Board of Directors Training
Building a stronger defense for your organization.
Purpose
This course aims to raise awareness of cyber risks and strengthen knowledge in the field of cybersecurity. The Board of Directors (board) is responsible for a company’s assets and value creation, and cybersecurity is a crucial factor here. Therefore, boards need cybersecurity skills to understand risks, ask relevant questions, and make the right decisions about IT security and handling cyberattacks.
Content
The teaching will be dialogue-based and build on both experience and common models. Along the way, the participants will be asked realistic, difficult dilemmas that management and board typically face in relation to risk management and crisis management. The teaching will be knowledge-based, dilemma-based and discussion-based.
This training is tailored as needed, but typically includes the following topics:
The current threat landscape
- The hackers: Who are the hackers and how do they work? An introduction to the types of actors who conduct cyberattacks, as well as their methods and motivations.
- Methods of attack: The most common methods of attack today. Focus on current and frequent attack types, such as phishing, ransomware, and supply chain attacks.
Board of Directors
- Responsibility: The board’s responsibilities, role, and competencies on the board.
- Governance: Introduction to relevant regulations for the organization as well as best practice for establishing governance structures.
- Tools: How is the board’s work with cyber security structured and which framework tools enable effective monitoring of risks.
- Crisis management: A review of the distinct phases, including the role of the board in a crisis.
Risk management
- Methods: How can cyber threats be assessed and presented in a risk perspective? Methods for evaluating threats and risks in an overall business perspective.
- Reporting: Learn how to ask the right questions to IT management and management. Focus on critical questions about primary vulnerabilities, threats, and potential losses from a cyberattack.
Output from the day
At the end of the course, the participants will:
- Gain increased awareness and knowledge of cybersecurity and risk management.
- Understand the board’s responsibilities related to the organization’s regulatory requirements for cybersecurity (NIS2/DORA/CER).
- Be better equipped to take responsibility as a board member in relation to cyber security and crisis management.
- Get practical material and tools for further use in board work.