secureskies
Expertise/04 · Board & Governance

The seat that
asks the questions.

Under NIS2 and DORA, management is personally liable for the cyber duty of care. The body meant to oversee it often lacks cyber expertise of its own. We fill that seat on the Beirat, Aufsichtsrat or Verwaltungsrat — advisory board, supervisory board or board of directors: questions to the CIO and the service providers, scrutiny of the answers, documentation of the oversight exercised.

01 · Starting point

Three roles,
one gap.

The CIO delivers, management decides, the body oversees. In most mid-sized companies the third role is missing the person who can tell a security dashboard from the actual state of security. That is exactly where we sit — not operating, not advising, but scrutinising.

Responsibility matrix for cyber oversightWho decides, who examines, who delivers
Leadership team
Beirat / Aufsichtsrat
with secureskies
CIO / CISO /
service provider
Set risk appetite and security strategy
Decides
Examines & challenges
Prepares
Approve the budget for security controls
Decides
Checks adequacy
Requests
Implement and run the controls
Commissions
—
Delivers
Report on the state of security
Receives
Examines the report, asks follow-up questions
Reports
Incident: decision under time pressure
Decides
Reachable within 48 h
Handles it
Evidence that the duty of care was exercised
Submits
Documents oversight
Supplies evidence
Carries the responsibilitySecureskies oversight functionContributes
02 · Method

Four meetings,
one oversight year.

Oversight is a rhythm, not an event. Each of the four meetings has a focus, each focus a document. Over the year that produces an audit trail showing that the body asked, management answered and the items were followed up.

Q1 meeting

State of play & risk appetite

  • Prior year’s 5×5 risk heatmap against the plan
  • Review of the annual security report
  • Confirm or adjust the risk appetite for the current year
Minutes · Q1 question catalogue
Q2 meeting

Identity & cloud posture

  • Detailed review with the CIO/CISO on privileged access and cloud configuration
  • Status of the actions from Q1
  • Service provider review: contracts, SLAs, evidence
Minutes · open items list
Q3 meeting

Resilience & supply chain

  • Backup, recovery, crisis organisation: exercise results instead of concepts
  • Supply chain and OT/KRITIS, where relevant
  • Regulatory check against NIS2, DORA, AI Act
Minutes · regulatory memo
Q4 meeting

Budget & evidence

  • Adequacy of the security budget for the following year
  • Annual self-assessment of cyber oversight
  • Close the evidence file for the year
Evidence file · self-assessment
Between meetings · reachable within 48 hours in the event of an incident, an audit request, an acquisition or a change of service providerAll year round
03 · Tools

One heatmap,
five questions.

The body does not get 60 slides, it gets one page: the 5×5 risk heatmap across five dimensions, the same template every quarter. With it, one question per dimension — the one we keep asking until the answer is evidenced.

5×5 risk heatmap — templatePopulated per mandate
1
2
3
4
5
Identity
Cloud posture
Supply chain
OT / KRITIS
Governance
Maturity lowMaturity high
Identity

Who holds domain admin rights today — and who approved that, and when?

Cloud posture

Which configuration drift would put us in the newspaper tomorrow, and who sees it first?

Supply chain

Which service provider can shut us down, and when did we last check its evidence?

OT / KRITIS

How long does production keep running when IT is down — measured, not estimated?

Governance

Which security decision did management take last quarter, and where does it stand?

04 · Service catalogue

Ten modules,
from the seat to the handover.

Four mandate forms and six building blocks that either extend a mandate or are booked on their own. Every module has an output document. A Beirat seat is not an advisory mandate in another guise: we examine, we follow up, we document — and in doing so we protect management, which decides.

01

Beirat member with a cyber focus

Mandate form · annual mandate

The specialist voice in the existing body. Four meetings a year following the oversight-year rhythm, reachable within 48 hours. We examine security reports, put the questions to the CIO and the service providers, and document that the body has exercised its duty of oversight. Appointment by the shareholders.

Output
  • Meeting minutes with questions, answers and follow-up items
  • Evidence file updated every quarter
  • Annual self-assessment of cyber oversight
ForMid-sized companies with a Beirat, group subsidiaries
Meetings4 / year · 48 h ad hoc
02

Beirat chair · mid-sized companies

Mandate form · annual mandate

Chairing the body with cyber as a focus alongside strategy and finance. For family businesses whose largest risk today is digital and whose Beirat has so far covered banking, tax and succession. We set the agenda, chair the meetings and keep contact with the owning family between the dates.

