FL Fredrik Lindstrom


Most cyber briefings are written for the SOC. This one is written for the board. Thirteen terms, defined for oversight, each paired with the single question to put to management before the next incident, not in the post-mortem.

A director does not need to know how encryption works. They need to know who holds the keys, and whether anyone has checked. Every term below is followed by the stake that makes it a board matter and the one question that surfaces whether it is actually handled.

Board briefing sheet — thirteen must-know cybersecurity terms for directors, each with a plain definition, the board-level stake, and the question to ask management.
Download the one-page sheet PDF, A4, text selectable, prints for board packs. No email required.

The thirteen terms

Core vocabulary Acute board exposure

  1. 1

    Ransomware

    Acute board exposure

    Malware that locks or steals your data, then demands payment. Modern crews do both: encrypt and threaten to leak.

    Stake: Paying may be illegal if the group is sanctioned. Not paying may halt operations for weeks.

    AskHave we decided, in advance, whether we would pay — and confirmed it is legal?

  2. 2

    Phishing and social engineering

    Acute board exposure

    Tricking a person into clicking, paying, or handing over access.

    Stake: Most breaches still start with a person who clicked, not a flaw no one knew about.

    AskWhen did we last test our own people, and what share failed?

  3. 3

    Multi-factor authentication

    Core vocabulary

    A second proof of identity beyond the password. A code, a key, a prompt.

    Stake: The highest-return control there is. Insurers now refuse to cover firms without it.

    AskIs MFA enforced everywhere, including admins, vendors and legacy systems?

  4. 4

    Zero trust

    Core vocabulary

    Trust nothing by default. Verify every user, device and request, every time.

    Stake: The architecture regulators and insurers now expect. Network location no longer earns access.

    AskWhere are we on the zero-trust roadmap, and what still runs on implicit trust?

  5. 5

    Attack surface

    Core vocabulary

    Everything an attacker could reach. It grows with every cloud app, vendor and remote device.

    Stake: You cannot defend what you do not know you own. Shadow IT widens it silently.

    AskDo we have a current inventory of everything internet-facing?

  6. 6

    Supply-chain risk

    Acute board exposure

    Your security now depends on your vendors' security. SolarWinds and MOVEit reached thousands through one supplier.

    Stake: You inherit every breach upstream of you, and the regulator still asks you.

    AskWhich third parties can reach our most sensitive data, and how do we assure them?

  7. 7

    Patch management

    Core vocabulary

    Closing known holes before attackers use them.

    Stake: Most intrusions walk through a known door a patch already existed for.

    AskWhat is our mean time to patch a critical vulnerability?

  8. 8

    Business email compromise

    Acute board exposure

    Impersonating an executive or supplier to redirect a payment.

    Stake: The FBI ranks it the costliest cybercrime by dollar loss. No malware required.

    AskWhat stops a spoofed CEO email from authorising a wire transfer?

  9. 9

    Endpoint detection and response

    Core vocabulary

    Continuous monitoring on every device, with the ability to isolate and respond.

    Stake: The gap between break-in and detection — dwell time — decides whether it stays an incident or becomes a catastrophe.

    AskHow long could an intruder sit in our network before we noticed?

  10. 10

    Encryption

    Core vocabulary

    Scrambling data so it is useless without the key, at rest and in transit.

    Stake: Many breach laws offer safe harbor if the stolen data was encrypted. Key control is the catch.

    AskIs our sensitive data encrypted, and who holds the keys?

  11. 11

    Incident response

    Acute board exposure

    The rehearsed plan for the breach you will eventually have.

    Stake: Under 30% of firms are confident in their incident response (Barclays, 2026). Confidence comes from rehearsal.

    AskWhen did this board last sit through a breach tabletop?

  12. 12

    Breach disclosure and materiality

    Acute board exposure

    The legal duty to tell regulators and markets when a material incident happens.

    Stake: US public companies must disclose a material incident within four business days of deciding it is material (SEC, 2023).

    AskWho decides materiality here, and could we file within four days?

  13. 13

    Cyber insurance

    Core vocabulary

    Transferring some of the financial risk of a breach to an insurer.

    Stake: Policies now demand MFA, EDR and tested backups, and exclude acts of war. Coverage you cannot claim is not coverage.

    AskWhat does our policy exclude, and do we actually meet its control requirements?

Strong security posture produces compliance as a by-product. The reverse never works.

Sources: NIST Cybersecurity Framework 2.0 (2024) · Verizon Data Breach Investigations Report · SEC Form 8-K, Item 1.05 (2023) · FBI IC3.


Related

What AI actually contains — a corrected taxonomy of the capability stack, and why agents are an architecture rather than a stage of intelligence.

What each AI tier actually decides — regulatory exposure tracked against the consequence of the decision, with the reversibility column most charts leave off.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.