Governance

Cyber risk oversight: how directors can meet regulator expectations

Cyber risk has moved well beyond the IT department. Australian regulators, courts and cyber security agencies are now sending a consistent message to directors: cyber resilience is a board-level governance issue, and passive reliance on management assurance is no longer enough.

Recent decisions involving Australian Clinical Labs, Vinomofo, RI Advice and FIIG Securities show that regulators are looking for evidence of active oversight, proportionate controls, adequate resourcing, timely incident assessment and clear accountability. ASIC’s recent guidance on cyber resilience and frontier AI reinforces the same point: boards and executives need to act now, focus on the fundamentals, and be able to demonstrate that cyber resilience is working in practice.

For directors, the question is no longer, “Do we have a cyber security program?”

The better question is, “Can we evidence that our cyber risk management is effective, proportionate to our organisation, and tested under real-world conditions?”

Figure 1: Cyber Risk for Boards

The regulatory message is becoming clearer

Several themes now stand out.

First, regulators expect cyber risk to be managed as a core business risk. It is tied to customer trust, operational continuity, legal compliance, financial exposure and reputation. Directors do not need to become cyber technologists, but they do need to understand whether the organisation’s cyber risk settings are appropriate for its size, complexity, data holdings and threat environment.

Second, regulators are looking beyond policies. Having an incident response plan, a cyber strategy or an external provider is not enough. The expectation is that controls are implemented, tested, monitored, independently validated where appropriate, and improved when weaknesses are identified.

Third, resourcing matters. A board cannot credibly claim cyber risk is important while approving inadequate funding, accepting prolonged capability gaps, or allowing critical controls to remain unresolved without clear risk acceptance.

Fourth, incident response and notification obligations need serious board attention. Recent privacy enforcement action has shown that slow or inadequate assessment of a suspected eligible data breach can itself create legal exposure, separate from the original cyber incident.

Finally, artificial intelligence is increasing the pressure. ASIC and Five Eyes cyber security agencies have warned that AI is accelerating the speed, scale and sophistication of cyber threats. This does not mean every board needs a new AI cyber program overnight. It does mean the basics need to be demonstrably robust, because weaknesses that were once manageable may now be exploited faster and chained together more easily.

What directors should be doing now

1. Put cyber risk formally on the board agenda

Cyber should not appear once a year, buried in an IT update. It should be a standing governance topic for the board or relevant committee, with clear escalation to the full board when risks affect strategy, operations, customers, regulatory obligations or reputation.

Directors should confirm where cyber oversight sits: full board, audit and risk committee, technology committee or another forum. The important point is not the label. It is whether the structure creates real accountability, informed challenge and decision-making.

A good board pack should show the top cyber risks, changes in threat environment, current control gaps, significant incidents, third-party exposure, remediation progress, and decisions required from directors. If the report is full of jargon, traffic lights and unexplained acronyms, it is not good enough.

Board minutes should also show active oversight. Regulators and courts will not be impressed by a record that says the board “noted” a cyber update without evidence of challenge, direction or follow-up.

2. Demand evidence, not comfort

Directors should be wary of vague statements such as “our controls are strong”, “we have an incident response plan”, or “our suppliers are secure”. These are comfort statements. Regulators are increasingly interested in evidence.

Better board questions include:

“What independent testing has been performed, and what did it find?”

“What critical risks remain outside appetite?”

“Which remediation items are overdue, and who owns them?”

“What assumptions are we making about our ability to recover?”

“Which third parties could materially disrupt us or expose sensitive data?”

“Have we tested the incident response plan with executives and directors, not just IT?”

Good cyber governance is not about perfect security. It is about being able to show that the organisation understands its risks, has appropriate controls, tests those controls, escalates weaknesses and makes informed decisions.

3. Confirm the organisation knows its critical assets and data

One of the most basic questions remains one of the most important: do we know what matters most?

Directors should require management to identify the organisation’s critical systems, key data holdings, essential business services, privileged access pathways, cloud environments and high-risk suppliers. This should include personal information, sensitive information, customer records, financial data, intellectual property and operational systems.

If management cannot clearly explain where critical data is held, who can access it, how it is protected, how long it is retained and how it would be recovered, the board has a governance problem.

This matters especially during technology change, cloud migration, acquisitions and system integrations. Recent privacy cases show that regulators will scrutinise whether reasonable steps were taken to protect personal information during migrations, acquisitions and inherited technology environments.

4. Review whether cyber controls are proportionate and working

ASIC’s recent position is blunt: cyber risk management must be demonstrably effective and proportionate to the size, nature and complexity of the business.

That means directors should not ask only whether controls exist. They should ask whether controls are appropriate and operating effectively.

At a minimum, boards should seek reporting on access controls, multi-factor authentication, patching, vulnerability management, logging and monitoring, backups, endpoint protection, email security, privileged access management, incident response readiness and third-party risk management.

For Australian organisations, the ASD Essential Eight remains a useful baseline, but directors should avoid treating any framework as a checkbox exercise. The real issue is whether the organisation’s controls match the risk profile, data sensitivity, operational dependency and threat environment.

Where management reports exceptions, directors should ask: What is the business impact? Who accepted the risk? What is the deadline? What compensating controls exist? What would accelerate remediation?

