Supply chain security: How CISOs can explain costs to the board | TechTarget
Supply chain cybersecurity risk is more than a technical control problem; it is a financial risk management decision that impacts the entire enterprise. CISOs must first determine how much a supplier's breach would cost their companies and then compare that potential loss to the amount spent to safeguard their systems. From there, CISOs can explicitly distinguish among inherent, mitigated and residual risk.
The core issue is this: Organizations increasingly depend on vendors and partners whose security failures can become the organization's operational and financial problem. These risks translate into four financial dimensions: liability, disruption, downtime and security investment. Addressing these dimensions -- supply chain security risk costs -- requires deliberate decisions by executives and the board.
This article discusses how CISOs can reframe supply chain riskas a financial concern and demonstrates how to quantify it. It then provides executives with a decision-making framework and action plan to understand, mitigate...
Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE