Help your board oversee cyber risk with confidence.
Directors are expected to oversee cyber risk with the same care they bring to financial and legal risk. Most don't want a technical briefing. They want to understand the organisation's real exposure, know what to ask management, and be ready for the day something goes wrong.
I work with boards and committees to build that understanding through practical, candid conversation rather than slide decks.
Questions we work through
- What are our most material cyber risks, in business terms?
- Is the reporting we receive telling us what we actually need to know?
- Are we investing in the right things?
- What is the board's role in the first 24 hours of a serious incident?
- What should we be asking management that we aren't?
Ways I work with boards
Board cyber briefing
A focused session of 60 to 90 minutes, delivered as part of a board meeting or strategy day.
Covers: the threat picture relevant to your sector; current expectations of boards and directors; the questions to ask management; and what good board reporting looks like.
You walk away with: a shared understanding across the board and a short list of questions to take back to management.
Board and executive incident simulation
A facilitated scenario exercise that lets directors and executives rehearse a serious cyber incident before it happens.
Covers: who makes which decisions; when regulators, insurers, customers and staff are told; and how the board and management work together under pressure.
You walk away with: a short findings report and prioritised actions to close the gaps the exercise reveals.
Cyber governance review
An independent look at how your board oversees cyber risk, using the AICD and CSCRC Cyber Security Governance Principles as a reference framework.
Covers: roles and responsibilities, board reporting, risk appetite, and incident readiness.
You walk away with: a plain-English report and a board session to discuss the findings and next steps.
Sessions for chairs and committee chairs
Confidential one-to-one sessions for board chairs and risk or audit committee chairs, whether you're preparing for a difficult discussion or want a sounding board on cyber oversight.
You walk away with: clarity on the questions to ask, and confidence in how to lead the conversation.
Who this suits
Boards and committees of listed and unlisted companies, not-for-profits, and public sector bodies that want a clearer, more confident grip on cyber risk.
How it's delivered
Sessions are delivered by video, fitting into your existing board calendar.
Information on this page is general in nature and is not legal advice.
