Charles Blauner
Former Global Head of
Information Security for Citi
Having a well-documented governance process is very important. What the SEC has said is that you have to tell us how you do governance. You should be very clear about what your risk identification and lifecycle process looks like. 'Who has the right to approve risk acceptances? What is the process by which you and the board set risk tolerances?'
Mario Duarte
Former VP of security
for Snowflake
Every CISO needs to go look at their continuous monitoring controls. Do you have the right incident response — people, process, and technology — to quickly connect the dots and help the management team understand what happened, remediate the breach, and decide if an incident is material?
Selim Aissi
Former CISO
for Ellie Mae
Boards are getting more security savvy. What kind of metrics should they be demanding? What is the threat landscape? What technical security controls are in place? How are the risks identified across the company? How is the risk measured?