Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Board Question Bank & Preparation Brief

Prepares the reporter for the questions a board will actually ask, including the uncomfortable ones, with guidance on answering honestly.

Available soon

Format
Word
Size
63 KB
Length
18 pages
Version
1.0
Updated

What's inside

  • Purpose and audience
  • The preparation brief
  • Required inputs with owners
  • The question bank
  • Capturing questions, decisions and commitments
  • Follow-up template
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose and audience

This brief prepares the reporter — [[e.g. Head of Information Security or CISO]] — for the questions a [[e.g. Board, or its Audit & Risk Committee]] will ask about cyber risk, including the uncomfortable ones, and for answering them honestly. It has two parts: a preparation brief for the days before the meeting, and a question bank grouped by theme.

It is used with the report written to the Board Reporting Narrative Model. The report says where the organisation stands; this brief prepares the reporter for what the board will ask once it has read it. The executive sponsor, [[e.g. Chief Operating Officer or CFO]], uses it for the rehearsal.

Guidance — delete before approval

Keep your own copy of the question bank. After every meeting, add the questions the board actually asked, with the answer that worked, and remove any that no longer apply. Within a year it will be more useful than this template.

The reporting cycle (Board & Executive Reporting Calendar) puts the rehearsal 7 working days before the meeting. Leave room to change the report afterwards: papers go to the board secretary 5 working days before it.

The preparation brief

The days before the meeting

The last steps of the reporting cycle, counted in working days from the board meeting (day 0). The Board & Executive Reporting Calendar holds the full cycle; the adopter's own board calendar overrides these defaults.

When

Step

Who

9 working days before

Executive sponsor review

Executive sponsor

7 working days before

Question bank rehearsal

Reporter and executive sponsor

5 working days before

Papers submitted to the board secretary

Reporter

Meeting day

Board meeting

Board

3 working days after

Actions and decisions recorded (BR-09)

Board secretary with reporter

What to do each day

When

Preparation

9 working days before

The executive sponsor reads the draft report and the one-page summary. Ask them to mark every sentence they would challenge if they were a director: those become rehearsal questions.

Between 9 and 7 working days before

Pick the questions for the rehearsal: the [[ten]] most likely from the bank below, every question marked uncomfortable that applies, and any question the board asked last time that the report still does not answer. Check the news and sector alerts for breaches the board may have read about (BQ-04).

7 working days before

Rehearsal (see below). Afterwards, correct the report where the rehearsal found a gap. A question you could not answer in rehearsal is a sign the report is missing something.

Between 7 and 5 working days before

Finalise the report. Prepare the 'have ready' material for the likeliest questions as a short appendix or as notes you carry, not as extra slides.

5 working days before

Papers to the board secretary. From here, no figure changes without telling the chair (BR-08).

The day before

Brief the executive sponsor on anything that has changed since the papers went out. Read the last meeting's minutes and action log (BR-09).

Meeting day

Open with the position (BR-02). Answer questions using the principles below. Note every commitment you make.

3 working days after

Agree the record of decisions and actions with the board secretary; send any promised answers by the date you gave.

The rehearsal

The rehearsal is a step of its own in the reporting cycle (7 working days before the meeting; reporter and executive sponsor). It is the step most often skipped and the one that most improves the meeting.

  1. Book [[60 to 90]] minutes with the executive sponsor, and if possible one person who thinks like a director: [[the company secretary, a non-executive, the CFO]].
  2. Present the report as you will in the meeting, in the time you will have — usually [[10 to 15]] minutes. Stop at the time limit, wherever you are.
  3. Take the questions. The sponsor asks the chosen questions, in no set order, as a sceptical director would. At least [[three]] should be uncomfortable ones.
  4. Answer each in about [[one]] minute. The first sentence should answer the question; the rest supports it.
  5. Record each gap: a question you could not answer, answered with a guess, or answered with technical detail. Fix the report or prepare the answer before papers go out.
  6. Agree who answers what. Some questions belong to the sponsor, to finance or to legal. Decide in advance who takes them.

