<p>This contribution examines the role and (forthcoming) regulations for supervisory board members (and non-executive directors) regarding cybersecurity. The European regulation in this area (the Digital Operational Resilience Act (DORA)) and the Network and Information Security Directive (NIS and NIS&#xa0;2) are considered together with the rather progressive Dutch Corporate Governance Code. The desired role of the supervisory director is then highlighted. To this end, several recommendations are made (as for the Executive Board). The suggestions focus on active dialogue with the organisation, leading by example, raising awareness of the importance of cybersecurity within the company and its stakeholders, and reporting as transparently as possible. In addition, not only must cybersecurity responsibilities be clearly defined and properly embedded in corporate governance, but also the knowledge and expertise within the various bodies of the company must be brought up to standard, together with up-to-date scenario manuals and training.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

From cybersecurity to cyber resilience in the board room: key steps for supervisory board members and non-executives

  • Annika Galle,
  • Hélène Vletter-van Dort

摘要

This contribution examines the role and (forthcoming) regulations for supervisory board members (and non-executive directors) regarding cybersecurity. The European regulation in this area (the Digital Operational Resilience Act (DORA)) and the Network and Information Security Directive (NIS and NIS 2) are considered together with the rather progressive Dutch Corporate Governance Code. The desired role of the supervisory director is then highlighted. To this end, several recommendations are made (as for the Executive Board). The suggestions focus on active dialogue with the organisation, leading by example, raising awareness of the importance of cybersecurity within the company and its stakeholders, and reporting as transparently as possible. In addition, not only must cybersecurity responsibilities be clearly defined and properly embedded in corporate governance, but also the knowledge and expertise within the various bodies of the company must be brought up to standard, together with up-to-date scenario manuals and training.