Board Cyber Risk Oversight: A Director's Real Job
Cyber risk is a board accountability now, not an IT problem. What directors are actually responsible for, the questions to ask, and the legal exposure.

Board Cyber Risk Oversight: A Director's Real Job
Cyber risk stopped being an IT problem some time ago. It is now a board accountability, and directors who still treat it as something the technology team handles are exposed in a way they may not realise. Board cyber risk oversight is the work of governing that risk from the top, making sure the business understands what it stands to lose, has invested sensibly to protect it, and knows what it will do when, not if, something gets through. I have sat on boards and chaired advisory boards through the years when this shifted from a niche concern to a standing agenda item, and I have watched capable directors get caught out because they assumed someone else owned it.
This is a guide for directors and founders on what cyber risk oversight actually requires, where the line sits between governing and doing, and the questions a board should be asking long before an incident forces the conversation.
Why cyber risk oversight belongs to the board, not the IT team
The instinct is understandable. Cyber sounds technical, so it feels like it should live with the people who understand the technology. The problem is that cyber risk is not really a technology risk. It is a business risk that happens to have a technical trigger.
When a breach hits, the damage is not measured in servers. It is measured in customer trust, regulatory exposure, contractual liability, operational downtime and the cost of putting it all back together. Those are exactly the things a board exists to govern. The IT team can tell you how an attack happened and what to patch. Only the board can weigh how much risk the business should carry, how much to invest against it, and what the organisation's tolerance actually is. That is a governance judgement, and it cannot be delegated to the people running the systems any more than financial risk can be delegated entirely to the finance team.
There is a hard edge to this too. Directors carry a duty to exercise care and diligence, and regulators increasingly expect that duty to extend to cyber risk. A board that never asked the questions, never saw the reporting and never tested whether the business was ready is not in a strong position after the fact. Oversight is not optional, and ignorance is not a defence.
What directors are actually accountable for
The most common mistake boards make with cyber is swinging to one of two extremes. Either they ignore it as too technical, or they overcorrect and try to involve themselves in decisions that belong to management. Neither is oversight.
The board's job is not to choose the firewall or run the incident response. The board's job is to make sure the business has identified its most valuable and most vulnerable assets, has invested proportionately to protect them, has a plan for when something fails, and reports on all of this honestly and regularly. Directors govern the framework and the accountability. Management owns the implementation. Getting that line right is the whole discipline, and it is the same line that separates a functioning board from one that has outgrown its governance structure.
In practice that means the board should be able to answer a short set of questions at any time. What are our crown jewels, the data and systems we cannot afford to lose. Who is accountable for protecting them. How much have we invested and is it proportionate to the risk. What would we do in the first twenty-four hours of a serious breach. If the board cannot answer those, it is not exercising oversight, it is hoping.
The questions every board should be asking
Good oversight is mostly good questions asked consistently. A board does not need to become technical to govern cyber well. It needs to be relentless about the right handful of issues.
Start with the assets. Ask management to name the specific data and systems whose loss or exposure would do the most damage, and to explain how they are protected. If the answer is vague, that is your finding.
Move to the basics. Most breaches do not come from sophisticated attacks. They come from unpatched systems, weak access controls and people clicking things they should not. Ask whether the business has implemented recognised baseline controls such as the Essential Eight published by the Australian Cyber Security Centre, and if not, why not. This is the cyber equivalent of asking whether the doors are locked.
Ask about people. Ask when the last phishing test was run and what it showed. Ask whether staff know how to report something suspicious. Culture and training defeat more attacks than any single piece of software.
Ask about readiness. The question that separates prepared boards from exposed ones is simple. When were we last tested, and what happened. A business that has never run an incident simulation does not know whether its plan works, and the middle of a real breach is a terrible time to find out.
Finally, ask about third parties. Your risk does not stop at your own perimeter. A supplier, a contractor or a piece of software with access to your systems is your exposure too. Boards that only look inward miss where a growing share of incidents originate.
