Board Question Bank & Preparation Brief
Prepares the reporter for the questions a board will actually ask, including the uncomfortable ones, with guidance on answering honestly.
Available soon
- Format
- Word
- Size
- 63 KB
- Length
- 18 pages
- Version
- 1.0
- Updated
What's inside
- Purpose and audience
- The preparation brief
- Required inputs with owners
- The question bank
- Capturing questions, decisions and commitments
- Follow-up template
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose and audience
This brief prepares the reporter — [[e.g. Head of Information Security or CISO]] — for the questions a [[e.g. Board, or its Audit & Risk Committee]] will ask about cyber risk, including the uncomfortable ones, and for answering them honestly. It has two parts: a preparation brief for the days before the meeting, and a question bank grouped by theme.
It is used with the report written to the Board Reporting Narrative Model. The report says where the organisation stands; this brief prepares the reporter for what the board will ask once it has read it. The executive sponsor, [[e.g. Chief Operating Officer or CFO]], uses it for the rehearsal.
Guidance — delete before approval
Keep your own copy of the question bank. After every meeting, add the questions the board actually asked, with the answer that worked, and remove any that no longer apply. Within a year it will be more useful than this template.
The reporting cycle (Board & Executive Reporting Calendar) puts the rehearsal 7 working days before the meeting. Leave room to change the report afterwards: papers go to the board secretary 5 working days before it.
The preparation brief
The days before the meeting
The last steps of the reporting cycle, counted in working days from the board meeting (day 0). The Board & Executive Reporting Calendar holds the full cycle; the adopter's own board calendar overrides these defaults.
When | Step | Who |
|---|---|---|
9 working days before | Executive sponsor review | Executive sponsor |
7 working days before | Question bank rehearsal | Reporter and executive sponsor |
5 working days before | Papers submitted to the board secretary | Reporter |
Meeting day | Board meeting | Board |
3 working days after | Actions and decisions recorded (BR-09) | Board secretary with reporter |
What to do each day
When | Preparation |
|---|---|
9 working days before | The executive sponsor reads the draft report and the one-page summary. Ask them to mark every sentence they would challenge if they were a director: those become rehearsal questions. |
Between 9 and 7 working days before | Pick the questions for the rehearsal: the [[ten]] most likely from the bank below, every question marked uncomfortable that applies, and any question the board asked last time that the report still does not answer. Check the news and sector alerts for breaches the board may have read about (BQ-04). |
7 working days before | Rehearsal (see below). Afterwards, correct the report where the rehearsal found a gap. A question you could not answer in rehearsal is a sign the report is missing something. |
Between 7 and 5 working days before | Finalise the report. Prepare the 'have ready' material for the likeliest questions as a short appendix or as notes you carry, not as extra slides. |
5 working days before | Papers to the board secretary. From here, no figure changes without telling the chair (BR-08). |
The day before | Brief the executive sponsor on anything that has changed since the papers went out. Read the last meeting's minutes and action log (BR-09). |
Meeting day | Open with the position (BR-02). Answer questions using the principles below. Note every commitment you make. |
3 working days after | Agree the record of decisions and actions with the board secretary; send any promised answers by the date you gave. |
The rehearsal
The rehearsal is a step of its own in the reporting cycle (7 working days before the meeting; reporter and executive sponsor). It is the step most often skipped and the one that most improves the meeting.
- Book [[60 to 90]] minutes with the executive sponsor, and if possible one person who thinks like a director: [[the company secretary, a non-executive, the CFO]].
- Present the report as you will in the meeting, in the time you will have — usually [[10 to 15]] minutes. Stop at the time limit, wherever you are.
- Take the questions. The sponsor asks the chosen questions, in no set order, as a sceptical director would. At least [[three]] should be uncomfortable ones.
- Answer each in about [[one]] minute. The first sentence should answer the question; the rest supports it.
- Record each gap: a question you could not answer, answered with a guess, or answered with technical detail. Fix the report or prepare the answer before papers go out.
- Agree who answers what. Some questions belong to the sponsor, to finance or to legal. Decide in advance who takes them.
Guidance — delete before approval
If there is no one to rehearse with, record yourself answering the questions and listen back. It is less comfortable, and nearly as useful.
