Board Cyber Readiness
The six questions your board will ask about cyber.
Every board now owns cyber risk. These are the six questions that surface it — from an audit committee, an insurer, a regulator, or an investor. Below each, what a good answer sounds like.
What is our single largest cyber risk — in dollars — and who owns it by name?
A good answer:
A good answer is a number and a named executive. Silence here is what a board minute records.
What would a ransomware event actually cost us — recovery, downtime, and regulatory penalty combined?
A good answer:
A range, modeled from our operations. Not "we have backups."
Are we adequately insured — and would our insurer agree?
A good answer:
Evidence our carrier has already accepted. Renewals now turn on it.
Who is governing our AI systems — and what is our liability if one makes a bad decision?
A good answer:
A named owner and a record. For most organizations this answer does not yet exist.
If our systems went down tomorrow morning, how long until we recover — and at what cost per hour?
A good answer:
A rehearsed number, not an assumption discovered during the incident.
If a regulator asked us to prove our cyber governance today, what would we hand them?
A good answer:
A documented trail, prepared before the letter arrives.
Take the questions to your next meeting.
Get the board-ready one-pager — the six questions with the answers to expect, formatted to bring into the room. Instant download. No spam. Nothing sold.
Your email is used only to send the guide. Vendor-neutral by design.
