Executive Summary

The first two articles in this series established two propositions: cyber risk is an enterprise risk that belongs on the board agenda, and boards can only govern it with independent evidence — cyber assurance — rather than management’s unverified word. This third article addresses the people on whom both propositions land: the directors themselves. What, in practical terms, does a cyber-accountable board actually do?

The answer is not that directors must become technologists. No board member is expected to configure a firewall, and a director who tries is doing management’s job while leaving their own undone. The board’s job is oversight, and cyber oversight has a definable discipline that can be learned, scheduled and evidenced. It rests on three verbs. Directors must know enough to govern — the organisation’s digital dependence, its most plausible loss scenarios, its appetite for cyber risk and who is accountable for managing it. Directors must ask the questions that convert reporting into oversight — and insist on reporting worth asking questions about. And directors must verify — requiring independent evidence that what management reports is actually true.

This article turns those three verbs into a working agenda: the knowledge baseline every director needs, the standing questions for each quarter, the evidence a board should demand annually, the committee structures that make oversight function, and the first steps a board can take in its next two meetings. It closes with a ten-point scorecard against which any Caribbean board can assess itself today.

What Does Cyber Accountability Mean for a Caribbean Director?

Director accountability for cyber risk is no longer a matter of best-practice aspiration; it is being written into the region’s legal and commercial fabric. Data-protection statutes across the Caribbean impose obligations on organisations — and, in various forms, on those who direct them — to safeguard personal data and to report breaches. Financial regulators increasingly treat technology and cyber risk as a board-level supervisory topic for licensed institutions, expecting directors to demonstrate oversight, not merely delegation. Courts and shareholders in every major jurisdiction have made clear that duty-of-care arguments extend to foreseeable digital harms. And commercially, the question arrives before any regulator does: cyber insurers, lenders, franchise partners and international customers now routinely ask what the board knows and does about cyber risk — in writing, before renewal or signature.

The uncomfortable feature of this accountability is that it cannot be transferred. A board can delegate the management of cyber risk to executives, IT teams and providers — indeed it must. What it cannot delegate is oversight. When the breach occurs, “we relied on our IT provider” is an explanation, not a defence. The directors who fare best in the aftermath of an incident are invariably those who can produce a record: the agenda items, the questions asked, the independent assessments commissioned, the remediation tracked. Accountability, in other words, is evidenced — which is why the discipline described in this article matters as much as the intent behind it.

What Must Directors Know?

Cyber-literate oversight begins with a knowledge baseline that is business-shaped, not technical. Every director should be able to answer five questions about their own organisation without notes:

  • What are we dependent on? Which systems, providers and data flows would stop the business if they failed — the core banking platform, the ERP, the payments gateway, the reservation system, the cloud tenancy.
  • What are our most plausible loss scenarios? Not the universe of cyber threats, but the three or four that fit our organisation: ransomware halting operations, payment-instruction fraud, exfiltration of customer or member data, a critical provider failing.
  • What is our appetite? What exposure have we explicitly decided to accept, and what have we decided we will spend to avoid — the risk-appetite question introduced in the first article of this series.
  • Who is accountable? Which executive owns cyber risk, how the three lines are populated, and where independent assurance comes from.
  • What happens on the worst day? The essentials of the incident-response plan: who leads, how the board is informed, what external support is on standby, and what our notification obligations are.

Acquiring this baseline is a scheduling decision, not a career change. A structured board education session of half a day, repeated annually and refreshed when the business or threat landscape changes materially, is sufficient to make every director a competent participant in cyber oversight — and it is precisely the kind of diligence that regulators, insurers and courts recognise.

What Must Directors Ask?

Oversight happens in the asking — but only if the questions recur and the reporting deserves them. The standing questions belong on the agenda every quarter: What changed in our exposure this period — new systems, new providers, new threats? What incidents and near misses occurred, and what did we learn? Where are we against our risk appetite? What is the status of open findings and remediation commitments? What did our people do — training completed, phishing-simulation results, access reviews performed?

