What should a director ask the CISO about cyber risk?
Eight questions a board director should put to the CISO, set to the company’s regulator — and a one-tap way to send them before the next meeting.
Your eight questions
Eight questions with checkable answers, set to the company’s regulator. Send them to the CISO before the meeting, not during it.
Each one has an answer that sits in a document, an organisation chart or a number — not in a reassurance. The link in the message opens a board brief already set to the same entity class, so the CISO can answer on slides.
- Which instruments bind us — and does our cyber policy cite RBI/DoS/2026-27/461?RBI Cyber Directions, 2026 (Non-Banking Financial Companies) is the one supervisors will test against. Citing a sibling instrument is an avoidable own goal.
- Who files our first incident report — due within 6 hours, to CERT-In — and who deputises at 2 a.m. on a Sunday?The clock starts whether or not the owner is reachable.
- What is our external security rating today, and where does it sit against our industry?Insurers, customers and supervisors can already see it. The board should see it first.
- Which of our internet-facing systems are not on the critical-asset list — and who decides what goes on it?SEBI’s CDSL order turned on one unlisted server, and held the failure institutional.
- Which vendors’ AI agents hold credentials into our systems, and who can switch each one off?An unowned agent is an unmanaged privileged account.
- Do our cyber insurance proposal-form answers match what an outsider can see — and who checks before renewal?The answers are warranties, and several — mail authentication, certificates, exposed services — are public. A gap is discoverable before binding, or after a loss.
- When did this board last approve the IT, cybersecurity and business continuity strategies?The 2026 RBI Directions make it a recurring agenda item, not a one-time adoption.
- Are we on track for our next dated obligation — Full compliance with the Rules, 13 May 2027?It is the next dated obligation in our register, and it will not move.
Send them to your CISO
The message carries a link that opens a board brief already set to this entity class — the answers, laid out as slides.
Are you the CISO? Turn the answers into a board brief →
Why these eight
- The instrument. The RBI issued seven parallel cyber Directions on 31 July 2026, one per entity class. A policy citing a sibling fails the first supervisory question.
- The first filing. CERT-In’s clock runs six hours from noticing. That is not long enough to find out who files.
- The external rating. Insurers, customers and supervisors can already see one. The board should see it first.
- The critical-asset list. SEBI’s CDSL order turned on one internet-facing server nobody had classed as critical.
- Vendor AI agents. An agent holding a credential into your systems is a privileged account, whoever operates it.
- Cyber insurance. Proposal-form answers are warranties, and several are visible from outside. See what a rating changes in cyber insurance.
- The regulator’s own test, and the next date — the two that change by company.
Indicative, and not legal advice. Every instrument behind these questions is read from the issuing regulator’s own notification. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- What questions should a board ask about cybersecurity?
- Questions with checkable answers rather than reassurance: which instrument the cyber policy cites, who files within the first reporting window and who deputises, what the organisation’s external security rating is against its industry, which internet-facing systems sit outside the critical-asset register, and which vendors’ AI agents hold credentials into the organisation’s systems.
- Why ask about the critical-asset list?
- Because SEBI’s ₹1 crore CDSL order of 20 July 2026 traced the 2022 ransomware attack to an internet-facing server that was never classified as critical, and so was never tested or monitored. SEBI held the failure institutional rather than individual — which makes the process for deciding what counts as critical a board matter.
- Is anything about the recipient recorded when I send the questions?
- No. The email, WhatsApp and copy options compose the message on your own device. The site records only that a message was sent, by which channel, and for which entity class.