Skip to content
Afriskora Training Solutions
Governance & risk

Cybersecurity for Boards: Ten Questions Directors Should Ask Management

Afriskora Editorial Team · 5 October 2026 · 3 min read

Cyber risk is now a governance responsibility. Ten plain-language questions that help directors without a technical background oversee security effectively.

Ransomware attacks on African businesses, municipalities and public entities have shown that a cyber incident can halt operations, expose personal information and damage reputations for years. Governance codes, including the King Code, make the governance of technology and information a board responsibility. Yet many directors feel unable to challenge management because the subject seems too technical.

You do not need to be a technologist to govern cyber risk. You need to ask good questions and insist on clear answers. Here are ten to start with.

1. What are our most important assets, and what would happen if we lost them?

Security spending should protect what matters most: customer data, payment systems, operational technology or intellectual property. Management should be able to name these "crown jewels" and explain the impact of losing them.

2. What is our cyber risk appetite?

How much disruption or data loss is the board willing to accept? Without an agreed appetite, there is no basis for deciding whether security investment is too little or too much.

3. Who is accountable?

Is there a named executive responsible for information security, with the authority and budget to act? Does that person report to the board or a committee regularly?

4. How would we know if we were breached?

Many breaches are discovered months after they happen. Ask how the organisation monitors for attacks, and how quickly suspicious activity would be detected and escalated.

5. Could we recover from ransomware, and how long would it take?

Ask when backups were last restored in a test, whether they are protected from attackers, and how long critical systems would take to recover. The answer "we have backups" is not enough.

6. How do we manage third-party risk?

Suppliers with access to your systems or data can be the weakest link. Ask how critical suppliers are assessed and what contracts require of them.

7. Are our people part of the defence?

Most attacks still start with an email or a phone call. Ask about awareness training, phishing simulations and how quickly staff report suspicious messages.

Under POPIA, the Information Regulator and affected people must be notified of a security compromise involving personal information as soon as reasonably possible. Sector regulators, such as financial services authorities, may have their own reporting rules. Management should know who decides and who communicates.

9. Have we rehearsed a major incident?

A tabletop exercise in which executives walk through a simulated attack reveals gaps in decision-making, communication and authority before a real crisis does.

10. What does good look like, and how are we tracking it?

Ask for a small number of meaningful measures, such as time to patch critical vulnerabilities, phishing reporting rates and backup recovery test results, presented as trends rather than technical detail.

Making it routine

Put cyber risk on the risk committee's agenda at least quarterly, include it in the board's annual training plan and ask internal audit to review key controls. Over time, these questions become part of normal oversight rather than a reaction to the latest headline.

Training for leaders

Our Cybersecurity Leadership for Non-Technical Executives course includes a live ransomware tabletop exercise. Directors' Duties and Board Effectiveness covers the wider oversight role, and Enterprise Risk Management helps integrate cyber risk into the organisation's risk framework.

Related courses

More from Insights

Cybersecurity for Boards: Ten Questions Directors Should Ask Management | Afriskora Training Solutions