Bestyrelsens håndtering af cyber attacks er det seneste år kommet helt op i toppen af bestyrelsens dagsorden, ifølge et stort amerikansk advokatfirma, der til sine kunder har udarbejdet en guide omkring udarbejdelse af en handlingsplan: “The plan should address how to mitigate and remediate the attack technologically; when and how disclosure should be made internally – including to the board of directors – and to the public (both customers and investors); public relations; and whether and to what extent law enforcement and regulators need to be contacted (e.g., in the case of consumer privacy breaches). The plan should be flexible, tested repeatedly in the application and, most importantly, clearly designate who among the board, the company’s management and other staff will have ownership with respect to measures for dealing with any cyber-attack should one occur. l arrange for cyber-risk training and education for board members to ensure that they are conversant in the technology and cyber risks relevant to the company’s business operations and/or financial reporting controls, and consider competence in information technology when filling a new board position.”