Answering honestly
The board will judge the organisation's security partly by whether it trusts the person reporting it. Trust is built by accurate answers, not confident ones.
- Answer the question asked, first. One sentence that answers it — yes, no, a number, a position — then the reason.
- Say what you do not know. 'I don't know' is a complete and acceptable answer when followed by what you would need to find out, and when.
- Never guess a number. A figure said in the meeting goes in the minutes and outlives the meeting. Say 'I will confirm the exact figure by [[date]]'.
- Offer to come back by a date — and do it. Give a date, normally within [[5]] working days. Record it as an action (BR-09) and send the answer using the follow-up template in this brief.
- Label facts, estimates and opinions. 'The figure is…', 'We estimate…', 'My view is…'. A director should never mistake one for another.
- Do not reassure beyond the evidence. Avoid 'we are fully protected', 'it could not happen here', 'we are compliant' without qualification.
- Bad news first. If a question touches something that has gone wrong, say so at once rather than letting it emerge (BR-07).
- Stay in business terms. If a director asks a technical question, answer briefly and offer detail outside the meeting (BR-05).
- Correct with evidence, not defence. If a director has a fact wrong, say what the figure is and where it comes from. If they are right and you are wrong, say so.
- Hand over when it is not yours. Legal, financial and personnel questions may belong to someone else in the room. Say who, and let them answer.
Phrases that help:
Instead of | Say |
|---|---|
"I think it's around 80%, roughly." | "I don't have the exact figure with me. I'll send it to the secretary by Friday." |
"We're fully protected against that." | "We have [[control]] in place and tested it in [[month]]. It reduces the risk; it doesn't remove it." |
"That's quite technical, but basically…" (five minutes) | "In short: [[one sentence]]. I'm happy to go through the detail with anyone after the meeting." |
"Yes, we're compliant." | "We meet [[n]] of [[N]] requirements. The gaps are [[x]], due by [[date]]." |
"I'd rather not speculate." | "My judgement is [[view]], but that is an opinion, not a finding. I'll confirm it by [[date]]." |
Required inputs with owners
What the reporter brings, or has to hand, at the meeting. Everything with a figure comes from the signed-off Board Reporting Data Collection Workbook (BR-08).
Input | Supports questions | Owner |
|---|---|---|
The report and the Cyber Risk One-Page Board Summary | All | Reporter |
The signed-off Board Reporting Data Collection Workbook | Any question about a figure | Reporter with risk function |
The risk appetite statement and the top-risk extract from the risk register (BM-01) | BQ-01 to BQ-03 | Risk function |
The incident log for the period, and the status of incident actions (BM-04) | BQ-04 to BQ-06 | Data owners [[e.g. IT operations, risk, procurement, HR]] |
A note on any major breach in the sector or supply chain since the last meeting | BQ-04 | Reporter |
The critical-supplier list and assessment status (BM-05) | BQ-07, BQ-08 | [[Procurement]] |
Recovery test records (BM-06) and the board's escalation points in the incident response plan | BQ-09 to BQ-11 | [[IT operations]] |
Programme plan and spend against budget (BM-07); a ranked, costed list of next items | BQ-12 to BQ-14 | Reporter with [[finance]] |
Applicable regulation and status; any legal advice on directors' duties | BQ-15 to BQ-17 | [[Legal or compliance]] |
Board and staff training records (BM-08) | BQ-18, BQ-19 | [[HR]] and board secretary |
The last meeting's minutes and action log (BR-09) | Any follow-up question | Board secretary |
The question bank
26 questions boards ask about cyber risk, grouped by theme. Each has a stable ID for rehearsals, and four notes: why a board asks it, what a good answer contains, what to have ready, and the trap to avoid. Questions marked uncomfortable are those reporters most often answer badly; rehearse every one that applies to you.
