Skip to main content

Corporate governance

Key questions for an organisation’s board of directors

Recognising and managing risk is a crucial part of the role of an organisation’s board of directors and senior management. To enable boards to do this, organisations must have an appropriate framework to identify and manage risk on an ongoing basis.

Given the magnitude and prominence of cyber risk for most organisations, informed oversight of risk involves the board being satisfied that cyber risks are adequately addressed by the risk management framework of the organisation. Important controls include ensuring the organisation has appropriate safeguards in place against malicious cyber activities, and that recovery capabilities are adequate.

Risk management framework

Identifying cyber risk

Monitoring cyber risk

Controls

Response