PLAYBOOK

Cyber Risk Discussion Guide for Boardrooms

Helping boards ask better questions about cybersecurity & resilience

Continue reading

To help frame the types of governance gaps and oversight challenges boards commonly encounter when managing cyber risk, this guide draws on two case studies. These examples reflect patterns frequently observed across organizations where cyber risk management can evolve to better align with board‑level responsibilities, oversight structures, and decision‑making processes.

CASE STUDY

First American Financial (2023)

When cyber risk failed to reach the board

Learn more

CASE STUDY

SolarWinds/SUNBURST (2020)

When cyber risk became a securities issue

Learn more

Common gaps in board‑level cyber risk management

01

Lack of board-level cyber oversight

Failure to ensure cybersecurity governance at an executive level

02

Inadequate risk management practices

Absence of proactive threat assessments and mitigation strategies

03

Technical vulnerabilities

Poor firewall configurations and failure to apply security patches

04

Neglect of employee training

Lack of cybersecurity awareness and response preparedness among staff

05

Underinvestment in cybersecurity resources

Insufficient funding and staffing dedicated to cyber resilience

Areas of focus for high-performing boards

01

Cybersecurity should be a strategic priority

Boards should prioritize cyber risk as a critical business risk and embed it within governance structures. Regular security audits and assessments include routine reviews of security policies, technologies, and compliance.

02

Proactive threat management

Organizations should consider adopting a risk-based approach to continuously identify and mitigate cyber threats. Without proactive threat assessments and mitigation, organizations operate with blind spots that materially increase cyber risk.

03

Employee training and awareness

Comprehensive and ongoing cybersecurity education should be integrated into corporate culture. Recurring control weaknesses, including firewall misconfigurations and delayed patching, signal gaps in organizational cyber maturity.

04

Resilient infrastructure investments

Boards should consider sufficient financial and technological resources are allocated to cybersecurity initiatives.

05

The role of cyber insurance

Cyber insurance is a critical complement to cybersecurity, helping provide financial protection and rapid access to breach counsel and incident response experts. Insurer requirements also strengthen security practices. For boards, prioritizing cyber insurance helps enhance resilience, support governance, and helps ensure operational continuity in an evolving threat landscape.

The 2026 edition of our cyber boardroom guide

This guide will help determine the difference between foundational and advanced boardroom questions when it comes to cyber risk management.

+ Click below to expand each of the sections and learn more.

This resource has been designed for guidance only.

Growing organization questions

Are we defending ourselves?

  • Limiting discussions to only specific areas of cybersecurity (such as system scans) can set the organization up for failure, as it is only a small part of an effective risk management framework.

Established organization questions

Are we building resilience?

  • Cyber resilience is the ability to adapt, detect, manage, and recover from incidents.

Why it matters

  • For cybersecurity to be practicable, organizations should consider cyber hygiene practices and run regular exercises to detect threats and uncover vulnerabilities. Boards and executives should assume, for planning purposes, that they will at one point experience a cyberattack of some type, and prepare their organization to respond and recover with minimal damage, cost, and reputational impact.

Growing organization questions

How much do we spend on cybersecurity?

  • Helping ensure that an organization first and foremost has dedicated fiscal resources to address cyber risk and prioritize investment in a cyber risk resilience strategy is important.

Established organization questions

Are cybersecurity investments aligned with business priorities and regulatory expectations?

  • Overinvesting in cyber risk management or risk management strategies that do not align with business needs can have negative impacts.
  • Underinvestment in cyber risk management can increase both the likelihood and severity of incidents, while amplifying regulatory exposure, reputational damage, and financial/operational impact.

Why it matters

  • Overinvesting in non-priority areas can lead to inefficiencies.
  • Boards should ensure cybersecurity spending helps mitigate actual risks while enabling growth.

Growing organization questions

Do we have cyber insurance?

  • Cyber insurance can be an effective way to transfer an element of an organization’s unidentified risks.

Established organization questions

Does our cyber insurance policy align with our risk exposure, and how does it integrate into our incident response strategy?

