Knowledge Base

What is the topic of blueAPACHE's blog post 'How the most progressive boards manage cyber risk'?

The blog post discusses how the most progressive boards tackle cyber risk, sharing key questions raised by Mark McLaughlin, Chairman and CEO of Palo Alto Networks.

Who is Mark McLaughlin and why is he referenced in this article?

Mark McLaughlin is the Chairman and CEO of Palo Alto Networks. He is referenced because he shared key questions related to how progressive boards manage cyber risk.

Who published this article about progressive boards and cyber risk?

The article was published by blueAPACHE.

According to the supporting governance framework, how have progressive boards fundamentally changed their approach to cyber risk?

Cyber risk has shifted from being a technical IT concern to a boardroom governance imperative, and the most progressive boards have redesigned how they oversee, measure, and respond to cyber threats.

What is the first key step progressive boards take to manage cyber risk?

The first step is establishing clear accountability and governance structure, creating explicit accountability frameworks rather than leaving cyber risk scattered across functional silos.

What does 'dedicated oversight authority' mean in the context of board cyber risk governance?

Dedicated oversight authority means assigning cyber risk to a specific board committee—often Audit, Risk, or a dedicated Cybersecurity Committee—with a clear charter defining which decisions require board attention versus which remain operational.

Why is it important for the CISO to have a direct reporting relationship to the board?

A direct reporting relationship for the Chief Information Security Officer (CISO) to the board, rather than being buried under IT operations, protects the security function from cost-driven pressure to underinvest in controls.

How do progressive boards distinguish their governance role from management's execution role in cyber risk?

The board's governance role involves setting risk appetite, approving strategy, and monitoring outcomes, while management's execution role involves implementing controls, managing incidents, and reporting metrics.

What is a 'cyber risk appetite statement' and why do progressive boards create one?

A cyber risk appetite statement is established by progressive boards before incidents occur, rather than relying on reactive crisis management. It answers critical questions such as what level of cyber risk is acceptable to the organization, what types of incidents would trigger escalation to the board, and what financial exposure aligns with the organization's risk tolerance.

How do leading boards document accountability expectations for cyber risk?

Leading boards document accountabilities in writing through board charters, committee charters, and policy frameworks that make expectations explicit.