ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Directors Briefing

Directors Briefing: Cyber expertise needs a home on bank boards

'A director with cybersecurity expertise on a board is a high-return, low-effort action that materially strengthens the boardroom.'

July 8, 2024
Reading Time: 2 mins read
Leveraging Crowdsourced Security to Defend Against Rising Threats

Board expertise evolves with the times. Just consider that two decades ago, financial experts on corporate boards were a rarity. Today every public company board has designated at least one financial expert, because the Sarbanes-Oxley Act mandates it.

This article is from the July-August 2024 edition of ABA Banking Journal Directors Briefing. Subscribe here.
Bob Zukis, CEO of the Digital Directors Network, says the same evolution needs to happen with cyber experts. Recent survey data indicates only 12 percent of the S&P 500 boards currently have a member who is a cyber expert, but the number should be 100 percent, he says.

The Securities and Exchange Commission decided otherwise in 2023, when it dropped a proposal to require public companies to disclose which, if any, of their board directors had significant knowledge of or experience in cybersecurity. The National Association of Corporate Directors applauded that move, calling it unduly prescriptive.

But Zukis calls the decision “a mistake.” Whether they’re required to disclose it or not, bringing cyber expertise onto the board is particularly important for financial services companies, he adds, because “the sector is one big, highly connected information system.”

A recent ABA Banking Journal article identified third-party risks, AI-enabled phishing and ransomware—seizing an organization’s data and finances—as some of the rising cyber threats facing banks. The article noted that more than 800,000 cybercrimes were reported in the U.S. in 2022.

Banks have recognized for years the need to increase their board technology expertise, and they’re doing it. Bank Director’s 2023 technology survey found that 51 percent of participants said their board has at least one member they would consider to be a technology expert. Among those who did not, 38 percent said they were actively seeking a director with technology expertise.

But being knowledgeable about the broad domain of technology is not the same as being well-versed in cybersecurity, which is a specialized and rapidly evolving discipline. Large companies, Zukis notes, are recognizing this, and some are creating technology and cyber committees with directors who can understand the upside of IT and how to protect the downsides.

“Having a director with cybersecurity expertise on a board is a high-return, low-effort action that materially strengthens the boardroom as a control in the cybersecurity system,” Zukis says.

Where cybersecurity oversight doesn’t belong, Zukis declares, is the audit committee—which is where it often ends up: “Audit is the kitchen junk drawer of corporate governance. Don’t know where to put it? Throw it in there. We think that’s a leading bad practice, because there’s a skills and scope misalignment.” Audit’s focus is financial, and cybersecurity probably can’t get the attention it needs there.

Of course, it’s relatively uncommon for small banks to even have a board technology committee. Directors Briefing’s admittedly unscientific review of bank committee structures finds board technology committees start to crop once banking companies cross the $10 billion asset threshold.

Zukis says the risk committee is a good place for smaller banks to place oversight of cybersecurity. And he urges them to keep looking for cyber experts.

“Something on the order of 60 percent of global GDP is derived through digital systems,” Zukis says. “We don’t have a choice but to govern and understand these issues.”

Zukis leads Digital Directors Network, an organization for IT, cybersecurity and boardroom leaders he formed seven years ago to advance the practice and profession of digital and cybersecurity oversight.

Tags: Community bankingCyber crimeCybersecurityDirectors
ShareTweetPin

Related Posts

CFPB urges states to ban ‘junk fees,’ revamp consumer protection laws

Government holiday closures will not change compliance timelines

Compliance and Risk
December 19, 2025

President Trump’s recent executive order closing federal government agencies on Dec. 24 and 26 does not affect the timing requirements in regulations with requirements based on business days, such as Regulation Z (TRID and right of rescission), Regulation...

Banking agencies: Shared National Credit quality remains moderate

OCC: Financial system sound, cybersecurity threats persist

Compliance and Risk
December 19, 2025

OCC report said that “a recent firewall access incident” should serve as a warning to banks about managing risks to aging infrastructure and end of life of IT assets.

Report: Biden administration to ease federal marijuana restrictions

Trump directs agencies to ease federal marijuana restrictions

Compliance and Risk
December 18, 2025

President Trump ordered federal agencies to quickly implement an existing proposal to reclassify marijuana to expand the availability of cannabis for medicinal purposes.

CFPB issues decision on TILA preemption of state laws

OCC, FDIC issue clarification on lending to bank insiders

Commercial Lending
December 18, 2025

The OCC and FDIC said they will not take action against banks for extensions of credit to complex-controlled portfolio companies that otherwise would violate the Federal Reserve’s restrictions on lending to bank insiders, provided banks satisfy certain conditions.

FOMC minutes: Persistent inflation clouds path forward

Fed publishes staff manual for supervision of large banks

Compliance and Risk
December 18, 2025

As part of a new push to increase transparency, the Federal Reserve made public the first of several staff manuals on the supervision of the largest banks.

ABA, 52 state bankers associations urge Congress to close stablecoin interest loophole

ABA, 52 state bankers associations urge Congress to close stablecoin interest loophole

Compliance and Risk
December 18, 2025

ABA joined 52 state bankers associations in sending a joint letter to Congress urging lawmakers to clarify and enforce the statutory prohibition on payment stablecoin issuers and affiliated platforms offering yield, rewards or interest to stablecoin holders because...

NEWSBYTES

Government holiday closures will not change compliance timelines

December 19, 2025

Consumer sentiment rises in December, down from last year

December 19, 2025

Existing home sales increased in November

December 19, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: Cybersecurity in a mobile-first banking landscape

December 18, 2025

Podcast: The 2026 outlook for bank M&A

December 11, 2025

Podcast: The outlook for tech-forward community banking

December 4, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.