Home Security Is IT security getting your board's attention?

Is IT security getting your board's attention?

Not all boards are taking IT security seriously. Perhaps surprisingly, some organisations don't have a security strategy, or don't see it in the context of a broader IT strategy, Centre for Internet Safety managing director Nigel Phair told iTWire.

While IT should be involved from the start in the development of a security strategy, the CISO should be part of the security function (not IT), and should be concerned with aligning security measures with the business strategy.

The CISO should report to the board and the audit committee: "it's just (another aspect of) risk," said Phair at VMware's Evolve 2017 event in Melbourne yesterday, adding that strategy, risk and governance are the board's concerns.

The board needs to make decisions at a high level, eg "is gold-plated security appropriate?", although those in regulated industries may not have much choice. Then it is the CISO's job to explain what that actually means in terms of time and cost.

Bronze or silver plating might be appropriate, but an informed decision should be made. For example, how much downtime is acceptable? One minute? One hour? One day?

The performance of Australian organisations in this regard is "pretty hit and miss", Phair said, and it's not just about the size of the business. The big banks do it well, he said, but one ASX 200 company is not on top of IT security to the degree he expected.

Establishing the ROI for IT security investments "is tough," said Phair, "with physical security you've got something (tangible)."

"IT security is a business driver that adds value," he said, but the risks have to be managed.

The growing number of commercial-grade security conferences is a promising sign, he suggested, noting that vendors are throwing money into such events at a time when people want to learn about the issues.


Australia is a cyber espionage hot spot.

As we automate, script and move to the cloud, more and more businesses are reliant on infrastructure that has the high potential to be exposed to risk.

It only takes one awry email to expose an accounts’ payable process, and for cyber attackers to cost a business thousands of dollars.

In the free white paper ‘6 Steps to Improve your Business Cyber Security’ you’ll learn some simple steps you should be taking to prevent devastating and malicious cyber attacks from destroying your business.

Cyber security can no longer be ignored, in this white paper you’ll learn:

· How does business security get breached?
· What can it cost to get it wrong?
· 6 actionable tips



Ransomware is a type of malware that blocks access to your files and systems until you pay a ransom.

The first example of ransomware happened on September 5, 2013, when Cryptolocker was unleashed.

It quickly affected many systems with hackers requiring users to pay money for the decryption keys.

Find out how one company used backup and cloud storage software to protect their company’s PCs and recovered all of their systems after a ransomware strike.


Stephen Withers

joomla visitors

Stephen Withers is one of Australia¹s most experienced IT journalists, having begun his career in the days of 8-bit 'microcomputers'. He covers the gamut from gadgets to enterprise systems. In previous lives he has been an academic, a systems programmer, an IT support manager, and an online services manager. Stephen holds an honours degree in Management Sciences and a PhD in Industrial and Business Studies.


Popular News