The Cyber-Accountable Board: What Directors Must Know, Ask and Verify
Executive Summary The first two articles in this series established two propositions: cyber risk is an enterprise risk that belongs on the board agenda, and boards can only govern it with independent evidence — cyber assurance — rather than management’s unverified word. This third article addresses the people on whom both propositions land: the directors...