Guidance — delete before approval

If there is no one to rehearse with, record yourself answering the questions and listen back. It is less comfortable, and nearly as useful.

Answering honestly

The board will judge the organisation's security partly by whether it trusts the person reporting it. Trust is built by accurate answers, not confident ones.

  1. Answer the question asked, first. One sentence that answers it — yes, no, a number, a position — then the reason.
  2. Say what you do not know. 'I don't know' is a complete and acceptable answer when followed by what you would need to find out, and when.
  3. Never guess a number. A figure said in the meeting goes in the minutes and outlives the meeting. Say 'I will confirm the exact figure by [[date]]'.
  4. Offer to come back by a date — and do it. Give a date, normally within [[5]] working days. Record it as an action (BR-09) and send the answer using the follow-up template in this brief.
  5. Label facts, estimates and opinions. 'The figure is…', 'We estimate…', 'My view is…'. A director should never mistake one for another.
  6. Do not reassure beyond the evidence. Avoid 'we are fully protected', 'it could not happen here', 'we are compliant' without qualification.
  7. Bad news first. If a question touches something that has gone wrong, say so at once rather than letting it emerge (BR-07).
  8. Stay in business terms. If a director asks a technical question, answer briefly and offer detail outside the meeting (BR-05).
  9. Correct with evidence, not defence. If a director has a fact wrong, say what the figure is and where it comes from. If they are right and you are wrong, say so.
  10. Hand over when it is not yours. Legal, financial and personnel questions may belong to someone else in the room. Say who, and let them answer.

Phrases that help:

Instead of

Say

"I think it's around 80%, roughly."

"I don't have the exact figure with me. I'll send it to the secretary by Friday."

"We're fully protected against that."

"We have [[control]] in place and tested it in [[month]]. It reduces the risk; it doesn't remove it."

"That's quite technical, but basically…" (five minutes)

"In short: [[one sentence]]. I'm happy to go through the detail with anyone after the meeting."

"Yes, we're compliant."

"We meet [[n]] of [[N]] requirements. The gaps are [[x]], due by [[date]]."

"I'd rather not speculate."

"My judgement is [[view]], but that is an opinion, not a finding. I'll confirm it by [[date]]."

Required inputs with owners

What the reporter brings, or has to hand, at the meeting. Everything with a figure comes from the signed-off Board Reporting Data Collection Workbook (BR-08).

Input

Supports questions

Owner

The report and the Cyber Risk One-Page Board Summary

All

Reporter

The signed-off Board Reporting Data Collection Workbook

Any question about a figure

Reporter with risk function

The risk appetite statement and the top-risk extract from the risk register (BM-01)

BQ-01 to BQ-03

Risk function

The incident log for the period, and the status of incident actions (BM-04)

BQ-04 to BQ-06

Data owners [[e.g. IT operations, risk, procurement, HR]]

A note on any major breach in the sector or supply chain since the last meeting

BQ-04

Reporter

The critical-supplier list and assessment status (BM-05)

BQ-07, BQ-08

[[Procurement]]

Recovery test records (BM-06) and the board's escalation points in the incident response plan

BQ-09 to BQ-11

[[IT operations]]

Programme plan and spend against budget (BM-07); a ranked, costed list of next items

BQ-12 to BQ-14

Reporter with [[finance]]

Applicable regulation and status; any legal advice on directors' duties

BQ-15 to BQ-17

[[Legal or compliance]]

Board and staff training records (BM-08)

BQ-18, BQ-19

[[HR]] and board secretary

The last meeting's minutes and action log (BR-09)

Any follow-up question

Board secretary

The question bank

26 questions boards ask about cyber risk, grouped by theme. Each has a stable ID for rehearsals, and four notes: why a board asks it, what a good answer contains, what to have ready, and the trap to avoid. Questions marked uncomfortable are those reporters most often answer badly; rehearse every one that applies to you.

The uncomfortable questions at a glance:

ID

Question

Theme

BQ-03

Why is this risk still outside appetite after [[two]] reports?

Appetite and exposure

BQ-04

Could this happen to us? (after a breach in the news)

Incidents

BQ-05

Have we been breached? How would we know?

