CapstoneFinal BJM0509222.pdf
Mentor: Randy Milch
May 9th, 2022
Is a Cybersecurity Expert Needed on Public Company Boards Today?
Executive Summary
According to the 2021 Cyber Threat Report by SonicWall, there is a 62% increase in ransomware since 2019. There have been 304 million ransomware attacks, 51.1 million crypto jacking attacks, and 32.2 million IoT malware attacks since the beginning of 2021. The global cost of cybercrime peaked at $6.6T USD at the end of 2021. The sophistication of attacks such as the SolarWinds and Microsoft attacks, along with the massive fallout from those attacks in terms of potential loss of IP, personal information, and money, signals that public and private companies face unprecedented risks. The rise in attacks, combined with escalating damage, makes a compelling case for the appointment of cybersecurity experts to public boards, similar to the need for financial experts post-Enron.
The logic for a cybersecurity expert on boards stems from the limited technical understanding of cybersecurity among most board members. A 2019 survey of Fortune 100 companies revealed that less than 33% of CIOs believed the board understood cybersecurity information without a dedicated expert.
Federal Scrutiny and Oversight of Public Companies
The federal government's scrutiny on cybersecurity disclosures has intensified due to increased attacks and their ramifications. Executive orders and SEC guidelines have outlined key areas for disclosure:
- Disclosure and materiality: Companies should disclose material cybersecurity risks that may affect investor perception.
- Board risk governance: Companies must disclose the board's role in managing cybersecurity risks.
- Disclosure controls and procedures: Companies need to outline how cybersecurity information is communicated to management and the board.
Congressional Actions
S808, introduced by Senators in March 2021, is aimed at enhancing transparency in cybersecurity oversight at publicly traded companies. The act mandates that companies declare the individuals regarded as cybersecurity experts on their boards.
SEC Proposed Rule on Cybersecurity Expert Disclosure
On March 9, 2022, the SEC proposed rules requiring companies to disclose material cybersecurity incidents and the board's cybersecurity expertise. The rules emphasize the need for proactive oversight on cybersecurity risk.
Assessment of Fortune 20 Companies
A review of the proxy statements of the Fortune 20 companies reveals uneven focus on cybersecurity. While all acknowledge cybersecurity as a major risk, only 6 have cybersecurity expertise on their board, and only one has a dedicated committee.
The Case against SolarWinds Board
Legal actions against SolarWinds board members highlight the need for diligent oversight concerning cybersecurity risks that are central to their business.
Board Member Opinions on Cybersecurity Expert
A survey conducted among board members in December 2021 and January 2022 revealed that while 76.9% address cybersecurity risk in audit committees, very few boards have a cybersecurity-specific committee. Many expressed the importance of a cybersecurity expert for driving effective discussions and oversight.
Conclusion
Over the last five years, U.S. companies have experienced a significant rise in cybersecurity threats. As regulatory pressure increases, the need for dedicated cybersecurity expertise on boards is becoming essential. Immediate actions recommended include:
- Creating a committee focused solely on cybersecurity to ensure dedicated oversight.
- Appointing a cybersecurity expert to the board to engage thoughtfully in risk mitigation.