From cybersecurity to cyber resilience in the board room: key steps for supervisory board members and non-executives
摘要
This contribution examines the role and (forthcoming) regulations for supervisory board members (and non-executive directors) regarding cybersecurity. The European regulation in this area (the Digital Operational Resilience Act (DORA)) and the Network and Information Security Directive (NIS and NIS 2) are considered together with the rather progressive Dutch Corporate Governance Code. The desired role of the supervisory director is then highlighted. To this end, several recommendations are made (as for the Executive Board). The suggestions focus on active dialogue with the organisation, leading by example, raising awareness of the importance of cybersecurity within the company and its stakeholders, and reporting as transparently as possible. In addition, not only must cybersecurity responsibilities be clearly defined and properly embedded in corporate governance, but also the knowledge and expertise within the various bodies of the company must be brought up to standard, together with up-to-date scenario manuals and training.