Output
  • Annual agenda and chairing of meetings
  • Owners’ letter after every meeting
  • Evidence file for the body
ForFamily businesses
03

Beirat chair · family holding

Mandate form · annual mandate

For holdings with several investments: one consistent cyber oversight across the portfolio. Every investment reports in the same heatmap template so the holding can compare; escalation paths to the owning family are set before they are needed.

Output
  • Portfolio heatmap across all investments
  • One common reporting template per investment
  • Escalation rules, holding ↔ investment
ForFamily holdings, PE portfolios
FormatChair or portfolio mandate
04

Preparation for the Aufsichtsrat

Mandate form · without a seat

No seat, but preparation: before every meeting the Aufsichtsrat or its audit committee receives an assessment of the cyber items on the agenda and the questions it should be asking. After the meeting we put the answers in context. For bodies that cannot or do not want to appoint a further member.

Output
  • Preparation memo for each meeting
  • Question catalogue and follow-up
  • Annual report to the committee chair
ForSupervisory boards, audit committees
FormatAnnual mandate, meeting-based
05

Onboarding & training for the body

Building block · NIS2 Art. 20 · DORA Art. 5

NIS2 obliges management bodies to complete training on cyber risks; DORA requires the management body to have active knowledge of ICT risks. We train the Beirat, the Aufsichtsrat and management together — on your systems, your service providers, your reports — and document attendance as evidence.

Output
  • Training concept for management bodies
  • Half-day format per body
  • Evidence of attendance and content
ForAll bodies under NIS2 / DORA
06

Report review & reporting template

Building block · board report of 8–12 pages

We examine the security report the body receives for what is missing: trend instead of snapshot, decision instead of status, evidence instead of assertion. Where needed we rebuild the reporting template with the CIO/CISO — 8 to 12 pages, the 5×5 heatmap on page one, the same structure every quarter.

Output
  • Review memo on the existing report
  • Reporting template with 5×5 heatmap
  • Sign-off by the body
ForBodies without cyber expertise of their own
07

Service provider and CIO challenge

Building block · once per oversight year

A structured detailed review with the CIO, the CISO and the two or three critical service providers: contracts, SLAs, audit reports, access rights, exit capability. We keep asking until the evidence is on the table, and report to the body where statement and evidence diverge.

Output
  • Service provider register with criticality
  • List of divergences, statement vs. evidence
  • Recommendation to the body
ForCompanies with outsourced IT
RhythmQ2 meeting
08

Crisis support for the body

Building block · 48 h

After an incident, management needs someone in the body who decides, documents and can talk to the insurer, the regulator and the owners — not another expert opinion. We are in the conversation within 48 hours, structure the decision paper and record what was decided, when and on what basis. Handling the incident operationally stays with the incident response team.

Output
  • Decision papers for the body
  • Decision log with time stamps
  • Communication line to owners, insurer, regulator
ForEvery mandate, in an incident
ReferenceIncident remediation · 1,000+ servers
09

Cyber due diligence for investments

Building block · M&A · PE

Before an acquisition or an investment: where does the target company stand on identity, cloud posture, supply chain, OT/KRITIS and governance — and what does it cost to close the gap? We deliver the target’s heatmap, the open items with an effort estimate and the questions for the negotiation. After closing, that becomes the integration plan.

Output
  • 5×5 heatmap of the target company
  • Red flag list with effort
  • 100-day cyber integration plan
ForHoldings, PE houses, groups
ReferenceM&A integration of three subsidiaries, EMEA
10

Evidence file & mandate handover

Building block · year end of the mandate

At the end of every oversight year there is a file an auditor or a regulator can read without us: minutes, question catalogues, answers, decisions, open items, self-assessment. When the mandate ends we hand it over in a structured way to the body or to the successor — with an introductory conversation.

Output
  • Evidence file per oversight year
  • Annual self-assessment of cyber oversight
  • Handover record to the body or the successor
ForEvery mandate
RhythmQ4 meeting