The uncomfortable questions at a glance:
ID | Question | Theme |
|---|---|---|
BQ-03 | Why is this risk still outside appetite after [[two]] reports? | Appetite and exposure |
BQ-04 | Could this happen to us? (after a breach in the news) | Incidents |
BQ-05 | Have we been breached? How would we know? | Incidents |
BQ-08 | If our main IT or cloud provider went down for a week, what would happen? | Third parties |
BQ-09 | If ransomware hit us tomorrow, how long until we are trading again? | Resilience and recovery |
BQ-10 | Would we pay a ransom? | Resilience and recovery |
BQ-13 | What would you do with more money? | Investment and value |
BQ-15 | Are we compliant? | Regulation and personal liability |
BQ-17 | Could I be personally liable? | Regulation and personal liability |
BQ-18 | Is the board itself trained? | Regulation and personal liability |
BQ-21 | We are not interesting to attackers, are we? | Are we a target? |
BQ-25 | What keeps you awake at night? | Open questions |
Guidance — delete before approval
Replace the generic 'have ready' items with the names of your own documents, and add your organisation's figures where you know them. Keep the traps: they are the part most worth reading the night before.
Appetite and exposure
BQ-01 | Are we within the risk appetite we set? |
|---|---|
Why they ask | It is the one question only the board can own: it set the appetite, and it must judge whether the organisation is inside it. |
A good answer | One of the three position statements ('within appetite', 'outside appetite, within tolerance', 'outside tolerance'), chosen by the rule — outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite — then the count of top risks above appetite and past tolerance, their movement, and the date by which each will be back within appetite. |
Have ready | BM-01 Risks outside appetite; the risk appetite statement; the Cyber Risk One-Page Board Summary. |
The trap | Answering with activity ('we've done a lot this quarter') or with a colour. If there is no appetite statement, say so; do not invent a position. |
BQ-02 | What are the three things most likely to hurt us, and what would each cost? |
|---|---|
Why they ask | Directors want to know where to direct their attention, in terms they can weigh against other business risks. |
A good answer | Three risks, each with service, harm, a cost range with its basis, and likelihood in words — the Exposure part of the report. |
Have ready | The top risks from the risk register, with the per-day cost figures agreed with finance (Board Reporting Narrative Model). |
The trap | A list of threat types (ransomware, phishing) with no link to our services. Or a single precise cost figure you cannot defend. |
BQ-03 | Why is this risk still outside appetite after [[two]] reports? — uncomfortable |
|---|---|
Why they ask | The board suspects a plan that is not working, or a risk nobody wants to own. |
A good answer | Why the plan slipped (a cause, not an excuse), the new date, what the board could do to speed it up, and — if the risk cannot come back within appetite at a price worth paying — a recommendation to accept it formally. |
Have ready | The history of the risk across reports; the plan and its owner; the options and costs as an ask (BR-06). |
The trap | Promising a new date without saying why the old one was missed. Two missed dates without an ask to the board is a reporting failure, not only a delivery one. |
Incidents
BQ-04 | Could this happen to us? (after a breach in the news) — uncomfortable |
|---|---|
Why they ask | Directors read the same headlines as everyone else and may be asked about it by customers, investors or their other boards. |
A good answer | What is known about how it happened, in two sentences; whether the same route exists here, checked, not assumed; the answer — yes, partly, or no — with the reason; and what, if anything, is being done. If it has not been checked yet, say when it will be. |
Have ready | A one-paragraph note on any major breach in your sector or supply chain since the last meeting, prepared in the preparation week. |
The trap | 'It couldn't happen here.' Also avoid using the headline to ask for money in the same breath, unless you have a costed ask ready. |
BQ-05 | Have we been breached? How would we know? — uncomfortable |
|---|---|
Why they ask | Boards know that many breaches are found months later, often by someone else. |
A good answer | The significant incidents in the period (BM-04 Significant incidents and time to contain), how the organisation detects intrusions, what it does not see, and what an honest estimate of the gap is. |
Have ready | The incident log; a plain description of detection coverage and its known blind spots. |
The trap | 'No, we have not been breached.' Say 'we have found no evidence of…' and explain what you would be able to see. |
