A questionnaire arrives from a client. Sixty questions about information security, to be returned before the end of the month. Someone fills it in. The answers are largely affirmative, and rightly so: there is policy, there are measures, there is a supplier who takes care of it.
The questionnaire goes back. Nobody has checked whether the answers are true.
That is not bad faith. It is what happens when an organisation has to declare something it cannot verify. On paper a great deal is arranged. Yet it often remains unclear whether the most important measures do what you expect of them at the moment it matters.
That is not a detail. As long as effectiveness cannot be demonstrated, your resilience rests on assumptions. And assumptions are hard to steer by, hard to adjust, and hard to defend when a client, an auditor or your own supervisory board starts asking questions.
Why this is a board-level matter
Cyber risk becomes a board matter the moment it touches continuity, client trust, legal obligations or standstill.
The core question is then not whether measures exist. The core question is whether you can substantiate that the right measures exist, are carried out, and work as intended.
That takes more than an overview of measures or a statement from a supplier. It takes coherence between four things: what is critical, what that depends on, who is accountable for it, and what evidence exists.
Without that coherence a recognisable picture emerges. A great deal is arranged. Nobody can point to what the organisation actually relies on.
What I typically see
- the declaration to a client was completed by someone who could not verify the underlying situation
- there is a continuity plan, and it has never been tested, not even on paper
- the supplier sends an annual report that nobody on the board can read, and which therefore nobody contradicts
- the supplier's certificate is read as a guarantee, while nobody has looked at what it actually covers
- after an incident a measure was taken, and nobody afterwards established whether that measure resolves the problem
- the previous director knew where the weak spots were, and that was not handed over on departure
- there is an insurance policy, and nobody has worked out what it requires you to have arranged yourself
- a finding is reported, someone replies that it has been picked up, and there the trail ends
- responsibilities are recorded in a document drawn up for an audit and never opened since
- the question "can we demonstrate this" only reaches the table when someone from outside asks it, and then under time pressure.
Each element is defensible on its own. Together they do not add up to a picture you can govern by.
The questions this raises
You do not need to know any technical detail. You do need to know which certainties you require and what your decisions rest on.
- Which processes, services or data must not come to a standstill?
- What do those depend on, and who provides it?
- Which event would genuinely hurt the business there?
- Who is accountable for effectiveness, follow-up and the acceptance of risk?
- What shows that the most important measures exist and are carried out?
- What shows that they also work under pressure?
- Which assumptions are you currently treating as certainties?
- What do you declare to clients, and who has checked whether that is accurate?
- Which decisions are needed once it turns out evidence is missing?
These questions move cyber away from technology and return it to continuity, accountability and evidence.
What a Reality Check delivers here
A Reality Check does not test whether you comply with an entire standard. It starts from one concrete board-level question and makes visible what is substantiated, what rests on assumptions, and where you need to take a decision.
On this subject, that typically produces:
- a sharp picture of the critical processes the question concerns
- an overview of what those processes actually depend on
- the distinction between existing policy, activity carried out, and genuine evidence
- an overview of evidence that is missing or fragmented
- insight into what you declare to clients and whether it can be substantiated
- decision points for the board, sharp enough to make the trade-off yourself
- clear ownership for follow-up and accountability.
What a Reality Check does not deliver is an improvement programme or a cost estimate. What it costs to close a gap depends on choices you still have to make. Those choices stay yours.
The value does not lie in more documentation. The value lies in the difference between presence and effectiveness.
In short
Resilience is not demonstrable because measures exist. It is demonstrable when it is clear which measures are critical, who is accountable for them, and what evidence shows that they work.
Outsourcing moves execution, not responsibility. And a declaration nobody has checked is not a declaration. It is an expectation with your signature under it.
