The 12 Hardest Board Questions on Cybersecurity — Answered
Boards are legally accountable for cybersecurity oversight under SEBI CSCRF, IRDAI guidelines, and RBI Master Directions. These are the 12 questions they actually ask — and the answers that require evidence, not narrative.
Published 13 Apr 2026Read time 10 minCategory GRC · Board GovernanceBy CreativeCyber
12 BOARD QUESTIONS MAPPED ACROSS 3 DOMAINS — COMPLIANCE, RISK/FINANCIAL, OPERATIONS — EVERY ANSWER MUST COME FROM LIVE DASHBOARD DATA
domains boards must cover: compliance/regulatory, risk/financial, operations/assurance
0
acceptable "I don't know" answers from a board that has exercised meaningful oversight
The following questions are drawn from actual board and audit committee discussions across India's banking, insurance, and capital markets sectors. They are hard because they require quantified, evidenced answers — not reassurance. Each answer below describes what a defensible response looks like, and how RiskSage makes it possible to answer each question with evidence rather than assertion.
BOARD QUESTION DIFFICULTY MATRIX — WHY THESE ARE THE HARDEST
The hardest questions (top-right quadrant) require real-time financial quantification — they cannot be answered from a compliance checklist or CISO narrative