Cybersecurity for Executives & the Board
Boards are not expected to understand firewalls. They are expected to know whether the organisation has decided how much cyber risk it will carry, whether someone owns that decision, and whether the answer they were given last quarter was true. This briefing is built around the questions a director should be able to ask without technical vocabulary, the answers that should worry them, and the specific duties that Malaysian law now places on the people at the top rather than on the IT department.
Programme Agenda
Cyber Risk as a Governance Problem
Reframing security from a technical spend to a risk the board already knows how to handle. Risk appetite, tolerance, treatment and transfer, applied to a domain where the numbers feel less certain.
What Directors Are Actually Accountable For
Duties under the Companies Act, the Personal Data Protection Act as amended in 2024, and the Cyber Security Act 2024 where the organisation is a designated NCII entity. Where accountability cannot be delegated to a vendor or a CIO.
The Eight Questions to Ask Management
A working set of oversight questions covering crown jewels, third-party dependency, detection capability, backup recoverability, incident rehearsal, insurance, and the gap between the policy and the practice. Including what a satisfactory answer sounds like.
Reading a Security Report Without Being Technical
Interpreting maturity scores, penetration test summaries, patch compliance figures and incident counts. Spotting the report that has been written to reassure rather than to inform.
Deciding on Spend
Judging a security budget request when the benefit is an absence of events. Comparing proposals on risk reduction rather than product features, and recognising the controls that deliver disproportionate value.
When an Incident Reaches the Board
Escalation triggers, the board's role during a live incident versus management's, regulatory notification decisions, customer communication, and the legal privilege questions that arise early.
Third Parties, Cloud and Concentration Risk
The supplier who holds your data, the platform that runs your operations, and what happens when they are the ones breached. Contractual protections and the limits of them.
Board Simulation: A Disclosed Breach
A short scenario played out at board level. Participants take positions on notification, disclosure, customer response and public statement, then review the consequences of each choice.
Learning Outcomes:
Frame cyber risk in the same governance language the board already uses
State where director accountability sits under Malaysian law and where it cannot be delegated
Put a structured set of oversight questions to management and judge the answers
Read a security report critically rather than accepting a summary score
Assess a security investment proposal on risk reduction
Act appropriately during a live incident without displacing management
Weigh notification and disclosure decisions against regulatory and reputational exposure
Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Senior / Leadership
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cybersecurity
- Practical Cybersecurity for Business and IT · Intermediate, 2 days
- Information Security and Risk Management · Intermediate, 2 days
- Cybersecurity Advanced and Governance · Advanced, 2 days
- Cyber Security Act 2024 (Act 854) and NACSA Readiness · All levels, 1 day
- Data Breach Response and Incident Management · All levels, 1 day
- Incident Response and Digital Forensics · Intermediate, 2 days
- Cloud Security Fundamentals (AWS, Azure, GCP) · Intermediate, 2 days
- OT and ICS Security · All levels, 2 days