Purpose
Directors need decision-grade language, not tool inventories. This pack helps the board ask better questions, recognise vanity metrics, and demand dated evidence when management claims “we are secure”.
What’s inside
1. One-page risk heatmap template
Plot likelihood against impact for ransomware, BEC, third-party SaaS compromise, insider misuse, and regulatory exposure. Require owners and next review dates on every red/amber cell.
2. Questions boards should ask the CISO
- What is our mean time to detect and contain for the top three scenarios?
- Which privileged paths still lack MFA / passkeys?
- When did we last restore a critical system from backup under timed conditions?
- Which vendor ratings or awards are we relying on — and when do they expire?
- What material limitations appear on any public HKISG rating we cite?
3. KPIs that avoid vanity metrics
Prefer:
- Patch lag for internet-facing critical CVEs
- Privileged account coverage for phishing-resistant MFA
- Tabletop exercise completion with findings closed
- Backup restore success rate
Avoid:
- Raw “number of blocked attacks” without context
- Training completion alone without phishing resilience outcomes
- Tool count as a maturity proxy
Hong Kong governance context
Boards of Hong Kong entities should understand how cyber risk intersects with directors’ duties, customer trust, and personal data obligations. This pack is educational — it is not legal advice. Use counsel for PCPD notification decisions and contractual claims.
How to run a 30-minute briefing
- Five minutes: heatmap changes since last meeting
- Ten minutes: one deep-dive incident or near-miss
- Ten minutes: investment ask linked to residual risk
- Five minutes: decisions and owners
Trust signals you can inspect
When management references external assurance, ask for:
- Scope, date, and expiry of any public score
- Whether membership fees were separate from scoring (Governance)
- Link to the published methodology