Are we OK? What your board should be asking about security

Are we OK? What your board should be asking about security

Learn the 12 questions your board should be asking about security, and what a good answer sounds like.

Most executives can tell when a security answer is weak. What is harder is knowing which question to ask, and what a good answer would even sound like.

The worst moment to discover you cannot answer the question is while it is being asked.

What you get

  • Twelve questions covering ownership, obligations, resilience and third-party exposure
  • What a good answer to each one sounds like
  • The warning signs that mean nobody actually owns the problem

Take it into your next board or executive meeting. If the answers come back vague, that usually means nobody has been given the job of holding this together.

Get your copy

This field is required.
This field is required.
This field is required.
This field is required.

We collect your name, work email, company and (optionally) phone so we can send you this resource and respond if you have questions. We handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles. See our privacy policy. We will only send you further material if you tick the box above, and you can unsubscribe at any time.

Prepared by Ilya Polyakov, principal of IronGate IT Consulting. Formerly Chief Security Architect at NSW Government, Executive Manager of Cyber Architecture at CBA, and security advisory at APRA. General information only, current as at August 2026, and not legal advice.