Mention "Risk Committee" or "Enterprise Risk" to upper management and you will probably get an eye role. If you suggest a standing meeting about risk - it might get you fired. BUT - I believe the risk committee meeting can be the most valuable meeting on your calendar. Here's how:
Why Risk Committee Meetings Are Important
Successful risk committee meetings are all about effective communication. So they have to be short, meaningful, and drive action that benefits the business. Here are a few keys for to success: 1 | Focus on the most important topics impacting the organization; 2 | Teams from cross-functional areas must have an opportunity to collaborate; 3 | Leadership requires visibility into progress and barriers to key activities; and 4 | Problems should be identified and resolved quickly.Who Should Attend the Risk Committee Meeting
Risk Committee meetings are about cross-functional collaboration in the spirit of removing barriers and making progress. For this to happen leaders or delegates from the following functional areas should be in attendance: 1 | Legal/Compliance 2 | Information Technology (i.e,. Product, Operations, Information Security) 3 | Leadership from Business Functional Areas 4 | Operations 5 | Strategy (if applicable) 6 | Enterprise Risk (if applicable)Structure of the Risk Committee Meeting
Risk Committee members are very busy so meetings should be optimally structured to maximize impact in a relatively short amount of time. To ensure a productive meeting leverage these principles: 1 | Assign a meeting coordinator to facilitate the meeting, gather and distribute information; 2 | Leverage a shared collaboration space to share data (i.e, a shared folder or dedicated application); 3 | The meeting should be limited to 45 minutes (1 hour for larger organizations); 4 | The meeting should be quarterly (there may be more frequent lower-level meetings); 5 | Leverage a standing agenda in which everyone understands their role and reporting habits; 6 | Clearly define key performance indicators (KPIs) in which each participant should provide an update; 7 | Status should be limited to on-track or off-track. If off-track clearly state what is required to "get unstuck"; 8 | Require advanced preparation from all committee members (including status from direct reports); and 9 | Status from committee members should be combined and distribution in advance.Collecting Key Performance Indicators
Key performance indicators will be unique to each organization, but here are a few areas to consider collecting: 1 | Status of key projects focused on defined business objectives (pulling from the organizations annual strategy); 2 | Results of internal and external audit reports; 3 | Results from enterprise risk assessments; 4 | Results of penetration tests or vulnerability assessments; 5 | Feedback from committee members or leaders of functional areas; and 6 | Periodic survey results from the management team.Let's Get Started
If you stick to the guidelines above - your risk committee meeting could be the most valuable meeting on your calendar. If you want to learn more about how we help organization manage risk let's grab coffee. Learn More About the vCISO Solution Contact Us
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)