Incidents

BQ-08

If our main IT or cloud provider went down for a week, what would happen?

Third parties

BQ-09

If ransomware hit us tomorrow, how long until we are trading again?

Resilience and recovery

BQ-10

Would we pay a ransom?

Resilience and recovery

BQ-13

What would you do with more money?

Investment and value

BQ-15

Are we compliant?

Regulation and personal liability

BQ-17

Could I be personally liable?

Regulation and personal liability

BQ-18

Is the board itself trained?

Regulation and personal liability

BQ-21

We are not interesting to attackers, are we?

Are we a target?

BQ-25

What keeps you awake at night?

Open questions

Guidance — delete before approval

Replace the generic 'have ready' items with the names of your own documents, and add your organisation's figures where you know them. Keep the traps: they are the part most worth reading the night before.

Appetite and exposure

BQ-01

Are we within the risk appetite we set?

Why they ask

It is the one question only the board can own: it set the appetite, and it must judge whether the organisation is inside it.

A good answer

One of the three position statements ('within appetite', 'outside appetite, within tolerance', 'outside tolerance'), chosen by the rule — outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite — then the count of top risks above appetite and past tolerance, their movement, and the date by which each will be back within appetite.

Have ready

BM-01 Risks outside appetite; the risk appetite statement; the Cyber Risk One-Page Board Summary.

The trap

Answering with activity ('we've done a lot this quarter') or with a colour. If there is no appetite statement, say so; do not invent a position.

BQ-02

What are the three things most likely to hurt us, and what would each cost?

Why they ask

Directors want to know where to direct their attention, in terms they can weigh against other business risks.

A good answer

Three risks, each with service, harm, a cost range with its basis, and likelihood in words — the Exposure part of the report.

Have ready

The top risks from the risk register, with the per-day cost figures agreed with finance (Board Reporting Narrative Model).

The trap

A list of threat types (ransomware, phishing) with no link to our services. Or a single precise cost figure you cannot defend.

BQ-03

Why is this risk still outside appetite after [[two]] reports? — uncomfortable

Why they ask

The board suspects a plan that is not working, or a risk nobody wants to own.

A good answer

Why the plan slipped (a cause, not an excuse), the new date, what the board could do to speed it up, and — if the risk cannot come back within appetite at a price worth paying — a recommendation to accept it formally.

Have ready

The history of the risk across reports; the plan and its owner; the options and costs as an ask (BR-06).

The trap

Promising a new date without saying why the old one was missed. Two missed dates without an ask to the board is a reporting failure, not only a delivery one.

Incidents

BQ-04

Could this happen to us? (after a breach in the news) — uncomfortable

Why they ask

Directors read the same headlines as everyone else and may be asked about it by customers, investors or their other boards.

A good answer

What is known about how it happened, in two sentences; whether the same route exists here, checked, not assumed; the answer — yes, partly, or no — with the reason; and what, if anything, is being done. If it has not been checked yet, say when it will be.

Have ready

A one-paragraph note on any major breach in your sector or supply chain since the last meeting, prepared in the preparation week.

The trap

'It couldn't happen here.' Also avoid using the headline to ask for money in the same breath, unless you have a costed ask ready.

BQ-05

Have we been breached? How would we know? — uncomfortable

Why they ask

Boards know that many breaches are found months later, often by someone else.

A good answer

The significant incidents in the period (BM-04 Significant incidents and time to contain), how the organisation detects intrusions, what it does not see, and what an honest estimate of the gap is.

Have ready

The incident log; a plain description of detection coverage and its known blind spots.

The trap

'No, we have not been breached.' Say 'we have found no evidence of…' and explain what you would be able to see.

BQ-06

What happened in [[incident]], and is it fixed?

Why they ask

The board is responsible for oversight of the response and wants assurance the cause, not only the symptom, has been dealt with.

A good answer

What happened, the harm and cost, what caused it, what has been fixed, what remains and by when, and what the board will see to know it has worked.

Have ready

The incident report and its actions; the entry in the action log (BR-09).

The trap

Declaring it fixed when only the immediate cause is closed. Separate 'contained', 'recovered' and 'cause removed'.

