APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

  • Home
Editor's Pick (1 - 4 of 8)
left
Welcoming Big Data Technology amidst Changes

Darren Cockrel, CIO, Coyote Logistics

Leveraging Compliance to Your Advantage

Mark Bloom, Global CIO, Aegon

Demystifying the Role of IT in Millennial Organizations

Jeff Fithian, VP, Strategic Initiatives and CIO, Dynamic Materials Corporation

Productivity and Security- Can you ever have both?

Julie Cullivan, SVP, Business Operations & CIO, Fireeye

Lessons Learned from a CIO

John Miller, Vice President and CIO, American Textile Company

New Hr Capabilities To Face Evolving Technologies

Anti Deisnasari, Director Of Compliance, Seabank Indonesia

Strengthening The Compliance Fortress In The Banking Sector

Chuan Lim Ang, Managing Director And Sg Head Of Compliance, Cimb

Navigating Legal Challenges By Adapting To Technological Shifts

Valerie Feria Amante, Chief Legal, Ethics & Compliance Officer, Jollibee Group Of Companies

right

The Building Blocks of Cyber Security Compliance

Sasha Kalb, Vice President, Risk and Compliance, Asia Pacific, American Express Global Business Travel

Tweet
content-image

Sasha Kalb, Vice President, Risk and Compliance, Asia Pacific, American Express Global Business Travel

In the increasingly complex environment of regulatory enforcement, it is crucial that organizations today are Compliance-aware. Corruption and bribery, data privacy, extensive use of third parties, and employee duty of care, are all areas that must be the focus of any comprehensive Compliance program. Increasingly, cyber security must be added to this list. Cyber attacks are becoming more common and sophisticated. When such attacks occur, the damage to an organization can be overwhelming, highly publicized and immediate.

While many people are hesitant to discuss cyber security due to its heavily technical nature, the theory behind building a cyber security program is the same as any Compliance discipline. Of course, there is a highly specialized element, for which information technology expertise is required; however the organizational elements that support this are consistent with a basic Compliance risk management program. Such elements include:

Training

Many cyber security incidents are caused by individuals falling victim to phishing or social engineering scams.

It is critical that employees are trained to be security aware. Cyber security training should be added to a regular training roster, alongside other disciplines, such as sanctions and anti-corruption.

Testing

Testing employees’ knowledge is important for gauging true awareness. Within my organisation, we run phishing tests designed to train our employees. This is done through highly tailored e-mails that are designed to look legitimate, but are actually false phishing attempts. Any employee who falls victim to the tests is required to take additional training.

Ad hoc communications

Never waste an opportunity to use a good crisis. Take advantage of events in the news media to raise awareness and train employees.

Physical security

Remember that cyber security is reliant on both information technology and physical security. Are your offices secure? Do your company’s computers auto-lock after a period of inactivity? These are important considerations.

Incident response

When there is an allegation, or confirmed incident, the corporate response should be the same as for any compliance incident – it is crucial to follow company procedure exactly. Companies should mobilize their incident response and investigation teams, and react with appropriate speed and resources.

Following the recent cyber attack on Yahoo!, the Yahoo Board investigation noted that the company’s failures in areas such as communication, management, and internal reporting resulted in a lack of proper handling of the breach. These failures contributed to the flow of negative news, shareholder lawsuits, resulting in a drop in sale price, and losses in personnel.

As with any other risk area, a strong Compliance program is the best way to protect an organization from the effects of a cyber breach. A truly comprehensive program should include elements of policy, training and communication to help prevent an occurrence; testing and monitoring to help detect a potential breach; and processes around investigation and remediation, as a best-practice response should a breach occur.

tag

Information Technology

Physical Security

cyber attack

Weekly Brief

loading
Top 10 Compliance Solutions Providers in APAC - 2025
Featured Issue

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://www.apacciooutlook.com/views/the-building-blocks-of-cyber-security-compliance-nwid-4399.html