Just as important is the quality of what the board is asked to consume. Much cyber reporting is activity noise: counts of blocked emails, patched machines and closed tickets that describe effort without describing exposure. A cyber-accountable board insists on a reporting format built for governance — typically a single dashboard covering the organisation’s top risks and their trend, control health for the handful of defences that matter most, incidents and near misses with lessons, remediation aging with named owners, and the date and result of the most recent independent testing. If a report cannot fit that page, the problem is the report, not the page. Directors should be as untroubled asking a naive-sounding cyber question as they are asking one about the accounts; in our experience the “naive” questions — can we restore the backups? who else can approve a payment change? — are the ones that find the gaps.

What Must Directors Verify?

 

 

Knowing and asking still leave the board dependent on what management presents. Verification closes the loop, and it is where the previous article’s discipline — cyber assurance — becomes a board instrument. A cyber-accountable board requires, at minimum, an annual rhythm of independent evidence: an independent assessment or audit of the cyber control environment, scoped to the organisation’s top loss scenarios; technical testing that proves whether controls withstand real attack techniques, with results reported to the board in business terms; demonstrated — not asserted — recovery capability, meaning an actual restoration test and an executive-level incident exercise in which directors themselves have participated at least once; and independent confirmation that previous findings were remediated and closed, because an unresolved finding the board has seen is the most dangerous document in the building.

The board’s verification instrument is the cyber assurance map introduced in Article 2: one page showing each material risk, who provides assurance over it, at what depth, and when it was last obtained. Reviewed annually by the board or its designated committee, the map converts “we believe we are covered” into a governed portfolio of evidence — and its blank spaces into next year’s assurance plan.

THE GOVERNANCE TEST

For every material cyber assertion management makes, a cyber-accountable board can answer one question: how do we know that is true? If the answer is “because management told us,” the board has information. If the answer is “because it was independently examined,” the board has oversight.

 

Which Governance Structures Make Cyber Oversight Work?

Discipline needs a home. Four structural decisions determine whether cyber oversight functions in practice. First, committee ownership: cyber risk should be explicitly assigned — typically to the audit committee or a risk committee, with the full board retaining strategy-level discussion — and written into the committee’s terms of reference, because a risk that belongs to every committee belongs to none. Second, expertise: boards should honestly assess their cyber literacy. Recruiting a director with technology-risk experience helps larger organisations; for most Caribbean boards, structured education plus access to independent advisers is the practical route — what matters is that the board can engage critically, not that it employs a resident technician. Third, management interface: a named executive — whoever owns cyber risk — should appear before the board or committee on a fixed cadence, supported by the reporting dashboard, with the chief audit executive and any external assurance provider enjoying direct, unfiltered access. Fourth, escalation: the board should agree in advance what it must be told and when — the incident-severity thresholds, the hours-not-days notification expectation, and who convenes the board in a crisis — because the middle of the incident is the wrong time to design the protocol.

Where Should a Board Begin? Five Steps for the Next Two Meetings

 

  1. Commission a board-level cyber governance assessment. An independent review of how cyber oversight currently operates — agendas, reporting, structures, assurance held — against the discipline described here. It gives the board its own baseline, in its own language.
  2. Schedule the education session. Half a day, business-shaped, covering the five knowledge questions — and put the annual refresh in the calendar now.
  3. Assign ownership and fix the agenda. Write cyber risk into a committee’s terms of reference and make the quarterly standing questions a permanent agenda item.
  4. Adopt the one-page reporting dashboard. Agree with management the governance-grade format the board will receive — and retire the activity noise.
  5. Book the exercise. Put an executive tabletop simulation with board participation on this year’s calendar. Nothing educates a board faster than rehearsing its own worst day.

The Dawgen Global Perspective

In Dawgen Global’s work with Caribbean boards, the difference between organisations that govern cyber risk well and those that merely worry about it is rarely money and never jargon. It is discipline: a board that knows its dependencies, asks the same hard questions every quarter, and refuses to accept any material assertion without independent evidence. That discipline is buildable — usually within two or three board cycles — and it changes behaviour throughout the organisation, because management attends to what the board reliably inspects.

