CYBER RISK IS
BOARD RISK.
Every security input the board receives comes from the function being overseen. Independent testing is how that is corrected for every other material risk.
independent assurance · direct reporting · plain language
Governing a risk you are briefed on by the people managing it
Almost every input the board receives on security originates with management. That is a structural feature of the reporting line, and the reason independent assurance exists for every other material risk.
Statements the company makes on your authority
Regulatory disclosure regimes ask what the company knew and when. Answers that rest on unverified management assurance are considerably weaker after an incident than before one.
Risk acquired with a transaction
A target's security posture becomes yours at completion, including any incident already underway and undetected. Technical diligence is frequently the thinnest part of a deal review.
YOUR CHALLENGE
The board receives a quarterly security paper from the executive responsible for security. It reports controls deployed, coverage achieved, and issues closed.
None of those are outcomes. They describe activity by the function producing the report, which is precisely the arrangement that audit, external valuation, and independent assurance exist to correct elsewhere in the business.
Disclosure regimes including the SEC cybersecurity rules and the EU NIS2 Directive have raised the expectation that boards engage substantively with this risk, which is difficult to evidence from management reporting alone.
Where oversight typically thins out
- →Every security input to the board originates with the function being overseen
- →Metrics that report activity (tickets closed, coverage percentages) rather than outcome
- →No independent validation that security investment produced any effect
- →Uncertainty about director exposure under applicable disclosure regimes
- →No basis for judging whether incident response would function under pressure
- →Transactions closing with technical diligence that never tested anything
- →Disclosure obligations resting on assurances the board cannot verify
THE QUESTIONS AN ENGAGEMENT ANSWERS
Four questions that cannot be answered from a policy document, a maturity score, or a control inventory.
What would an adversary actually reach?
Not a maturity score or a traffic light. The specific systems and data a competent attacker got to during a test, and how long it took. This is the one question that cannot be answered from a policy document.
Did anything detect it?
Detection and response are the controls that determine whether an intrusion becomes an incident. Whether they functioned is a matter of record after a test, and speculation before one.
Has the position changed since last time?
Governance is demonstrated by trend, not by a single engagement. Repeat testing against comparable scope shows whether remediation held or whether the same class of finding keeps returning.
What are we accepting, and did we decide to?
Every organisation carries residual risk. The governance question is whether the board accepted it deliberately or inherited it through nobody reporting it upward.
WHAT YOU CAN DECIDE AFTERWARDS
Whether management's picture is accurate
Usually it broadly is, and confirming that has value in itself. Where it is not, the gap is specific and evidenced.
Whether the security investment is proportionate
Evidence of what held and what did not is a better input to a budget discussion than either a vendor's claim or an anxious quarter. It supports increasing spend and, occasionally, declining to.
What the board can state on the record
A documented independent engagement, with scope and limitations recorded, is a materially stronger governance position than management assurance alone, particularly if it is examined after an incident.
WHAT THE BOARD RECEIVES
FREQUENTLY ASKED
How is this different from what our CISO already reports?+
It is not necessarily different in content. A good CISO may report exactly the same findings. The difference is the reporting line. Independent testing commissioned by the board removes the structural question of whether the function assessing performance is the function being assessed, which is why audit works the way it does.
Will this undermine our security leadership?+
It should not, and where it does the engagement has been set up wrongly. Competent security leaders generally want independent evidence, because it substantiates what they have been asking for. We scope with the CISO involved unless the board has a specific reason to do otherwise.
Do you quantify our financial exposure?+
No. Loss modelling produced by a testing firm from a handful of findings is speculation with a decimal point, and it tends to be treated as fact once it reaches a board pack. We report what was reached, what detected it, and what it would take to fix. You and management are better placed to price it.
Can you brief directors who are not technical?+
Yes. The briefing covers what was attempted, what succeeded, what detected it, and what the board should be asking next. Technical detail sits in an appendix for anyone who wants it, and is not required reading for anyone who does not.
Can you assess a target before we complete?+
Yes, subject to the target's cooperation and a defined scope. What is achievable pre-completion is usually narrower than a full engagement, and the report states what was not covered.
Verify what the board is being told
Independent testing, reported to the board or audit committee directly. Scoping is confidential and normally involves the CISO.