Draft for Tamir's review. Not published.
Set a few measures the board can follow
One update a year doesn't let directors say whether the company is exposed. Ask quarterly for the status of basic controls: access, patching, tested backups and monitoring. Add the tested time to restore critical systems, open high-risk findings with owners and dates, incidents and near misses, and third-party access.
Trends matter more than any single number. Define the critical systems first, and how long the business can run without each.
Separate compliance from protection
Ask for two views together. One is compliance status against the requirements, with evidence. The other is readiness for the attacks that matter to your business, such as remote access, exposed control systems and slow recovery.
Check what an assessment's scope excluded and what the excluded sites can reach. If scores improved, ask whether the controls changed or only the definitions did. A certification customers require is worth having when its scope covers the systems they care about and gaps are fixed rather than documented around.
Depending on your seat
If you're on the board and the insurer's terms contradict management's assurances, ask for the insurer's findings. Compare management's completion reports with evidence that the controls operate. Before approving a security statement for a customer contract, compare each claim with what was actually assessed, with counsel.
If you're the CEO and customers or the insurer ask for a certification, ask them which certification and scope they accept. Get a gap assessment before engaging anyone for the full project, and fix access, patching and backups first.
What to check before you decide
- Define the critical systems and how long the business can run without each.
- Require a quarterly report on basic controls, open high-risk findings with dates, and incidents with what changed after each.
- Ask when recovery of critical systems was last tested and how long it took.
- Ask for compliance status and protection status side by side, with evidence for each.
- Where scores or definitions changed, ask for a trace from each material score to evidence of an operating control.
- Compare every security statement you're asked to sign with the scope actually assessed.
- Arrange an independent assessment periodically, reported to the board directly.
Questions people ask
Our board gets one cyber update a year and can't say if we're exposed, what should directors ask for quarterly?
Ask for a few measures the board can understand and track: the status of basic controls, the time to restore critical systems from backup as tested, the open high-risk findings with dates, incidents and near misses, and third-party access. Trends matter more than any single number. It depends on the company's critical systems and on whether the measures are already collected.
Our security program is behind, the security lead resigned and the regulator's deadline is close, what should the board do?
Get the program's state and the commitments at risk, decide what can be delivered by the deadline with interim leadership, and talk to the regulator with a plan before the date. Hire on the program's real needs rather than on urgency. It depends on which commitments are at risk and on how the regulator treats a plan with dates.
Critical infrastructure security requirements apply to our grid company, how does the board oversee real protection rather than compliance alone?
Ask for two views side by side: the compliance status against the requirements, and the protection status against the attacks that matter to a grid, such as remote access, control system exposure and recovery. Where the two differ, the board has its agenda. It depends on which systems the requirements cover and on what the company has tested.
Is a utility cyber assessment useful if remote facilities were excluded?
Judge scope against material business dependencies rather than site prominence. Selection depends on what excluded facilities can access, affect, or prevent the business from doing.
What should directors do when cyber scorecards show improvement without supporting evidence?
Reconcile scoring changes separately from changes in actual control effectiveness. Reliance depends on stable definitions, supporting evidence, and an explanation of what the board could previously infer.
Should directors approve a security attestation broader than the evidence supports?
Align representations with verified scope and known limitations. Contractual interpretation belongs with counsel, while technical review determines what the existing evidence does and does not establish.
How should directors respond when cyber insurance terms contradict management’s security assurances?
Reconcile the insurer’s stated assumptions with verified control evidence and the organization’s risk assessment. Insurance terms are one input, and improved controls do not guarantee lower premiums or coverage for a particular incident.
Customers and our insurer ask for a security certification, is it worth it and how do I do it without it being just paperwork?
Worth it when customers require it to buy, which they increasingly do; make it change real risk by choosing a scope that covers the systems customers care about and by fixing gaps rather than documenting around them. It depends on which certification your customers accept and on how far your current controls are from it.
How I can help with this decision
- Ask or talk (Free)
- I give my view on the measures a board can track without a technical education, and where your reporting and the evidence are likely to differ.
- Review (Pay if it was worth it)
- I write an independent assessment of the company's protection against the risks that matter and its compliance status, for the board. I recommend the reporting routine and what to fix or verify first.
- Retain (When it makes sense)
- I stay available to the board to review the quarterly report and test results before each meeting.