Three pieces of advice
1. Understand your unique exposure
Map the vulnerabilities in your business model, the technology you use, the services you depend on and the third parties with access to your systems. You cannot manage a risk you have not defined.
2. Train, train, train
Train employees to practice good cyber hygiene. Test contingency plans so everyone knows how to respond if an attack succeeds. Prepare the board and management to act, ensuring that they know which third-party specialists can help contain an attack quickly. A contingency plan that has never been tested is not a plan. It is just a document.
3. Make cybersecurity a standing agenda item
Cybersecurity is not a one-off exercise. The board needs regular reporting: Are systems being patched and updated? When were contingency plans last tested? The conversation must be ongoing, because the company’s preparedness needs to keep pace with the threat.