Board Governance
The 10 cyber questions every Australian board should ask
Cyber resilience sits inside directors' duties, and the ACSC and AICD now publish exactly the questions boards are expected to ask. Here are the ten that matter, with the shape of a good answer for each. The pattern to notice: every good answer involves evidence, and most of that evidence should be independent.
The ten questions
- 1. When were our security controls last tested by someone independent of the people who run them? Good answer: a date within the year, a named firm and findings the board saw.
- 2. When did we last successfully restore from backup, end to end? Good answer: a test date and duration, not an assurance that backups 'run nightly'.
- 3. What would a three-day outage of our core systems cost? Good answer: a number, owned by finance, not a shrug.
- 4. Where does our Essential Eight maturity actually sit? Good answer: a level per strategy, independently assessed, with an uplift plan.
- 5. Who has privileged access to our systems, and who reviewed that list last quarter? Good answer: a short list and a review cadence.
- 6. Were our cyber insurance questionnaire answers verified against reality? Good answer: yes, independently, because optimistic answers void claims.
- 7. What is our single points of failure list: people, providers, systems? Good answer: a documented register with owners.
- 8. If our MSP was breached, how would we know, and what happens next? Good answer: a tested incident response path that does not depend on the breached party self-reporting promptly.
- 9. What data do we hold that we no longer need? Good answer: a retention position, because data you deleted cannot be breached.
- 10. What are staff doing with AI tools and our data? Good answer: a discovery-based usage map and a policy, not a guess.
The Australian regulatory hook
These questions are not best-practice garnish; they map to obligations. ASIC has treated cyber resilience as sitting inside directors' duties since its Federal Court action over inadequate cyber risk management, and its guidance expects boards to oversee it the way they oversee financial risk. For APRA-regulated entities, CPS 234 makes information security capability a board responsibility in terms, and CPS 230 extends that to operational resilience and material service providers, which is precisely where your MSP lives. The Privacy Act's notifiable data breach scheme means question nine (what data do we still hold?) has a statutory edge. Directors asking these ten questions are not being difficult; they are discharging duties that increasingly get tested in public.
The uncomfortable pattern
If most answers in your boardroom come from the same provider who runs the systems, you do not have assurance; you have advertising. Independent verification is precisely what the governance guidance calls for, and it is the entire reason this firm exists.
Get the questions with scoring
Download the Board IT Risk Questions guide, or go straight to an independent answer.
Get the Board Guide