Where AI raises the stakes
Cyber risk was already a board issue before artificial intelligence entered the picture. AI has not changed the nature of the duty, but it has raised the stakes on both sides of the equation, which is why it belongs in this conversation rather than in a separate one.
On the attacker's side, AI has made social engineering cheaper and more convincing. Phishing that once had obvious tells now arrives in clean, personalised language. Voice and video can be faked well enough to fool a rushed employee. The volume and quality of attacks have both gone up. On the defender's side, businesses are adopting AI tools quickly, often faster than their governance can keep up, and every new tool that touches company data is a new surface to protect and a new question about where that data goes.
The board's response is not to become expert in AI security. It is to fold AI into the same oversight discipline. When management proposes a new AI tool, the board should expect the same questions it would ask of any system handling sensitive data. Who has access, where does the data live, what is the exposure if it is compromised. This connects directly to the broader work of governing technology at board level, which I cover in what to show your board about AI and in the wider view of AI for boards. Cyber is one thread of that larger responsibility, and it is the one with the sharpest immediate consequences.
The regulatory and legal reality in Australia
The expectation on directors has hardened. Australian regulators have made clear that cyber governance sits within a director's duty of care, and they have shown a willingness to act where boards have been passive. For financial services and other regulated sectors, prudential standards set explicit requirements for information security and for board-level accountability. Even outside regulated industries, privacy obligations and the duty to act with reasonable care create real exposure when a board has failed to govern a foreseeable risk.
I am not a lawyer and this is not legal advice, so any board serious about this should get proper guidance specific to its industry and obligations. The point for directors is simpler. The regulatory direction of travel is one way. The expectation that boards will actively oversee cyber risk is only going to increase, and the organisations that treat it as a genuine governance responsibility now will be far better placed than those that wait to be forced. The Australian Institute of Company Directors publishes governance guidance for directors through the AICD, and cyber has become a standing part of that conversation for good reason.
Building cyber into the board's rhythm
Oversight fails when it is a one-off. A board that discusses cyber once after a scare and then forgets it for two years is not governing the risk, it is reacting to it. The fix is rhythm.
Cyber belongs on the board agenda on a regular cycle, not only when something goes wrong. That means a standing reporting line from management, in language the board can actually use rather than a technical dump. It means periodic testing, a simulated incident that puts the plan under pressure and surfaces the gaps while they are cheap to fix. It means clarity on who the board hears from in a crisis and how fast. And it means the board revisiting its risk appetite as the business grows, because the exposure of a five million dollar business and a fifty million dollar business are not the same, and the controls that were adequate at one stage quietly become inadequate at the next.
Board cyber risk oversight is not about turning directors into technologists. It is about applying the same discipline the board brings to every other serious risk. Know what you stand to lose. Invest proportionately. Be ready for failure. Ask the hard questions before you are forced to. Do that consistently, and cyber becomes a governed risk like any other rather than the thing that blindsides the business and the board with it.
Your suppliers are your attack surface
A growing share of serious incidents do not start inside the business at all. They start with a supplier, a contractor or a piece of software that has access to your systems or your data. Your risk does not stop at your own perimeter, and a board that only looks inward is governing half the problem.
The board should expect management to know which third parties have access to critical systems or sensitive data, what security those third parties maintain, and what happens to the business if one of them is compromised. A small software vendor with a login to your customer database is your exposure, not just theirs. The supply chain has become one of the most common routes into otherwise well-defended businesses, precisely because attackers know the weakest link is often not the target itself but someone it trusts.
This is not about auditing every supplier to death. It is about the board making sure the business has identified the third parties that matter, holds them to a standard proportionate to the access they have, and has thought through what it would do if one of them failed.
