SlideShare a Scribd company logo
www.ferma.eu
LIVE WEBINAR – FOLLOW US
@FERMARISK
#FERMAWEBINAR
FERMA Risk Leadership at the heart of Europe
Suscribe to our newsletter: www.ferma.eu
Contact us: enquiries@ferma.eu
www.ferma.eu
AT THE JUNCTION OF CORPORATE
GOVERNANCE AND CYBER
SECURITY
LIVE WEBINAR
@FERMARISK
#FERMAWEBINAR
www.ferma.eu
www.ferma.eu
Polling question #1
www.ferma.eu
Why corporate governance and cybersecurity
are now linked?
• A business need
– Help organisations to increase their resilience to cyber event while creating value with
digitalization opportunities
• A new global legal context
– European cyber laws (NIS, GDPR, ePrivacy for telecommunications), a strict new cyber
law in China; evolving US cyber laws (state enacted: MA, NY; Federal: CISA, more
pending), amongst others, are introducing new IT security and legal requirements for
organisations but all remain silent on the governance aspect of cybersecurity
• Beyond IT, a corporate issue
– Risk management readiness can only be achieved within a strong governance
framework, and through a highly coordinated approach across all departments of an
organization
www.ferma.eu
What do we mean by governance of cyber risk?
1. Similar to corporate governance: it is a set of processes, practices and policies put in
place to direct and control the cyber security
2. It’s a framework whose objective is to increase cyber resilience
3. It’s important to identify the most important stakeholders who can influence and affect
the governance of cyber risk (role of the Board, IT, legal, finance…)
www.ferma.eu
Polling question #2
www.ferma.eu
Two strong pillars to support the proposal
• The eight principles set out in the
OECD recommendation on Digital
Security Risk Management (2015)
• The Three Lines of Defence
model, recognised as a standard
of Enterprise Risk Management
(ERM)
www.ferma.eu
Main proposal: a cyber risk governance group
– A cross-function team headed by the
risk manager
• Composed of operational functions from the
1st line of defence and key functions from the
2nd line of defence
• To determine cyber risk exposures in financial
terms and design possible mitigation plans
– Why cross-disciplinary?
• Expertise, by being cross-disciplinary, the group
has the subject and organisational knowledge
to identify the most harmful cyber risks for the
organisation and list the suitable responses
www.ferma.eu
Risk Management – Internal Audit relationship
• “Auditability by design”
– Right from the beginning, cooperation between the cyber risk governance group and Internal Audit is
needed to ensure continuous measurement and improvement of mitigation plans
– Unique capacity for Internal Audit to independently review the efficiency of the cyber controls, risks
and governance processes implemented
• A Risk Committee
– as a board committee, it might be responsible for enterprise risks and reviews the cyber risk
assessments performed by the Group
• The Audit Committee
– It independently reviews the audit of the cyber risk governance
system performed by the Internal Audit function
www.ferma.eu
Polling question #3
www.ferma.eu
Case Study
• Educational Testing Service (ETS)
– Our Mission: To advance quality and equity in education by providing fair and valid
assessments, research and related services. Our products and services measure
knowledge and skills, promote learning and performance, and support education and
professional development for all people worldwide.
• Global
• Data intensive
• Complex IT Systems
• Real time
• Heavily partnered
• Complex global legal/regulatory environments
• Cyber threats to confidentiality, integrity, availability
• Transformative change on many fronts
www.ferma.eu
• ETS maintains dedicated organizations
and staff with responsibility for information
security, physical security and test
security, as well as disaster
recovery/business continuity, privacy and
internal audit.
• These organizations communicate and
collaborate via a corporate-level Security
Steering Committee, lead by our Chief
Information Security Officer and
comprised of the leaders responsible for
each function.
ETS Security Ecosystem
Audit
BC/DR
Privacy
Legal
Compliance
Test
Security
Physical
Security
Information
Security
Security Steering
Committee
www.ferma.eu
CAPA/Risk Management and
Quality Policies
Security Steering Committee:
• Determines risk exposures and
mitigating controls
• Oversight of significant security
initiatives and capital
investments
• Also defines policy and
responds to complex incidents
ETS Cyber Risk Governance Structure
www.ferma.eu
CAPA/Risk Management and
Quality Policies
• Risk Committee =
Enterprise Risk Executive Committee
• Cyber Risk Governance Group =
Security Steering Committee
• Security Steering Committee made up of
representatives from 1st, 2nd, and 3rd lines of
defense
Remember the proposal?
www.ferma.eu
CAPA/Risk Management and
Quality Policies
• Evolving as predictive
• Decision support for top leadership
• Guardrails
• What needs to be true?
How did we come up with this approach?
• Initially reactive
• From the ground up over several years
• Firefighting – incident management – joint projects
• Gradually more proactive
• Risk identification – mitigating controls
• Task Force
www.ferma.eu
Polling question #4
www.ferma.eu
Polling question #5
www.ferma.eu
www.ferma.eu
www.ferma.eu
Q&A
www.ferma.eu
SUBJECT: Applying Enterprise Risk Management to Environmental, Social and
Governance-related Risks with
WHEN: end of April
HOW: email invitation and/or register on www.ferma.eu
THANK YOU & JOIN OUR NEXT WEBINAR
RECORD YOUR 2 CPD POINTS
CONTACT US: enquiries@ferma.eu