Supporting that discipline is the purpose of Dawgen Global’s board-level cyber governance services: confidential briefings and education sessions for directors, independent assessments of cyber oversight against recognised frameworks, facilitation of executive and board tabletop exercises, and the design of board reporting and assurance maps that make oversight evidenced rather than assumed. The next article in the series moves from the boardroom to the function through which much of the board’s verification flows: internal audit, and the new assurance model created when it joins forces with cybersecurity.

The Cyber-Accountable Board: A Ten-Point Scorecard

Score one point for each statement your board can honestly make today.

  1. Cyber risk is a standing item on a designated committee’s agenda, written into its terms of reference.
  2. Every director has completed a structured cyber education session within the past year.
  3. The board can name the executive who owns cyber risk — and that executive agrees.
  4. A documented cyber risk appetite exists and was approved by the board.
  5. The board receives a one-page, governance-grade cyber dashboard every quarter.
  6. An independent assessment or audit of cyber controls was completed within the past year.
  7. Technical testing results — expressed in business terms — reached the board within the past year.
  8. Backup restoration has been demonstrated, and directors have participated in an incident exercise.
  9. A cyber assurance map exists and the board reviewed it within the past year.
  • Every finding from the last assessment carries a named owner and a date — and closures are independently verified.

Eight or more: a genuinely cyber-accountable board. Five to seven: the framework is forming — close the gaps this year. Below five: the board’s exposure is not primarily technical; it is governance — and it is addressable within two meetings.

Frequently Asked Questions

Does our board need a cybersecurity expert as a director?

It helps, but it is not the decisive factor — and it can backfire if one “expert director” becomes the excuse for everyone else’s disengagement. What a board needs is collective literacy sufficient to engage critically, plus access to independent specialist advice. Education and assurance are more reliable than a single seat.

How often should the board discuss cyber risk?

Quarterly at committee level with the standing questions, annually in depth at full-board level — including independent assessment results and the assurance map — and immediately upon any material incident. Frequency should rise with digital dependence and regulatory exposure.

Should cyber risk sit with the audit committee or a risk committee?

Either works; ambiguity does not. Smaller boards typically assign it to the audit committee, which already owns assurance relationships. Larger or regulated organisations often prefer a risk committee, with the audit committee retaining oversight of the assurance itself. The essential step is writing the assignment into the terms of reference.

What is the board’s role during a cyber incident?

Oversight, not operation: satisfying itself that the response is led and resourced, that legal and notification obligations are being met, that communications protect the organisation’s credibility, and that decisions with existential weight — such as any question of ransom — receive board-level judgement. A board that has rehearsed in a tabletop exercise performs this role in hours; a board that has not, improvises.

Move From Cybersecurity Assumptions to Independent Cyber Assurance

Dawgen Global combines cyber governance, risk-based internal audit, penetration testing, resilience assessment and remediation validation to help Caribbean organisations determine whether their cybersecurity controls are properly designed and operating effectively. To see how your board measures against the discipline in this article, request a confidential board cyber governance assessment or a private briefing for your directors.

 

About Dawgen Global

Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.

The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.

To explore a partnership, reach out:

by Dr Dawkins Brown

Dr. Dawkins Brown is the Executive Chairman of Dawgen Global , an integrated multidisciplinary professional service firm . Dr. Brown earned his Doctor of Philosophy (Ph.D.) in the field of Accounting, Finance and Management from Rushmore University. He has over Twenty three (23) years experience in the field of Audit, Accounting, Taxation, Finance and management . Starting his public accounting career in the audit department of a “big four” firm (Ernst & Young), and gaining experience in local and international audits, Dr. Brown rose quickly through the senior ranks and held the position of Senior consultant prior to establishing Dawgen.

https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.
https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.

© 2023 Copyright Dawgen Global. All rights reserved.

© 2024 Copyright Dawgen Global. All rights reserved.