Five Cyber Questions Every Audit Committee Should Ask

Aug 12, 2026 | Audit and Accounting, Advisory and Business

Five Cyber Questions Every Audit Committee Should Ask

Good cyber oversight starts with clear questions about risk, resilience and accountability.

Cybersecurity reporting is often too technical for audit committees and boards. Dashboards may show alerts, vulnerabilities or system activity, but still fail to answer the core governance question: is the organisation becoming more resilient and are material cyber risks being managed?

Audit committee members do not need to understand every technical detail. They do, however, need to ask questions that force management to explain the business impact, ownership and evidence behind cyber risk management activities.

Why this matters

Cyber risk can affect service delivery, financial reporting, operations, regulatory compliance and reputation. Audit committees should therefore ensure that cyber risk is visible in governance structures and not buried within IT operational reporting.

What management should consider

  • What are our most critical systems and data, and who owns them?
  • Can we recover from ransomware without paying and when last was this tested?
  • Who has privileged access and how is their activity monitored?
  • Are outsourced providers contractually accountable for cyber incidents and control failures?
  • When last did management test the incident response plan through a realistic scenario?
  • Are high-risk vulnerabilities being remediated within agreed timelines?
  • Do cyber metrics show risk reduction, not only technical activity?

Common pitfalls to avoid

Accepting technical dashboards without asking what risk remains.; Treating cyber risk as separate from operational resilience.; Failing to assign ownership for unresolved cyber actions..

Key takeaway

Audit committees should move the cyber discussion from technical activity to business risk, evidence, ownership and readiness.

Practical first step

Ask management to present the top five cyber risks in business language, including owner, current control status and unresolved actions.

How Nexia SAB&T can assist

Nexia SAB&T can assist with audit committee cyber briefings, cyber maturity assessments, cyber risk register reviews and board-level cyber reporting design.

Author details: Rob Galetti | IT Audit and Cybersecurity | Nexia SAB&T

Date: 12 August 2026

Recent Articles

Cyber Resilience Is Becoming a Regulatory Expectation

Cyber Resilience Is Becoming a Regulatory Expectation

Regulators increasingly expect organisations to prevent, withstand, respond to and recover from cyber incidents. Cybersecurity has shifted from being a technical best practice to a governance and regulatory expectation, especially in sectors that provide critical...

Read More 9
You Can Outsource IT, But Not Cyber Accountability

You Can Outsource IT, But Not Cyber Accountability

Service providers may operate controls, but management remains accountable for understanding the risk. Many organisations rely on managed service providers, cloud providers, software vendors, payroll providers and outsourced IT support. Outsourcing can provide...

Read More 9
Your Tax Deadlines for August 2026

Your Tax Deadlines for August 2026

07 August: PAYE submissions and payments 25 August: VAT manual submissions and payments 28 August: Excise duty payments 31 August: VAT electronic submissions and payments PIT Provisional Tax payments (first provisional tax payment) CIT Provisional Tax payments where...

Read More 9