🟣Governing Through a Cyber Crisis:
In 2024, the Australian Institute of Company Directors (AICD), in partnership with the Cyber Security Cooperative Research Centre (CSCRC) and Ashurst, released “Governing Through a Cyber Crisis: Cyber Incident Response and Recovery for Australian Directors.” 18 months later, these guidelines are relevant more than ever.
☑️ Readiness: Build the Foundations Before the Breach.
Boards are expected to lead from the top, not just sign off on policy. Effective readiness means:
- A comprehensive, regularly tested Cyber Incident Response Plan, integrated with business continuity and communications frameworks.
- Clear board-level roles and responsibilities, including when to activate sub-committees or crisis structures.
- Scenario testing and simulation exercises that involve directors, not just IT teams, ensuring governance mechanisms work under pressure.
- Data governance frameworks that clearly identify where sensitive information resides, who owns it, and how it’s protected.
- Supply-chain due diligence: recognising that vulnerabilities often sit outside the organisation’s perimeter.
☑️ Response: Act Decisively, Communicate Transparently.
- When an incident unfolds, speed and clarity are critical. Boards should expect imperfect information but must ensure that:
- Management activates the crisis plan and establishes clear reporting cadence.
- Stakeholder communication is transparent, coordinated, and empathetic with customers, regulators, and the market.
- Legal and regulatory obligations are promptly addressed.
- External experts (forensics, legal, and communications) are mobilised early.
- Larger organisations are encouraged to establish a Cyber Incident Sub-Committee to enable agile oversight, freeing the full board to focus on strategic and reputational governance
☑️ Recovery and Remediation: Oversight Beyond the Crisis.
- The “long tail” of cyber risk extends months or years beyond the initial event. Boards play a central role in ensuring:
- Root-cause analysis is independently reviewed and acted upon.
- Remediation programs are well-resourced, customer-focused, and transparent.
- Employee wellbeing is prioritised, fatigue and moral strain are common post-incident.
- Regulatory investigations, compensation, and class actions are managed with integrity and accountability.
- Lessons learned are embedded into the organisation’s cyber governance and shared responsibly with peers to strengthen the wider ecosystem.
Boards that treat cyber resilience as part of enterprise risk management, rather than an IT line item will be the ones that navigate crises with credibility and protect stakeholder trust.
Read the full report here:
https://lnkd.in/eRfjqsUc
11