State of play & risk appetite
- Prior year’s 5×5 risk heatmap against the plan
- Review of the annual security report
- Confirm or adjust the risk appetite for the current year
Under NIS2 and DORA, management is personally liable for the cyber duty of care. The body meant to oversee it often lacks cyber expertise of its own. We fill that seat on the Beirat, Aufsichtsrat or Verwaltungsrat — advisory board, supervisory board or board of directors: questions to the CIO and the service providers, scrutiny of the answers, documentation of the oversight exercised.
The CIO delivers, management decides, the body oversees. In most mid-sized companies the third role is missing the person who can tell a security dashboard from the actual state of security. That is exactly where we sit — not operating, not advising, but scrutinising.
Oversight is a rhythm, not an event. Each of the four meetings has a focus, each focus a document. Over the year that produces an audit trail showing that the body asked, management answered and the items were followed up.
The body does not get 60 slides, it gets one page: the 5×5 risk heatmap across five dimensions, the same template every quarter. With it, one question per dimension — the one we keep asking until the answer is evidenced.
Who holds domain admin rights today — and who approved that, and when?
Which configuration drift would put us in the newspaper tomorrow, and who sees it first?
Which service provider can shut us down, and when did we last check its evidence?
How long does production keep running when IT is down — measured, not estimated?
Which security decision did management take last quarter, and where does it stand?
Four mandate forms and six building blocks that either extend a mandate or are booked on their own. Every module has an output document. A Beirat seat is not an advisory mandate in another guise: we examine, we follow up, we document — and in doing so we protect management, which decides.
The specialist voice in the existing body. Four meetings a year following the oversight-year rhythm, reachable within 48 hours. We examine security reports, put the questions to the CIO and the service providers, and document that the body has exercised its duty of oversight. Appointment by the shareholders.
Chairing the body with cyber as a focus alongside strategy and finance. For family businesses whose largest risk today is digital and whose Beirat has so far covered banking, tax and succession. We set the agenda, chair the meetings and keep contact with the owning family between the dates.
For holdings with several investments: one consistent cyber oversight across the portfolio. Every investment reports in the same heatmap template so the holding can compare; escalation paths to the owning family are set before they are needed.
No seat, but preparation: before every meeting the Aufsichtsrat or its audit committee receives an assessment of the cyber items on the agenda and the questions it should be asking. After the meeting we put the answers in context. For bodies that cannot or do not want to appoint a further member.
NIS2 obliges management bodies to complete training on cyber risks; DORA requires the management body to have active knowledge of ICT risks. We train the Beirat, the Aufsichtsrat and management together — on your systems, your service providers, your reports — and document attendance as evidence.
We examine the security report the body receives for what is missing: trend instead of snapshot, decision instead of status, evidence instead of assertion. Where needed we rebuild the reporting template with the CIO/CISO — 8 to 12 pages, the 5×5 heatmap on page one, the same structure every quarter.
A structured detailed review with the CIO, the CISO and the two or three critical service providers: contracts, SLAs, audit reports, access rights, exit capability. We keep asking until the evidence is on the table, and report to the body where statement and evidence diverge.
After an incident, management needs someone in the body who decides, documents and can talk to the insurer, the regulator and the owners — not another expert opinion. We are in the conversation within 48 hours, structure the decision paper and record what was decided, when and on what basis. Handling the incident operationally stays with the incident response team.
Before an acquisition or an investment: where does the target company stand on identity, cloud posture, supply chain, OT/KRITIS and governance — and what does it cost to close the gap? We deliver the target’s heatmap, the open items with an effort estimate and the questions for the negotiation. After closing, that becomes the integration plan.
At the end of every oversight year there is a file an auditor or a regulator can read without us: minutes, question catalogues, answers, decisions, open items, self-assessment. When the mandate ends we hand it over in a structured way to the body or to the successor — with an introductory conversation.