Boards, not just IT teams, are accountable for cyber risk
What happened
Australian guidance and reforms place board accountability for cyber risk and set reporting windows that start when the entity is aware. The update is operationally real because boards must now see actable exposure maps and costed closure options, not just slide decks. Watch whether boards demand supplier-delivered exports and audit‑ready packages during renewals
Why the category manager should care
Treat board accountability and incident windows as contract requirements; require telemetry and export formats that feed board reports
Key facts
- Reforms set incident reporting windows measured from awareness, not briefing
- Guidance requires continuous visibility across identities, cloud and on‑prem systems