Governing the Dark Side of Digitalization: Managing Cyber Risk

Executive and Supervisory Boards are ultimately held accountable for the long-term success of their organizations. With respect to digitalization, they have to do both exploit the potential of digital technologies for business and protect the business against the risks of an accelerating digitalization. While many boards have already embarked on tapping into the digital business opportunities, field evidence suggests that they largely ignore the flip-side of digitalization: cyber risk. However, the risk side of digitalization is so critical that legislators all around the world are imposing higher and higher compliance cyber security standards on organization. Latest legislation in the US and EU holds boards responsible for cyber security and makes them personally liable for damages caused in case of cyber risks are taken imprudently or managed recklessly. Yet boards struggle to actively engage in strategic cyber security planning and control for a number of reasons. According to our own research, these  include missing knowledge and understanding for digital technologies and the risks involved in adopting them, a lack of practical guidance on how to manage and control cyber risk, and ineffective communication between boards and cybersecurity managers and experts.

[Source: BSI – Bundesamt für Sicherheit in der Informationstechnik]

 

Our project aims at overcoming these deficiencies by educating boards, providing them with tools to overlook cybersecurity on an organizational level, and facilitating communication between boards and cybersecurity managers. To this end, we currently investigate how to effectively support boards and cybersecurity managers in jointly ...

  1. Estimating their Organization’s Threat Exposure,
  2. Establishing their Organization’s Risk Appetite,
  3. Identifying and Analysing Cyber Threat Scenarios,
  4. Analysing the Business Impact of Cyberthreats,
  5. Understanding their Organization’s Cyber Vulnerability,
  6. Understanding their Organization’s Cyber Resilience,
  7. Prioritizing Budgets and Measures based on Cyber Risk Estimates.