  • A clear understanding of your cyber policy’s structure is critical when helping ensure it delivers appropriate risk transfer and facilitates effective financial recovery following a cyber incident.

Why it matters

  • Cyber insurance should be a proactive component of risk management, not just a financial safeguard. Policies should be reviewed regularly to help ensure coverage meets your business goals and evolving threats.

Growing organization questions

Are we monitoring cyber risks?

  • Continuous monitoring is important to establish if the cyber risk management strategy performs as intended.

Established organization questions

How do our monitoring capabilities identify high-impact risks across the organization and supply chain?

  • Monitoring and analyzing security threats is crucial for helping prevent potential attacks and reducing their impact. However, high-performing boards aim to establish a clear connection between the topics they are briefed on and their impact on risk.

Why it matters

  • A risk-based approach prioritizes critical vulnerabilities, not just raw vulnerability counts.
  • Third-party audits and independent reviews help to provide assurance of resilience.
  • Effective monitoring that is risk-aligned helps organizations focus resources on protecting their most valuable assets, supports compliance and claims defensibility, and provides actionable insights that improve both prevention and recovery outcomes.

Growing organization questions

Are we protected against cyber threats?

  • Implementation of security systems, technologies, and associated practices and procedures to help protect data and assets are often regarded as a necessity and is performed by organizations at varying levels.

Established organization questions

How does our cybersecurity strategy contribute to business growth and trust?

  • Leaders who integrate cybersecurity strategy, planning, and execution into business initiatives are likely to be better placed in maintaining brand reputation, fostering customer trust and loyalty, ensuring operational stability, and driving revenue growth.

Why it matters

  • A strong cybersecurity foundation helps enhance customer confidence, regulatory trust, and competitive positioning.
  • Cybersecurity investments should be evaluated based on their business impact, not just compliance obligations.

Growing organization questions

Is our cybersecurity strategy being communicated?

  • Communication to the board is essential when it comes to having a baseline understanding of an organization’s cybersecurity investment strategy.

Established organization questions

How is our cybersecurity strategy being communicated?

  • A cybersecurity strategy is not set-and-forget; it should be an evolving, constant communication piece that speaks to new products or services, attracting and retaining customers, entering new markets, and solving business problems.

Why it matters

  • Cybersecurity strategies should be considered in the context of internal and external parties, as well as the enterprise business strategy and objectives.

Growing organization questions

Who is responsible for cybersecurity within the organization, and how is information reported to the board?

  • Clarifies whether cybersecurity is under IT, legal, risk, or stand-alone reporting lines.
  • Prompts an understanding of communication flow: Does cyber risk surface regularly at board meetings or only post-incident?

Established organization questions

Have we established clear governance structures, with defined accountability for cyber risk at the executive and board levels, including a cyber risk owner or sponsor?

  • Boards should confirm whether a cyber risk subcommittee exists or if cyber is part of an enterprise risk committee.
  • Encourages boards to consider appointing a non-executive director with cyber experience or formally assessing board cyber literacy.

Why it matters

  • Clear ownership at the board level helps improve oversight, escalation processes, and risk mitigation.
  • Boards that appoint a designated cyber lead or include cyber expertise in committees are better positioned to oversee strategic cyber risk.
  • Cyber governance frameworks (e.g., NIST, ISO 27001) highlight board responsibility in setting cyber risk appetite and evaluating performance.
  • Given the pace at which board‑level standards and expectations related to cyber, technology, and resilience are evolving, organizations should consider monitoring guidance from established organizations that educate corporate directors in the United States, such as the National Association of Corporate Directors (NACD).

Growing organization questions

Do we assess the cybersecurity posture of our key third-party vendors before and after onboarding, and are they contractually required to maintain minimum security standards?

  • Moves beyond a “yes/no” security posture to considerations of life cycle risk management.
  • Promotes discussion of vendor due diligence and oversight of subcontractors (fourth parties).

Established organization questions

Do we maintain a central register of critical third parties with visibility into their cyber resilience, and do we test our response to potential supply chain incidents? What is our strategy surrounding noncritical third parties?

