Executive self-assessment

Board Cybersecurity Governance Assessment

Measure whether cybersecurity reporting gives the board decision-quality visibility rather than operational noise.

Result logic

What this tool evaluates

Evaluates board accountability, risk appetite, material risk, metrics, incidents, resilience, vendors, assurance, decisions, and reporting cadence.

Accountability 20%
Risk appetite & materiality 22%
Reporting & metrics 23%
Resilience & third parties 18%
Decisions & cadence 17%
0 / 10
0%
01 Are board and executive cybersecurity oversight responsibilities documented and understood?
02 Is there a named executive accountable for coordinating cyber-risk decisions and reporting?
03 Has leadership defined cyber risk appetite, escalation thresholds, or decision criteria?
04 Does the board receive the organization’s most material cyber risks with business impact, owner, treatment, and trend?
05 Are board cyber metrics linked to risk outcomes rather than raw tool/activity volume?
06 Can leadership distinguish current exposure, control effectiveness, remediation progress, and residual risk?
07 Are significant incidents, recovery capability, exercises, and lessons reported at the right level?
08 Are critical third-party and concentration risks visible to leadership?
09 Are material risk acceptance decisions formally recorded with owner, rationale, conditions, and expiry?
10 Does the board or audit committee review cyber risk on a defined recurring cadence with tracked actions?