Cyber Board Essentials

A board-level view of where your cyber exposure actually sits, who owns it, and what you can say about it under pressure. Facilitated with your executive team, scored against an international framework, and written for a board rather than for IT. Delivered as a structured programme with Impetus Advisory.

UK  |  Ireland  |  Europe  |  North America

The buying moment

Boards do not buy cyber. They buy defensibility; the ability to answer a hard question confidently when someone with leverage asks it. The cyber work is how you get there.

Four people now ask that question, and three of them arrive on a date.

The insurer

Renewal now requires evidence of governance, tested incident response and third-party control. The questionnaire has grown every year and the answers are checked.

The enterprise customer

Supplier security assessment is standard procurement. Failing one does not produce a remediation plan; it produces exclusion from the tender, usually without an explanation.

The acquirer or investor

Cyber posture is assessed in diligence and material governance gaps are priced. Findings that surface after the LOI cost considerably more than findings that surface before it.

The regulator

NIS2 places cyber governance duties on the board itself. Whether it reaches you, and when, is worth knowing now rather than in the quarter it lands.

Most leadership teams cannot confidently answer three questions: how exposed are we, who owns this, and what should we prioritise. The board is where the buck stops, and the people in that room are usually operationally fluent and cyber-illiterate. That is not a criticism; it is a description of a gap nobody has been asked to close until recently.

The MSP blind spot

Most mid-market companies assume their MSP or MSSP has this covered. They do not, and the reason is structural rather than a failure of goodwill.

Providers assess and report against the tools they are licensed to resell. They measure what they can remediate; they do not measure what a board needs to know. An MSP report can show every light green because it only covers what is deployed. It cannot tell a board whether the incident response plan has been tested this year, whether third-party exposure is understood, or whether the governance structure would survive an insurer's questionnaire.

The work is independent by construction. No software partnerships, no reseller relationships, nothing to place at the end of it. Findings are measured against what the board is accountable for rather than against tool deployment.

The board risk register is not the IT risk register

Most organisations already maintain an operational risk register covering patching, end-of-life hardware and scan results. That is an IT operations artefact and it belongs where it is.

What a board needs sits at a different altitude. It expresses cyber risk in the terms a board actually decides on: insurance renewal at risk, customer audit failure, regulatory exposure, valuation discount. This work does not replace what IT already runs; it creates the governance layer above it, which is the layer everybody else asks to see.

How the work runs

Three phases. Each stands alone; the programme is designed so a board can stop after any one of them.

Cyber Readiness Diagnostic

A facilitated working session with the CEO, CFO and the operational lead, run against a structured instrument covering seven domains. Output is a readiness score with category breakdown, the top five exposure areas, an indicative view on whether NIS2 is likely to reach you, and a board-ready executive summary. Larger organisations add a detailed domain analysis, a 90-day priority roadmap and a board deck.

Cyber Governance Uplift

Four working sessions across four to eight weeks that turn the findings into governance. A board-level cyber risk register expressed in business impact terms; a RACI ownership matrix naming accountability at board, executive and operational level; a twelve-month roadmap across immediate, structural and delegated horizons; a board reporting framework and KPI set; and a presentation to the board or audit committee. A structured 90-day check-in is included as standard.

Execution Oversight

For boards that conclude they need help turning the roadmap into operational change. Fractional oversight of remediation against the Phase 2 plan, vendor and MSSP selection, coordination across IT and engineering, and board-ready reporting on risk reduction. Delivered by The Impact CTO.

Phase 3 is not the point of Phases 1 and 2. Many boards finish at Phase 2 with ownership established and run the work themselves; the programme is built to make that possible rather than to make it awkward.

The Phase 1 output; the Diagnostic Snapshot issued at the end of the working session. Baseline readiness score, regulatory applicability, domain posture and the exposures for board attention. Illustrative engagement, sample data.
Sample Phase 1 Diagnostic Snapshot: a board readiness score of 32 out of 100 against NIST CSF 2.0 at Tier 1, a regulatory applicability panel covering NIS2 scope, GDPR convergence and other regimes, posture percentages across seven domains with a convergence overlay, and four priority exposures for board attention labelled ratify, approve, authorise and direct. Illustrative data.