BQ-06 | What happened in [[incident]], and is it fixed? |
|---|---|
Why they ask | The board is responsible for oversight of the response and wants assurance the cause, not only the symptom, has been dealt with. |
A good answer | What happened, the harm and cost, what caused it, what has been fixed, what remains and by when, and what the board will see to know it has worked. |
Have ready | The incident report and its actions; the entry in the action log (BR-09). |
The trap | Declaring it fixed when only the immediate cause is closed. Separate 'contained', 'recovered' and 'cause removed'. |
Third parties
BQ-07 | Which suppliers could stop us operating, and have we checked them? |
|---|---|
Why they ask | Much of the organisation's risk now sits with suppliers it does not control, and several regulators expect the board to know which ones matter. |
A good answer | The number of critical suppliers, how many have been assessed against the organisation's standard (BM-05 Critical suppliers assessed), the most important gaps and what is being done. |
Have ready | The third-party register; the list of critical suppliers with their assessment status. |
The trap | Treating a supplier's certificate as proof that the service we buy is secure. It is one piece of evidence. |
BQ-08 | If our main IT or cloud provider went down for a week, what would happen? — uncomfortable |
|---|---|
Why they ask | Directors know concentration on a few large providers is a real risk and want to know if there is a fallback. |
A good answer | Which services would stop, which would continue, what the manual or alternative arrangements are, whether they have been tested, and what an outage of that length would cost. |
Have ready | BM-06 Critical services restored in tests; business continuity plans for the critical services. |
The trap | Relying on the provider's advertised availability. The question is about our plan when it fails. |
Resilience and recovery
BQ-09 | If ransomware hit us tomorrow, how long until we are trading again? — uncomfortable |
|---|---|
Why they ask | It is the scenario directors fear most, and the one where their decisions in the first hours matter. |
A good answer | The recovery time for each critical service, whether it has been proved in a test (BM-06 Critical services restored in tests), the longest one, and what would decide the difference between days and weeks. |
Have ready | Recovery test records with dates and actual times; the incident response plan's decision points for the board. |
The trap | Quoting the target recovery time as if it had been achieved. Say which services have been restored in a test and which have not. |
BQ-10 | Would we pay a ransom? — uncomfortable |
|---|---|
Why they ask | It is a board decision, often needed within hours, with legal, ethical and insurance consequences. |
A good answer | That the decision belongs to the board; whether the board has agreed a position in advance; the legal constraints (for example sanctions law) and the insurer's terms, as advised by [[legal counsel]]; and a proposal to agree a position before it is needed if there is none. |
Have ready | The incident response plan's escalation to the board; [[the cyber insurance policy summary]]; legal advice if taken. |
The trap | Giving your personal view as if it were the organisation's policy, or saying 'we would never pay' when the board has not decided. |
BQ-11 | Have we tested it, or do we just have a plan? |
|---|---|
Why they ask | Boards have learned that untested plans fail, and want evidence rather than documents. |
A good answer | Which tests were run, when, what they showed, what failed and what was fixed. A failed test honestly reported is a good answer. |
Have ready | Recovery and exercise records for the last 12 months. |
The trap | Describing the plan in detail instead of the test. |
Investment and value
BQ-12 | What are we getting for the money we spent? |
|---|---|
Why they ask | The board approved the budget and must judge whether to continue funding it. |
A good answer | Delivery of the programme against plan (BM-07 Security programme delivery) and, more importantly, which risks moved and by how much because of it. |
Have ready | The programme plan with spend against budget; the risks each funded item was meant to reduce. |
The trap | Answering with outputs (tools bought, projects completed) rather than outcomes (risk reduced). |
BQ-13 | What would you do with more money? — uncomfortable |
|---|---|
Why they ask | The board is testing whether the reporter has priorities, and whether current spending is being used well. |
A good answer | The next one or two items in priority order, each with what it would buy in risk reduction, the cost, and why it is not already funded. And what you would stop if the budget were cut. |
