← Insights
What boards should actually ask about cybersecurity.
Board cyber reports are often full of charts and short on answers. Five questions that get to the truth.
Most board cybersecurity updates show counts of blocked attacks, patch percentages, and a heat map. None of it tells directors whether the company is prepared. Better questions do.
Five questions for your next meeting
- What are our three most likely ways to be seriously harmed, and what are we doing about each? Expect specific answers, such as ransomware, a vendor breach, or payment fraud, not a list of tools.
- When did we last test our incident response plan, and what failed? A plan that has never been rehearsed is a document, not a capability.
- Could we restore our critical systems from backup, and how long would it take? Ask when that was last proven.
- Which vendors could hurt us most if they were breached? Third-party risk is now one of the most common causes of major incidents.
- Which framework do we measure ourselves against, and where are the gaps? NIST and ISO 27001 give directors a consistent yardstick from year to year.
What a good answer sounds like
A good answer is plain, specific, and honest about gaps. It names an owner and a date. If your board hears only reassurance, it is time for an independent view.