{"id":1843,"date":"2013-10-19T08:57:55","date_gmt":"2013-10-19T03:27:55","guid":{"rendered":"http:\/\/www.naavi.org\/?p=1843"},"modified":"2013-10-19T08:58:42","modified_gmt":"2013-10-19T03:28:42","slug":"board-room-responsibility-for-cyber-security","status":"publish","type":"post","link":"https:\/\/www.naavi.org\/wp\/board-room-responsibility-for-cyber-security\/","title":{"rendered":"Board Room Responsibility for Cyber Security"},"content":{"rendered":"<p style=\"text-align: justify;\">The undersigned has been highlighting the need for Directors of Companies and the CEO to take responsibility for Cyber Security in an organization. Section 85 of ITA 2008 as well as Section 79 has clearly laid out the need for &#8220;Due Diligence&#8221; without which Directors of Companies may find themselves saddled with civil and criminal liabilities.<\/p>\n<p style=\"text-align: justify;\">The infamous Baazee.com litigation dragged the CEO Mr Avnish\u00a0Bajaaj to a Court battle which prolonged for 8 years. Though he escaped conviction because of a technical error by the Police which in reasonable probability could be deliberate, the need for due diligence at Board levels was well emphasized in the process.<\/p>\n<p style=\"text-align: justify;\">This article in Forbes titled <a href=\"http:\/\/www.forbes.com\/sites\/jodywestby\/2012\/05\/16\/boards-are-still-clueless-about-cybersecurity\/\" target=\"_blank\">&#8220;Boards are still Clueless about Cyber Security&#8221;<\/a>\u00a0highlights that even in US the level of Board attention on Cyber Security is still lacking. According to a Carnegie Mellon report,<\/p>\n<p style=\"text-align: justify; padding-left: 30px;\">71% of their boards rarely or never review privacy and security budgets<br \/>\n79% of their boards rarely or never review roles and responsibilities<br \/>\n64% of their boards rarely or never review top-level policies<br \/>\n57% of their boards rarely or never review security program assessments.<\/p>\n<p style=\"text-align: justify;\">If this is the situation in a Compliance sensitive\u00a0corporate community\u00a0like US, one can imagine that the status in India can be pretty bad.<\/p>\n<p style=\"text-align: justify;\">The undersigned has a personal experience of how the well known\u00a0CEOs of ICICI\u00a0Bank, Axis Bank and PNB\u00a0have shown absolute incompetence and arrogance in understanding the cyber security risks which have landed some of their customers in trouble when confronted with complaints on Phishing and other frauds. It is only when one or more of such celebrity CEOs find themselves confronting FIRs like Avnish\u00a0Bajaj, they will realize their true responsibilities. However as the wheels of justice grind slowly, it is possible that these executives may be long retired when law tries to catch up with them. However, if law can catch up with a retired executive like the Coal Secretary Mr Parakh, may be one day law will also catch up with the current CEOs of Banks who are playing with Customer&#8217;s lives by adopting a commercially motivated risky banking policies.<\/p>\n<p style=\"text-align: justify;\">It is high time that the Boards of all IT user organizations to start devoting some attention on Cyber Security before it is too late.<\/p>\n<p>Naavi<\/p>\n<p>Also Read:<\/p>\n<p><a href=\"http:\/\/about.bloomberglaw.com\/practitioner-contributions\/cyber-risk-and-the-board-of-directors-closing-the-gap\/\" target=\"_blank\">&#8220;Cyber Risk and the board of directors-closing the gap&#8221;<\/a><\/p>\n<p><a href=\"http:\/\/www.bankinfosecurity.co.uk\/whitepapers.php?wp_id=820&amp;user_email=naavi2011@gmail.com&amp;elq=ae2ce22465114f6a9bccca3a0c72dc9f&amp;rf=2013-08-29-bttn&amp;elq=ae2ce22465114f6a9bccca3a0c72dc9f&amp;elqCampaignId=8108\" target=\"_blank\">New Measures to Mitigate Mobile Banking Risks<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The undersigned has been highlighting the need for Directors of Companies and the CEO to take responsibility for Cyber Security in an organization. Section 85 of ITA 2008 as well as Section 79 has clearly laid out the need for &hellip; <a href=\"https:\/\/www.naavi.org\/wp\/board-room-responsibility-for-cyber-security\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_editorskit_title_hidden":false,"_editorskit_reading_time":0,"_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","_uag_custom_page_level_css":"","footnotes":""},"categories":[7],"tags":[],"class_list":["post-1843","post","type-post","status-publish","format-standard","hentry","category-cyber-law"],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false,"post-thumbnail":false},"uagb_author_info":{"display_name":"Vijayashankar Na","author_link":"https:\/\/www.naavi.org\/wp\/author\/naavi\/"},"uagb_comment_info":0,"uagb_excerpt":"The undersigned has been highlighting the need for Directors of Companies and the CEO to take responsibility for Cyber Security in an organization. Section 85 of ITA 2008 as well as Section 79 has clearly laid out the need for &hellip; Continue reading &rarr;","_links":{"self":[{"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/posts\/1843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/comments?post=1843"}],"version-history":[{"count":2,"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/posts\/1843\/revisions"}],"predecessor-version":[{"id":1845,"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/posts\/1843\/revisions\/1845"}],"wp:attachment":[{"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/media?parent=1843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/categories?post=1843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.naavi.org\/wp\/wp-json\/wp\/v2\/tags?post=1843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}