C3SA FIELD GUIDE

BOARD CYBERSECURITY READINESS GUIDE

Questions directors and executives should ask before a cyber incident tests governance, decision rights and resilience. Use it to prepare for a board discussion, or as a checklist before commissioning training or an exercise.

THE GUIDE

SIX THINGS TO SETTLE BEFORE THE INCIDENT.

Strong cyber governance is easier to build when ownership, decision rights and priorities are explicit before an incident, not during one.

01

Know the crown-jewel services and data

Directors cannot oversee cyber risk without knowing which services and information the organization cannot afford to lose. This list drives recovery priorities, investment and exercise scenarios.

Questions to ask

  • Which services must keep running, and for how long can each be down?
  • Which data would cause the most harm if stolen, altered or published?
  • When was this list last reviewed?
02

Clarify cyber risk ownership

Cyber risk is a business risk. Someone in management should own it, and the board should know who that is and how it is reported.

Questions to ask

  • Who in management is accountable for cyber risk?
  • Which board committee oversees it?
  • What metrics do we receive, and do they show trends rather than activity?
03

Define crisis decision rights

In a major incident, decisions come fast: shutting down systems, notifying regulators, engaging law enforcement, communicating publicly and, in ransomware cases, whether to engage with the attacker. Decide in advance who can make each call.

Questions to ask

  • Who can authorize taking critical systems offline?
  • Who decides on regulatory and customer notifications?
  • What is the board's role versus management's during a crisis?
04

Test material incident escalation

Many notification obligations depend on how quickly an incident is recognized as material. Escalation thresholds should be written down and tested.

Questions to ask

  • What makes an incident material for us?
  • How quickly would the board hear about one?
  • Have we tested escalation outside business hours?
05

Understand third-party concentration risk

Critical services often depend on a small number of suppliers, cloud providers or managed service providers. A failure or compromise at one of them can become your incident.

Questions to ask

  • Which suppliers could stop our critical services?
  • Do our contracts require them to notify us of incidents, and how quickly?
  • What is our fallback if a critical provider becomes unavailable?
06

Exercise the board before the breach

A plan that has never been exercised is an assumption. A facilitated tabletop exercise lets directors and executives practise decisions under time pressure and reveals gaps safely.

Questions to ask

  • When did the board last take part in a cyber exercise?
  • What changed as a result?
  • Is the next exercise scheduled?

Last reviewed September 24, 2026. This guide is general information, not legal advice. Print or save this page to use it as a workshop handout or pre-engagement checklist.

NEXT STEP

MOVE FROM CHECKLIST TO EVIDENCE.

C3SA can help validate the current state, identify material gaps, define the target state and support implementation, testing and readiness.

UNDER ATTACK? CYBERFIRE →