More Related Content

What's hot

European Risk Management Seminar 2018 - Sustainability Report
European Risk Management Seminar 2018 - Sustainability ReportEuropean Risk Management Seminar 2018 - Sustainability Report
European Risk Management Seminar 2018 - Sustainability Report
FERMA
 
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
FERMA
 
Risk Manager European Profile 2018
Risk Manager European Profile 2018Risk Manager European Profile 2018
Risk Manager European Profile 2018
FERMA
 
FERMA European Risk Manager Report 2020: full set of results
FERMA European Risk Manager Report 2020: full set of results  FERMA European Risk Manager Report 2020: full set of results
FERMA European Risk Manager Report 2020: full set of results
FERMA
 
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPARPreparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
FERMA
 
The European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentationThe European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentation
FERMA
 
Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience
FERMA
 
Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019
FERMA
 
Sustainability & Risk Management
Sustainability & Risk ManagementSustainability & Risk Management
Sustainability & Risk Management
Turlough Guerin GAICD FGIA
 
Sustainability as risk management
Sustainability as risk managementSustainability as risk management
Sustainability as risk management
Metso Group
 
Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management
FERMA
 
Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?
FERMA
 
People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...
FERMA
 
Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020
FERMA
 
A combined solution to compliance and risk management for sustainability repo...
A combined solution to compliance and risk management for sustainability repo...A combined solution to compliance and risk management for sustainability repo...
A combined solution to compliance and risk management for sustainability repo...
Ardea International
 
Turkish bank association event UNEP FI intro speech 7 february
Turkish bank association event UNEP FI intro speech 7 februaryTurkish bank association event UNEP FI intro speech 7 february
Turkish bank association event UNEP FI intro speech 7 february
Harry Papageorgiou
 
6. unep fi presentation.ukraine. may 2011
6. unep fi presentation.ukraine. may 20116. unep fi presentation.ukraine. may 2011
6. unep fi presentation.ukraine. may 2011csrcentre
 
Ace emerging-risks-barometer-2013
Ace emerging-risks-barometer-2013Ace emerging-risks-barometer-2013
Ace emerging-risks-barometer-2013Factor-X
 
Transition to sustainability
Transition to sustainabilityTransition to sustainability
Transition to sustainability
Harry Papageorgiou
 
Financial Institutions Taking Action on Climate Change
Financial Institutions Taking Action on Climate ChangeFinancial Institutions Taking Action on Climate Change
Financial Institutions Taking Action on Climate Change
Dr Lendy Spires
 

What's hot (20)

European Risk Management Seminar 2018 - Sustainability Report
European Risk Management Seminar 2018 - Sustainability ReportEuropean Risk Management Seminar 2018 - Sustainability Report
European Risk Management Seminar 2018 - Sustainability Report
 
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
 
Risk Manager European Profile 2018
Risk Manager European Profile 2018Risk Manager European Profile 2018
Risk Manager European Profile 2018
 
FERMA European Risk Manager Report 2020: full set of results
FERMA European Risk Manager Report 2020: full set of results  FERMA European Risk Manager Report 2020: full set of results
FERMA European Risk Manager Report 2020: full set of results
 
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPARPreparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
 
The European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentationThe European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentation
 
Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience
 
Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019
 
Sustainability & Risk Management
Sustainability & Risk ManagementSustainability & Risk Management
Sustainability & Risk Management
 
Sustainability as risk management
Sustainability as risk managementSustainability as risk management
Sustainability as risk management
 
Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management
 
Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?
 
