The corporate board bears a crucial responsibility for managing cybersecurity risks that threaten organizations of all sizes. As overseers of the company’s cybersecurity posture, board members must take active steps to protect its assets and data from cyber threats. However, some board members may not fully understand their personal liability for lack of oversight in this area.
Under corporate governance laws, board members have a fiduciary duty to act in the best interests of the shareholders and protect the company from cyber threats. If a board member fails in this duty, they may face personal liability for any resulting losses or damages. According to the landmark 1996 ruling in Caremark, directors can be held accountable if they fail to properly monitor and oversee the company or if their inaction results in a loss. Furthermore, if the company breaches data protection laws, such as the EU’s GDPR, board members may be accountable.

A framework for addressing cybersecurity risk.
To effectively mitigate cybersecurity risk, the corporate board should take the following steps:
- Stay informed: Invite the CISO or vCISO to present updates, but don’t rely solely on these presentations. Have a board member with technical expertise stay current with industry news, attend security conferences and events, and engage with security experts.
- Assess risk posture: Conduct a comprehensive risk assessment to identify areas of weakness and potential vulnerabilities.
- Develop a cybersecurity strategy: Based on the results of the risk assessment, outline steps to mitigate risk and protect against cyber threats, including the implementation of technologies, processes, and training programs.
- Allocate resources: Ensure the organization has adequate funding and staffing to implement and maintain its security posture.
- Foster a culture of security: Encourage security awareness and training throughout the organization and incorporate security into company policies and procedures.
- Insure a true representation of risks: Consider forming a cybersecurity committee working directly with the CISO to ensure a clearer understanding of risks, as executive management may suppress or under-appreciate cybersecurity risks.
- Engage with third-party vendors: Partner with a security vendor to supplement internal security efforts and stay updated on the latest security technologies and best practices.
- Monitor and review regularly: Establish regular review processes to ensure the organization’s cybersecurity posture remains effective, including reporting from the CISO on threats and regular reviews of security policies, incident response plans, and metrics.
Clearly, the corporate board has a critical role to play in mitigating cybersecurity risk. By staying informed, assessing the organization’s risk posture, developing a comprehensive cybersecurity strategy, allocating adequate resources, fostering a culture of security, engaging with a third-party vendor, and monitoring and reviewing regularly, the board can help ensure that the company is taking the necessary steps to protect itself against cyber threats.

More on Cybersecurity
- Would You Ignore a 1-in-3 Chance of a $250,000 Loss?
If someone told you that you had a one in three chance of an accident this year that could cost your business $250,000, what would you do? Would you roll the dice and hope it doesn’t happen?Or would you buy an insurance policy that dramatically reduces your risk? That’s the same calculation every small and… Read more: Would You Ignore a 1-in-3 Chance of a $250,000 Loss? - The cybersecurity reality for SMBsIn today’s digital environment, SMBs can no longer assume “we’re too small to matter” when it comes to cyber-threats. Microsoft’s report underscores how the risk has become pervasive and how the stakes are significant for organizations with limited resources yet major responsibilities. The findings reveal both awareness and a gap between knowing the risk and… Read more: The cybersecurity reality for SMBs
- Protecting Yourself from FinTech Fraud: Five Common Scams and How to Stay Safe
Financial technology, or FinTech, has made managing money faster and easier than ever. Apps can send money, invest, or pay bills in seconds. That same convenience can also make you a target for fraud. According to Stripe’s Guide to FinTech Fraud Detection, criminals use many different tricks to steal money or personal data. Understanding how… Read more: Protecting Yourself from FinTech Fraud: Five Common Scams and How to Stay Safe - Ransomware: What Small Businesses Need to Know
When ransomware first hit headlines, attackers often lingered in networks for weeks or even months before making demands. That window has shrunk dramatically. Today, the average time from initial compromise to ransom is just 17 hours, with reports showing some attacks happening in as little as 6 hours. In other words, by the time many… Read more: Ransomware: What Small Businesses Need to Know - When AI Bots Break the Rules: Lessons from Perplexity’s Stealth Crawling
Artificial intelligence is reshaping how we access and use information, but with that power comes responsibility. Recent findings by Cloudflare and investigative reporting from CyberScoop have revealed troubling behavior by Perplexity, an AI-powered answer engine, that challenges the ethical foundation of AI data practices. ????️♂️ The Incident: Crawling Behind Closed Doors Cloudflare discovered that Perplexity’s… Read more: When AI Bots Break the Rules: Lessons from Perplexity’s Stealth Crawling - What is Salt Typhoon and why should I care????? What is Salt Typhoon? Salt Typhoon is a state-sponsored Chinese Advanced Persistent Threat (APT) believed to operate under China’s Ministry of State Security. Its espionage operations began around 2020 and have heavily targeted U.S. critical infrastructure CyberScoop. ???? How did they infiltrate U.S. telecom networks? ???? Scope of the breach: What was affected? ???? Broader… Read more: What is Salt Typhoon and why should I care?
- Would You Ignore a 1-in-3 Chance of a $250,000 Loss? – October 23, 2025
- The cybersecurity reality for SMBs – October 21, 2025
- Protecting Yourself from FinTech Fraud: Five Common Scams and How to Stay Safe – October 14, 2025