Third parties

BQ-07

Which suppliers could stop us operating, and have we checked them?

Why they ask

Much of the organisation's risk now sits with suppliers it does not control, and several regulators expect the board to know which ones matter.

A good answer

The number of critical suppliers, how many have been assessed against the organisation's standard (BM-05 Critical suppliers assessed), the most important gaps and what is being done.

Have ready

The third-party register; the list of critical suppliers with their assessment status.

The trap

Treating a supplier's certificate as proof that the service we buy is secure. It is one piece of evidence.

BQ-08

If our main IT or cloud provider went down for a week, what would happen? — uncomfortable

Why they ask

Directors know concentration on a few large providers is a real risk and want to know if there is a fallback.

A good answer

Which services would stop, which would continue, what the manual or alternative arrangements are, whether they have been tested, and what an outage of that length would cost.

Have ready

BM-06 Critical services restored in tests; business continuity plans for the critical services.

The trap

Relying on the provider's advertised availability. The question is about our plan when it fails.

Resilience and recovery

BQ-09

If ransomware hit us tomorrow, how long until we are trading again? — uncomfortable

Why they ask

It is the scenario directors fear most, and the one where their decisions in the first hours matter.

A good answer

The recovery time for each critical service, whether it has been proved in a test (BM-06 Critical services restored in tests), the longest one, and what would decide the difference between days and weeks.

Have ready

Recovery test records with dates and actual times; the incident response plan's decision points for the board.

The trap

Quoting the target recovery time as if it had been achieved. Say which services have been restored in a test and which have not.

BQ-10

Would we pay a ransom? — uncomfortable

Why they ask

It is a board decision, often needed within hours, with legal, ethical and insurance consequences.

A good answer

That the decision belongs to the board; whether the board has agreed a position in advance; the legal constraints (for example sanctions law) and the insurer's terms, as advised by [[legal counsel]]; and a proposal to agree a position before it is needed if there is none.

Have ready

The incident response plan's escalation to the board; [[the cyber insurance policy summary]]; legal advice if taken.

The trap

Giving your personal view as if it were the organisation's policy, or saying 'we would never pay' when the board has not decided.

BQ-11

Have we tested it, or do we just have a plan?

Why they ask

Boards have learned that untested plans fail, and want evidence rather than documents.

A good answer

Which tests were run, when, what they showed, what failed and what was fixed. A failed test honestly reported is a good answer.

Have ready

Recovery and exercise records for the last 12 months.

The trap

Describing the plan in detail instead of the test.

Investment and value

BQ-12

What are we getting for the money we spent?

Why they ask

The board approved the budget and must judge whether to continue funding it.

A good answer

Delivery of the programme against plan (BM-07 Security programme delivery) and, more importantly, which risks moved and by how much because of it.

Have ready

The programme plan with spend against budget; the risks each funded item was meant to reduce.

The trap

Answering with outputs (tools bought, projects completed) rather than outcomes (risk reduced).

BQ-13

What would you do with more money? — uncomfortable

Why they ask

The board is testing whether the reporter has priorities, and whether current spending is being used well.

A good answer

The next one or two items in priority order, each with what it would buy in risk reduction, the cost, and why it is not already funded. And what you would stop if the budget were cut.

Have ready

A short, costed list of the next items, ranked by risk reduced.

The trap

A long wish list, or 'we could always use more'. Both suggest there is no plan.

BQ-14

Are we spending the right amount?

Why they ask

There is no correct figure, and directors know it; they want to know how the level was chosen.

A good answer

That the spend is set by the risks the board wants within appetite, not by a benchmark; what the current spend buys; and what would change at a higher or lower level.

Have ready

The link between the budget and the top risks; peer figures only if from a reliable source, labelled as such.

The trap

Quoting a percentage-of-IT-budget benchmark as if it answered the question.

Regulation and personal liability

BQ-15

Are we compliant? — uncomfortable

Why they ask

Directors want reassurance, and regulated directors have personal duties.

A good answer

Compliant with what, specifically; where the organisation stands on each obligation that applies; known gaps, their dates and who is accountable; and the difference between being compliant and being within appetite.

