New Cybersecurity Governance Code Puts Cyber Risks on Boardroom Agenda – Infosecurity Magazine

Deputy Editor, Infosecurity Magazine
The UK government has published a new Code of Practice on cybersecurity governance, targeting directors and other senior business leaders.
The draft document aims to establish cybersecurity as a key focus for businesses, on par with financial and legal risks.
The code highlights a number of areas business leaders should focus on to enhance their cybersecurity governance practices:
The code has been designed by the Department for Science, Innovation and Technology (DSIT) in partnership with industry directors, cyber and governance experts and the UK’s National Cyber Security Centre (NCSC).
The government is now inviting industry input into the draft document, with a call for views running until March 19, 2024.
The government emphasized that with digital technologies now underpinning business resilience, executive and non-executive directors must take a greater role in leading technology governance strategies.
Viscount Camrose, Minister for AI and Intellectual Property, commented: “Cyber-attacks are as damaging to organizations as financial and legal pitfalls, so it’s crucial that bosses and directors take a firm grip of their organization’s cybersecurity regimes – protecting their customers, workforce, business operations and our wider economy. 
“This new Code will help them take the lead in safely navigating potential cyber threats, ensuring businesses across the country can take full advantage of the emerging technologies which are revolutionising how we work.”
In the US, new rules from the Securities and Exchange Commission (SEC) requires publicly-listed companies to describe the board of directors’ oversight of risks from cyber threats.
Christian Borst, EMEA CTO at Vectra, said that the draft code highlights the need for businesses to urgently overhaul their approaches to cybersecurity, taking a more holistic approach.
“While incident response plans and cyber awareness training are essential to good security hygiene, businesses need to go much further to stay secure in a growing world of cybersecurity risks. Today it’s vital that security leaders, architects, and analysts focus on improving cyber resilience,” he outlined.
Sarah Pearce, Partner at law firm Hunton Andrews Kurth, welcomed the new code, particularly the guidance around having a regularly practised incident response plan in place.
"Our extensive experience assisting clients with cyber security incidents and data breaches has demonstrated quite clearly that those businesses taking precautionary measures fare far better in such instances than those that fail to do so. Preparation will mitigate harm and reduce impact on a business and its operations more broadly," she noted.

The UK government also published new statistics relating to its Cyber Essentials certification scheme in its announcement. This shows that two-thirds of businesses that adhere to the scheme have a formal incident response plan, compared to 18% who don’t.

source

Related Posts

After 6 months and little explanation, Norton Healthcare patients, employees still feeling effects of cyber attack – WDRB

Spotty shower possible. Storms after midnight Updated: April 16, 2024 @ 12:31 pmNorton Healthcare, a company serving about 600,000 patients a year with nearly $5 billion in assets, continues to…

Read more

CA's top cybersecurity job has been vacant for almost 2 years – CalMatters

Technology Californians get hacked all the time. The state’s top cybersecurity job is vacant In summaryGov. Newsom has yet to appoint a commander who is tasked with informing businesses and…

Read more

13 Cyber Security Measures Your Small Business Must Take – Tech.co

Our content is funded in part by commercial partnerships, at no extra cost to you and without impact to our editorial impartiality. Click to Learn MoreCybersecurity has been important to…

Read more

AVG Antivirus Free review – Ghacks

AVG AntiVirus Free is a longstanding security program for Microsoft Windows that protects computer systems from viruses, trojans and other malicious code.One interesting fact about AVG is that it maintains…

Read more

Vlog Episode #247: Chris Long on Improving Technical SEO Skills & Playing Offense SEO – Search Engine Roundtable

In part one, we learned about Chris Long and his experience working with Bill Slawski. Then, in part two, we spoke about helping people with SEO on LinkedIn and using…

Read more

Information Security Vs. Cybersecurity: What's The Difference? – Forbes

Information Security Vs. Cybersecurity: What’s The Difference?  Forbessource

Read more

Leave a Reply

Your email address will not be published. Required fields are marked *