- How is the mandate going to impact my CISO role? Or my cyber organization? Or My metrics/KPI?
You will need to demonstrate defensible cybersecurity reporting using a method that is easy to understand and leverages your existing professionals.
- How does this change the nature of the touchpoints between the cyber performance and compliance touchpoints?
A holistic risk management approach is necessary that ties in both assessment activities to identify cybersecurity gaps, and a quantification methodology to rapidly calculate impact and overlay it over your insurance portfolio to calculate your risk tolerance.
- How does this impact the organization’s skills, roles, and team?
Not much if you use a cybersecurity performance management platform that can leverage your existing processes.
- How does this change board oversight and reporting?
You will need to have a defensible process to calculate materiality that is repeatable and easy to implement.