Have ready

A list of the laws and standards that apply, with the status of each.

The trap

A single 'yes'. Compliance is rarely complete, and a 'yes' in the minutes is hard to live with if a gap is found later.

BQ-16

Which regulations apply to us, and what do they require of this board?

Why they ask

NIS2 and DORA place duties on the management body itself, not only on the organisation.

A good answer

Whether the organisation is in scope of NIS2, DORA or other regimes and why; what they require of the board — approving the risk-management measures and overseeing them (NIS2 Article 20(1)); defining, approving and overseeing the ICT risk framework and setting risk tolerance (DORA Article 5(2)); training (NIS2 Article 20(2), DORA Article 5(4)); and how the board's own process meets that.

Have ready

A one-page summary of applicable regulation, confirmed by [[legal or compliance]].

The trap

Giving a legal opinion. Say what the regulation requires in plain terms and point to the legal advice.

BQ-17

Could I be personally liable? — uncomfortable

Why they ask

Directors have read that the law now names them.

A good answer

That NIS2 allows management bodies to be held liable for infringements of the risk-management duties, under the national law that applies; that DORA gives the management body ultimate responsibility for ICT risk; that the best protection is visible, recorded oversight — decisions in the minutes, actions followed up; and that the question of personal exposure is one for [[legal counsel]].

Have ready

The minutes and action log showing the board's decisions; the legal team's view, if one exists.

The trap

Reassuring them that they are not liable. You are not their lawyer.

BQ-18

Is the board itself trained? — uncomfortable

Why they ask

NIS2 Article 20(2) requires members of management bodies to follow training, and DORA Article 5(4) requires management body members to keep sufficient knowledge and skills, including through regular training.

A good answer

How many directors have completed training in the last 12 months (BM-08 Board and staff security training), what it covered, when the next session is, and a proposal if coverage is incomplete. Expectation: at least once a year (NIS2 Art 20(2); DORA Art 5(4)).

Have ready

Board training records; the date and outline of the next session.

The trap

Treating it as awkward and skipping it. Present it as the board's own measure, with a date.

People and culture

BQ-19

Are our staff the weakest link?

Why they ask

Most directors have heard that people cause most breaches.

A good answer

What the evidence shows here — incidents that started with staff actions, reporting rates for suspicious messages, training coverage — and what the organisation does so that one mistake does not become a breach.

Have ready

BM-08 Board and staff security training; incident causes; phishing-exercise results if used.

The trap

Blaming staff. A culture where people fear reporting mistakes hides incidents; say what is done to make reporting easy.

BQ-20

Do we have the right people, and enough of them?

Why they ask

The board wants to know whether delivery depends on one or two individuals.

A good answer

The roles that exist, how many are filled, any single points of failure, and how external support fills the gaps.

Have ready

The security team structure and key-person dependencies, including outsourced roles.

The trap

Using this question to ask for headcount without a costed ask (BR-06).

Are we a target?

BQ-21

We are not interesting to attackers, are we? — uncomfortable

Why they ask

A common and understandable belief in smaller or less visible organisations.

A good answer

That most attacks are not aimed at a chosen victim: criminals look for any organisation with a weakness and a way to be paid. Then what in our organisation would be worth attacking — payments, data, access to our customers — with one real example from the sector.

Have ready

Incidents in similar organisations; attempts seen against us in the period.

The trap

Answering fear with fear. State the realistic threat to our services, not the worst case in the world.

BQ-22

Who would attack us, and why?

Why they ask

Directors want to judge whether the defences match the likely attacker.

A good answer

The two or three kinds of attacker most relevant to us (for example criminal groups after money, a disgruntled insider, an attacker using us to reach a customer), what each would want, and which top risk each drives.

Have ready

The threat assumptions behind the top risks.

The trap

A long catalogue of threat actors with exotic names. Keep it to those that change our decisions.

Comparisons with peers

BQ-23

How do we compare with our peers?

Why they ask

Directors use peers to calibrate: they want to know if they are an outlier.

