briefing · beginner · 30 minutes

Purpose

Directors need decision-grade language, not tool inventories. This pack helps the board ask better questions, recognise vanity metrics, and demand dated evidence when management claims “we are secure”.

What’s inside

1. One-page risk heatmap template

Plot likelihood against impact for ransomware, BEC, third-party SaaS compromise, insider misuse, and regulatory exposure. Require owners and next review dates on every red/amber cell.

2. Questions boards should ask the CISO

  • What is our mean time to detect and contain for the top three scenarios?
  • Which privileged paths still lack MFA / passkeys?
  • When did we last restore a critical system from backup under timed conditions?
  • Which vendor ratings or awards are we relying on — and when do they expire?
  • What material limitations appear on any public HKISG rating we cite?

3. KPIs that avoid vanity metrics

Prefer:

  • Patch lag for internet-facing critical CVEs
  • Privileged account coverage for phishing-resistant MFA
  • Tabletop exercise completion with findings closed
  • Backup restore success rate

Avoid:

  • Raw “number of blocked attacks” without context
  • Training completion alone without phishing resilience outcomes
  • Tool count as a maturity proxy

Hong Kong governance context

Boards of Hong Kong entities should understand how cyber risk intersects with directors’ duties, customer trust, and personal data obligations. This pack is educational — it is not legal advice. Use counsel for PCPD notification decisions and contractual claims.

How to run a 30-minute briefing

  1. Five minutes: heatmap changes since last meeting
  2. Ten minutes: one deep-dive incident or near-miss
  3. Ten minutes: investment ask linked to residual risk
  4. Five minutes: decisions and owners

Trust signals you can inspect

When management references external assurance, ask for:

  • Scope, date, and expiry of any public score
  • Whether membership fees were separate from scoring (Governance)
  • Link to the published methodology