SEC Commissioner Luis A. Aguilar delivered remarks at the “Cyber Risks and the Boardroom” Conference in which he focused on steps that companies’ boards of directors can take to manage cybersecurity issues effectively.
Commissioner Aguilar stated that boards are responsible for making certain that corporations have established and implemented appropriate risk-management programs effectively. To ensure the adequacy of a company’s cybersecurity measures, Commissioner Aguilar recommended that boards begin by considering the Framework for Improving Critical Infrastructure Cybersecurity, which was released by the National Institute of Standards and Technology (“NIST”) in February 2014. The NIST Framework is intended to provide companies with a set of industry standards and best practices for managing their cybersecurity risks. Some commentators have already suggested that it will likely become a baseline for best practices by companies, Commissioner Aguilar said.
Commissioner Aguilar noted that the NIST Framework will be ineffective if no one at a company is able to translate its concepts into action plans. He stated that some boards have recommended mandatory cyber-risk education for directors, while others have suggested that boards be adequately represented by members with a good understanding of information technology issues. Regardless of the method, the boards need to close the knowledge gap in addressing cybersecurity concerns, Commissioner Aguilar emphasized.
Commissioner Aguilar went on to recommend that boards have a clear understanding of who at a company has the primary responsibility for cybersecurity risk oversight, and to devote full-time personnel to the task. According to Commissioner Aguilar, companies need to be prepared to respond within hours, if not minutes, to a cyber event to fully analyze it and prevent widespread damage. To do this, Commissioner Aguilar suggested, boards must put time and resources into making sure that management has developed a response plan which includes whether and how the cyber attack will be disclosed, internally and externally, to customers and investors.
See: Commissioner Aguilar’s Speech.
Related news: NIST Issues “Framework for Improving Critical Infrastructure Cybersecurity” (February 13, 2014).