A good answer

What can be compared honestly, from which source and how reliable it is; where we are ahead and behind; and a reminder that the board's appetite, not a peer average, sets the standard.

Have ready

Any reliable peer data — sector surveys, regulator reports, industry groups — labelled with its source and date.

The trap

Inventing a comparison, or quoting a vendor's survey as fact.

BQ-24

What is our security rating or score?

Why they ask

Directors may have seen an external rating of the organisation, or been sent one by a customer.

A good answer

What the rating measures (usually what can be seen from outside), what it does not, our current score if known, and whether the findings behind it matter to our top risks.

Have ready

Any external rating reports the organisation has received, with the findings checked.

The trap

Either dismissing ratings entirely or adopting one as a board measure without a target (BR-03).

Open questions

BQ-25

What keeps you awake at night? — uncomfortable

Why they ask

The board is asking for your judgement, beyond the figures.

A good answer

One risk, stated in business terms, and why it worries you more than the figures suggest — even if it is not on the top-risk list. Then whether you need anything from the board about it.

Have ready

A considered answer, agreed in the rehearsal with the executive sponsor.

The trap

'Nothing — we have it under control.' Or a list of ten things.

BQ-26

What do you need from us?

Why they ask

The board is inviting an ask. It may be the most valuable minute of the meeting.

A good answer

The decisions in the Ask part of the report, restated in one sentence each; and anything the board can do beyond money, such as setting priority or backing a policy.

Have ready

The Ask part of the report.

The trap

'Nothing at the moment.' If there is really nothing, say what the board will be asked next time.

Capturing questions, decisions and commitments

During the meeting, the reporter or the board secretary records every question that led to a commitment, and every question the bank did not anticipate. The record is agreed with the board secretary 3 working days after the meeting, and commitments go into the action log (BR-09).

Ref

Question asked (as asked)

Asked by

Answer given — fact, estimate or 'to follow'

Commitment

Owner

Due

[[M-01]]

[[question]]

[[name or role]]

[[answer]]

[[e.g. confirm figure]]

[[name]]

[[YYYY-MM-DD]]

EXAMPLE

Do our supplier assessments cover the payment-fraud risk?

Chair of committee

To follow — reporter did not have the detail

Send the answer and the suppliers still to assess

Reporter

[[date + 5 working days]]

After the meeting

  • Send every promised answer by its date, using the follow-up template below.
  • Add each unexpected question to your copy of the question bank, with the answer that worked or the answer you should have given.
  • Note any question that shows the report is missing something, and change the report next time; if it shows a measure is missing, check it against the Board Metric Selection Catalogue (BR-03).
  • Once a year, review which questions the board asks most often as part of the Board Reporting Effectiveness Self-Check (BR-10).

Follow-up template

A short written answer to a question the board asked, sent to the board secretary for circulation. Keep it to one page.

Field

Content

To

[[Chair of the board or committee]], via the board secretary

From

[[Name]], Reporter

Date

[[YYYY-MM-DD]] — the date promised at the meeting was [[YYYY-MM-DD]]

Question as minuted

[[Copy the question from the minutes, and the meeting date]]

Short answer

[[One or two sentences that answer the question]]

Detail

[[The facts behind the answer, in business terms; label estimates]]

Source

[[Where the figures come from; the data collection workbook reference]]

What changes

[[Anything the answer changes: a risk, a plan, the next report. Or 'nothing']]

Decision needed?

[[No / Yes — to be brought to the next meeting as an ask]]

EXAMPLE — a completed follow-up

Field

EXAMPLE content

Question as minuted

"Do our supplier assessments cover the payment-fraud risk, and which critical suppliers are still to be assessed?" (Audit & Risk Committee, 29 October 2026)

Short answer

Not yet. 9 of our 14 critical suppliers have been assessed (target: 14 of 14 by year end), but the assessment does not ask how suppliers protect the email accounts they use to send invoices and bank details.

Detail

The risk in the report is "payment fraud through a compromised supplier email account": single losses of €50k to €400k; not recoverable once paid. We are adding questions on email security to the assessment, and will use them for the remaining 5 suppliers: [[names]].

