Step 1: The management’s toolbox An effective cyber defence is anchored in top management. In essence, it is about the top management overseeing cyber and information security on equal footing with areas such as finance, HR, development and research. Similarly, the handling of personal information has become an area that requires top management oversight. Even the very best intentions regarding an effective cyber defence will fail without anchoring at the top management level. It is important for a leader to understand the cyber threat. It is equally important to realize that this threat is an underlying condition for all Danish organizations. The top management must take ownership of the organization’s cyber and information security objectives and strategies. The policies, procedures and guidelines used to manage cyber and information security within the entire organization must reflect these objectives and strategies. The top management must prioritize the establishment of repeatable processes designed to support the organization’s cyber and information security strategy. Without established and documented processes, there is a risk of handling cyber and information security risks on an ad hoc basis with an over dependency on few key personnel. The top management must ensure that the established processes are regularly controlled and improved in order to ensure their efficiency. When organizations develop and implement new infrastructure, systems and applications. There is an also a particularly important juncture in which to improve cyber and information security; that is The top management must ensure a formal process for factoring cyber and information security considerations from the start of new projects. In general, the top management must prioritize and oversee cyber and information security across the organization. In this context, it is important for the top management to ensure that the right skills are available either on premise or off premise, in the form of external consultants or advisers. The formulation of objectives and strategies, prioritization of resources, establishment of repeatable processes, and regular follow-ups are the management’s most important tools when overseeing cyber and information security. We recommend that the top management asks itself eight questions and asks its organization sixteen questions. The answers to these questions will give the top management an idea of how the organization works with cyber and information security. 4

Select target paragraph3