Agility Next
Services
Why Us
Proof
Resources
Pricing
Contact Us

Board Governance

The 10 cyber questions every Australian board should ask

Cyber resilience sits inside directors' duties, and the ACSC and AICD now publish exactly the questions boards are expected to ask. Here are the ten that matter, with the shape of a good answer for each. The pattern to notice: every good answer involves evidence, and most of that evidence should be independent.

The ten questions

  • 1. When were our security controls last tested by someone independent of the people who run them? Good answer: a date within the year, a named firm and findings the board saw.
  • 2. When did we last successfully restore from backup, end to end? Good answer: a test date and duration, not an assurance that backups 'run nightly'.
  • 3. What would a three-day outage of our core systems cost? Good answer: a number, owned by finance, not a shrug.
  • 4. Where does our Essential Eight maturity actually sit? Good answer: a level per strategy, independently assessed, with an uplift plan.
  • 5. Who has privileged access to our systems, and who reviewed that list last quarter? Good answer: a short list and a review cadence.
  • 6. Were our cyber insurance questionnaire answers verified against reality? Good answer: yes, independently, because optimistic answers void claims.
  • 7. What is our single points of failure list: people, providers, systems? Good answer: a documented register with owners.
  • 8. If our MSP was breached, how would we know, and what happens next? Good answer: a tested incident response path that does not depend on the breached party self-reporting promptly.
  • 9. What data do we hold that we no longer need? Good answer: a retention position, because data you deleted cannot be breached.
  • 10. What are staff doing with AI tools and our data? Good answer: a discovery-based usage map and a policy, not a guess.

The Australian regulatory hook

These questions are not best-practice garnish; they map to obligations. ASIC has treated cyber resilience as sitting inside directors' duties since its Federal Court action over inadequate cyber risk management, and its guidance expects boards to oversee it the way they oversee financial risk. For APRA-regulated entities, CPS 234 makes information security capability a board responsibility in terms, and CPS 230 extends that to operational resilience and material service providers, which is precisely where your MSP lives. The Privacy Act's notifiable data breach scheme means question nine (what data do we still hold?) has a statutory edge. Directors asking these ten questions are not being difficult; they are discharging duties that increasingly get tested in public.

The uncomfortable pattern

If most answers in your boardroom come from the same provider who runs the systems, you do not have assurance; you have advertising. Independent verification is precisely what the governance guidance calls for, and it is the entire reason this firm exists.

Get the questions with scoring

Download the Board IT Risk Questions guide, or go straight to an independent answer.

Get the Board Guide
Agility Next

Sydney HQ

119 Willoughby Road

Crows Nest NSW 2065

hello@agilitynext.com.au

Services

  • The Full IT Audit
  • MSP Audit
  • AI Audit
  • Cyber Risk Review
  • IT Cost Reduction
  • IT Due Diligence
  • IT Strategy Review

Company

  • Pricing
  • Methodology
  • Sample Report
  • IT Spend Benchmark Tool
  • Case Studies
  • Industries
  • Insights
  • About
  • Contact

Subscribe to The Audit

Monthly insights on IT governance and vendor management.

© 2026 Agility Next Pty Ltd · Proudly supported by 3P Digital

Privacy PolicyTerms & Guarantee