The first seventy-two hours: the board's role in a breach
When a serious breach hits, the board's job changes shape but it does not disappear. This is not the moment for directors to start running the response, which belongs to management and the specialists. But the board has real work in a crisis, and boards that have thought about it in advance handle it far better than those improvising under pressure.
The board's role in the first hours is oversight of the response, not execution of it. Is the right team engaged. Have the legal and regulatory obligations been identified, including any mandatory breach notifications and their deadlines. Is someone managing communications to customers, staff and the market honestly and quickly. Are we preserving evidence rather than destroying it in a rush to fix things. And is the business making decisions that protect the long term rather than just the next news cycle.
The organisations that come through a breach with their reputation intact are almost always the ones that were honest, fast and prepared. The ones that compound the damage are the ones that went quiet, downplayed it, or were visibly making it up as they went. A board that has rehearsed this, even once, knows which of those it will be.
What good cyber reporting to a board looks like
Most cyber reporting to boards is either a technical dump nobody can use or a single green light that tells the board nothing. Neither is oversight. Good reporting sits in between, in the language of risk rather than the language of systems.
A board does not need to know how many attacks the firewall blocked last month. It needs to know whether the controls protecting the crown jewels are working, where the gaps are, what is being done to close them, and how the business's exposure is changing over time. It needs the trend, not the noise. It needs to hear about the near misses, not only the clean months, because a near miss is the cheapest lesson available and burying it wastes it. And it needs honesty about what is not yet good enough, because a board that only ever hears good news is being managed rather than informing itself.
The test of good reporting is simple. After reading it, can the board say whether the business is more or less exposed than it was last quarter, and why. If it cannot, the reporting is decoration.
Understand what your cyber insurance actually covers
Many boards take quiet comfort from a cyber insurance policy without understanding what it does and does not do. That comfort can be dangerous. Insurance is a backstop for some of the financial cost of an incident. It is not a substitute for governance, and it does not restore lost customer trust or undo a regulatory finding.
Policies carry conditions, and a growing number require the insured business to maintain certain controls for a claim to be paid. A board that assumed it was covered can discover, at the worst possible moment, that a lapsed control or an unmet condition has voided the protection it was relying on. The board should understand in plain terms what the policy covers, what it excludes, what conditions attach, and where the real exposure sits beyond the limit of the cover. Insurance is one part of a cyber risk strategy. It is not the strategy.
FAQs
Whose job is cyber risk, the board or the IT team? Both, in different ways. The IT team owns implementation, the technical controls and the response. The board owns oversight, making sure the business has identified its key risks, invested proportionately, and has a tested plan. Cyber is a business risk with a technical trigger, so governing it cannot be fully delegated to technologists.
Do directors have legal exposure for cyber failures? Increasingly, yes. Cyber governance is treated as part of a director's duty of care, and regulators have shown a willingness to act where boards have been passive. A board that never asked the questions, saw no reporting and never tested readiness is poorly placed after an incident. Any board serious about this should seek advice specific to its industry.
What should a board actually ask about cyber? Start with five things: what are our most valuable and vulnerable assets, who is accountable for them, have we implemented recognised baseline controls, when were we last tested and what happened, and what is our third-party exposure. Consistent questions matter more than technical depth.
How does AI change cyber risk for boards? AI has made attacks cheaper and more convincing, and it has multiplied the number of tools touching company data. It does not change the board's duty, but it raises the stakes. The board should hold new AI tools to the same oversight questions it would ask of any system handling sensitive data.
How often should the board discuss cyber? On a regular cycle, not only after a scare. That means a standing reporting line from management in plain language, periodic incident simulations that test the plan, and a review of the business's risk appetite as it grows, because controls that were adequate at one stage become inadequate at the next.
Is cyber a real item on your board agenda, or just a worry?
There is a difference between worrying about cyber and governing it. One keeps you up at night, the other puts the right questions, reporting and readiness in place so the risk is managed rather than feared. If your board knows it should be doing more here but is not sure what good oversight looks like, that is a solvable problem.
