The Board's Cyber Question Is Usually the Wrong One
Boards do not govern cyber risk by asking whether the organisation is secure. They govern it by understanding which trade-offs are being made, by whom, and whether those decisions would survive scrutiny later.
Read insight