If we have selected the wrong experience for you, please change it above.
The Board’s role in cyber resilience
Sandra Emme began her entrepreneurial career in France as the co-founder of a number of IT start-ups, which went on to expand globally and were later bought out. For the past 15 years, she has worked for Google, where she is currently Industry Leader Cloud Enterprise and advises manufacturing companies on transformation, cyber and data strategy. In 2018, Sandra Emme joined the Board of Directors of Panalpina Welttransport Holding AG, followed in 2019 by the Board of Metall Zug AG. She has been a member of the Board of Belimo Holding AG since 2018 and of Zehnder Group AG since 2022. She is also a member of the Executive Board of digitalswitzerland and Lecturer in Digital Business Transformation at IMD Business School in Lausanne. Sandra Emme also has qualifications in Corporate Governance (HSG) and ESG (Competent Boards).
Opens in new window
swissVR Monitor: What is the general role of a Board of Directors in ensuring that their company is cyber resilient?
Sandra Emme: In my discussions with Board members, I am often struck by the fact that many of them do not realise they have an important role to play. In fact, I’d like to add that ensuring cyber resilience is not a responsibility that can be delegated to the IT Department; it is an integral part of the Board’s non-transferable role of providing overall management of the company under Article 716a of the Swiss Code of Obligations.
Cyber risk is a strategic risk in the same way financial and operational risk is, and Boards need to tackle it as such and ensure that it is integrated within the company’s broader risk management system. The Board’s core responsibility is to provide strategic management, defining tolerance of risk, providing adequate financial resources and overseeing clear governance.
The Board must also ensure it receives regular reports on threat levels and security indicators and oversee the effectiveness of emergency planning. It is advisable to document this process to provide a record of fiduciary responsibility, care and continuity. If there is an incident, the Board must ensure that statutory reporting provisions are complied with.
swissVR Monitor: Our survey of Board members shows that only around half of all Boards rehearse their crisis management plans for the eventuality of a cyber attack. What specific risks are the remaining half running?
Sandra Emme: If a Board seriously neglects the issue of cyber resilience, it is breaching its statutory duty of due diligence. A serious cyber attack involving massive financial loss threatens individual Board members with personal civil liability as well as criminal prosecution if statutory reporting responsibilities have not been complied with.
I’d also add that rehearsing crisis management does not mean that the Board actually gets involved operationally in the case of a crisis; that would be counterproductive and would actually hamper the management’s crisis team in doing its job. The Board’s role is, rather, to check whether the organisation is prepared for a crisis and whether the Board is receiving the information it needs. If Boards do not rehearse this, they risk wasting a lot of time and making the wrong strategic decisions once a crisis hits the company.
The first specific risk is legal liability: the Board is not liable for the attack itself but it is held responsible for inadequate preparation or strategic errors during a crisis, such as breaching the duty to provide ad hoc disclosure or data protection updates. In such cases, D&O insurers may refuse to cover the cost of such breaches.
Second, there is a risk of paralysis in a crisis. If the Board does not test its plans, it will not know which strategic decisions it will face under enormous time pressure, such as decisions on releasing special funds or informing major shareholders or regulators.
Third, there is the dilemma posed by ransom demands: if it has not discussed in advance how to react to a ransom demand, the Board cannot know once an attack is under way whether, and how, it should react to such demands. Nor will it have the resources readily available if it decides it should pay.
The fourth and final risk is that of reputational damage and financial loss: a cyber attack almost always causes reputational damage, even when the crisis is managed well. If the Board is unprepared and communications are not coordinated, though, the risk of damage and loss rises massively to the point of becoming an existential threat, especially to SMEs.
My advice is to conduct tabletop exercises and ensure that management has an ‘incident response retainer’ in place – an on-call contract with external experts who can provide immediate help and advice. Insurance providers often recommend such a contract or may even make it a condition of insuring companies against cyber risk.
swissVR Monitor: We also found that only about half of all Swiss Boards regularly receive briefings and reports from management about cyber incidents within the company. What is your view of what management should regularly be telling the Board about such incidents?