Source

Third-party register, as signed off in the Board Reporting Data Collection Workbook for the last meeting.

What changes

No change to the position: the risk stays Likely and outside appetite, within tolerance. The next report will show how many suppliers have answered the new questions.

Decision needed?

No.

Related documents

Document

Relationship

Board Reporting Narrative Model

The structure and rules of the report this brief prepares you to defend

Board Cybersecurity Report Deck Template

The deck presented at the meeting

Board Metric Selection Catalogue

The measures BM-01 to BM-08 named in 'have ready'

Board Reporting Data Collection Workbook

The single source of every figure you quote (BR-08)

Cyber Risk One-Page Board Summary

The page most directors will have read before they ask

Board & Executive Reporting Calendar

The reporting cycle, including the rehearsal step

Board Reporting Effectiveness Self-Check

The yearly review of the reporting, including the questions asked (BR-10)

Adapting this template

Guidance — delete before approval

Small organisation: the 'board' may be two or three owners or directors, and the questions come across a table rather than in a formal meeting. Use the themes as a checklist; pick the [[five]] questions most likely for your organisation and prepare those. The rehearsal can be [[20]] minutes with the managing director. The honest-answering principles apply unchanged.

Regulated entity (NIS2, DORA): expect the regulation and liability questions (BQ-15 to BQ-18) at every meeting until the board is confident of its own duties: under NIS2 Article 20 the management body approves and oversees the risk-management measures, can be held liable, and must follow training; under DORA Article 5 it bears ultimate responsibility for ICT risk, sets the risk tolerance and must keep its knowledge up to date through regular training. Agree the answers with [[legal or compliance]] before the meeting, and make sure the minutes record the board's questions and decisions: they are the evidence of oversight.

IT run by a service provider: many 'have ready' items — incident records, recovery tests, patching figures — come from the provider. Ask for them by the data return date in the reporting cycle, not the week of the meeting. The reporter answers the board, not the provider; if a question can only be answered by the provider, say so and give a date. Expect BQ-08 to be asked about the provider itself.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA).

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 5.1 — Leadership and commitment

Purpose and audience; the question bank: leadership engaged in cyber risk

ISO/IEC 27001:2022

Clause 9.3 — Management review

Capturing questions, decisions and commitments; follow-up template

NIST CSF 2.0

GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving”

Answering honestly; regulation and personal liability questions

NIST CSF 2.0

GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”

The preparation brief; the question bank: performance reviewed by the board

NIS2 — Directive (EU) 2022/2555

Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements

BQ-16, BQ-17; adapting this template: regulated entity

NIS2 — Directive (EU) 2022/2555

Article 20(2) — members of management bodies are required to follow training to identify risks and assess cybersecurity risk-management practices

BQ-18: board training

DORA — Regulation (EU) 2022/2554

Article 5(2) — the management body defines, approves, oversees and is responsible for the ICT risk management framework, bears ultimate responsibility for ICT risk and sets the risk tolerance

BQ-16, BQ-17; adapting this template: regulated entity

DORA — Regulation (EU) 2022/2554

Article 5(4) — members of the management body keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including through regular training

BQ-18: board training

Definitions

Term

Meaning in this brief

Action log

The record of actions the board agreed, each with an owner and a date, reported on until closed (BR-09).

Board

The body the report is presented to: [[e.g. Board, or its Audit & Risk Committee]].

Executive sponsor

The executive who reviews the report and runs the rehearsal: [[e.g. Chief Operating Officer or CFO]].

Follow-up

A written answer to a question the board asked, sent by the date promised at the meeting.

Management body

The term NIS2 and DORA use for the board of directors or equivalent body that directs the organisation.

Rehearsal

The step of the reporting cycle, 7 working days before the meeting, in which the reporter answers likely questions put by the executive sponsor.

Reporter

The person who writes and presents the report: [[e.g. Head of Information Security or CISO]].

Risk appetite

The amount and kind of risk the board is willing to accept in pursuit of its objectives.

Uncomfortable question

A question reporters most often answer badly: because the honest answer is uncertain, unwelcome, or outside their authority.