CEO's pay should be linked to security performance, says government committee

New report recommends that CEOs be held directly accountable for data breaches

CEOs' compensation - including salary, bonuses and stock options - should be linked to their companies' cyber security performance, according to a new report from the Culture, Media and Sport committee.

The report comes after an inquiry into cyber security and data breaches, which was initiated following last year's massive TalkTalk hack.

As part of the committee's recommendations, it suggested a laundry list of requirements for companies to minimise and respond to data breaches.

This included general company-wide policies, such as reporting cyber security and data protection strategies to the Information Comissioner's Office (ICO), as well as including cyber security in their annual bottom-line reporting alongside social and environmental reporting.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

However, the recommendations also included measures designed to make CEOs and IT decision makers more accountable in the wake of data breaches, as well as recommending that those who trade in stolen personal data should be sentenced to up to two years in jail.

The report advised that while CEOs should lead crisis response in the wake of a breach, full responsibility a breach should reside with whoever handles it day-to-day, who can be "fully sanctioned" if the company has not adequately protected itself.

It also recommended that CEOs' financial earnings be directly linked to their companies' security, "to ensure this issue receives sufficient CEO attention".

"Today's report by the Culture, Media and Sport Committee highlights the importance of good cyber-security practices for businesses of all sizes that have an online presence or service," said Talal Rajab, techUK's head of cyber and national security.

"To maintain user confidence in digital services, and the growth of the UK's digital economy, companies must have appropriate cyber-security policies and processes in place."

In addition to penalties for not preventing breaches, the report also advocated that the ICO should institute a series of escalating fines for companies that fail to disclose data breaches.

Advertisement - Article continues below

It was also noted that the ICO's current maximum fine of 500,000 "may not be a significant deterrent" for larger organisations. However, this is set to change anyway once the European General Data Protection Regulation comes into force in 2018.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/business-strategy/chief-information-officer-cio/354564/cios-are-taking-their-seat-at-the-boardroom
chief information officer (CIO)

CIOs are taking their seat at the boardroom table

17 Jan 2020
Visit/strategy/28223/cio-job-description-what-does-a-cio-do
Business strategy

CIO job description: What does a CIO do?

7 Jan 2020
Visit/careers/28219/it-manager-job-description-what-does-an-it-manager-do
Careers & training

IT manager job description: What does an IT manager do?

28 Oct 2019
Visit/security/ddos/28039/how-to-protect-against-a-ddos-attack
Security

How to protect against a DDoS attack

25 Oct 2019

Most Popular

Visit/business-strategy/public-sector/354608/uk-gov-launches-ps300000-sen-edtech-initiative
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/business-strategy/mergers-and-acquisitions/354602/xerox-to-nominate-directors-to-hps-board-reports
mergers and acquisitions

Xerox to nominate directors to HP's board – reports

22 Jan 2020
Visit/network-internet/web-browser/354614/microsoft-developer-declares-its-time-to-ditch-ie-for-edge
web browser

Microsoft developer declares it's time to ditch IE for Edge

23 Jan 2020