Most weeks I end up in a conversation where a managing director or a board asks us some version of "are we okay on cyber?" The instinct is right but the question doesn't work, because nobody can honestly answer it with a yes.
A director can ask better questions, though, and learn to tell a good answer from a comfortable one. That applies whether you chair a formal board, run the business with two partners, or are the owner who signs off the IT budget. If the decision stops with you, so does the accountability.
Why this has become a director's question
For a long time cyber risk was treated as an IT matter that got reported upward once a year. That position is getting harder to hold.
In February 2026 the Federal Court ordered FIIG Securities to pay a $2.5 million penalty after ASIC took action over cyber security failures that came before a breach affecting around 18,000 clients. It followed ASIC's 2022 case against RI Advice, where the court accepted that failing to manage cyber risk adequately can breach a licensee's obligations. Both were financial services firms with specific licence obligations, so the direct reach is narrower than the headlines suggest. Even so, the courts have now said twice that managing cyber risk takes real resources and documented controls, and that having an IT provider does not, by itself, show you managed anything.
In October 2025 the Australian Signals Directorate published a set of questions for boards to ask about cyber security, written to sit alongside the AICD's Cyber Security Governance Principles. Both are worth reading. What follows is my shorter version, for businesses that don't have a risk committee or a chief information security officer.
1. What would hurt us most, and could we run without it for a week?
Every other question depends on this one, because you can't judge whether protection is adequate until you know what it is protecting. For most SMBs the honest answer is a short list: the finance system, client records, the practice management or line-of-business application, email, and the ability to pay staff.
A good answer names those systems, says where the data lives and who is responsible for each, and puts a rough cost on a week without each one.
A warning sign is a list of technology (firewall, antivirus, backups) in place of a list of things the business does.
2. If we were hit tomorrow, who makes which decision?
A cyber incident is mostly a decision problem. Whether to shut systems down, when to call the insurer, whether to tell clients, whether a ransom is even on the table. Those calls get made in the first few hours, often at night, by whoever happens to be awake.
A good answer names a person for each of those decisions and points to a written incident response plan that fits on a few pages. The insurer's and lawyer's contact details are stored somewhere that doesn't rely on the systems that are down, and the plan has been rehearsed in the last twelve months. Whoever answers should also know your reporting obligations. Businesses covered by the Privacy Act must assess a suspected eligible data breach within 30 days, and businesses with turnover above $3 million that make a ransom payment now have 72 hours to report it.
A warning sign is "our IT provider would handle it." Your provider runs the technical response. They can't decide whether to notify your clients, and they shouldn't be the ones speaking to your insurer about your policy.
3. When did we last restore from a backup, and how long did it take?
I like this question because a good answer contains a date and a number. "Yes, we have backups" only tells you a job is running.
A good answer gives a specific date, says what was restored and how long it took, and checks that time against what you worked out in question one. It should also confirm that at least one copy sits where ransomware can't reach it, and that your Microsoft 365 data is backed up separately, because Microsoft's retention settings are not the same thing as a backup.
A warning sign is confidence without a date. The backup reports success every night and nobody has tried to get anything back out of it.
4. Who else holds our keys?
Every business now depends on outside parties with privileged access: the IT provider, the accounting platform, payroll, the developer who built the website, the vendor who supports one critical application. The AICD gave supply chain risk its own section when it updated its principles, and with good reason. A breach at a supplier can become your breach without anything going wrong inside your own walls.
A good answer is a list of every supplier with administrative or data access, what each one can reach, when that access was last reviewed, and what the contract says about telling you if they have an incident.
That list should include us. Directors should ask their managed service provider exactly what we can access and how we protect it, and expect a straight answer. It is one of the reasons we hold ISO 27001 certification: an independent auditor checks our answer, so you don't have to take our word for it.
A warning sign is that nobody is sure whether former suppliers still have working accounts.
5. How do we know, and compared to what?
Reassurance is cheap. Evidence costs something, which is why it is worth more. Ask what the business's security is actually measured against.
A good answer names a framework, such as an Essential Eight maturity level, an SMB1001 tier or ISO 27001. It states where you are against it today and lists the gaps, with a plan that has dates and costs attached. It includes some form of independent check at least once a year, whether that is an audit, a penetration test or a review by someone who doesn't run your systems day to day. And it is reported in business terms, not as a wall of technical metrics.
A warning sign is a monthly report full of green ticks and patch counts that never mentions a gap. Every environment has gaps. A report that never shows any is measuring the wrong things.
What about spending?
Directors often want a sixth question: are we spending enough? There is no correct percentage of revenue, and I'm wary of anyone who quotes one. The FIIG judgment offers a blunter comparison: by law firm HSF Kramer's reckoning, the penalty came to more than twice what the company would have spent getting its security right in the first place. Getting the five answers above to a good standard is almost always cheaper than finding out the hard way.
Ask for evidence, not reassurance.
You don't need to understand firewall rules to govern cyber risk. You need to know what matters most, who decides in a crisis, whether recovery has been proven, who else has access, and what your security is measured against. Put those five questions on the agenda at your next board or partners' meeting and write down the answers. The gaps tend to be obvious once they're on paper.
If you'd like a second opinion on the answers, that is the work our virtual CISO service does: board-level reporting against a recognised framework, without the cost of a full-time hire. If you want to know more about the role first, I wrote about what a vCISO does and who needs one. And if question three got a long pause, start with a restore test. It is the cheapest useful thing you can do this month.