  • Encourages boards to help ensure active monitoring, not just one-time onboarding checks.
  • Supports resilience planning and alignment with operational risk frameworks.

Why it matters

  • Vendor risk management should include due diligence, ongoing monitoring, breach notification protocols, and contractual protections.
  • Boards should expect a register of critical vendors and their risk tiering, security controls, and continuity arrangements.
  • Shared responsibility models for cloud and managed services require robust clarity on data protection and breach responsibilities.
  • Boards should expect visibility into noncritical third parties, as well. The scrutiny on the noncritical third parties may be scaled differently.

Growing organization questions

Are we meeting our obligations under all relevant cyber, privacy, and data protection regulations?

  • Helps ensure boards are thinking beyond FTC Act, state privacy laws (like the CCPA/CPRA), GLBA (for financial institutions), HIPAA (for healthcare), and internationally, the GDPR for firms handling EU personal data.
  • Prompts a discussion on accountability for compliance, especially where multiple regulatory regimes intersect.

Established organization questions

What assurance mechanisms do we have in place to demonstrate ongoing compliance with regulatory expectations (e.g., audits, scenario testing, external reviews), and how do we monitor changes to our obligations?

  • Encourages a structured, forward-looking approach to compliance.
  • Supports an evolving “compliance by design” mindset which is then embedded into business practices instead of tacked on reactively.

Why it matters

  • Regulatory frameworks increasingly require evidence of operational resilience, breach reporting, and third-party governance.
  • Boards should receive compliance updates, audit findings, and regulator communications as part of cyber governance reporting.
  • Meeting minimum standards is not enough — boards should strive for demonstrable maturity across technical and governance domains.

Growing organization questions

Do we have a formal, board-approved cyber incident response plan, and has it been tested in the past 12 months?

  • Acknowledges that many boards are unaware of whether their plan exists or is tested in practice.
  • Emphasizes the importance of drills and cross-functional involvement (legal, PR, HR, vendors, IT).

Established organization questions

Do our cyber crisis playbooks and communications protocols enable swift, coordinated decision-making during an incident, and do we formally review lessons learned with board involvement?

  • Drives discussion around readiness to communicate with regulators, customers, and shareholders.
  • Embeds continuous improvement and board accountability into post-incident review processes.

Why it matters

  • An incident response plan should be regularly tested through tabletop exercises and red team simulations.
  • Recovery capabilities should be aligned to recovery time objectives and recovery point objectives for critical business functions.
  • Lessons learned should inform updated controls, board briefings, and regulatory responses.

FINAL TAKEAWAY

Cyber boardroom evolution

01

The role of the board in cyber risk governance has evolved beyond protection and compliance.

02

Cybersecurity is now a core business enabler, directly impacting financial performance, regulatory standing, and competitive advantage.

About Lockton

As the world’s largest privately held, independent insurance broker, we don’t cater to shareholders or have external investors, unlike all our peers. This means we answer to the only voice that matters: yours. This independence allows us to create a partnership with you where every interaction, decision, and solution is solely focused on your business risk needs.

CLIENTS WORLDWIDE

CLIENT RETENTION

ANNUAL ORGANIC GLOBAL GROWTH

OFFICES WORLDWIDE

2025 GLOBAL REVENUE

ASSOCIATES WORLDWIDE

CONSECUTIVE YEARS AS BEST PLACES TO WORK

Get in touch

Brendan Fitzpatrick Vice President, Privacy and Cyber Risk Consultant brendan.fitzpatrick@lockton.com 703.309.7338

John Nahas Jr. Vice President, Privacy and Cyber Risk Consultant john.nahas@lockton.com 816.381.3034

This overview is for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Fiduciary duties and other legal obligations vary depending on an organization’s structure and the laws of the jurisdiction in which it is incorporated or operates. Directors, officers, trustees, and other leaders should consult qualified counsel regarding their specific situations.

© 2026 Lockton Companies. All rights reserved.