5. Check cyber capability and resourcing

A recurring lesson from recent ASIC action is that cyber failure is not only a technology problem. It can also be a resourcing problem.

Boards should ask whether the organisation has enough financial, technological and human capability to manage cyber risk. This includes internal capability, outsourced expertise, clear role ownership, adequate budget, and sufficient authority for cyber leaders to influence business decisions.

If the CISO or equivalent cannot obtain timely funding for critical controls, cannot escalate material risks, or lacks access to the board, that is a governance weakness.

Directors should also be careful about over-reliance on external providers. Outsourcing cyber work does not outsource accountability. The board still needs assurance that external providers are properly scoped, monitored and challenged.

6. Test incident response before the incident

A cyber incident is a poor time to discover that decision rights are unclear, backups do not restore, legal notifications are misunderstood, or communications drafts do not exist.

Directors should require regular incident simulations involving the board, CEO, legal, communications, technology, operations and customer-facing leaders. These simulations should test realistic scenarios, including ransomware, data exfiltration, supplier compromise, business email compromise, cloud outage and critical system disruption.

The board should see the outcomes of these exercises, including gaps, actions, owners and due dates.

A strong incident response program should answer:

Who decides whether to shut down systems?

Who determines whether notification obligations are triggered?

Who approves communications to customers, regulators, staff and media?

What services must be restored first?

How do we know backups are clean and recoverable?

What external support is already on standby?

The obligation is not just to have a plan. It is to have a plan that works under pressure.

7. Strengthen data breach assessment and notification processes

The Australian Clinical Labs decision is an important warning. The issue was not only the cyber attack itself. The case also involved failures relating to assessment and notification under the Notifiable Data Breaches scheme.

Directors should ensure management has a clear process for assessing suspected eligible data breaches quickly and thoroughly. That process should include legal, privacy, cyber security, communications and executive decision-makers.

The board should ask whether the organisation can identify when reasonable grounds exist to suspect or believe there has been an eligible data breach, what information must be gathered, who makes the call, and how quickly the OAIC and affected individuals can be notified if required.

Slow, narrow or overly optimistic assessment can create additional regulatory exposure.

8. Reassess supplier, cloud and technology change risk

Many serious cyber incidents involve suppliers, inherited systems, cloud misconfiguration or technology change. Boards should require clear visibility of critical third parties and cloud services.

Questions directors should ask include:

Which suppliers handle sensitive data or support critical operations?

Do contracts include breach notification, audit rights, security obligations and exit provisions?

Are critical suppliers included in incident response exercises?

Do we know our concentration risks?

Are cloud environments logged, monitored and configured securely?

How are cyber risks assessed during mergers, acquisitions and system migrations?

The Vinomofo determination is a useful reminder that cloud environments and data migration projects are not low-risk administrative tasks. They can create serious privacy and cyber exposure if access settings, logging, monitoring and security baselines are not properly managed.

9. Respond to AI-enabled cyber risk by strengthening the basics

AI is changing the threat environment, but the immediate board response should be disciplined rather than theatrical.

ASIC and Five Eyes cyber security agencies have both emphasised that AI is increasing the speed and scale of attacks. The answer is not panic. The answer is to strengthen cyber resilience fundamentals.

Directors should ask management how AI-enabled threats affect phishing, vulnerability exploitation, identity attacks, software development, monitoring, incident response and third-party risk.

They should also ask whether the organisation is using AI defensively, where appropriate, to identify vulnerabilities, detect unusual behaviour, improve software quality and speed up response.

But the baseline remains the same: reduce attack surface, patch faster, strengthen identity controls, address legacy systems, test response plans, and ensure cyber leaders have authority and resources.

10. Build a defensible record of oversight

Directors do not need to guarantee that no cyber incident will occur. That is impossible. What they do need is a defensible record that shows they took cyber risk seriously, asked informed questions, required evidence, made decisions, and followed through.

That record should include board papers, committee minutes, risk appetite decisions, cyber dashboards, incident simulation outcomes, assurance reports, remediation tracking, supplier risk reporting, legal briefings and budget decisions.

If a regulator later asks, “What did the board know, when did it know it, and what did it do?”, the organisation should be able to answer clearly.

The board’s immediate action list

Directors should ask management to bring the following to the next board or risk committee meeting:

  1. The top five cyber scenarios most likely to materially affect the organisation.
  2. A map of critical systems, sensitive data and high-risk suppliers.
  3. Current cyber risk appetite status and risks outside appetite.
  4. Independent assurance or testing results for key controls.
  5. A remediation register showing overdue items, owners and due dates.
  6. Incident response and data breach notification playbooks.
  7. Results from the most recent tabletop exercise.
  8. A cyber capability and resourcing assessment.
  9. Reporting on AI-enabled cyber risks and defensive use of AI.
  10. A clear list of board decisions required.

This is not about directors running cyber security. It is about directors governing cyber risk.

Final thought

The regulatory direction is obvious. Boards are expected to understand cyber risk, resource it properly, test resilience, challenge management and evidence their oversight.

The organisations that will be best placed are not necessarily those with the biggest security budgets. They will be the ones that know what matters most, execute the basics well, test honestly, fix weaknesses quickly and keep cyber risk connected to business strategy.

For directors, the time to act is now. Not after the next incident. Not after the next regulatory letter. Now.