Role of Boards in Cybersecurity Risk Profiling: The Case of Bangladeshi Commercial Banks
Keywords:
cyber security, cyber risk, board governance, enterprise risk management, risk profile,
Abstract
Cybercrime becomes costlier than physical crime in developed economies. As a result, it has become the top priority in governance issues in financial institutions. As a developing nation in Bangladesh, the banking sector faces multi-dimensional challenges to adopt IT applications in banking with cybercrime. The paper examines what the banking industry faces cyber security risks and how the board members contribute to identify and mitigate the risk. Through an in-depth interview among the directors of commercial banks in Bangladesh, we identified the possible cyber risk and prepared the risk profile describing the sources, implications, severity of impact, likelihood of occurrence and ranked them. The result shows that the IT governance risk, IT investment risk, and information risk are most critical among the significant cyber security risks. The results of the study have important implications for both corporate boards and policymakers.
Downloads
- Article PDF
- TEI XML Kaleidoscope (download in zip)* (Beta by AI)
- Lens* NISO JATS XML (Beta by AI)
- HTML Kaleidoscope* (Beta by AI)
- DBK XML Kaleidoscope (download in zip)* (Beta by AI)
- LaTeX pdf Kaleidoscope* (Beta by AI)
- EPUB Kaleidoscope* (Beta by AI)
- MD Kaleidoscope* (Beta by AI)
- FO Kaleidoscope* (Beta by AI)
- BIB Kaleidoscope* (Beta by AI)
- LaTeX Kaleidoscope* (Beta by AI)
How to Cite
References
A Al-Hadi, M Hasan, A Habib (2016) Risk committee, firm life cycle, and market risk disclosures. 24(2), 145-170.
Christian Biener, Martin Eling, Jan Wirfs (2015) Insurability of Cyber Risk: An Empirical Analysis. 40(1), 131-158.
Rainer Böhme, Gaurav Kataria (2006) On the Limits of Cyber-Insurance. 2, 31-40.
J Cebula, L Young (2010) A taxonomy of operational cyber security risks.
Catherine Daily, Dan Dalton, Albert Cannella (2003) Corporate Governance: Decades of Dialogue and Data. 28(3), 371.
J Danielsson, M Fouche, R Macrae (2016) Cyber risk as systemic risk.
M Eling, J Wirfs (2016) Cyber risk: too big to insure? Risk transfer options for a mercurial risk class.
Dean Dwonczyk (2010) Enterprise Risk Management: Today's Leading Research and Best Practices for Tomorrow's Executives, John Fraser, Betty J. Simkins, John Wiley & Sons, 2010, 577pp. (hardback), £70.00. ISBN: 978-0-470-49908-5. 7(1), 149-150.
M Greisiger, I Allclear, F Ireland, P Cox (2013) https://inass.org/wp-content/uploads/2022/05/2022083131-2.pdf. 15(4).
Edward Humphreys (2008) Information security management standards: Compliance, governance and risk management. 13(4), 247-255.
Wolfgang Kröger (2008) Critical infrastructures at risk: A need for a new conceptual approach and extended analytical tools. 93(12), 1781-1787.
(2016) The Handbook of Board Governance.
J Lewis, S Baker (2013) The economic impact of cybercrime and cyber espionage.
Alessandro Minichilli, Alessandro Zattoni, Fabio Zona (2009) Making Boards Effective: An Empirical Examination of Board Task Performance. 20(1), 55-74.
Arunabha Mukhopadhyay, Samir Chatterjee, Debashis Saha, Ambuj Mahanti, Samir Sadhukhan (2013) Cyber-risk decision models: To insure IT or not?. 56, 11-26.
Hulisi Öğüt, Srinivasan Raghunathan, Nirup Menon (2011) Cyber Security Risk Management: Public Policy Implications of Correlated Risk, Imperfect Ability to Prove Loss, and Observability of Self‐Protection. 31(3), 497-512.
Michael Parent, Balize Reich (2009) Governing Information Technology Risk. 51(3), 134-152.
Andrew Pettigrew (1992) On studying managerial elites. 13(S2), 163-182.
(2013) Managing Cyber Security as a Business Risk: Cyber Insurance in the Digital Age.
L Ponemon (2013) Cost of data breach study: Global analysis. 205-207.
Shaun Posthumus, Rossouw Von Solms (2004) A framework for the governance of information security. 23(8), 638-646.
A Raghavan, L Parthiban (2014) The effect of cybercrime on a Bank's finances. 2(2), 173-178.
Ortwin Renn, Katherine Walker (2008) Lessons Learned: A Re-Assessment of the IRGC Framework on Risk Governance. 331-367.
A Riem (2001) Cybercrimes of the 21st Century. 12-15.
Maurizio Sajeva, Marcelo Masera (2006) A strategic approach to risk governance of critical infrastructures. 2(4), 379.
S Shackelford (2012) Should your firm invest in cyber risk insurance?. 55(4), 349-356.
Carol Siegel, Ty Sagalow, Paul Serritella (2002) Cyber-Risk Management: Technical and Insurance Controls for Enterprise-Level Security. 11(4), 33-49.
Chris Skelcher (2005) Jurisdictional Integrity, Polycentrism, and the Design of Democratic Governance. 18(1), 89-110.
K Smith, M Smith, J Smith (2011) Marketing and Finance.
J Straight (2015) The Role of the Board in Cybersecurity: 'Learn, Ensure, Inspect', Dark Reading.
Roger Tourangeau, Lance Rips, Kenneth Rasinski (2000) The Psychology of Survey Response.
Marjolein Van Asselt, Ortwin Renn (2011) Risk governance. 14(4), 431-449.
Andrew Whitman (2015) Is ERM Legally Required? Yes for Financial and Governmental Institutions, No for Private Enterprises. 18(2), 161-197.
G Wilshusen (2010) Iraq and Afghanistan : agencies face challenges in tracking contracts, grants, cooperative agreements, and associated personnel : testimony before the Subcommittee on oversight and investigations, Committee on Armed Services, House of Representatives / John P. Hutton..
Published
2021-04-05
Issue
Section
License
Copyright (c) 2021 Authors and Global Journals Private Limited

This work is licensed under a Creative Commons Attribution 4.0 International License.