Where NIS2 fits

NIS2 is one of the four pressures rather than the product. The assessment tells you whether it is likely to reach you, roughly when, and what you would need to have in place; a finding inside a broader picture rather than the reason for the engagement.

The position as it stands: Ireland missed the October 2024 transposition deadline, the National Cyber Security Bill is at committee stage, the European Commission referred Ireland to the CJEU in July 2026 over the delay, and enactment is expected before the end of Ireland's EU Council Presidency in late 2026. On 7 July 2026 the Irish NCSC published its Guidance on Cyber Governance for Management Board Members in NIS2 Entities, which restates the board-level duties in plain language: approve the risk-management measures, oversee their implementation, undertake cybersecurity training, and maintain ongoing oversight. It signals that supervisors are likely to look first at governance arrangements.

Personal liability is not yet live in Irish law because the Bill has not been enacted. What has changed is that no board can now say it did not know what was expected of it.

The guidance carries a free, self-administered readiness checklist, and the difference is worth stating plainly. A checklist a board fills in itself tends to reflect what the board hopes is true. A session facilitated by someone independent, where the answers are challenged in the room and scored against a framework, tends to reflect what is actually true. That is the difference this work is built around, and it is the same difference an insurer or an acquirer is testing for.

What it is anchored to

The assessment is built on NIST Cybersecurity Framework 2.0, across seven domains: governance and accountability; risk identification and control; incident detection, response and reporting; operational resilience and recovery; third-party and supplier risk; baseline technical safeguards; and regulatory defensibility and evidence. Scores map to the NIST maturity tiers, so the result is referenceable rather than proprietary; an insurer or an acquirer can place it against something they already recognise.

The Irish NCSC has put the Cyber Fundamentals Framework at the centre of its board guidance, and Cyber Fundamentals is itself being transitioned to NIST CSF 2.0. Because this work is built on the same framework, it should carry across rather than need to be repeated when the national certification scheme becomes operational.

An eighth category sits outside the score as an overlay: the seam where cyber, privacy and incident-reporting obligations meet. Organisations that run these as separate programmes tend to produce duplicated effort, contradictory evidence, and security tooling that quietly collects more personal data than it can justify. It is reported separately because it is an emerging area of regulatory focus rather than an established one.

Who commissions this

The buyer is the CEO. The working session participants are the CEO, the CFO and whoever holds operational visibility; the CTO, CIO or IT lead. The audience for the deliverable, and the people carrying the accountability, are the directors as a body.

The executive who answers the assessment attests that their answers are accurate, rather than the answers being delegated to IT. That is deliberate. Delegation is how boards end up with an optimistic picture, and a record of the executive having engaged with the questions is itself part of the governance evidence.

This work earns its fee when something is coming: a renewal, an audit, a questionnaire, a transaction inside eighteen months, or a board that has been asked a question it could not answer. Absent a trigger, a governance assessment produces a document nobody reads, and it is better to say so than to sell one.

Where this sits

The big four firms operate above this segment and price accordingly. MSPs operate below it and cannot be independent about it. Compliance consultancies operate beside it, running checklists rather than governance. The middle is where mid-market boards actually live and it has been largely empty.

What this is, and what it is not

This is advisory work. It gives a board an independent, structured view of its cyber governance posture, an indicative read on whether NIS2 is likely to apply, and a prioritised plan for closing the gaps that matter.

It is not a regulatory audit, a certification, or a legal opinion, and it does not sign off compliance. Where a formal determination is needed, that sits with your legal advisers or an accredited assessor. What this produces is the governance position a board can hold and explain; deciding what the law requires of you is a separate question and a different professional.

Delivery

Cyber Board Essentials is delivered jointly with Impetus Advisory. Phases 1 and 2 are run by me or by one of the Impetus partners, depending on the engagement. Phase 3, execution oversight, is delivered by The Impact CTO alone.

Fixed fee, agreed in advance. Scope and fee are set before any work begins.

If an insurer, a customer or an acquirer is about to ask where your cyber governance stands, the first step is a conversation about what you would be able to tell them.

Book a call