Updated: 6 July 2026
Why should CEOs and boards actively engage with data security? Information security is no longer solely an IT concern – it is a business risk with a direct impact on finances (IBM 2024: average breach cost USD 4.88 million), reputation, and operational continuity. Regulations – UK GDPR, NIS2, DORA, PCI DSS – place explicit oversight responsibility on the board. Yet CEOs and directors frequently lack the tools to assess whether the organisation is adequately protected. The right questions, asked of the CISO or IT manager, give the board that visibility without requiring technical expertise – and signal clearly to the team that security is taken seriously at the highest level.
Data security questions for the board – at a glance:
- The board is legally accountable for security oversight under UK GDPR Art. 5, NIS2 Art. 20, and DORA Art. 5 – lack of active engagement is a genuine legal risk, not merely a governance shortcoming
- Board questions must address business risk, not technical detail – the CISO should be able to answer “how much are we risking” in financial terms, not in CVE numbers
- Regular (quarterly) security reporting to the board is a requirement of ISO 27001 (management review) and DORA (Art. 5 – the role of the management body)
- Symptoms of an ineffective security programme: no current risk register, no tested incident response plan, no metric-based security report for the board
- CEOs and CFOs should know the estimated cost of a realistic security incident for their organisation – this is the foundation of an informed budget decision
- Patronusec in the vCISO role helps boards prepare decision-ready materials in business language, conduct management reviews, and build security programmes with the right accountabilities
Table of Contents
What 10 questions should the CEO or board ask the CISO or IT manager?
The following questions require no technical knowledge – they are questions about business risk and organisational readiness.
Question 1: What are our three biggest cyber risks and what could they cost us?
What to expect: a specific list of risks with estimated financial impact (not “high risk” but “ransomware risk – estimated cost £1.5 to £4 million”). The answer should derive from a current risk assessment, not from memory.
Warning sign: a vague answer (“we face many threats”), no figures, or “difficult to say.” This indicates the absence of a formal risk assessment.
Question 2: If we were hit by ransomware today, how long before we are operating normally?
What to expect: a specific number of hours or days for critical systems (RTO), based on a backup restoration test conducted within the past 12 months.
Warning sign: “we have backups” without stating an RTO or confirming that backups have been tested. An untested backup is a hypothesis, not a safeguard.
Question 3: Who in the organisation can authorise disconnecting our systems from the internet at 3am during a crisis?
What to expect: a named individual with documented authority to make that decision and an emergency contact number that works out of hours.
Warning sign: “they’d need to contact the IT manager” or “we’d check who was available.” Decision paralysis during an incident costs hours – and hours cost money.
Question 4: When did we last check whether an external attacker could get into our network?
What to expect: the date of the most recent penetration test and a brief summary of results. For companies handling payment data or subject to NIS2, a penetration test is a regulatory requirement.
Warning sign: “never” or “a few years ago” – particularly for a firm processing sensitive data. Attackers scan organisations continuously; if we do not check ourselves, we do not know what they will find.
Patronusec Insight: The greatest value of well-framed board questions is the shift in dynamic between the board and the CISO. When the board asks “how much are we risking in financial terms” rather than “are we secure,” the CISO is obliged to translate technical risk into financial language – which is the foundation of effective security governance. Organisations where the board actively engages with security typically have better-implemented controls and lower incident costs. We help clients prepare board-ready materials as part of our vCISO service.
Question 5: Do we verify the security of our suppliers, such as software or cloud providers?
What to expect: a list of key suppliers with confirmation of their security certifications (ISO 27001, SOC 2, PCI DSS). Any supplier with access to company data must have documented security credentials.
Warning sign: “we assume they are secure because they are a large company.” MOVEit, SolarWinds, and dozens of other incidents demonstrated that “large company” does not mean “secure.” Responsibility for verifying suppliers sits with you.
Question 6: What happens if our key IT person leaves tomorrow? Do we have access to passwords and systems?
What to expect: confirmation that critical passwords and access credentials are stored in a company-managed Password Manager or PAM (Privileged Access Management) solution – not solely in one person’s memory.
Warning sign: “they would need to hand it over before leaving” or “we have it written down somewhere.” A single point of knowledge in IT is both a security risk (excessive access for one person) and an operational risk (what happens when they leave?).
Question 7: Have we had any security incidents in the past 12 months, even minor ones?
What to expect: an honest list of incidents (phishing clicks, unauthorised access, data sent to the wrong recipient) with a brief description of what happened and how it was resolved.
Warning sign: “no, nothing has happened.” Organisations reporting zero incidents typically lack the tools to detect them – the issue is absence of visibility, not absence of incidents. A CISO reporting zero incidents for a year should explain how they are measuring that.
Question 8: Do our employees know how to recognise phishing and what to do about it?
What to expect: confirmation of regular training and phishing simulations with results (for example, “15% clicked the simulated phishing link six months ago versus 7% today”). A number, not a general declaration.