People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...
 
Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020
 
A combined solution to compliance and risk management for sustainability repo...
A combined solution to compliance and risk management for sustainability repo...A combined solution to compliance and risk management for sustainability repo...
A combined solution to compliance and risk management for sustainability repo...
 
Turkish bank association event UNEP FI intro speech 7 february
Turkish bank association event UNEP FI intro speech 7 februaryTurkish bank association event UNEP FI intro speech 7 february
Turkish bank association event UNEP FI intro speech 7 february
 
6. unep fi presentation.ukraine. may 2011
6. unep fi presentation.ukraine. may 20116. unep fi presentation.ukraine. may 2011
6. unep fi presentation.ukraine. may 2011
 
Ace emerging-risks-barometer-2013
Ace emerging-risks-barometer-2013Ace emerging-risks-barometer-2013
Ace emerging-risks-barometer-2013
 
Transition to sustainability
Transition to sustainabilityTransition to sustainability
Transition to sustainability
 
Financial Institutions Taking Action on Climate Change
Financial Institutions Taking Action on Climate ChangeFinancial Institutions Taking Action on Climate Change
Financial Institutions Taking Action on Climate Change
 

Similar to FERMA Webinar: At the Junction of Corporate Governance and Cyber Security

Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
FERMA
 
Offset print-brochure-ferma-2017v3-1
Offset print-brochure-ferma-2017v3-1Offset print-brochure-ferma-2017v3-1
Offset print-brochure-ferma-2017v3-1
Manuel Lofino
 
Risk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR complianceRisk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR compliance
IT Governance Ltd
 
2 Security And Internet Security
2 Security And Internet Security2 Security And Internet Security
2 Security And Internet SecurityAna Meskovska
 
A Major Revision of the CISRCP Program
A Major Revision of the CISRCP ProgramA Major Revision of the CISRCP Program
A Major Revision of the CISRCP Program
GoogleNewsSubmit
 
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAEIT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
360 BSI
 
Security as a Strategy
Security as a Strategy Security as a Strategy
Security as a Strategy
James Deiotte
 
EUCI Mapping Cybersecurity to CIP
EUCI Mapping Cybersecurity to CIPEUCI Mapping Cybersecurity to CIP
EUCI Mapping Cybersecurity to CIPScott Baron
 
Cyber Security Risk Management
Cyber Security Risk ManagementCyber Security Risk Management
Cyber Security Risk ManagementShaun Sloan
 
Improving cyber-security through acquisition
Improving cyber-security through acquisitionImproving cyber-security through acquisition
Improving cyber-security through acquisition
Christopher Dorobek
 
Cyber Security Strategies and Approaches
Cyber Security Strategies and ApproachesCyber Security Strategies and Approaches
Cyber Security Strategies and Approaches
vngundi
 
GMFI Conference (3)
GMFI Conference (3)GMFI Conference (3)
GMFI Conference (3)Daniel Paula
 
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
U.S. News Healthcare of Tomorrow
 
EU/US boards’ approach to cyber risk governance - webinar presentation
EU/US boards’ approach to cyber risk governance - webinar presentationEU/US boards’ approach to cyber risk governance - webinar presentation
EU/US boards’ approach to cyber risk governance - webinar presentation
FERMA
 
Risk Based Security and Self Protection Powerpoint
Risk Based Security and Self Protection PowerpointRisk Based Security and Self Protection Powerpoint
Risk Based Security and Self Protection Powerpoint
randalje86
 
Automatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy StandardsAutomatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy Standards
automatskicorporation
 
CIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile WorldCIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile World
iMIS
 
CIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile WorldCIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile World
iMIS
 
Managing Security Risks in Manufacturing
Managing Security Risks in ManufacturingManaging Security Risks in Manufacturing
Managing Security Risks in Manufacturing
William McBorrough
 
Cyber Risk in the Energy Industry
Cyber Risk in the Energy IndustryCyber Risk in the Energy Industry
Cyber Risk in the Energy Industry
Tim Christ Executive Leadership
 

Similar to FERMA Webinar: At the Junction of Corporate Governance and Cyber Security (20)

Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
 
Offset print-brochure-ferma-2017v3-1
Offset print-brochure-ferma-2017v3-1Offset print-brochure-ferma-2017v3-1
Offset print-brochure-ferma-2017v3-1
 
Risk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR complianceRisk assessments and applying organisational controls for GDPR compliance
Risk assessments and applying organisational controls for GDPR compliance
 
2 Security And Internet Security
2 Security And Internet Security2 Security And Internet Security
2 Security And Internet Security
 
A Major Revision of the CISRCP Program
A Major Revision of the CISRCP ProgramA Major Revision of the CISRCP Program
A Major Revision of the CISRCP Program
 
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAEIT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
IT Risk Management & Leadership 30 March - 02 April 2014 Dubai UAE
 
Security as a Strategy
Security as a Strategy Security as a Strategy
Security as a Strategy
 
EUCI Mapping Cybersecurity to CIP
EUCI Mapping Cybersecurity to CIPEUCI Mapping Cybersecurity to CIP
EUCI Mapping Cybersecurity to CIP
 
Cyber Security Risk Management
Cyber Security Risk ManagementCyber Security Risk Management
Cyber Security Risk Management
 
Improving cyber-security through acquisition
Improving cyber-security through acquisitionImproving cyber-security through acquisition
Improving cyber-security through acquisition
 
Cyber Security Strategies and Approaches
Cyber Security Strategies and ApproachesCyber Security Strategies and Approaches
Cyber Security Strategies and Approaches
 
GMFI Conference (3)
GMFI Conference (3)GMFI Conference (3)
GMFI Conference (3)
 
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
 
EU/US boards’ approach to cyber risk governance - webinar presentation
EU/US boards’ approach to cyber risk governance - webinar presentationEU/US boards’ approach to cyber risk governance - webinar presentation
EU/US boards’ approach to cyber risk governance - webinar presentation
 
Risk Based Security and Self Protection Powerpoint
Risk Based Security and Self Protection PowerpointRisk Based Security and Self Protection Powerpoint
Risk Based Security and Self Protection Powerpoint
 
Automatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy StandardsAutomatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy Standards
 
CIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile WorldCIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile World
 
CIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile WorldCIO Summit: Data Security in a Mobile World
CIO Summit: Data Security in a Mobile World
 
Managing Security Risks in Manufacturing
Managing Security Risks in ManufacturingManaging Security Risks in Manufacturing
Managing Security Risks in Manufacturing
 
Cyber Risk in the Energy Industry
Cyber Risk in the Energy IndustryCyber Risk in the Energy Industry
Cyber Risk in the Energy Industry
 

More from FERMA

The role of risk management in corporate resilience
The role of risk management in corporate resilienceThe role of risk management in corporate resilience
The role of risk management in corporate resilience
FERMA
 
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
FERMA
 
Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020
FERMA
 
George Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland WaterGeorge Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland Water
FERMA
 
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
FERMA
 
GDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementationGDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementation
FERMA
 
GDPR & corporate governance: the role of risk management and internal audit o...
GDPR & corporate governance: the role of risk management and internal audit o...GDPR & corporate governance: the role of risk management and internal audit o...
GDPR & corporate governance: the role of risk management and internal audit o...
FERMA
 
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
FERMA
 
Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?
FERMA
 
Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018
FERMA
 
European risk management sustainability seminar report
European risk management sustainability seminar reportEuropean risk management sustainability seminar report
European risk management sustainability seminar report
FERMA
 
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
FERMA
 
1st international edition of the RMIS Panorama with the support of FERMA network
1st international edition of the RMIS Panorama with the support of FERMA network1st international edition of the RMIS Panorama with the support of FERMA network
1st international edition of the RMIS Panorama with the support of FERMA network
FERMA
 
FERMA Network: facts and figures about risk management associations in Europe
FERMA Network: facts and figures about risk management associations in EuropeFERMA Network: facts and figures about risk management associations in Europe
FERMA Network: facts and figures about risk management associations in Europe
FERMA
 

More from FERMA (14)

The role of risk management in corporate resilience
The role of risk management in corporate resilienceThe role of risk management in corporate resilience
The role of risk management in corporate resilience
 
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
 
Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020
 
George Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland WaterGeorge Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland Water
 
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
 
GDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementationGDPR & corporate Governance, Evaluation after 2 years implementation
GDPR & corporate Governance, Evaluation after 2 years implementation
 
GDPR & corporate governance: the role of risk management and internal audit o...
GDPR & corporate governance: the role of risk management and internal audit o...GDPR & corporate governance: the role of risk management and internal audit o...
GDPR & corporate governance: the role of risk management and internal audit o...
 
