Skip to content

CyberGov

The Cybersecurity and Privacy Governance Committee (CyberGov) is a recurring governance meeting that connects executive stakeholders with the organization’s cybersecurity risk posture. Adversarial supports CyberGov by generating the charter, populating meeting content from your risk register, and generating the governance report.

The CyberGov Charter is generated from the Compliance module. Distribute the charter as a pre-read before the initial meeting so participants understand the committee’s purpose and scope before the first session. Many organizations schedule CyberGov meetings approximately two weeks before a Board meeting to review the latest information and prepare any items requiring Board communication.

For details on generating and customizing the charter, see the charter entry in Program Documentation.

The first CyberGov meeting should be longer than subsequent sessions. Devote the extra time to:

  1. Introducing the Threat Profile — Walk through the six Threat Objectives, using examples from well-known news stories to make each objective concrete.
  2. Explaining the scoring rationale — Present the current likelihood and impact scores in an open, inviting manner. Encourage discussion and questions about why objectives are scored the way they are.

The charter can serve as the meeting’s pre-read, setting expectations for what will be covered.

After the initial meeting, CyberGov should meet quarterly. Target 60 minutes per session. The recurring agenda draws from the latest risk register data, incident summaries, and threat profile changes.

CyberGov meetings are supported by a configurable report generated from the Compliance module. Choose a reporting period, the risk urgencies and incident severities to include, and whether to include the full Risks and Incidents tables — see Governance Reports. Use the generated report as the basis for each quarterly meeting’s discussion.