Book Image

Building a Cyber Resilient Business

By : Dr. Magda Lilia Chelly, Shamane Tan, Hai Tran
Book Image

Building a Cyber Resilient Business

By: Dr. Magda Lilia Chelly, Shamane Tan, Hai Tran

Overview of this book

With cyberattacks on the rise, it has become essential for C-suite executives and board members to step up and collectively recognize cyber risk as a top priority business risk. However, non-cyber executives find it challenging to understand their role in increasing the business’s cyber resilience due to its complex nature and the lack of a clear return on investment. This book demystifies the perception that cybersecurity is a technical problem, drawing parallels between the key responsibilities of the C-suite roles to line up with the mission of the Chief Information Security Officer (CISO). The book equips you with all you need to know about cyber risks to run the business effectively. Each chapter provides a holistic overview of the dynamic priorities of the C-suite (from the CFO to the CIO, COO, CRO, and so on), and unpacks how cybersecurity must be embedded in every business function. The book also contains self-assessment questions, which are a helpful tool in evaluating any major cybersecurity initiatives and/or investment required. With this book, you’ll have a deeper appreciation of the various ways all executives can contribute to the organization’s cyber program, in close collaboration with the CISO and the security team, and achieve a cyber-resilient, profitable, and sustainable business.
Table of Contents (14 chapters)

Questions to ask your CFO

These questions will help facilitate a healthy discussion with your CFO and explore ways they can work more effectively with other executives in addressing your organization’s cyber resilience gaps and uplift program.

  • Have you considered cyber risk as a part of ERM?
  • As a CFO who manages the financial risk within an organization, how can you become a champion of security in the boardroom?
  • How can you shift your starting point from eliminating all risks to narrowing the range of acceptable outcomes?
  • How do you understand the implementation of cybersecurity hygiene? Is it more than just firewalls and authentication?
  • How do you ensure cyber risk quantification and financial optimization?
  • Are you confident that cyber risk needs to be addressed with a balance between mitigation and transfer? Have you considered cash flow management and risk transfer through cyber insurance?
  • How are you working with the CISO and CIO/CTO to adhere to regulatory requirements such as GDPR and PCI-DSS requirements?
  • How much time are you spending with the CISO and CIO to do a business review of the cybersecurity environment?