Manage HR Magazine | Monday, October 17, 2022
The CFO's expertise on the following cybersecurity issues is crucial in solving challenges such as Ransomware encrypting cryptocurrency, collaboration within the company, and third-party risk management.
FREMONT, CA: Cybersecurity and data privacy have been top strategic priorities for CFOs for several years. A similar approach is increasingly being adopted by regulators. The Securities and Exchange Commission (SEC) suggested changes to its rules on cybersecurity risk management and incident reporting by public companies. According to the SEC, cybersecurity threats and incidents pose an increasingly serious warning to public companies, investors, and market participants. According to feedback received by the commission during the comment period that ended in early May, some features of the proposal are controversial and require clarification. Whatever the details and timing of the actual rule, reporting enhancements of some kind are on the way. Thus, companies should assess their cybersecurity infrastructure policies and procedures, as well as their business continuity, contingency, and recovery plans.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Organizations need the CFO's expertise and viewpoints to address the following cybersecurity issues and challenges:
Cryptocurrency ransomware: An organization's CFO determines the risks associated with Ransomware and approves funding for resources, security consultants, etc., to respond to these attacks rapidly and cost-effectively and to answer the thorny question of paying criminals to unlock company systems and restore data. Tabletop exercises enable cyber-savvy finance executives to raise and address difficult ransomware issues. To be prepared for all options, they make changes and test crypto payment procedures before a ransom attack occurs in order to assess the risks and rewards of paying or not paying.
Insurance for cybercrime: As a result of a surge in ransomware incidents and other cyber threats, cyber insurance premiums have continued to rise while coverage limits have decreased. In 2021, a carrier may have offered $10 million for a specific coverage limit. As insurers intensify their scrutiny of prospective policyholders' security controls, underwriting and renewal processes have also grown more involved and burdensome. In these circumstances, the CFO's input on cyber insurance policies costs, coverage, and value are even more important.
Risk management for third parties: The CFO's risk management expertise and, in most cases, ownership of the procurement function can assist information security and data privacy functions in addressing the formidable and complicated challenge of managing third-party cybersecurity and data privacy risks and, in the case of suppliers, second and third tier suppliers. When sourcing decisions are made, finance leaders can ensure pricing priorities are balanced with risk management diligence. Because third-party risk assessments can take time, CFOs can also assist procurement teams in ranking vendors according to their risk levels. A vendor in a high-risk tier would undergo a more comprehensive risk assessment than one in a low-risk tier.
Check Out This : Top Treasury Management Services Companies
The budget: Budgets for information security and data privacy typically increase after a breach or near miss. In contrast, cybersecurity budgets tend to regress to the mean when organizations avoid major incidents over time. Despite this, many CISOs say that they face hardships in getting the funding they need to maintain strong defenses. This challenge is addressed by CFO-CISO relationships that produce useful industry benchmarks, evaluate current investment allocations, and quantify cybersecurity risks.
More in News