
Ransomware And The Board's Role: What You Need To Know
Examples of key security processes and controls
|
-
Integrated resilience planning: How are we continuing to advance our cyber resiliency planning to be able to recover from an attack? Have we established a comprehensive resiliency approach that includes crisis management, disaster recovery, business continuity and incident response plans working together? Have we defined mission critical systems and their dependencies as part of our planning? Do we have clear protocols for decision-making and communications, including timely notification of significant incidents to the board?
Tabletop exercises: When did management last participate in a ransomware-focused tabletop exercise to prepare for adequately responding to and recovering from a ransomware attack? What were the results and learnings from this exercise? The board should also periodically conduct its own ransomware tabletop exercise to practice its role and key decisions.
Testing backup systems: When was the last time we tested our backup systems to determine if they would function effectively during recovery? How long did it take for our backup systems to successfully run operations again? What were the other results and learnings from our tests?
Cyber insurance: How has our cyber insurance coverage changed since last year? What are the terms that management and the board need to be aware of prior to an attack?
Examples of cyber insurance terms to discuss with management
|
-
Specialist resources: Does management have the necessary resources identified on our own or through our insurance provider to support a ransomware response? Are appropriate resources on retainer? When was the last time we spoke with these resources and confirmed our arrangements?
Resource considerations to support a ransomware response
|
Paying a ransom is a risk-based decision. Risks to consider include reputational, brand, operational, financial and legal business implications. Boards play a crucial role in collaborating with management to decide whether to pay a ransom when successfully attacked. Preparing in advance and establishing agreed-upon guidelines for this decision is helpful when having to navigate it under pressure. Boards and management should incorporate this discussion into their ransomware resiliency planning, including specifics of how a payment would be made whether through an insurance broker, cryptocurrency advisor or another resource. As boards consider whether the company should pay the ransom, here are questions the board can ask management.
To pay or not pay a ransom: considerations and questions
|
Ransomware remains a formidable threat in today's digital landscape, evolving in sophistication and impact. To effectively combat ransomware, boards must oversee a comprehensive approach that includes robust defenses and resiliency planning for dealing with an attack. Companies that are well prepared for ransomware incidents are likely to fare much better than those that are not, highlighting the importance of proactive measures and strategic oversight.
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept
any responsibility or liability for the accuracy, content, images,
videos, licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright
issues related to this article, kindly contact the provider above.
Most popular stories
Market Research

- STEPN And The Argentina Football Association Announces Their Latest NFT Drop
- BC.GAME Launches Phase 2 Of Social Mining Campaign, Expanding Ecosystem Engagement With $BC Token
- Whale.Io Sets Sail For Token2049 Dubai As Wristband Sponsor, Gearing Up For $WHALE Token Launch
- Primexbt Launches Stock Trading On Metatrader 5
- BTSE Cares Foundation & Singapore Football Club Renew Winning Partnership
- Multibank Group To Tokenize $3 Billion In Real Estate Assets With MAG As It Readies To Launch $MBG
Comments
No comment