12
hardest board questions on cybersecurity — mapped to regulator, metric, and data source
4
regulators whose mandates boards are directly accountable for: RBI, SEBI, IRDAI, CERT-In
3
domains boards must cover: compliance/regulatory, risk/financial, operations/assurance
0
acceptable "I don't know" answers from a board that has exercised meaningful oversight

The following questions are drawn from actual board and audit committee discussions across India's banking, insurance, and capital markets sectors. They are hard because they require quantified, evidenced answers — not reassurance. Each answer below describes what a defensible response looks like, and how RiskSage makes it possible to answer each question with evidence rather than assertion.

BOARD QUESTION DIFFICULTY MATRIX — WHY THESE ARE THE HARDEST
HIGH MED LOW TECHNICAL COMPLEXITY BOARD IMPACT → Q4 DPDP Q5 Risk ₹ Q6 Insurance Q7 Budget ROI Q8 Risk App. Q1 CSCRF % Q2 IRDAI Hardest (need live CRQ data) Hard (need dashboard) Answerable (need posture %)
The hardest questions (top-right quadrant) require real-time financial quantification — they cannot be answered from a compliance checklist or CISO narrative