The governance gap
Cyber crime and data security is repeatedly the number one issue keeping Australian directors awake at night[5], yet only 4% of ASX 100 directors have an IT background[3] and boards still carry ultimate accountability for technology risk. With the average data breach now costing US$4.44 million globally and taking 241 days to contain[4], that gap is no longer tolerable.
APRA CPS 234 makes the board ultimately responsible for information security[1], and the newer CPS 230, in force since 1 July 2025, extends board-level accountability to the management of material service providers such as your MSP[2]. Most boards lack the technical depth to verify either is actually being met.
What every board should ask quarterly
- Service performance: are we meeting our SLAs, and where are the systematic misses?
- Security posture: which CPS 234 controls exist in evidence (not slide deck), and which are aspirational?
- Vendor concentration: what percentage of operational risk sits with a single provider?
- Cost trajectory: is technology spend tracking forecast, and where it is not, do we know why?
- Cyber incident readiness: when was the last live tabletop, and what did it reveal?
- Governance trail: do board minutes reflect substantive technology decisions or rubber-stamping?
How to read the answers
A management team that cannot crisply answer these questions in plain English is not necessarily incompetent, but they almost certainly need independent oversight. The role of independent technology advisory is to give the board a translation layer between operational technology reality and director-grade decision-making.