Carnegie Mellon CyLab Survey Exposes Gap in the Way Companies Manage Cyber Risks

A recent Carnegie Mellon University (CMU) CyLab survey of corporate board directors reveals a gap in board and senior executive oversight in managing cyber risks. Based on data from 703 individuals (primarily independent directors) serving on boards of public companies listed in the United States, only 36 percent of the respondents indicated that their board had any direct involvement with oversight of information security.

The survey also said that cybersecurity issues need to be seen as an enterprise risk management problem rather than an IT issue.

"Managing cyber risk is not just a technical challenge, but it is a managerial and strategic business challenge," said Pradeep Khosla, dean of CMU's College of Engineering and CyLab founder.

"There are real fiduciary duty and oversight issues involved here," said Jody Westby, adjunct distinguished fellow at Carnegie Mellon CyLab and the survey's lead author. "There is a clear duty to protect the assets of a company, and today, most corporate assets are digital."

"We also found that boards were only involved about 31 percent of the time in assessment of risk related to IT or personal data--the data that triggers security breach notification laws," said Westby.

Only 8 percent of survey respondents said their boards had a risk committee that is separate from the audit committee, according to Westby.

"Without the right organizational structure and interest from top officials, enterprise security can't be effective no matter how much money an organization throws at it," said Richard Power, co-author of the report and a distinguished fellow at Carnegie Mellon CyLab.

Power said the survey also shows that senior management hasn't budgeted for key positions requiring expertise in cybersecurity or privacy areas. "No wonder the number of security breaches has doubled in the past year--only 12 percent of the respondents have established functional separation of privacy and security, and most companies don't have C-level executives responsible for these areas," Power added.

To help company boards improve corporate governance of privacy and security, the survey recommends broad operational changes from establishing a board risk committee separate from the audit committee to reviewing existing top-level policies to creating a culture of security and respect for privacy.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Businessman using laptop analyzing data and growth graph chart

    AI Budgets in Education Show No Sign of Decline

    The vast majority of education organizations (98%) expect their AI infrastructure budgets to either increase or hold steady over the next year, according to a recent report from cloud storage provider Wasabi.

  • Interconnected Light Particles in Vibrant Streams

    Rubrik Agent Cloud Expands Policy Controls for Agent Prompts/Responses

    Rubrik has made Rubrik Agent Cloud generally available, adding expanded governance controls that enforce predefined and custom policies on both AI agent prompts and responses.

  • abstract cybersecurity data protection

    Rubrik Intros Google Workspace Data Protection

    Rubrik has announced the launch of Rubrik Data Protection for Google Workspace, a product the company said is designed to help enterprise customers protect data and restore operations across Google Workspace environments.

  • Silhouettes of business professionals stand against a blurred futuristic city skyline at night, with a glowing digital network data connection

    It's Time for Higher Ed to Get Serious About AI Strategy

    Without a coordinated strategy that involves multiple academic and administrative units across the entire campus, colleges risk wasting resources, duplicating efforts, and ultimately failing to deliver on the promise of deploying technology to improve learning and operations.