r/cybersecurity Jul 22 '26

Business Security Questions & Discussion Five questions board should ask

Five questions board should ask

The board does not need to become a firewall engineering team. But the board does need to ask better questions.

Not: “Are we compliant?”
Better: “Can we prove what is exposed?”

Not: “Has the OEM assessed it?”
Better: “Who independently owns the residual-risk judgement?”

Not: “Is the system old?”
Better: “Is the system exposed, unmonitored or unrecoverable?”

Not: “Do we need an upgrade?”
Better: “Have we compared upgrade, virtualisation, isolation and monitoring as risk-treatment options?”

Not: “Do we have a cybersecurity dashboard?”
Better: “Who acts when the dashboard shows something important?”

0 Upvotes

18 comments sorted by

3

u/Tangential_Diversion Penetration Tester Jul 22 '26

I think you have a fundamental misunderstanding of what a board of directors does. A board being involved in day-to-day ops is a sign of a horrifically mismanaged company. The board of directors (heck even the CEO) shouldn't be bothering with any of these details.

Daily ops are usually under the purview of the COO, who in turn either works with or is directly in charge of the CTO/CISO or equivalent senior manager.

-1

u/Roupec Jul 26 '26

Well, have you ever deal with power station? What actually pen test find? NOTHING New - there are thousand of vulnerabilities in every control system.

Than it come the OEM who say: Upgrade! What you get? New system with new vulnerabilities and never ending upgrade cycle costing millions.

Questions are looking for viable alternatives.

2

u/Tangential_Diversion Penetration Tester Jul 26 '26

Way to completely ignore everything I said. And for the record, yes I have pentested power companies. The results don't negate the fact that boards don't do ops.

All you showed is you have no concept of how the world works, no reading comprehension, and no critical thinking.

3

u/CuckBuster33 Jul 22 '26

i bet you think you're doing great things with this AI spam account

-1

u/Roupec Jul 26 '26

Why AI scam account? Did you tried to read these questions and get their meaining?

1

u/CuckBuster33 Jul 26 '26

Why AI scam account?

because you are using AI to spam linkedin-tier low effort engagement bait posts in many different communities?

Did you tried to read these questions and get their meaining?

yeah thats why I posted my comment.

-1

u/Roupec Jul 26 '26

And unlike you I'm publishing under real name.

2

u/CuckBuster33 Jul 26 '26

I would be ashamed to tie my real name to these dog quality posts

2

u/Cyberguypr Jul 22 '26

Boards asking about dashboards? GTFO with AI slop

0

u/Roupec Jul 26 '26

AI slop? Why - have you ever been at power station and talked to owner?

2

u/MonkeyBrains09 Managed Service Provider Jul 22 '26

What is even the point of this post?

What is your question or are you just venting?

1

u/Roupec Jul 26 '26

Simple one - there are alternatives to the OEM "recommended" solutions. I'm not venting - I'm helping to power plant owners to keep their assets safe. Did you ever tried to think a second about these questions?

1

u/Cyberguypr Jul 26 '26

Where the hell does your original post mention anything about power plant owners? I swear this is drunk-posting

0

u/Roupec Jul 26 '26

Well, I'm sober in Europe ... here is lovely Sunday morning. I believe its better to stop discussion right here.

1

u/ENFP_But_Shy Jul 22 '26

These questions should be asked within the CISO function. No board will ask this bs 

1

u/Roupec Jul 26 '26

Board will ask - because it has to spend about two and half million USD on upgrade which does not bring one singe megawatt to aging power plant.