What should a not-for-profit board know about IT risk?
Four things, none of which requires technical expertise to ask about. What personal data does the organisation hold and about whom. What protects it. When was that last assessed by somebody independent of the people who set it up. And what would happen, in practice, if it were breached tomorrow.
Those questions matter here more than in a comparable business because of who is affected. A not-for-profit holds donor payment details and participant records, and in disability, health, youth, family and community services those records describe circumstances that people would be harmed by having disclosed. The board's governance responsibility for risk extends squarely to that, whether or not anyone around the table considers themselves technical.
The quality of the answers is as informative as their content. Specific answers with dates attached indicate the risk is being managed. Reassurance that everything is fine, or a technical explanation that does not answer the question asked, indicates it is not being managed so much as hoped about. A board is entitled to specifics, and asking for them is the whole of the governance function here.
Make it an annual item rather than a reaction to something. One page to the board covering data held, controls in place, the date of the last independent assessment and what remains outstanding, plus immediate reporting of any material incident. That is enough to make the oversight genuine, and it means the conversation happens when everyone is calm rather than during an incident. If you want a report a board can actually read, the Cyber Security Scorecard is free, or call 1800 456 567.
Give the board something to govern
The free Cyber Security Scorecard produces a dated report a board can read and act on, rather than a technical document nobody discusses.
Related reading
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business