When it comes to cybersecurity training for board members, have you made any changes to training content or frequency? What new topics or exercises have you added (or plan to)?

261 views3 Comments
Sort By:
Oldest
Senior Information Security Manager in Software23 days ago
If you could give awareness training to only one person in the entire company, it should be the executive assistant to the CFO. The CFO receives numerous phishing emails about signing agreements and other requests, making them prime targets for spear phishing. Therefore, the board members and their administrative assistants need to be well-versed in social engineering and phishing tactics.

These assistants are often targeted with highly-crafted emails that are difficult to distinguish from legitimate ones. While a generic phishing email might be sent to me, someone might spend weeks crafting the perfect email to target the CFO or their assistant. This targeted awareness training is crucial. Board members don’t need to learn about cloud computing practices or configuring Docker images, but they do need to understand the specific threats they face.

Often, they receive the standard training that everyone else gets. However, they need more targeted training. It’s essential to sit down with them, explain what to look for, and what to be suspicious of. They need to be aware of the specific threats they face because they are often signing off on many legitimate things, making it easy for them to fall for well-crafted phishing attempts. Administrative assistants are also usually very busy and multitasking, which increases their vulnerability.

2
CIO in IT Services23 days ago
I conducted training for public board members last year, and I found that their basic understanding of cybersecurity was even more rudimentary than I had anticipated due to a lack of technical skills. I had to simplify the content significantly, making it more informational and conceptual. Even at the most basic level of Cyber 101, I had to bring it down another notch because they just didn’t understand it.

1
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
CISO in Software23 days ago
Is there recommended courses or curriculum for Fortune 500 boards?
1

Content you might like

Within the last month14%

Within the last 3 months51%

Within the last 6 months22%

No resume needed - I love my job!11%

View Results
3.1k views1 Upvote
IT Manager in Constructiona month ago
Hello,
the topic is so broad, what are you focused on?
Read More Comments
3.4k views2 Upvotes4 Comments

04%

1-374%

4-618%

7 or more2%

View Results
2.8k views1 Upvote
CTO in Software12 days ago
A couple of suggestions: 1) You ask coaching questions to assess whether the candidate has critical thinking; 2) Respectfully, you put the candidate under moderate pressure and observe how they react. This might involve saying ...read more
12 views1 Comment