Monday, November 10, 2025
HomeTechnologyThe 3 Key Priorities for CISOs in 2024

The 3 Key Priorities for CISOs in 2024


As the brand new yr begins, CISOs collect with their safety groups and company administration to scope out high priorities for 2024 and easy methods to handle these points. This yr — with a mess of latest privateness legal guidelines, Securities and Exchange Commission rules, cyber threats, and new applied sciences promising to unravel these threats — they is perhaps dropping sleep making an attempt to optimally stack the proverbial Tetris items of the cybersecurity technique.


Of all of the challenges vying for the CISO’s consideration, the non-public and obligation for information breaches the SEC has positioned on CISOs might be essentially the most difficult within the new yr, says Nicole Sundin, chief product officer at Axio. “With CISOs being elevated to the boardroom to debate these dangers, they’ll want a system of document to guard themselves and display obligation of care,” she notes.

1. Defend Yourself Against Personal Liability


Sundin likens CISOs to healthcare executives, who preserve detailed data of each motion they take with a view to defend themselves towards claims of malfeasance. Considering that many CISOs aren’t lined beneath company administrators and officers (D&O) insurance coverage insurance policies, they might be liable personally beneath
new SEC guidelines ought to a breach happen. That consists of private legal responsibility for each a breach with information loss or a privateness breach with out information loss.


Sundin recommends that CISOs take the next steps as quickly as attainable:


  • Create a company definition for “materiality,” with enter from the final counsel or the chief threat officer, to ascertain clear tips for what’s legally thought-about materially vital to traders or shareholders and what’s not.


  • Learn to talk to the board of administrators and different executives in monetary phrases. Tell the board precisely which safety controls are required, their value, and the potential loss to the corporate if a breach happens as a consequence of not having the safety controls in place.


CISOs should even be lively contributors when negotiating cyber insurance coverage insurance policies Sundin says. Normally CISOs have to log off on what the final counsel or CFO finally negotiates, however with out having direct enter — with a written document of their suggestions — they might change into legally liable defending a non-insurable exclusion.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Most Popular