In today’s digital landscape, cyber risk transcends technical concerns and has become a pivotal strategic issue for Fortune 500 company board directors. This course is designed to equip board members with a solid understanding of why cyber risk should be considered a core component of business strategy and how board members should provide oversight of the cyber risk management practices of the firms they govern.
Through a combination of expert-led discussions, participants will explore the following:
Cyber Risk and Business Strategy: Understand how cyber risk intertwines with organizational goals and affects strategic decision-making at the highest levels.
Regulatory and Compliance Considerations: Learn about the regulatory frameworks and compliance requirements that govern cyber risk management.
Critical Questions for Board Oversight: Discover the essential questions board directors should ask to ensure robust cyber risk governance, including risk assessments, incident response plans, and resource allocation.
Real-World Examples: Understand actual incidents and learn from organizations that have successfully navigated cyber challenges and those that have faced significant repercussions.
Creating a Cyber-Savvy Culture: Explore strategies for fostering a culture of cybersecurity awareness and accountability throughout the organization.
By the end of this course, board directors will be empowered to lead informed discussions around cyber risk, advocate for appropriate investment in cybersecurity measures, and enhance their organization's resilience against cyber threats. Join us in transforming cyber risk from a technical issue into a strategic business priority.
In this module, learners will explore the critical role of the board of directors in overseeing cyber risk management within an organization. You’ll understand the importance of adopting a standardized approach to ensure consistent and effective communication of cyber risks to both the board and stakeholders. This module introduces the FAIR (Factor Analysis of Information Risk) model as the leading industry standard for quantifying and reporting cyber risks, empowering organizations to make data-driven decisions and align cyber risk management with business objectives
Understanding Cyber Risk Oversight for Board Members•5 minutes
Key Questions for Board Members to Ask•2 minutes
FAIR - The Industry Standard for Board Reports•4 minutes
4 readings•Total 50 minutes
Course Syllabus•10 minutes
Introduction: The GPA Framework•15 minutes
Cybersecurity Governance - Critical Questions for Board Oversight•15 minutes
Understanding FAIR – The Open Standard for Cyber and Operational Risk Quantification•10 minutes
4 assignments•Total 9 minutes
Assessment of Understanding Cyber Risk Oversight for Board Members•2 minutes
Assessment of Key Questions for Board Members to Ask•2 minutes
Assessment of FAIR - The Industry Standard for Board Reports•2 minutes
Graded Assessment -1•3 minutes
4 discussion prompts•Total 20 minutes
Introductions•5 minutes
Responsibilities of Board Directors•5 minutes
Questions from Board Directors•5 minutes
Organizational Cyber Risk •5 minutes
Is the Business Ready for a Cyber Event?
Module 2•2 hours to complete
Module details
In this module, learners will dive into strategies for evaluating an organization’s readiness to manage and respond to cyber incidents. You’ll discover key indicators that help measure preparedness, explore essential questions board members can ask to assess cyber resilience, and learn how to leverage training programs and tabletop exercises to improve incident response capabilities. By the end of this module, you’ll understand how proactive preparation and strategic oversight can strengthen an organization’s ability to respond to cyber threats effectively.
Cybersecurity Governance - Critical Questions for Board Oversight•15 minutes
Understanding Cyber Incident Tabletop Exercises for Board Oversight•15 minutes
4 assignments•Total 9 minutes
Assessment of Key Readiness Indicators for Cyber Incident Management Using FAIR•2 minutes
Assessment of Questions to Assess Cyber Preparedness•2 minutes
Assessment of Training and Tabletop Exercises for Board Readiness•2 minutes
Graded Assessment - 2•3 minutes
3 discussion prompts•Total 30 minutes
Steps to Improve Cyber Risk Management•10 minutes
Board Questions Preparedness •10 minutes
Board Actions for Tabletop Exercises•10 minutes
Satisfying SEC Requirements
Module 3•1 hour to complete
Module details
This module provides board members and senior leaders with the knowledge and tools needed to navigate the evolving regulatory landscape of cybersecurity reporting. With a focus on the U.S. Securities and Exchange Commission (SEC) requirements, the module equips learners to fulfill their oversight responsibilities by understanding key compliance obligations.
Participants will explore the SEC's 4-day materiality reporting rule, critical considerations for timely disclosure of cyber incidents, and the annual (10-K) cybersecurity disclosure requirements. Through practical examples and guidance, learners will gain the insights necessary to support organizational compliance while maintaining transparency and protecting shareholder value.
The SEC Rule for Reporting Cyber Incidents•3 minutes
The SEC Rule for Annual (10-K) Cybersecurity Disclosures•3 minutes
Mid-course Video•1 minute
2 readings•Total 25 minutes
Understanding the SEC Rule on Cyber Incident Materiality Reporting•10 minutes
SEC Cybersecurity Disclosure Requirements and Board Oversight•15 minutes
3 assignments•Total 6 minutes
Assessment of The SEC Rule for Reporting Cyber Incidents•2 minutes
Assessment of The SEC Rule for Annual (10-K) Cybersecurity Disclosures•2 minutes
Graded Assessment -3 •2 minutes
2 discussion prompts•Total 20 minutes
SEC Preparedness•10 minutes
Board Skills and Experience for Cyber Risk Oversight•10 minutes
Cyber Incident Response Protocol
Module 4•1 hour to complete
Module details
In this module, board directors will learn the critical steps involved in responding to a cyber incident, from the initial detection to recovery and post-incident analysis. Understanding the right protocols and how to communicate across different levels of the organization—especially between technical and non-technical board leaders—is vital for effective incident management. Additionally, this module will cover the legal and regulatory requirements that board members need to be aware of during a cyber incident, ensuring compliance and minimizing organizational risk. By the end of this module, directors will be equipped with the knowledge to oversee and guide their organization’s response to a cyber crisis.
