The threats posed by cyberattacks and the implication of those attacks continue to increase and many say the rate of increase is accelerating. Those facts have caught the attention of leaders in business and government. We have seen the leaders of many countries talk about and put in place measures to deal with this very real threat. Just recently we saw an article published by the Harvard Business Review (HBR) publishedtitled, “All Boards Need a Technology Expert,”link: https://hbr.org/2015/09/all-boards-need-a-technology-expert that also addresses this issue.  The HBR article which calls out the need for boards of directors to have a member whothat can explain — to their board members (in non-technical terms) — the cyber threats they face.

RELATED:  Learn how to fight insider threats from the Office of the Director of National Intelligence’s National Insider Threat Task Force in a free webcast Nov. 17

The piece goes on and references a study that was sponsored by Raytheon and conducted by the Ponemon Institute that . That study found a shocking 80 percent of boards have not even been briefed on the company’s cybersecurity strategy. That is shocking given that two of the primary responsibilities of boards are to establish and review the strategies and goals of the organization and to oversee the operations and affairs of the organization in the context of risks and opportunities. It would seem that the cybersecurity strategy clearly fits into both of those areas of responsibility. One would think that 80 percent of boards receive regular briefings not just on the organization’s cyber strategy, but also the current level of cyberattacks being experienced by the organization.

I recently was contacted by a C-level executive that said he needed to get the attention of all top management and was looking for some information. He told me of the numbers he was going to use came from something I wrote about a year ago. The number he quoted shocked me. While accurate at the time of publication, they were way off now. To illustrate the continuous evolution of the cyber threat environment, he cited used the metric – new pieces of malware released per second. At the time that piece was published, the number was on average 2 new strains of malware being issued per second. I told him that was way off!  Using Symantec’s September report, that number is now over 14 new strains of malware being released per second. It was clear by the look on his face he was shocked and troubled. Imagine his face when I pointed out that in June 2015 the average number hit 22 new strains of malware being released per second.

The velocity of the cyber threat environment as measured by those numbers is very troubling to say the least. Think about that pace. Can anyone or any organization keep up with that magnitude of threat increase?  With those numbers, maybe the boards of directors will become fully engaged in this rapidly growing risk.