Articles & insights
CISOs and Executive Committees: 10 Cyber Questions Boards Should Ask in 2027
Ten cybersecurity questions boards and executive committees should ask in 2027: AI, identity, suppliers, resilience, evidence, incidents and ROI.
Explore the full story
A board does not need to become an expert in EDR, SIEM or encryption. It does, however, need to know which cybersecurity decisions require its attention.
In 2026, the World Economic Forum describes an environment shaped by accelerating AI, geopolitical fragmentation, technology dependencies and widening capability gaps. INTERPOL, meanwhile, describes increasingly industrialised, AI-assisted cybercrime in Africa. NIST has strengthened governance in the Cybersecurity Framework 2.0 with a dedicated GOVERN function.
The message for 2027 is straightforward: cybersecurity is no longer just a defence problem. It is a matter of governance, continuity, dependency and evidence.
Board rule
A good cyber question does not ask “how many alerts do we have?” It asks: which business risk have we reduced, how do we know, and what still needs to be decided?
1. What are the three cyber scenarios that could stop our business?
The board should be able to name the genuinely material scenarios.
Examples:
- prolonged unavailability of identity or cloud services;
- ransomware affecting a critical environment;
- fraud/BEC causing a major financial loss;
- compromise of a strategic supplier;
- destruction or corruption of data;
- compromise of an AI agent authorised to take action.
What you want to hear
A scenario, a business impact, an owner, a level of preparedness and a mitigation plan.
Red flag
“We have 1,200 critical vulnerabilities.”
Without a connection to assets, scenarios and impact, that number is not enough to make a decision.
2. Which dependencies could bring us to a halt without a direct attack on us?
Modern cyber risk runs through suppliers: cloud, SaaS, telecoms, MSPs, integrators, identity, payments, APIs, data providers and software components.
The board should ask:
- which suppliers are genuinely critical;
- which service cannot be replaced in the short term;
- what plans exist in case of unavailability;
- which concentrations of dependency have been accepted.
The WEF 2026 report highlights dependencies and supply chains as risk multipliers.
3. Who can obtain elevated privileges — including humans, machines and AI agents?
Identity remains one of the most powerful routes to business impact.
The question is no longer simply “who has an admin account?”
It must also include:
- service accounts;
- API keys;
- cloud workloads;
- bots;
- AI agents;
- supplier access;
- temporary identities.
Follow-up question
How many standing privileges could become temporary or just-in-time?
4. Which AI uses are actually in production — and which can take action?
Request an inventory that distinguishes:
- generative AI used in read-only mode;
- internal copilots;
- models embedded in business applications;
- agents able to call tools;
- agents able to execute transactions or modify data.
The more a system can act, the more important identity, authority and logging controls become.
See: Responsible AI Governance in Francophone Africa.
5. Can we restore critical services within the promised timeframe?
A backup policy is not evidence of resilience.
Ask for:
- the date of the last restoration test;
- the scope tested;
- the actual duration;
- missing dependencies;
- the gap between RTO/RPO targets and observed results.
The difference between backup and resilience is simple: restoration must have been tested.
6. Which cyber decision must the executive committee make this quarter?
Reporting that never requests a decision is often operational reporting, not executive reporting.
Examples of board/executive committee decisions:
- accepting a supplier risk;
- funding a resilience architecture;
- reducing a legacy environment;
- mandating a privileged-access policy;
- stopping an uncontrolled AI use;
- balancing business speed against control.
The CISO should spell out: decision required, options, consequences and recommendation.
7. Which critical controls can we actually demonstrate?
The gap between “policy” and “evidence” becomes significant during an audit or crisis.
Request evidence for a few vital controls:
- privileged-access reviews;
- restoration tests;
- monitoring of critical assets;
- remediation of exploitable vulnerabilities;
- exception management;
- supplier tests;
- crisis exercises.
This evidence-based approach is at the heart of a mature ISO/IEC 27001 ISMS.
8. Can we make a decision in under an hour during a crisis?
A serious incident creates a governance problem as much as a technology problem.
The board should know:
- who is in command;
- who can isolate a system;
- who decides to communicate;
- who engages authorities or partners;
- which decisions require the CEO;
- how disagreements are handled.
Crisis exercises are useful precisely because they test these decisions before they become expensive.
9. Where are we spending money without evidence of effectiveness?
Cyber ROI is not simply “this solution blocked X attacks”.
The board can ask:
- which controls cost the most;
- which risks they reduce;
- what evidence of effectiveness exists;
- which technologies are redundant;
- which costs compensate for missing processes or skills.
Cyber spending is justified when it is tied to a clearly defined risk reduction, obligation or resilience capability.
10. If our CISO leaves tomorrow, what remains?
This is an excellent maturity question.
A mature organisation does not depend solely on one person's tacit knowledge.
It has:
- clear roles;
- procedures;
- a risk map;
- evidence;
- governance;
- deputies;
- a culture of accountability.
The CISO must build a system, not become the system.
A board's minimum dashboard
| Dimension | Example of a useful indicator |
|---|---|
| Risk | Changes in accepted material risks |
| Resilience | Restoration test results |
| Identity | Privileged exposure / exceptions |
| Suppliers | Unremediated critical risks |
| Vulnerabilities | Exploitable exposure on critical assets |
| Incident | Detection/containment capability for key scenarios |
| AI | Critical uses inventoried and controlled |
| Audit | Major findings and time to closure |
| Skills | Critical dependencies on a person/team |
What boards should no longer accept in 2027
- an overall score without an explanation of risk;
- thousands of alerts presented as evidence of performance;
- a security policy disconnected from business decisions;
- AI uses that have not been inventoried;
- critical suppliers without an exit scenario;
- backups that have never been restored;
- a crisis plan that has never been exercised;
- a critical risk with no owner.
ECW Dakar 2026
The ECW Executive Forum on 19 December puts these issues at the level where they belong: executives, CISOs, CIOs, CTOs, institutions, investors and technology companies.
Explore the Forum · Join ECW Live
Sources
- World Economic Forum — Global Cybersecurity Outlook 2026: https://www.weforum.org/publications/global-cybersecurity-outlook-2026/
- INTERPOL — African Cyberthreat Assessment 2026: https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa
- NIST — Cybersecurity Framework 2.0: https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
- ENISA — Threat Landscape 2026: https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape
- ISO — ISO/IEC 27001:2022: https://www.iso.org/standard/27001
