article thumbnail

How a Federal Ban on Ransomware Payments Could Help CISOs

Harvard Business Review

The ban would would elevate the cybersecurity conversation to the CEO, the CFO, and the board, and potentially end the practice of scapegoating CISOs when a breach happens. The White House is considering a ban on ransomware payments, which could change the chief information and security officer (CISO) job.

CFO 19
article thumbnail

"I'd Like My Life Back" -- a lesson for CEOs in building an organization that listens to warnings

Great Leadership By Dan

Here are seven critical elements of an effective program to both identify and act on warning signs: High-level oversight – does your company have an organizational structure led by senior management that oversees issues such as compliance, quality and safety, while being able to respond quickly and appropriately to credible warnings?

CEO 240
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Social Media Compliance Isn't Fun, But It's Necessary

Harvard Business Review

The risks and penalties are real. Just ask Gene Morphis, ex-CFO of clothing retailer Francesca's. Once a policy is in place, training is critical. These hurdles aren't unique to financial services — insurance, pharmaceuticals, health care and government all face regulation, to name a few examples.

article thumbnail

Case Study: Is Holacracy for Us?

Harvard Business Review

Listening, Derek Melis, his friend and CFO, was relieved. Rogier hadn’t once mentioned holacracy or self-managed teams, even though the executive team and the board had been talking for months about transitioning to just such a system at the global construction company. Please don’t let that cloud your judgment as CFO.

article thumbnail

To Guard Against Cybercrime, Follow the Money

Harvard Business Review

A cybercriminal might impersonate a CFO or CEO, and then send an email to accounts payable asking for a wire transfer, or to HR requesting a dump of employee tax information. With the right technology, training, and business processes, you can strengthen your cyber resilience. Security is a business problem more than an IT problem.