Let’s talk about cyber-security risks. After all, everyone else is.

The Securities and Exchange Commission talked about the issue for five hours last week, at its much-anticipated cyber-security roundtable. The Center for Audit Quality published guidance on cyber-security risks one day before the SEC’s confab, diplomatically but firmly stating that external auditors are not responsible for testing a company’s IT controls beyond those relevant to financial reporting. And earlier this year the National Institute of Standards and Technology published a basic framework for managing cyber-security risks.