CYBERSECURITY ACTION STEPS FOR OFFICERS AND DIRECTORS
- EDUCATE YOURSELF ON INFORMATION SECURITY.
Officers and directors need to educate themselves on information security. This education should not be limited to a single meeting, but rather should be a recurring agenda item in meetings.
- FORM AN INFORMATION SECURITY COMMITTEE.
Form an information security committee that is charged with the design, implementation, and day-to-day oversight of cybersecurity compliance efforts. The board should periodically review the composition, purposes, and activities of the committee.
- REGULARLY EVALUATE SECURITY STATUS.
Require that the information security committee issue regular reports detailing information security threats and mitigation strategies.
- REVIEW PLANS AND POLICIES.
Apprise yourself of the information security plans and policies for the organization.
- PRIORITIZE SECURITY EFFORTS.
Prioritize security efforts with a view to allocating those efforts to the protection of the most sensitive systems and information assets.
- KNOW WHAT HAPPENS IF A BREACH OCCURS.
Inquire about business continuity, disaster recovery, incident response, and insurance as each relates to information security.
- BE VIGILANT OF SUPPLIERS.
Ensure critical suppliers and vendors have management processes and agreements in place to address information security, including the availability of alternate suppliers.
- EMBED INFORMATION SECURITY IN NEW RELATIONSHIP DECISIONS.
Require information security risks be included in any due diligence of a proposed target corporation, key new customers, and business partners.
- WORK WITH YOUR GENERAL COUNSEL.
Work with your general counsel to establish processes to extend the attorney-client privilege and work product doctrine to relevant information security issues, particularly audits and forensics investigations following a potential breach.