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
 
Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?
 
Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018
 
European risk management sustainability seminar report
European risk management sustainability seminar reportEuropean risk management sustainability seminar report
European risk management sustainability seminar report
 
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
 
1st international edition of the RMIS Panorama with the support of FERMA network
1st international edition of the RMIS Panorama with the support of FERMA network1st international edition of the RMIS Panorama with the support of FERMA network
1st international edition of the RMIS Panorama with the support of FERMA network
 
FERMA Network: facts and figures about risk management associations in Europe
FERMA Network: facts and figures about risk management associations in EuropeFERMA Network: facts and figures about risk management associations in Europe
FERMA Network: facts and figures about risk management associations in Europe
 

Recently uploaded

一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
taqyed
 
Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
Aurelien Domont, MBA
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
bosssp10
 
An introduction to the cryptocurrency investment platform Binance Savings.
An introduction to the cryptocurrency investment platform Binance Savings.An introduction to the cryptocurrency investment platform Binance Savings.
An introduction to the cryptocurrency investment platform Binance Savings.
Any kyc Account
 
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Holger Mueller
 
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Lviv Startup Club
 
Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)
Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)
Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)
Lviv Startup Club
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
Brand Analysis for an artist named Struan
Brand Analysis for an artist named StruanBrand Analysis for an artist named Struan
Brand Analysis for an artist named Struan
sarahvanessa51503
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
SOFTTECHHUB
 
Authentically Social Presented by Corey Perlman
Authentically Social Presented by Corey PerlmanAuthentically Social Presented by Corey Perlman
Authentically Social Presented by Corey Perlman
Corey Perlman, Social Media Speaker and Consultant
 
Bài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.doc
Bài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.docBài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.doc
Bài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.doc
daothibichhang1
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
dylandmeas
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
Aggregage
 
Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...
Lviv Startup Club
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024
Kirill Klimov
 
Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024
FelixPerez547899
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Arihant Webtech Pvt. Ltd
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
JeremyPeirce1
 

Recently uploaded (20)

一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
一比一原版加拿大渥太华大学毕业证(uottawa毕业证书)如何办理
 
Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
 
An introduction to the cryptocurrency investment platform Binance Savings.
An introduction to the cryptocurrency investment platform Binance Savings.An introduction to the cryptocurrency investment platform Binance Savings.
An introduction to the cryptocurrency investment platform Binance Savings.
 
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
 
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
 
Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)
Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)
Helen Lubchak: Тренди в управлінні проєктами та miltech (UA)
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
Brand Analysis for an artist named Struan
Brand Analysis for an artist named StruanBrand Analysis for an artist named Struan
Brand Analysis for an artist named Struan
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
 
Authentically Social Presented by Corey Perlman
Authentically Social Presented by Corey PerlmanAuthentically Social Presented by Corey Perlman
Authentically Social Presented by Corey Perlman
 
Bài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.doc
Bài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.docBài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.doc
Bài tập - Tiếng anh 11 Global Success UNIT 1 - Bản HS.doc
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
 
Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024
 
Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
 

FERMA Webinar: At the Junction of Corporate Governance and Cyber Security

  • 1. www.ferma.eu LIVE WEBINAR – FOLLOW US @FERMARISK #FERMAWEBINAR FERMA Risk Leadership at the heart of Europe Suscribe to our newsletter: www.ferma.eu Contact us: enquiries@ferma.eu
  • 2. www.ferma.eu AT THE JUNCTION OF CORPORATE GOVERNANCE AND CYBER SECURITY LIVE WEBINAR @FERMARISK #FERMAWEBINAR
  • 5. www.ferma.eu Why corporate governance and cybersecurity are now linked? • A business need – Help organisations to increase their resilience to cyber event while creating value with digitalization opportunities • A new global legal context – European cyber laws (NIS, GDPR, ePrivacy for telecommunications), a strict new cyber law in China; evolving US cyber laws (state enacted: MA, NY; Federal: CISA, more pending), amongst others, are introducing new IT security and legal requirements for organisations but all remain silent on the governance aspect of cybersecurity • Beyond IT, a corporate issue – Risk management readiness can only be achieved within a strong governance framework, and through a highly coordinated approach across all departments of an organization
  • 6. www.ferma.eu What do we mean by governance of cyber risk? 1. Similar to corporate governance: it is a set of processes, practices and policies put in place to direct and control the cyber security 2. It’s a framework whose objective is to increase cyber resilience 3. It’s important to identify the most important stakeholders who can influence and affect the governance of cyber risk (role of the Board, IT, legal, finance…)
  • 8. www.ferma.eu Two strong pillars to support the proposal • The eight principles set out in the OECD recommendation on Digital Security Risk Management (2015) • The Three Lines of Defence model, recognised as a standard of Enterprise Risk Management (ERM)
  • 9. www.ferma.eu Main proposal: a cyber risk governance group – A cross-function team headed by the risk manager • Composed of operational functions from the 1st line of defence and key functions from the 2nd line of defence • To determine cyber risk exposures in financial terms and design possible mitigation plans – Why cross-disciplinary? • Expertise, by being cross-disciplinary, the group has the subject and organisational knowledge to identify the most harmful cyber risks for the organisation and list the suitable responses
  • 10. www.ferma.eu Risk Management – Internal Audit relationship • “Auditability by design” – Right from the beginning, cooperation between the cyber risk governance group and Internal Audit is needed to ensure continuous measurement and improvement of mitigation plans – Unique capacity for Internal Audit to independently review the efficiency of the cyber controls, risks and governance processes implemented • A Risk Committee – as a board committee, it might be responsible for enterprise risks and reviews the cyber risk assessments performed by the Group • The Audit Committee – It independently reviews the audit of the cyber risk governance system performed by the Internal Audit function
  • 12. www.ferma.eu Case Study • Educational Testing Service (ETS) – Our Mission: To advance quality and equity in education by providing fair and valid assessments, research and related services. Our products and services measure knowledge and skills, promote learning and performance, and support education and professional development for all people worldwide. • Global • Data intensive • Complex IT Systems • Real time • Heavily partnered • Complex global legal/regulatory environments • Cyber threats to confidentiality, integrity, availability • Transformative change on many fronts
  • 13. www.ferma.eu • ETS maintains dedicated organizations and staff with responsibility for information security, physical security and test security, as well as disaster recovery/business continuity, privacy and internal audit. • These organizations communicate and collaborate via a corporate-level Security Steering Committee, lead by our Chief Information Security Officer and comprised of the leaders responsible for each function. ETS Security Ecosystem Audit BC/DR Privacy Legal Compliance Test Security Physical Security Information Security Security Steering Committee
  • 14. www.ferma.eu CAPA/Risk Management and Quality Policies Security Steering Committee: • Determines risk exposures and mitigating controls • Oversight of significant security initiatives and capital investments • Also defines policy and responds to complex incidents ETS Cyber Risk Governance Structure
  • 15. www.ferma.eu CAPA/Risk Management and Quality Policies • Risk Committee = Enterprise Risk Executive Committee • Cyber Risk Governance Group = Security Steering Committee • Security Steering Committee made up of representatives from 1st, 2nd, and 3rd lines of defense Remember the proposal?
  • 16. www.ferma.eu CAPA/Risk Management and Quality Policies • Evolving as predictive • Decision support for top leadership • Guardrails • What needs to be true? How did we come up with this approach? • Initially reactive • From the ground up over several years • Firefighting – incident management – joint projects • Gradually more proactive • Risk identification – mitigating controls • Task Force
  • 21. www.ferma.eu SUBJECT: Applying Enterprise Risk Management to Environmental, Social and Governance-related Risks with WHEN: end of April HOW: email invitation and/or register on www.ferma.eu THANK YOU & JOIN OUR NEXT WEBINAR RECORD YOUR 2 CPD POINTS CONTACT US: enquiries@ferma.eu

Editor's Notes

  1. Julie to ask question: What is most important in order for a cybersecurity governance structure to work for your organization? + present answers (multiple answers are possible) Laetitia to launch poll … then share results live Julie to comment results Julie– NEXT SLIDE: Polling question 5: - Do you take cross-functional purchase decisions on cyber insurance in cooperation with business units and IT?