All resources
Guide · Governance

ASX governance: the 4% directors problem

Only 4% of ASX 100 directors have IT backgrounds. With an average global data breach cost of $4.44 million, that gap is no longer tolerable.

By , Founder12 min readPublished 15 Sept 2025Updated 17 Oct 2025

The governance gap

Cyber crime and data security is repeatedly the number one issue keeping Australian directors awake at night[5], yet only 4% of ASX 100 directors have an IT background[3] and boards still carry ultimate accountability for technology risk. With the average data breach now costing US$4.44 million globally and taking 241 days to contain[4], that gap is no longer tolerable.

APRA CPS 234 makes the board ultimately responsible for information security[1], and the newer CPS 230, in force since 1 July 2025, extends board-level accountability to the management of material service providers such as your MSP[2]. Most boards lack the technical depth to verify either is actually being met.

What every board should ask quarterly

  • Service performance: are we meeting our SLAs, and where are the systematic misses?
  • Security posture: which CPS 234 controls exist in evidence (not slide deck), and which are aspirational?
  • Vendor concentration: what percentage of operational risk sits with a single provider?
  • Cost trajectory: is technology spend tracking forecast, and where it is not, do we know why?
  • Cyber incident readiness: when was the last live tabletop, and what did it reveal?
  • Governance trail: do board minutes reflect substantive technology decisions or rubber-stamping?

How to read the answers

A management team that cannot crisply answer these questions in plain English is not necessarily incompetent, but they almost certainly need independent oversight. The role of independent technology advisory is to give the board a translation layer between operational technology reality and director-grade decision-making.

Research sources

Evidence-based, transparently sourced.

All statistics and research findings on this page are supported by authoritative sources. Behind The SLA is committed to evidence-based advisory and transparent methodology.

  1. [1]
    APRA. (2019). Prudential Standard CPS 234 Information Security
    The board of an APRA-regulated entity is ultimately responsible for information security, and the entity must maintain a capability commensurate with the size and extent of threats to its information assets.
    View source
  2. [2]
    APRA. (2025). Prudential Standard CPS 230 Operational Risk Management
    In force from 1 July 2025. Requires regulated entities to manage operational risk and the risks arising from material service providers, including a service-provider management policy and register.
    View source
  3. [3]
    Phair, N. & Alavizadeh, H., UNSW Institute for Cyber Security (UNSW Canberra). (2022). Cyber security skills of company directors: ASX 100
    Analysis of 798 director positions across the ASX 100: only 4% of directors have an information technology background, and 80% of boards have neither IT nor cyber experience.
    View source
  4. [4]
    IBM Security. (2025). Cost of a Data Breach Report
    Average global data breach cost: US$4.44 million (down from US$4.88 million in 2024); US average a record US$10.22 million; 241 days on average to identify and contain.
    View source
  5. [5]
    Australian Institute of Company Directors. (2025). Director Sentiment Index
    Cyber crime and data security is repeatedly the number one issue keeping Australian directors awake at night.
    View source

Methodology Note: Behind The SLA conducts independent research validation for all published statistics. Where proprietary research is cited, it is based on aggregated, anonymised data from client engagements spanning 15+ years of MSP industry experience.

Want this applied to your organisation?

An independent advisory conversation costs nothing, and clarifies whether what you have read here is relevant to where you actually are.

Schedule a conversation