Step-by-step Guide for Board Actions During a Cyber Event•4 minutes
Cyber Incident Communication and Preparedness•4 minutes
Cybersecurity Legal and Regulatory Considerations•3 minutes
3 readings•Total 25 minutes
Preparing for Cyber Incident Response: Best Practices for Board Directors•10 minutes
Effective Communication of Cyber Risk to the Board•5 minutes
Legal and Regulatory Considerations for Cyber Incident Response•10 minutes
4 assignments•Total 9 minutes
Assessment of Step-by-step Guide for Board Actions During a Cyber Event•2 minutes
Assessment of Cyber Incident Communication and Preparedness•2 minutes
Assessment of Cybersecurity Legal and Regulatory Considerations•2 minutes
Graded Assessment - 4•3 minutes
3 discussion prompts•Total 30 minutes
Cyber Preparedness Responsibility•10 minutes
Preparing Staff for a Cyber Incident•10 minutes
Cyber Incident Response Processes•10 minutes
Building FAIR™ into the Risk Management Program
Module 5•1 hour to complete
Module details
This module introduces the Factor Analysis of Information Risk (FAIR™) framework, providing board directors with foundational knowledge to understand and oversee cyber risk management. FAIR™ is the only international standard for quantifying cyber risk, enabling organizations to translate technical threats into financial terms. This approach helps boards align cybersecurity priorities with business objectives and regulatory requirements.
Leveraging FAIR™ for Cyber Insurance, ROI, and Reputation Risk•5 minutes
Using FAIR™ to Enhance Board-Level Cyber Risk Discussions•10 minutes
3 assignments•Total 6 minutes
Assessment of Effective Cyber Risk Management with FAIR•2 minutes
Assessment of Putting risk quantification into the business context•2 minutes
Graded Assessment - 5•2 minutes
2 discussion prompts•Total 15 minutes
Quantifying Cyber Risk•5 minutes
Board Challenges with Cyber Risk•10 minutes
Consequences of Inadequate Preparation: Operational and Legal Risks
Module 6•1 hour to complete
Module details
In this module, board directors will explore the critical operational and legal consequences organizations may face if they are unprepared for cyber incidents. The module delves into real-world examples of business disruptions and lawsuits resulting from inadequate cyber risk management, emphasizing the importance of proactive preparation. Directors will gain insights into the far-reaching impact that insufficient cybersecurity measures can have on an organization’s financial stability, reputation, and legal standing.
Regulatory and Class Action Lawsuit Cyber Incident Example•4 minutes
2 readings•Total 20 minutes
Public Hacks •10 minutes
Cybersecurity – A Team Sport Requiring Board-Level Engagement•10 minutes
3 assignments•Total 6 minutes
Assessment of Real-world Cyber Incident Impact Examples•2 minutes
Assessment of Regulatory and Class Action Lawsuit Cyber Incident Example•2 minutes
Graded Assessment - 6•2 minutes
2 discussion prompts•Total 20 minutes
Public Hack Case Study•10 minutes
Importance of Board Engagement with Cybersecurity•10 minutes
Board Member Collaboration for M&A
Module 7•1 hour to complete
Module details
Mergers and acquisitions (M&A) are high-stakes processes that require careful attention to various risks, including cyber risks. Board members play a crucial role in ensuring that cyber risks are adequately assessed and managed throughout the M&A lifecycle. This module focuses on the importance of collaboration between board members to identify, evaluate, and mitigate potential cyber risks during these complex transactions. By integrating the FAIR framework for cyber risk quantification, board members can gain valuable insights that influence deal valuations, guide post-merger integration, and ensure long-term organizational success.
Integrating Cyber Risk Assessments into M&A Processes•2 minutes
Using Cyber Risk Quantification in M&A Decisions•2 minutes
FAIR Assesses Financials During M&A•2 minutes
3 readings•Total 30 minutes
Applying the FAIR Framework in Mergers and Acquisitions•10 minutes
Assessing Cyber Risk in Mergers and Acquisitions: A FAIR Approach•10 minutes
Understanding the Financial Impact of M&A: The FAIR Advantage•10 minutes
4 assignments•Total 9 minutes
Assessment of Integrating Cyber Risk Assessments into M&A Processes•2 minutes
Assessment of Using Cyber Risk Quantification in M&A Decisions•2 minutes
Assessment of FAIR Assesses Financials During M&A•2 minutes
Graded Assessment - 7•3 minutes
3 discussion prompts•Total 20 minutes
Key Benefits of FAIR in M&A•10 minutes
Financial Benefits of Integrating FAIR into M&A Process•5 minutes
FAIR's Approach to Changing M&A Processes•5 minutes
Testing Cyber Readiness
Module 8•1 hour to complete
Module details
In today's rapidly evolving cybersecurity landscape, it's crucial for organizations to assess their preparedness for potential cyber incidents. Testing cyber readiness through simulated exercises, such as tabletop drills, is an essential step in ensuring an organization's ability to respond effectively to cyber threats. This module focuses on the importance of tabletop exercises in evaluating incident response capabilities, highlighting how these exercises help identify gaps in processes, communication, and decision-making. It also explores the benefits of analyzing the results to enhance future responses and strengthen overall cyber resilience.
The FAIR Institute is a research-driven non-profit organization dedicated to advancing the discipline of cyber and operational risk management through education, standards, and collaboration.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.