Have ready | A short, costed list of the next items, ranked by risk reduced. |
The trap | A long wish list, or 'we could always use more'. Both suggest there is no plan. |
BQ-14 | Are we spending the right amount? |
|---|---|
Why they ask | There is no correct figure, and directors know it; they want to know how the level was chosen. |
A good answer | That the spend is set by the risks the board wants within appetite, not by a benchmark; what the current spend buys; and what would change at a higher or lower level. |
Have ready | The link between the budget and the top risks; peer figures only if from a reliable source, labelled as such. |
The trap | Quoting a percentage-of-IT-budget benchmark as if it answered the question. |
Regulation and personal liability
BQ-15 | Are we compliant? — uncomfortable |
|---|---|
Why they ask | Directors want reassurance, and regulated directors have personal duties. |
A good answer | Compliant with what, specifically; where the organisation stands on each obligation that applies; known gaps, their dates and who is accountable; and the difference between being compliant and being within appetite. |
Have ready | A list of the laws and standards that apply, with the status of each. |
The trap | A single 'yes'. Compliance is rarely complete, and a 'yes' in the minutes is hard to live with if a gap is found later. |
BQ-16 | Which regulations apply to us, and what do they require of this board? |
|---|---|
Why they ask | NIS2 and DORA place duties on the management body itself, not only on the organisation. |
A good answer | Whether the organisation is in scope of NIS2, DORA or other regimes and why; what they require of the board — approving the risk-management measures and overseeing them (NIS2 Article 20(1)); defining, approving and overseeing the ICT risk framework and setting risk tolerance (DORA Article 5(2)); training (NIS2 Article 20(2), DORA Article 5(4)); and how the board's own process meets that. |
Have ready | A one-page summary of applicable regulation, confirmed by [[legal or compliance]]. |
The trap | Giving a legal opinion. Say what the regulation requires in plain terms and point to the legal advice. |
BQ-17 | Could I be personally liable? — uncomfortable |
|---|---|
Why they ask | Directors have read that the law now names them. |
A good answer | That NIS2 allows management bodies to be held liable for infringements of the risk-management duties, under the national law that applies; that DORA gives the management body ultimate responsibility for ICT risk; that the best protection is visible, recorded oversight — decisions in the minutes, actions followed up; and that the question of personal exposure is one for [[legal counsel]]. |
Have ready | The minutes and action log showing the board's decisions; the legal team's view, if one exists. |
The trap | Reassuring them that they are not liable. You are not their lawyer. |
BQ-18 | Is the board itself trained? — uncomfortable |
|---|---|
Why they ask | NIS2 Article 20(2) requires members of management bodies to follow training, and DORA Article 5(4) requires management body members to keep sufficient knowledge and skills, including through regular training. |
A good answer | How many directors have completed training in the last 12 months (BM-08 Board and staff security training), what it covered, when the next session is, and a proposal if coverage is incomplete. Expectation: at least once a year (NIS2 Art 20(2); DORA Art 5(4)). |
Have ready | Board training records; the date and outline of the next session. |
The trap | Treating it as awkward and skipping it. Present it as the board's own measure, with a date. |
People and culture
BQ-19 | Are our staff the weakest link? |
|---|---|
Why they ask | Most directors have heard that people cause most breaches. |
A good answer | What the evidence shows here — incidents that started with staff actions, reporting rates for suspicious messages, training coverage — and what the organisation does so that one mistake does not become a breach. |
Have ready | BM-08 Board and staff security training; incident causes; phishing-exercise results if used. |
The trap | Blaming staff. A culture where people fear reporting mistakes hides incidents; say what is done to make reporting easy. |
BQ-20 | Do we have the right people, and enough of them? |
|---|---|
Why they ask | The board wants to know whether delivery depends on one or two individuals. |
A good answer | The roles that exist, how many are filled, any single points of failure, and how external support fills the gaps. |
Have ready | The security team structure and key-person dependencies, including outsourced roles. |
The trap | Using this question to ask for headcount without a costed ask (BR-06). |
Are we a target?
