CYBERSECURITY ACTION STEPS FOR OFFICERS AND DIRECTORS

  • EDUCATE YOURSELF ON INFORMATION SECURITY.

Officers and directors need to educate themselves on information security. This education should not be limited to a single meeting, but rather should be a recurring agenda item in meetings.

 

  • FORM AN INFORMATION SECURITY COMMITTEE.

Form an information security committee that is charged with the design, implementation, and day-to-day oversight of cybersecurity compliance efforts. The board should periodically review the composition, purposes, and activities of the committee.

 

  • REGULARLY EVALUATE SECURITY STATUS.

Require that the information security committee issue regular reports detailing information security threats and mitigation strategies.

 

  • REVIEW PLANS AND POLICIES.

Apprise yourself of the information security plans and policies for the organization.

 

  • PRIORITIZE SECURITY EFFORTS.

Prioritize security efforts with a view to allocating those efforts to the protection of the most sensitive systems and information assets.

 

  • KNOW WHAT HAPPENS IF A BREACH OCCURS.

Inquire about business continuity, disaster recovery, incident response, and insurance as each relates to information security.

 

  • BE VIGILANT OF SUPPLIERS.

Ensure critical suppliers and vendors have management processes and agreements in place to address information security, including the availability of alternate suppliers.

 

  • EMBED INFORMATION SECURITY IN NEW RELATIONSHIP DECISIONS.

Require information security risks be included in any due diligence of a proposed target corporation, key new customers, and business partners.

 

  • WORK WITH YOUR GENERAL COUNSEL.

Work with your general counsel to establish processes to extend the attorney-client privilege and work product doctrine to relevant information security issues, particularly audits and forensics investigations following a potential breach.