Security Leadership

Six questions a board should ask, and what a good answer sounds like

·5 min read

“Are we secure?” is unanswerable and everyone in the room knows it. These six are answerable, and the quality of the answer tells you more than any maturity score.

Board security reporting has a bad equilibrium. The board asks a question that cannot be answered honestly, the security lead responds with a heat map, and everyone leaves slightly less informed than they arrived. Better questions produce better programs, so here are six that work.

1. What are the three events that would hurt us most, and what would they cost?

A good answer is specific and quantified: named scenarios, a dollar and downtime estimate, and the reasoning behind the estimate. A weak answer lists threat categories such as ransomware, insider or nation-state, without connecting any of them to your business.

2. Which risks have we deliberately accepted?

Every organization accepts risk. A healthy program has a written, dated, owned list of accepted risks reviewed on a schedule. If the answer is “none,” the acceptance is happening informally, which means nobody senior has actually agreed to it.

3. If we were compromised right now, how long until we knew?

Look for a number derived from actual detection coverage and tested response, not a vendor's marketing figure. “We don't know” is an acceptable first answer if it comes with a plan to find out.

4. What did last quarter's spend buy us in risk reduction?

This is the question that separates a program from a procurement habit. A good answer ties spend to specific movement on specific risks. A weak answer lists tools deployed.

5. Which third parties could take us down?

Expect a short, ranked list with the dependency named, and ideally an answer about fourth parties too. Most organizations discover their concentration risk during someone else's outage.

6. What would you fix if I gave you unbudgeted money tomorrow?

The most revealing question of the six. If the answer is immediate and specific, there is a real prioritized plan behind it. If it takes a week to produce, the prioritization does not exist yet.

The meta-question

Notice that none of these ask for a maturity score, a framework percentage or a color. Those are useful internal instruments and poor governance instruments. Boards govern by understanding consequence, ownership and trade-off, and security is not special in that respect.

Start with a straight conversation

Thirty minutes, no deck, no pitch. Tell us what prompted the call and we will tell you what we would do about it, including when the answer is that you do not need us yet.