BQ-21 | We are not interesting to attackers, are we? — uncomfortable |
|---|---|
Why they ask | A common and understandable belief in smaller or less visible organisations. |
A good answer | That most attacks are not aimed at a chosen victim: criminals look for any organisation with a weakness and a way to be paid. Then what in our organisation would be worth attacking — payments, data, access to our customers — with one real example from the sector. |
Have ready | Incidents in similar organisations; attempts seen against us in the period. |
The trap | Answering fear with fear. State the realistic threat to our services, not the worst case in the world. |
BQ-22 | Who would attack us, and why? |
|---|---|
Why they ask | Directors want to judge whether the defences match the likely attacker. |
A good answer | The two or three kinds of attacker most relevant to us (for example criminal groups after money, a disgruntled insider, an attacker using us to reach a customer), what each would want, and which top risk each drives. |
Have ready | The threat assumptions behind the top risks. |
The trap | A long catalogue of threat actors with exotic names. Keep it to those that change our decisions. |
Comparisons with peers
BQ-23 | How do we compare with our peers? |
|---|---|
Why they ask | Directors use peers to calibrate: they want to know if they are an outlier. |
A good answer | What can be compared honestly, from which source and how reliable it is; where we are ahead and behind; and a reminder that the board's appetite, not a peer average, sets the standard. |
Have ready | Any reliable peer data — sector surveys, regulator reports, industry groups — labelled with its source and date. |
The trap | Inventing a comparison, or quoting a vendor's survey as fact. |
BQ-24 | What is our security rating or score? |
|---|---|
Why they ask | Directors may have seen an external rating of the organisation, or been sent one by a customer. |
A good answer | What the rating measures (usually what can be seen from outside), what it does not, our current score if known, and whether the findings behind it matter to our top risks. |
Have ready | Any external rating reports the organisation has received, with the findings checked. |
The trap | Either dismissing ratings entirely or adopting one as a board measure without a target (BR-03). |
Open questions
BQ-25 | What keeps you awake at night? — uncomfortable |
|---|---|
Why they ask | The board is asking for your judgement, beyond the figures. |
A good answer | One risk, stated in business terms, and why it worries you more than the figures suggest — even if it is not on the top-risk list. Then whether you need anything from the board about it. |
Have ready | A considered answer, agreed in the rehearsal with the executive sponsor. |
The trap | 'Nothing — we have it under control.' Or a list of ten things. |
BQ-26 | What do you need from us? |
|---|---|
Why they ask | The board is inviting an ask. It may be the most valuable minute of the meeting. |
A good answer | The decisions in the Ask part of the report, restated in one sentence each; and anything the board can do beyond money, such as setting priority or backing a policy. |
Have ready | The Ask part of the report. |
The trap | 'Nothing at the moment.' If there is really nothing, say what the board will be asked next time. |
Capturing questions, decisions and commitments
During the meeting, the reporter or the board secretary records every question that led to a commitment, and every question the bank did not anticipate. The record is agreed with the board secretary 3 working days after the meeting, and commitments go into the action log (BR-09).
Ref | Question asked (as asked) | Asked by | Answer given — fact, estimate or 'to follow' | Commitment | Owner | Due |
|---|---|---|---|---|---|---|
[[M-01]] | [[question]] | [[name or role]] | [[answer]] | [[e.g. confirm figure]] | [[name]] | [[YYYY-MM-DD]] |
EXAMPLE | Do our supplier assessments cover the payment-fraud risk? | Chair of committee | To follow — reporter did not have the detail | Send the answer and the suppliers still to assess | Reporter | [[date + 5 working days]] |
After the meeting
- Send every promised answer by its date, using the follow-up template below.
- Add each unexpected question to your copy of the question bank, with the answer that worked or the answer you should have given.
- Note any question that shows the report is missing something, and change the report next time; if it shows a measure is missing, check it against the Board Metric Selection Catalogue (BR-03).
- Once a year, review which questions the board asks most often as part of the Board Reporting Effectiveness Self-Check (BR-10).
Follow-up template
A short written answer to a question the board asked, sent to the board secretary for circulation. Keep it to one page.
Field | Content |
|---|---|
To | [[Chair of the board or committee]], via the board secretary |
From | [[Name]], Reporter |
Date | [[YYYY-MM-DD]] — the date promised at the meeting was [[YYYY-MM-DD]] |
Question as minuted | [[Copy the question from the minutes, and the meeting date]] |
Short answer | [[One or two sentences that answer the question]] |
Detail | [[The facts behind the answer, in business terms; label estimates]] |
Source | [[Where the figures come from; the data collection workbook reference]] |
What changes | [[Anything the answer changes: a risk, a plan, the next report. Or 'nothing']] |
Decision needed? | [[No / Yes — to be brought to the next meeting as an ask]] |
EXAMPLE — a completed follow-up
Field | EXAMPLE content |
|---|---|
Question as minuted | "Do our supplier assessments cover the payment-fraud risk, and which critical suppliers are still to be assessed?" (Audit & Risk Committee, 29 October 2026) |
