Have you been having trouble getting your board of directors to care about information security? This weekend\u2019s news that NASDAQ\u2019s Directors Desk web application was compromised\u00a0by hackers may help to improve your situation.Details have been elusive thus far, but reports indicate that multiple breaches occurred, resulting in \u201csuspicious files\u201d on the company\u2019s servers. A statement released by NASDAQ\u00a0assures us that its trading systems and customer data were not compromised, and those in the know tend to agree that infiltrating the trading systems would be substantially more difficult\u00a0than breaking into the web environment and leaving a few files behind. As the investigation continues, hopefully we'll learn more,\u00a0but what can we take away from this story so far? The list of attractive hacker targets continues to grow. Whoever perpetrated this breach chose not to go after traditionally lucrative targets like customer\/employee data or a more difficult and devastating attempt to dismantle one of the world\u2019s biggest exchanges. Instead the target was a more accessible set of extremely sensitive corporate data\u00a0\u2013 details about mergers, acquisitions, dividends, and earnings. Without much sophistication, criminals could use this information to execute rather impressive \u201cinsider trading\u201d transactions or simply find an outlet like Wikileaks for some of the more embarrassing tidbits. Normal monitoring should have caught this breach sooner. A federal official told the Associated Press\u00a0that the attacks took place over the course of a year, while NASDAQ\u2019s statement said the files were found through the company\u2019s \u201cnormal monitoring systems.\u201d It would appear that the monitoring functions were not as frequent or effective as they should have been. The government will get even more involved\u00a0if there\u2019s a perceived lack of control. While we still don\u2019t know if hackers gained any useful information from this attack, the potential implications touched many of today\u2019s most buzz-worthy topics... investor confidence, corporate oversight, and financial market stability. Legislators on both sides of the house were quick to press NASDAQ and other exchanges, as well as regulators, for more information about what\u2019s being done \u201cto ensure the ongoing integrity and security of exchange trading systems and clearinghouses.\u201d If they don't like the answers, expect more rules and oversight to follow. It\u2019s a good time for a heart-to-heart with your board about security. You don\u2019t have to build an horrific awareness campaign about the hackers lurking around every corner... but it\u2019s important for the board of directors to know that their mobile devices, email accounts, and online communications may very likely be a target of attack. Directors and top executives who often expect policy exceptions should understand the potential risks those exceptions expose. Also, it wouldn\u2019t hurt to look into the way your board members communicate to make sure top-level secrets are appropriately protected. Chris McClean is an analyst at Forrester Research.