan",
    "url" : "https://businessinsights.bitdefender.com/author/razvan-muresan"
  },
  "datePublished" : "2017-02-13T16:09:07.000Z",
  "headline" : "Boards focus on cyber-risk regularly, but only 1 in 7 have deep security knowledge",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/rsz_conference-room-768441_960_720-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/boards-cyber-risk-security-knowledge",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```