Short answer | Not yet. 9 of our 14 critical suppliers have been assessed (target: 14 of 14 by year end), but the assessment does not ask how suppliers protect the email accounts they use to send invoices and bank details. |
Detail | The risk in the report is "payment fraud through a compromised supplier email account": single losses of €50k to €400k; not recoverable once paid. We are adding questions on email security to the assessment, and will use them for the remaining 5 suppliers: [[names]]. |
Source | Third-party register, as signed off in the Board Reporting Data Collection Workbook for the last meeting. |
What changes | No change to the position: the risk stays Likely and outside appetite, within tolerance. The next report will show how many suppliers have answered the new questions. |
Decision needed? | No. |
Related documents
Document | Relationship |
|---|---|
Board Reporting Narrative Model | The structure and rules of the report this brief prepares you to defend |
Board Cybersecurity Report Deck Template | The deck presented at the meeting |
Board Metric Selection Catalogue | The measures BM-01 to BM-08 named in 'have ready' |
Board Reporting Data Collection Workbook | The single source of every figure you quote (BR-08) |
Cyber Risk One-Page Board Summary | The page most directors will have read before they ask |
Board & Executive Reporting Calendar | The reporting cycle, including the rehearsal step |
Board Reporting Effectiveness Self-Check | The yearly review of the reporting, including the questions asked (BR-10) |
Adapting this template
Guidance — delete before approval
Small organisation: the 'board' may be two or three owners or directors, and the questions come across a table rather than in a formal meeting. Use the themes as a checklist; pick the [[five]] questions most likely for your organisation and prepare those. The rehearsal can be [[20]] minutes with the managing director. The honest-answering principles apply unchanged.
Regulated entity (NIS2, DORA): expect the regulation and liability questions (BQ-15 to BQ-18) at every meeting until the board is confident of its own duties: under NIS2 Article 20 the management body approves and oversees the risk-management measures, can be held liable, and must follow training; under DORA Article 5 it bears ultimate responsibility for ICT risk, sets the risk tolerance and must keep its knowledge up to date through regular training. Agree the answers with [[legal or compliance]] before the meeting, and make sure the minutes record the board's questions and decisions: they are the evidence of oversight.
IT run by a service provider: many 'have ready' items — incident records, recovery tests, patching figures — come from the provider. Ask for them by the data return date in the reporting cycle, not the week of the meeting. The reporter answers the board, not the provider; if a question can only be answered by the provider, say so and give a date. Expect BQ-08 to be asked about the provider itself.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA).
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 5.1 — Leadership and commitment | Purpose and audience; the question bank: leadership engaged in cyber risk |
ISO/IEC 27001:2022 | Clause 9.3 — Management review | Capturing questions, decisions and commitments; follow-up template |
NIST CSF 2.0 | GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving” | Answering honestly; regulation and personal liability questions |
NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | The preparation brief; the question bank: performance reviewed by the board |
NIS2 — Directive (EU) 2022/2555 | Article 20(1) — management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements | BQ-16, BQ-17; adapting this template: regulated entity |
NIS2 — Directive (EU) 2022/2555 | Article 20(2) — members of management bodies are required to follow training to identify risks and assess cybersecurity risk-management practices | BQ-18: board training |
DORA — Regulation (EU) 2022/2554 | Article 5(2) — the management body defines, approves, oversees and is responsible for the ICT risk management framework, bears ultimate responsibility for ICT risk and sets the risk tolerance | BQ-16, BQ-17; adapting this template: regulated entity |
DORA — Regulation (EU) 2022/2554 | Article 5(4) — members of the management body keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including through regular training | BQ-18: board training |
Definitions
Term | Meaning in this brief |
|---|---|
Action log | The record of actions the board agreed, each with an owner and a date, reported on until closed (BR-09). |
Board | The body the report is presented to: [[e.g. Board, or its Audit & Risk Committee]]. |
Executive sponsor | The executive who reviews the report and runs the rehearsal: [[e.g. Chief Operating Officer or CFO]]. |
Follow-up | A written answer to a question the board asked, sent by the date promised at the meeting. |
Management body | The term NIS2 and DORA use for the board of directors or equivalent body that directs the organisation. |
Rehearsal | The step of the reporting cycle, 7 working days before the meeting, in which the reporter answers likely questions put by the executive sponsor. |
Reporter | The person who writes and presents the report: [[e.g. Head of Information Security or CISO]]. |
Risk appetite | The amount and kind of risk the board is willing to accept in pursuit of its objectives. |
Uncomfortable question | A question reporters most often answer badly: because the honest answer is uncertain, unwelcome, or outside their authority. |