Here are seven urgent questions the board should be able to answer if they have an adequate understanding of cybersecurity:
- How is the organization protecting its most valuable assets?
- What layers of cybersecurity protection are in place to prevent an attack?
- How would the organization detect a breach?
- In the event of a breach or an attack, how would the organization respond?
- How would the board play a role in responding to an attack?
- What are the plans for recovery after a breach?
- Does cybersecurity at the organization have adequate financial and human-capital resources?