Cyber risk management and governance

Cyber risk governance is how an organization decides which cyber risks it will accept, who owns each one, and how the board knows whether they are still inside that line. Our cyber risk management services build that system: an appetite the board has approved, a register people actually use, and indicators that show when something has moved.

What cyber risk governance is

Security operations keeps systems safe day to day. Governance sits above it and answers a different set of questions: how much risk is acceptable, who decided, and what evidence shows the decision is being kept.

Without it, security spend follows whoever pushed hardest last. With it, a budget request, a policy exception or a new vendor is judged against a line the board has already drawn.

Who needs cyber risk governance

Boards and risk committees that are asked to oversee cyber risk and receive a slide of red, amber and green with no numbers behind it.

Regulated firms. Federally regulated financial institutions work to OSFI Guideline B-13 on technology and cyber risk. Provincially regulated credit unions and insurers answer to their provincial regulator, covered on security for credit unions and insurers.

Public bodies under BC FIPPA, which must make reasonable security arrangements for personal information and be able to show it.

Anyone asked “what is our cyber risk?” by an insurer, a lender, an acquirer or a large customer, and who cannot yet answer in one page.

How the six services fit together as one programme

Few organizations need all six at once, so each is scoped on its own. They are built to connect.

  1. A NIST CSF 2.0 programme gives the structure and a current-to-target profile.
  2. A risk appetite, register and KRIs turn that structure into decisions the board can track. Start with how to write a cyber risk appetite statement.
  3. Business impact analysis and continuity sets the recovery targets the register relies on.
  4. A vendor risk management programme extends the register to suppliers who hold your data or access.
  5. Enterprise risk and cyber insurance connects cyber to the enterprise register and to what the insurer is told.
  6. GRC platform selection and implementation comes last, once the process works.

Where you also need a named senior owner for security, this work sits inside the vCISO and security programme.

What changes when it works

The board sees a short set of indicators against limits it approved. Out-of-appetite risks carry a named owner and a decision with a review date. When an insurer or customer asks, the answer comes from the register.

The framing is Canadian first: PIPEDA, BC FIPPA, BC PIPA and OSFI where they apply, with NIST CSF 2.0 and ISO 27001 as the international structure. Privacy obligations sit with compliance and privacy.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Is cyber risk governance the same as compliance?

No. Compliance asks whether you meet a stated requirement. Risk governance asks which risks you are carrying, whether you meant to carry them, and who decided.

Who owns cyber risk in an organization?

The executive who owns the business process owns the risk to it. The security lead measures and advises, and the board sets the appetite and checks that decisions stay inside it.

Do we need a GRC platform first?

No. Buy the platform last, once the register, the owners and the review cycle work on paper, so the tool records a process you already run.

Is this legal advice?

No. We are not lawyers; we work alongside your counsel wherever a question turns on what a statute or regulator requires.

Start with the question you were asked

Tell us who is asking about cyber risk, a board, a regulator, an insurer or a customer, and what you have today. The reply says which of these services would answer it. See also all security services.

Discuss a scope

Risk and governance services

Each page below says what the work is, what it produces, and what it does not cover.

Tools and programmes

NIST CSF 2.0 programme

Current and target profiles, a gap assessment, a roadmap and a reporting cadence, built on NIST CSF 2.0 or aligned to COBIT.

Vendor risk programme

A standing third-party risk programme: know every vendor, tier them by what they can reach, check each in proportion, and close access when they go.

GRC platform selection

Choosing and standing up a governance, risk and compliance platform, or a simpler build, with no stake in which vendor wins.

Measure and report

Risk register and KRIs

A cyber risk register with real owners, KRIs with thresholds and data sources, and a one-page board and executive view built from both.

Business impact analysis

Critical processes, their dependencies, and how long each can be down. The recovery targets that drive backup, disaster recovery and continuity decisions.

ERM and cyber insurance readiness

Cyber risk tied into enterprise risk management, a clear line between what you retain and what you insure, and an application an underwriter can rely on.