No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Companies Must Have Corporate Cybersecurity Experts, SEC Says

July 27, 2023
in Protection
0
Companies Must Have Corporate Cybersecurity Experts, SEC Says



The US Security and Exchange Commission (SEC) has held up a magnifying glass to an enterprise’s cybersecurity expertise.

The original proposal from the SEC in March 2022 said that it wanted companies to publicly declare one cybersecurity expert on the board of directors and one within management. Today, the SEC backed off the requirement for the board expert — although it still wants “registrants to describe the board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks from cybersecurity threats.”

That means the SEC is not actively pushing for a board cybersecurity expert’s credentials, at least for the moment. But it is still insisting that management cybersecurity expertise be reported to them.

But what constitutes such expertise? Experts agree that that is a very difficult question.

The SEC explicitly did not define cybersecurity expertise, leaving that critical decision to each company. It gave hints as to some possible areas to determine that expertise, mentioning certifications, academic degrees, and work experience.

“Although the intent may be implied, the proposed SEC rule on cyber does not actually require more cybersecurity expertise on boards or in senior management. The … rule may not clearly outline what constitutes that expertise, but this is no different from other SEC disclosure requirements put in place for directors, such as the disclosure of financial expertise of directors who serve on the audit committee,” says Andrew Morrison, a Deloitte Risk & Financial Advisory principal.

Market Will Decide Who’s an Expert

Various specialists interviewed say that the SEC will not approve or deny anyone’s credentials and determine whether they meet the unspecified requirements. It will leave that to the market.

That could play out in two ways. First, when the enterprise suffers an especially destructive data breach, shareholders and investors may punish the company by lowering its stock price if those market forces decide that the credentials were insufficient. Two, a company might reconsider credentials it initially approved if all the other companies in that segment produce experts with more impressive credentials.

“The SEC is likely hoping that the new disclosure requirements will create some healthy competition around cybersecurity. Organizations will look at what their peers disclosed and try to do better, or at least not substantially worse,” says Brian Levine, an EY (formerly Ernst & Young) managing director.

Asked whether he thinks the new rule will make boards looking for new members prioritize cybersecurity experience, Levine is skeptical, but allows that “it might at least be a tie-breaker.”

Experience Is Key

When discussing the categories that the SEC shared, most security specialists give overwhelming emphasis to experience, with few being impressed by either most certificates or university training. Still, the most popular certs — including Certified Information System Security Professional (CISSP), Certified Information Systems Auditor (CISA), CompTIA Security+, Certified Ethical Hacker (CEH), and Certified Information Security Manager (CISM) — and computer science degrees are generally considered helpful for the management role, if too specific for the board role.

Andy Ellis, operating partner at YL Ventures, worries that some companies will rely too heavily on metrics that are easy to quantify — such as certs and degrees — because it will make it easier to find the talent, assuming the company is looking for this management expert externally.

“Recruiters can do a Google search based on metrics and find the perfect candidate who checks all of the boxes, even if qualitatively they are not a good candidate,” Ellis says.

For a board role, Ellis says it is much less about knowing the answers than it is about knowing the right questions to ask. If the CISO tells the board that they have properly implemented MFA, does the board member know enough about MFA and authentication to ask, “How many factors are we using and which ones are we using? Are we using the most stringent accurate methods or the lowest cost and least effective ones?” And when the answer comes, will that board member know if the answers are valid?

Brian Walker, CEO at security consulting firm The CAP Group, also is skeptical that certifications are helpful at the Fortune 500 level. The big value of a cybersecurity expert, whether in management or on the board, is making critical on-the-spot security decisions, such as whether something is truly a reportable breach. Says Walker, “At what point is an incident material? Simply determining if it’s material or not isn’t a quick activity. When do you declare?”

Recruit, Train, or …?

For a board position, enterprises have two ways to go: recruit true cyber experts to join the board, or turn existing board members into cyber experts.

The first option is difficult. Fortune 500 companies almost always have board members from one of three places: CEOs and former CEOs of other companies; investors of all kinds; and internal board members, typically the CEO and either the CFO or the COO. It’s hard to find true cybersecurity experts in those groups.

“If all the board needs to do is demonstrate expertise and the SEC is leaving the door open to directors demonstrating expertise through industry certification, then it would follow that sitting directors would wind up in certification bootcamps or executive cyber schools,” says Igor Volovich, the VP of compliance strategy at Qmulos. “Having observed such efforts first-hand, I can attest to the highly limited utility of such efforts.”

The SEC is trying to address the lack of serious attention cybersecurity typically receives at large companies. Board members will generally say supportive things about having low tolerance for risk and the importance of security protections.

But when the board makes budget decisions and considers giving the CISO far more authority, they overwhelmingly tend to not support cybersecurity with their actions.

Editorial Team

Editorial Team

Related Posts

This Waterproof JBL Portable Speaker Is on Sale for $40 Right Now
Protection

This Waterproof JBL Portable Speaker Is on Sale for $40 Right Now

May 2, 2026
Amazon Prime Members Can Get Two of These E-Books Free in May 2026
Protection

Amazon Prime Members Can Get Two of These E-Books Free in May 2026

May 1, 2026
Is Apple Intelligence Making Up Words Now?
Protection

Is Apple Intelligence Making Up Words Now?

May 1, 2026
10 Hacks Every Opera Browser User Should Know
Protection

10 Hacks Every Opera Browser User Should Know

May 1, 2026
Hacks Every Google Chat User Should Know
Protection

Hacks Every Google Chat User Should Know

May 1, 2026
This LG 4K Portable Projector Is $200 Off Right Now
Protection

This LG 4K Portable Projector Is $200 Off Right Now

May 1, 2026
Load More
Next Post
Military briefing: Ukraine switches to artillery power for eastern push

Military briefing: Ukraine switches to artillery power for eastern push

Popular News

  • Gold posts its biggest 2-month drop ever. How its price could still double over the next 5 years.

    Gold posts its biggest 2-month drop ever. How its price could still double over the next 5 years.

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Dogecoin May Rise 20% in May as DOGE Whale Holdings Hit Record Levels

    0 shares
    Share 0 Tweet 0
  • Bitcoin As Hedge: Taiwan Lawmaker Takes Reserve Proposal To The Top

    0 shares
    Share 0 Tweet 0
  • Bitcoin ETFs Post Strong April Inflows as Ether Turns Positive

    0 shares
    Share 0 Tweet 0

Latest News

Kashkari warns Iran war could limit Fed rate cuts amid inflation concerns

Kashkari warns Iran war could limit Fed rate cuts amid inflation concerns

May 3, 2026
0

## Market Snapshot Fed Rate Cuts Predictions for 2026 are showing a shift, with a decrease in expectations for rate...

German chancellor downplays row with Trump after troop drawdown announced

German chancellor downplays row with Trump after troop drawdown announced

May 3, 2026
0

German chancellor downplays row with Trump after troop drawdown announced

Crypto

Crypto Industry Under Siege: 29 Attacks Recorded In April 2026 Alone

May 3, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The crypto industry is seriously under attack...

Iran says it has received US response to its latest offer for talks

Iran says it has received US response to its latest offer for talks

May 3, 2026
0

Iran says it has received US response to its latest offer for talks

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.