What the board should actually ask whoever leads security
A thirty-slide technical report is not oversight. A few right questions, asked regularly, are.

Many boards receive a security update once or twice a year: vulnerability dashboards, a tally of minor incidents, a list of projects under way. It is a report that reassures through its completeness, but rarely helps the board understand where the real risk concentrates — because it answers "what are we doing", not the question that actually matters: "what could stop us, and are we ready?"
The questions that shift the conversation
What are the three scenarios we’re most worried about this year, and why those specifically? What have we decided not to do, for budget or time reasons, and who approved that choice? If we suffered the incident we fear most today, how long would it take us to realise it? These questions shift the discussion from a tally of activities to the quality of judgement behind the decisions.
A fourth question, often overlooked: what has changed since the last briefing, and why? A security programme that looks identical report after report is not necessarily stable — more often, it has stopped informing the board’s decisions and is merely confirming them.
Cadence matters as much as the questions
An annual update always arrives too late to correct course. A quarterly cadence, even a brief one, lets the board follow a trajectory rather than a single snapshot — and makes it far easier, when an incident does happen, to show that oversight was continuous rather than reconstructed after the fact.
The takeaway
The board doesn’t need to judge the technical quality of the security measures. It needs to be able to judge the quality of judgement behind the priorities chosen — and that comes from a few right questions, asked regularly, not from a longer report.



