Cybersecurity: It's Not Rocket Science; It's "Reasonableness"

No ratings

Presented at SecureBoston 2017 by

Panel Discussion-Each day there is a headline grabbing news piece involving another cyber-attack resulting in the theft of digital information (e.g., government classified materials, PII and healthcare records, intellectual property, financial information) or the disruption of government and business functions. Nation-states, terrorists, hacktivists, and cyber-criminals are relentless. Companies are told "it's not a matter of if, but when" they will be attacked. Compounding that, federal and state regulators are stepping in with new requirements, mandating companies in all sectors to address cybersecurity with little, if any, real guidance on how to do so. Despite being a victim of a cyber-attack, a business most likely will still have to defend its actions in claims from government agencies and litigation involving class action and shareholder derivative suits. What to do? The technology supporting cybersecurity is complex, but the business response is not. Rather than looking at cybersecurity as a technical issue, companies must recognize it as a risk management issue that needs to be addressed just like any other business risk. Moderator:Kevin Powers, Founding Director, MS in Cybersecurity Policy and Governance, Boston College