Warning sign: “we ran a training session at the start of the year.” A single annual training event does not change behaviour – Verizon DBIR consistently shows the human element is present in 68% of breaches. Without regular exercises and measurable outcomes, training is a compliance formality.
Patronusec Insight: The phishing question is a reliable indicator of whether the security programme is active or merely documented. An active programme has data: “in our last simulation, 18% of employees clicked the phishing link; six months earlier it was 32%.” A paper programme has a confirmation: “we ticked the training boxes this year.” The difference between these answers tells the board more about programme maturity than any formal report. Phishing simulations and training are part of our vCISO service.
Question 9: Do we have cyber insurance, and what does it cover?
What to expect: confirmation of a policy with a brief description of scope (IR costs, customer notification, regulatory fines, ransom) and its limits. An ideal answer also includes what the insurer required us to implement as a condition of the policy.
Warning sign: “we don’t have any” or “I’m not sure.” Cyber insurance is increasingly standard – and the insurer’s minimum security requirements are themselves a useful baseline for controls.
Question 10: How do we report on security to the board, and how often?
What to expect: regular (quarterly) board reports with key metrics: risk status, incident summary, test results, security programme progress, and budget. ISO 27001 requires an annual management review as a minimum.
Warning sign: “we report when something happens” or “we can prepare a presentation if the board asks.” Reactive security reporting is a symptom of absent governance – the board learns about problems after the fact.
Want to build a regular security dialogue between the board and your CISO or IT team?
Patronusec in the vCISO role prepares quarterly board reports in business language and conducts management reviews required by ISO 27001. The board receives what it needs to make decisions – not a technical briefing.
Book a free consultation on board security reporting
What answers should prompt the board to investigate further?
The following signals should lead the board to a deeper review of the security programme.
Red flags in CISO or IT responses:
- “Everything is under control” without concrete metrics supporting that assessment
- “We have all the tools we need” – tools without processes and people do not protect
- “We have not had any incidents” without explaining how incidents are detected
- “We back up daily” without stating when restoration was last tested
- “We do pentests when we have time” rather than a scheduled programme with results
- “The board does not need to know the technical details” – the board should understand business risks
What to do after identifying gaps:
The goal is not to penalise the CISO for honest answers – it is diagnosis. If responses indicate gaps, the next steps are: assess priority (what is most critical?), build an action plan with timeline and budget, assign a responsible owner and a delivery date, and follow up at the next review.
FAQ – Data security questions for the board
Is the CEO personally liable for a data security breach?
Yes – to varying degrees depending on the regulatory framework. UK GDPR Art. 5.2 places accountability for compliance and the ability to demonstrate it on the data controller (typically the organisation). NIS2 Art. 20 places governance obligations directly on the management body. DORA Art. 5 requires active board engagement in ICT risk management. In the event of a breach, a regulator may examine whether the board implemented appropriate measures.
How often should the board discuss security?
ISO 27001 requires an annual management review as a minimum, but best practice is quarterly. DORA requires at least annual reporting to the management body covering the ICT risk programme and incidents. For organisations with a high risk profile – fintech, healthcare, critical infrastructure – quarterly is the minimum.
What is a management review under ISO 27001?
A management review is a formal meeting at which the board assesses the state of the ISMS (information security management system): audit results, incident status, progress against security objectives, changes in external context. Outputs must be documented. It is a requirement of ISO/IEC 27001:2022 Clause 9.3.
How do you translate cyber risk into financial language for the board?
The formula: Risk = Probability × Impact. For the board: “We estimate that at current control levels, the probability of a ransomware incident is X% per year. The estimated cost of such an incident (restoration, regulatory fines, customer loss) is Y. An investment of Z would reduce the probability by half and reduce recovery time by 80%.” This framing allows the board to make an informed budget decision.
How does Patronusec support the board-CISO dialogue?
In the vCISO role, we prepare quarterly board reports in business language – no technical jargon, concrete numbers, and decision-ready recommendations. We also conduct management reviews required by ISO 27001 and advise on how to structure security reporting for regulators such as the ICO or FCA.
What if the company does not have a CISO – who answers these questions?
In small and mid-sized organisations, the CISO function is often combined with the IT manager role or outsourced to a vCISO. If no one can answer these 10 questions, that is itself a signal that the organisation needs either an internal security structure or an external vCISO as an adviser. Patronusec offers vCISO models scaled to organisational size – from a few hours per month to full outsourcing of the CISO function.
Data security and the board-CISO dialogue – free consultation
Patronusec as a vCISO partner helps boards build active security oversight – from board materials and management reviews to building a security culture across the organisation.
In a free 30-minute consultation we will help you:
- Assess whether the current board-CISO dialogue gives the board sufficient visibility into risk
- Plan the structure of a quarterly security report for the board
- Identify the key questions the board should be asking regularly
- Discuss support options: vCISO, management reviews, board-level security briefings
Free consultation | vCISO service | ISO 27001 | DORA compliance | NIS2