Sandra Emme: Simply listing incidents, for example, does not address the level of strategic responsibility the Board has. The focus must be on managing risk, and the Board must be able to take specific and well-founded investment decisions. Quantifying cyber risk in monetary terms is the best way of doing that: how many Swiss Francs are we willing to risk?
Future-oriented reporting needs to cover a number of dimensions. The first is reporting on the greatest cyber risks and how they can be mitigated – in other words, what are the major risks to the company’s business model, and how is management mitigating them?
Second, how can we protect our ‘crown jewels’? How well protected are our most business-critical systems and our most valuable data? Backups should always be stored separately from the main network, for example, placing them out of the reach of external encryption.
The third dimension is reactivity or resilience, with metrics for average detection time. How long does it take for the company to become aware that its network is under attack? How long does it then take to react to that attack? And if an external software manufacturer warns of a security vulnerability, how long does it take for the internal team to patch that vulnerability?
The fourth dimension addresses supply chains and third parties – the need to assess cyber risk across the supply chain, which is often a major gateway for criminals.
The fifth dimension involves identifying human risk and AI risk, drawing not only on training but also on a strategic assessment of the security of any AI tools employees are using.
The sixth and final dimension involves an independent view from outside the company or the findings of independent cyber audits, penetration testing or maturity assessments along with security scores, enabling objective benchmarking of the company.
swissVR Monitor: The great majority of Boards do not include members with expertise in cyber issues. When should a Board appoint someone with specific cyber or IT expertise?
Sandra Emme: Not every Board member needs to be an IT expert, but for the whole Board to be tech-blind is strategically very risky indeed. A targeted appointment is a particularly good idea if the ‘enablement gap’ is widening: the Board needs a member who can act as an interpreter and critically engage with what management has to say about the company’s IT systems.
Another reason for making a specific appointment is the fundamental transformation in the IT landscape, including global migration to new ERP systems, ‘cloud-first’ strategies and instances of AI disrupting core business models. Having a Board member with relevant expertise is also essential to ensuring that the company’s cyber maturity meets requirements. If cyber audits reveal gaps, Boards should not wait for the company to fall victim to a major attack – and for shareholders facing personal losses to demand greater know-how within the Board – before they take action in this area.
It’s also a good idea to make a targeted appointment in listed companies: investors and advisers on shareholder voting rights are increasingly calling for Boards to have active digital skills, with at least one member with proven experience in technology and cyber-related issues.
It’s less common to find medium-sized companies with a full-time IT expert, and having one can make one of the few available Board seats too specific in terms of skills. Convening an external advisory board or inviting an external CISO to act as an adviser is a good way of providing independent input to sit alongside cyber reporting from management.
swissVR Monitor: When is it a good idea for the Board to set up a Cyber Committee or an IT Committee?
Sandra Emme: Having that kind of committee is increasingly seen as best practice across many different sectors. However, it is only essential where the IT landscape within the company is so complex that neither the Board as a whole nor a traditional Audit Committee has the time to develop a deep understanding of the issues at stake. This is particularly the case where there is convergence between OT (operational technology) and IT. If manufacturing companies blend production plants using OT with traditional IT in automated factories, the result is highly complex new vectors for a cyber attack.
Other reasons for having a Cyber Committee or an IT Committee would be that the company needs to reduce massive IT debts, has invested heavily in AI, or needs to carry out complex IT integration following acquisitions.
And a dedicated Cyber Committee or IT Committee can also carry out ‘deep dives’, enhancing the Board’s knowledge and understanding in areas with particular strategic relevance for the company, such as SOC (security operations centre) strategy, protection of supply chains, cyber security, and AI/Internet of Things trends as part of the company’s innovation strategy.
Finally, setting up such a committee may also be a response to regulatory pressure. For listed or highly regulated companies, a Technology and Cyber Committee is crucial to provide the ‘deep dives’ to test IT architectural issues, large IT budgets and security audits, and to provide the Board of Directors with evidenced recommendations.