“Our board started asking questions.”
Your board wants an answer you can defend.
A nonprofit we work with went through exactly this. Their board began asking about cybersecurity, and the honest answer from management was that they believed things were fine but could not demonstrate it.
We ran an assessment and presented the findings to the board directly. That meeting changed the conversation, not because the findings were alarming, but because for the first time everyone in the room was looking at the same evidence rather than trading reassurances.
They upgraded their services, signed for three years, and later renewed for five.
Right now
What is probably true today.
Based on what we find in businesses that arrive this way. Not all of it will apply. Enough of it usually does.
-
You believe things are broadly fine, and you are probably right about most of it.
-
You cannot currently prove any of it, which is a different problem and the one the board actually has.
-
The board is not asking for reassurance. They are asking because they carry fiduciary responsibility and have realised they have no visibility.
-
Somebody will eventually ask whether you have a written incident response plan. That question has a yes or no answer.
Regardless of who you hire
What to do this week.
None of this requires us. Do it yourself, or hand it to whoever helps you with technology.
-
1
Write down what you would say if asked at the next meeting
Read it back and mark every sentence containing "I think," "probably," or "should be." Those are the parts a board cannot act on.
-
2
Ask the board what would satisfy them
Sometimes it is a written plan. Sometimes it is an independent assessment. Sometimes it is simply a standing agenda item. Knowing which saves a great deal of effort aimed at the wrong target.
-
3
Get something independent in writing
Board confidence comes from evidence someone outside the organization produced. That is most of the value of an assessment in this situation.
Worth reading next
How to Talk to Your Board or Investors About Cybersecurity Risk in Business Terms They Understand
Boards disengage when cybersecurity turns technical. A translation framework: outcomes at risk, realistic scenarios, financial impact, decision needed.
How to Create a Cybersecurity Budget For Small Business
A repeatable framework for deciding what to spend on cybersecurity: impact first, then capabilities, then a 12-18 month roadmap your CFO can defend.
If you would rather not work through it alone
Fifteen minutes, and we will tell you what we would do.
No pitch on the first call. Tell us what happened and we will tell you honestly how serious it is, what we would tackle first, and whether you need an assessment at all.
No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.