SME boards and cyber risk – 4 steps directors need to take to understand and manage it

SME boards and cyber risk header image

Boards of directors for small and medium-sized organisations are having to get up to speed rapidly on the threat of cyber attack and data breach. It is a significant risk factor and not something they can afford to leave to their IT department or supplier.

In this article, John Acornley, our Chairman at Securious and a highly experienced Non-Executive Director for numerous growth businesses, explains how non-technical directors can understand and manage the cyber risk in their organisation 

SME boards and risk management

Risk management on SME Boards is varied. For example, some boards may include non-executive directors and committees which look specifically at risk whereas other boards may be composed of purely executive directors  

Boards generally look for reassurance from executive directors and managers and where appropriate look for assurance from third parties who are independent of directors and management 

Digital environments and the rise of cyber risk

As we move into the future, digital environments are constantly developing as sources of opportunity and risk 

SMEs are recognising the importance of key resources to manage digital development and the security of systems and data. Examples include the appointment of a CTO (Chief Technology Officer) and well as in some cases a CISO (Chief Information Security Officer) 

Every business now faces a real and present cyber risk

There is no current business that does not face some type of cyber risk. The reality is, if your business has not already experienced an incidence of cyber security breach, it is likely to do so in the near future 

For example, ransomware attacks, accidental or malicious data breaches involving personal and corporate data will be very difficult and costly to deal with, resulting in disruption and possibly fines for the organisation as well as potentially significant reputational damage.  

What should Boards do to understand and manage cyber risk?

1) Seek assurance and understand your position

The first stage is for the Board get reassurance from management including the CTO and CISO as well as assurance from a third-party source. 

Engaging an external cyber security company like Securious to perform a cyber security audit will result in third party assurance from looking at the digital systems and well as the policies and procedures from an external cyber threat perspective based upon the current external cyber threat landscape.  

This audit will cover the technology, people and processes within the organisation and will highlight vulnerabilities that have not been identified or properly addressed internally.  These vulnerabilities can then be actioned by the introduction of new technologies and updated policies and procedures.  

2) Evaluate whether the above is in line with the Board’s risk appetite for cyber risk

Having internal reassurance and third party assurance is the best way of ensuring that cyber risk is understood and managed within the Board’s risk appetite 

3) Think about your supply chain

It will also be appropriate to consider the cyber threat on suppliers and customers and other stakeholders in the organisation that are critical to business continuity   

4) Prepare for the worst

Finally, it is also important to have a specific incident response plan in the event that the organisation does have a cyber attack. This will reduce the stress and strain when a cyber attack does occur 

Concluding thoughts 

If organisations do the above on a regular basis, the outcome should be that the Board will have a good understanding of the cyber risk of the organisation which can be matched against the Board’s appetite for cyber risk. Also when the organisation is subjected to a cyber attack there is a plan in place as to how to deal with this 

You can connect with John Acornley at LinkedIn if you want to ask him about this article or fill in the form below with any questions.