ISA TO BRIEF COUNCIL ON FOREIGN RELATIONS ON CYBERSECURITY

Posted on June 28, 2017 at 4:49 pm

(WASHINGTON, D.C.) – Internet Security Alliance President Larry Clinton will be the featured speaker at the meeting of the Council on Foreign Relations Roundtable on Digital Policy at noon, June 29th.  Mr. Clinton will speak on “US Government Efforts to Improve Cyber Security” “The latest massive cyber-attacks only highlight the need for industry and government […]


Maintaining Cybersecurity During Mergers & Acquisitions

Posted on June 27, 2017 at 10:56 am

Mergers and acquisitions are risky times. Headlines treat the combination of companies as job done after the announcement, but insiders know combining operations is no easy task. These days, add cyber risk to the list of prime considerations companies should weigh before, during, and after any M&A decision. Companies involved in transactions are often prime […]


Board Directors Need to Have Discussions on Which Risks to Avoid, Which Risks to Accept, and Which to Mitigate Through Insurance

Posted on June 22, 2017 at 11:06 am

Total cybersecurity is an unrealistic goal. Cybersecurity is a continuum requiring strategic decision-making about where and how to spend security dollars. Attempting to guard every system equally is a recipe for exhausting the budget on low-priority systems. And it’ll result in bad security, since the company’s crown jewels will lack the sophisticated protections they need. […]


Directors Need to Set the Standards and Expectations for Management to Establish Well-Staffed and Well-Funded Cyber-Risk Framework

Posted on June 20, 2017 at 10:44 am

Much like any response plan, a cybersecurity framework is only successful if it is well-staffed and well-funded. Otherwise, it simply will not be able to adequately handle the stresses caused by a breach. In a world where malware and ransomware are increasing both in frequency and severity – Wannacry, for example, affected 200,000 computers in […]


Boards Need Access to Adequate Cybersecurity Expertise – And Need to Give it Adequate Time on Meeting Agendas

Posted on June 19, 2017 at 12:56 pm

Cyber literacy can be considered similar to financial literacy – not everyone on the board is an auditor, but everyone should be able to read a financial statement and understand the financial language of business. As we all know, cybersecurity is very much a moving target. The threats and vulnerabilities change almost daily, and the […]


Boards Need to Be Aware of Evolving Cyber-Legal Landscape

Posted on June 14, 2017 at 10:24 am

Boards of directors face several versions of risk from cyber breaches. Obviously, there is the risk of loss or manipulation of the data. There is also a risk of reputational loss. However, regardless of the actual data or reputational impacts boards need to be concerned about legal risks that can occur unrelated to the other […]


HHS Points The Way Forward For Improved Cybersecurity

Posted on June 12, 2017 at 11:35 am

Last month President Trump issued an Executive Order on cybersecurity that called on all federal agencies to assess their status on information security and for the leadership to take steps required to mediate threats. Last week the Department of Health and Human Services (HHS) released its Healthcare Industry Cybersecurity Task Force report, which provides a […]


C-Suite: Cybersecurity is #1 Issue, ISA Report

Posted on June 5, 2017 at 1:16 pm

SC Media Reports: It’s been a topic of discussion for some time: Cyber threats are serious risks to enterprises and it is the responsibility of the boards to provide oversight. The problem, according to a new blog post written by Stacey Barrack, senior director of the Internet Security Alliance (ISA), is that most of the team […]


Brainstorming on Information Security Best Practices Highlights the 2017 Chicago CISO Executive Leadership Summit

Posted on at 11:55 am

Chief Information Security Officers (CISOs) recognize that collaboration is key to cyber security resilience. Sharing best practices in intimate, executive roundtable working groups among peers on topics ranging from must have questions and strategies for the board of directors to securing connected devices and the Internet of Things (IoT) will be featured at the 2017 […]


Cybersecurity Principle Number 1 for Boards – It’s Not Just About “IT”

Posted on June 2, 2017 at 12:07 pm

It has now become clear that cyber-risk needs oversight at the board of directors level. The problem is that most corporate boards are comprised of “digital immigrants” — people not born into the digital world they now inhabit — and therefore need to learn how to understand cyber-risk. That educational process has been undertaken by […]