Even in the smallest organizations, a single person is not sufficient to properly perform all IT and cybersecurity-related tasks. In business environments, cybersecurity is as much a social responsibility as it is a technical one. Diverse perspectives and ideas need to be heard and combined to determine the best course of action regarding cybersecurity measures. Therefore, one of the most important steps in implementing a comprehensive cybersecurity program is assembling a Steering Committee to oversee the implementation of the program's components.

The goal of a Steering Committee is to bring together a diverse group of stakeholders to provide perspectives and make decisions regarding what is best for the organization's cybersecurity while ensuring alignment with key business objectives. The committee should meet on a schedule deemed appropriate for the organization. An organization with fewer than five employees and only a handful of systems may only need to meet bi-monthly, whereas an organization with ten or more employees and systems may benefit from meeting monthly or even bi-weekly.

When building your organization's Steering Committee, ensure that stakeholders are selected from all areas where digital resources are used. Consider including managerial personnel from each business department, as they are often well-versed in the unique cybersecurity concerns associated with their areas of operation. However, the committee should not be limited to managers and administrators alone. It can be equally beneficial to appoint one or two frontline employees, as they are often the individuals interacting with the organization's technology on a daily basis.

A key objective when assembling the committee should be to make it as representative as possible. This helps ensure that cybersecurity best practices can be effectively implemented and communicated throughout the organization, from executive leadership to frontline staff.

You will also need to designate a single individual as the chair of the Steering Committee. In the context of a small business, this will often be the owner. However, it does not have to be. If there is an individual within the organization who possesses advanced information technology knowledge and strong communication skills, they may be a suitable choice to serve as chair.

The committee chair is responsible for using cybersecurity-related information, data, and insights to guide discussions and keep meetings focused and productive. Another committee member should serve as the scribe, maintaining meeting minutes and distributing summaries to committee members for future reference.

Depending on the size of the organization, the committee may consist of anywhere from three to six members. It is important to ensure that the committee is not limited solely to internal employees. To help keep the organization aligned with business objectives and industry best practices, appropriate external contractors and consultants should also be considered.

Many small businesses choose to outsource their information technology management to a third party. An effective cybersecurity Steering Committee requires subject matter experts (SMEs) to function properly, making third-party IT consultants valuable additions when applicable. An accountant or financial advisor may also be appropriate to include, as they can provide insight into budgeting considerations and help determine the financial feasibility of proposed cybersecurity initiatives.

Once the Steering Committee has been assembled, ensure that the established meeting schedule is followed and that all documentation is properly maintained and stored. In the event of a major cybersecurity incident or organizational crisis, emergency meetings may be necessary.

Topics involving cybersecurity policies, operations, incidents, concerns, recommendations, and disagreements should be reviewed by the Steering Committee. The committee should also collaborate on drafting and reviewing the organization's cybersecurity policies, which will be discussed later in this framework.

Example

A small Main Street café could assemble a cybersecurity Steering Committee consisting of the business owner, the baristas responsible for operating the Point-of-Sale (POS) systems, the outsourced accountant, and the outsourced IT technician.

The baristas may raise concerns regarding the lack of physical security surrounding the POS systems. The accountant might identify risks associated with the transportation and handling of documents containing sensitive financial information between the café and the accounting firm. The IT technician could provide insight into technical controls that could mitigate these issues.

The business owner would then be responsible for evaluating the recommendations, determining their financial feasibility, and making executive decisions regarding implementation. Through collaboration, the committee can identify cybersecurity concerns from multiple perspectives and develop practical solutions that align with both security requirements and business objectives.