By Ann Marie van den Hurk, Mind The Gap Advisory
Boards are asking about cyber crisis readiness more often than they ever have. The question is whether they are asking the right things.
After 30 years in crisis and a career spent at the intersection of executive decision-making and high-visibility incidents, the same pattern repeats. A board member raises a hand during a quarterly briefing and asks something like: Are we prepared for a cyberattack? The CISO answers with a framework name, a compliance percentage, or a budget number. Everyone in the room nods.
The question is considered answered. It is not answered. It has been deflected by a response that sounds like readiness but describes something else entirely.
Boards are now directly accountable for what happens during a cyber crisis. The SEC’s incident disclosure rules, the EU’s NIS2 and DORA frameworks, and CIRCIA’s approaching 72-hour reporting requirement have made cyber governance a personal liability question for directors, not just an organizational risk category.
That accountability requires better questions.
The question boards are actually asking versus the one they think they are asking
When a board member asks “are we cyber ready”, they are usually asking one of three things without realizing they are asking three different questions.
Are we protected from an attack?
Prevention. Answered by security posture, threat detection, and investment levels.
Are we resilient enough to recover?
Operational continuity. Answered by business continuity planning, backups, and recovery timelines.
Are we governed well enough to make the right decisions when an incident becomes public?
Decision authority. Almost never answered.
The third question is the one that determines how a cyber crisis unfolds in public.
Prevention and resilience matter. But it is the decision governance layer, who decides, who communicates, who authorizes action before verification is complete, that determines whether leadership holds authority or loses it in the first 20 minutes.
The five questions every board should be asking
These are not compliance questions. They are governance questions.
The difference matters. Compliance measures what is documented. Governance reveals how leadership actually behaves under pressure.
1. Who is the named individual authorized to make the call that cannot wait for consensus?
A plan that names a role has not resolved decision authority. It has deferred it. The board should know the name.
2. What threshold triggers executive activation?
Most organizations have notification paths. Very few define the specific conditions, technical, reputational, regulatory, that escalate an incident to executive level. That threshold should be explicit and known in advance.
3. What can leadership communicate publicly before technical verification is complete?
Stakeholders judge leadership in the first hours. Pre-authorized holding language is the difference between controlled response and improvisation under pressure.
4. When was the last time the crisis plan was tested under real pressure conditions?
A tabletop with unlimited time and full information is not a test. It is a review. The board should understand the difference.
5. Who owns the cross-functional operating picture?
Security, Legal, Communications, and Operations each see a different version of reality during a crisis. The board should know who is responsible for unifying that picture, and how quickly that happens.
What the answers reveal
These questions are diagnostic. The quality of the answers tells the board more than any dashboard or report.
If answers are specific, naming individuals, defining thresholds, and pointing to tested protocols, decision authority infrastructure exists.
If answers rely on frameworks, percentages, or org charts, readiness is documented but not operational.
The distinction only becomes visible under pressure.
A board that asks these questions before an incident improves the odds that weaknesses surface in simulation, not in a live event already shaping regulatory, investor, and public judgment.
Where to start
If your board has not asked these questions, or if the answers are unclear, that is the signal.
Crisis Decision Authority Diagnostic →
This is designed to surface exactly where decision authority breaks before pressure forces the issue.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
