<?xml version="1.0" encoding="UTF-8"?>
<article article-type="research-article" xml:lang="en" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher">global-journal-of-computer-science-and-technology-e-network-web-security</journal-id>
<journal-title-group>
<journal-title>Global Journal of Computer Science and Technology - E: Network, Web &amp; Security</journal-title>
</journal-title-group>
<issn publication-format="print">0975-4350</issn>
<issn publication-format="electronic">0975-4172</issn>
<publisher><publisher-name>Global Journals Publishing Group Incorporated</publisher-name></publisher>
<self-uri xlink:href="https://globaljournals.org/journal-seo-export/jats/54731.xml" />
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">54731</article-id>
<title-group>
<article-title>A Board Recipe for Minimizing Supply-Chain Cyber Loss</article-title>
<subtitle>Board Leadership in Supply Chain Cyber Risk</subtitle>
</title-group>
<contrib-group>
<contrib contrib-type="author"><name><surname>Deane</surname><given-names>Jason K.</given-names></name><xref ref-type="aff" rid="aff1" />
</contrib>
<contrib contrib-type="author"><name><surname>Baker</surname><given-names>Wade H.</given-names></name></contrib>
</contrib-group>
<aff id="aff1">UNITED STATES</aff>
<pub-date publication-format="electronic" date-type="pub" iso-8601-date="2023-10-04">
<day>04</day>
<month>10</month>
<year>2023</year>
</pub-date>
<volume>23</volume>
<issue>E2</issue>
<fpage>1</fpage>
<lpage>5</lpage>
<abstract><p>Introduction-After attending corporate board meetings for approximately 85 different Fortune 500 organizations and listening to CEOs and CISOs discuss cyber risk in supply chains; and after then meeting with many of them personally, we came away with three primary takeaways. First, the main cybersecurity interest of most upper-level managers is primarily in avoiding major negative consequences (i.e., Black Swans) to their firms. Second, over 90% of corporate board members we have met with are either neutral or not confident with their security program’s effectiveness. But finally, and of major concern to us, was the observation that CISOs primarily tell their boards “anecdotes” or “stories,” and they do not present boards with any substantive and specific direction to avoid supply-chain cyber loss.</p></abstract>
<self-uri content-type="pdf" xlink:href="https://globaljournals.org/GJCST_Volume23/1-A-Board-Recipe-for-Minimizing-Supply.pdf" />
<self-uri content-type="html" xlink:href="https://globaljournals.org/scholarly-articles/a-board-recipe-for-minimizing-supply-chain-cyber-loss/" />
</article-meta>
</front>
<body>
<sec>
<title>Full Text</title>
<p>After attending corporate board meetings for approximately 85 different Fortune 500 organizations and listening to CEOs and CISOs discuss cyber risk in supply chains; and after then meeting with many of them personally, we came away with three primary takeaways. First, the main cybersecurity interest of most upper-level managers is primarily in avoiding major negative consequences (i.e., Black Swans) to their firms.  Second, over 90% of corporate board members we have met with are either neutral or not confident with their security programâ€™s effectiveness.  But finally, and of major concern to us, was the observation that CISOs primarily tell their boards â€œanecdotesâ€ or â€œstories,â€ and they do not present boards with any substantive and specific direction to avoid supply-chain cyber loss.  We believe this is unfortunate because, based on a different set of experiences we have had, namely performing several thousand forensic studies, including about one thousand for the U.S. Secret Service-most with about 100 page or more reports, we believe corporate boards can take specific reasoned actions and thereby reduce significantly their organizationâ€™s exposure to, and subsequent losses from, supply-chain cyber-attacks.</p>
</sec>
</body>
</article>