Corporate boards must deal with new cyber risks as more work from home: expert
Angela Tan
Singapore
THE Covid-19 pandemic has forced many people to work from home, creating new challenges and risks for corporate boards to handle, warned Richard Sheath, director of Independent Audit.
The London-based expert on governance and board evaluations told The Business Times on Tuesday that even before the crisis, it was hard for boards to know how best to deal with cyber risk.
The issue is now adding to the stress scale for most boards.
"In the old days, employees generally operated within controlled environments and networks and in line with security protocols,'' Mr Sheath explained.
"Now it's mostly about using multiple devices in less secure places - and that's opened up crevices in the cybersecurity landscapes for many organisations."
The risks are huge - which makes this a board issue, not just an operational challenge. There is a raft of new questions that boards need to be asking management to get assurance that the risks are minimised or that a plan is being put in place to close the gaps.
Independent Audit worked with cyber security specialists Cobweb Cyber to produce a list of best practices for boards.
Mr Sheath said that even at companies with good controls and a strong risk awareness, boards should be aware that new risks justify new levels of caution.
Boards must ascertain new exposures and assess their scale and scope in their organisations.
Such exposures include whether the IT department knows who is using which devices, whether patches are fully up to date, whether physical environments are secure, to what extent laptops and other devices are encrypted, whether home PC and device security settings are in line with corporate standards, what exposures are introduced by the use of home routers, and what confidential discussions and data transfers are taking place through the various media.
Boards don't need to know the detail - but they do need to work out with management what level of mitigation and assurance is acceptable, and over what time frame,'' Mr Sheath said.
Boards should not assume that the pre-crisis cyber risk response is still adequate to meet the new threat levels.
"Even the tightest of organisations needs to refresh its people's awareness, simply because hackers are quickly detecting new ways in, raising the potential scale of attacks,'' Mr Sheath said.
He added that boards should know how the external threats have changed and how far the usual protections and mitigants are coping in response.
It would be a mistake to allow management to carry on managing resources in the same old way even though the game has changed.
"Do past constraints on budgets need to be released in order to enable immediate risk responses, for example, providing new devices and new software?
"Only those who were 100 per cent on top of their game can afford to adopt a business-as-usual approach to systems and resources," Mr Sheath said.
It is also worth keeping an eye on internal threats amid the Covid-19 outbreak.
Said Mr Sheath: "Are the internal human stresses of threatened - or actual - redundancy, lower pay or the mental anxieties arising from isolation or family pressures increasing the risk of attacks from insiders? Or the risk of fraud-related hacking?"
Under normal circumstances, most people assume that systems-related risks fall under the purview of a chief technology officer or the IT department.
"But what about the softer behavioural and working-from-home risks? Accountabilities need to be clear," Mr Sheath said.
Just relying on assurances that things are covered by an IT policy is not enough.
"The board audit/risk committee can't avoid getting into details on this one - they need to take a look to make sure management has covered the ground and communicated in a clear and understandable way. If the non-executive directors can't understand what's required, what chance does everyone else have?"
To hammer the message home, boards should be leading by example, spelling out steps they have taken - collectively and as individuals taking personal responsibility - to keep the organisation as safe as possible.
As meetings take place virtually, this also means understanding the risks involved, and showing management that the board is taking them very seriously.
TRENDING NOW
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Despite the de-dollarisation debate, demand for dollar liquidity in Asia is growing
Can a first-time homebuyer couple earning S$18,000 a month afford a new EC unit?
Asia needs new energy security architecture