Cyber Security Governance for Australian Boards & Directors

Cyber security governance – the oversight and management of cyber risk by a board – is now a core boardroom focus in Australia.

Board‑level discussion focused on cyber security governance and risk oversight for Australian boards and directors.

Executive Summary

Cyber security governance is how an organisation’s board of directors ensures cyber risks are properly managed and mitigated as part of its corporate governance responsibilities. In recent years, high-profile data breaches and rising cybercrime costs have highlighted that cyber security must be overseen at the highest levels of business leadership. Today, Australian boards and directors are expected to treat cyber risk as seriously as financial or legal risks – not just as an IT matter. 

Effective cyber security governance at board level means that directors proactively guide and oversee the organisation’s approach to cyber security, ensuring there are clear strategies, adequate resources, robust risk management processes, a security-aware culture, and strong incident readiness. This not only protects shareholders and stakeholders, but also fulfils directors’ fiduciary duties of care and diligence in an era where regulators and courts may hold boards liable for severe cyber security lapses.

Cyber risk on the leadership agenda?

This Executive Cyber Brief is designed as a practical pre-read for MDs, GMs and Ops leaders before the next leadership meeting.

Executive Cyber Risk Brief

Why is Cyber Security Governance a Board Responsibility?

IRAP stands for Infosec Registered Assessors Program. It is an Australian Government initiative, governed by the Australian Cyber Security Centre (ACSC, part of ASD), that endorses qualified cyber security professionals (IRAP assessors) to conduct independent security assessments of ICT systems. In simpler terms, IRAP provides a structured process for having an external expert review your organisation’s security and ensure it meets the government’s standards. 

IRAP’s primary goal is to protect government data by assessing whether appropriate security controls are in place in systems that handle such dataEndorsed IRAP assessors come from the private or public sector and are certified by ASD to evaluate systems, suggest mitigations, and highlight residual risks. They check your security against official Australian Government policies and guidelines, especially the Information Security Manual (ISM). 

Key points about IRAP: 

  • Not a “certification” in itself: Importantly, an IRAP assessor does not directly certify or accredit your system. Instead, the assessor produces a report on your security controls, which is then used by a government authority (the “authorising officer”) to decide if your system can be approved (authorised) to handle government information. Think of IRAP as an independent audit – it provides assurance and identifies gaps, but the final sign-off lies with the government agency consuming your service. 
  • Scope of IRAP: IRAP assessments are typically required for systems that will store or process Australian Government data, such as cloud services offered to agencies, outsourced IT solutions, or vendor platforms that manage sensitive information. The IRAP program originally emerged to support cloud security (replacing older certification schemes in 2020), but it now applies to a broad range of technology including on-premises systems (especially at higher classifications). 
  • Outcome of IRAP: After an IRAP assessment, you receive a Security Assessment Report (SAR) and a Controls Matrix. The SAR summarises the system’s security posture, listing strengths and weaknesses found, while the controls matrix details the implementation status of each applicable ISM control (with justifications). These documents are intended for both executive decision-makers and technical teams to understand exactly where the system stands against the requirements16. 

The AICD Cyber Security Governance Principles (Simplified)

To help boards navigate cyber oversight, the Australian Institute of Company Directors (AICD) has published Cyber Security Governance Principles (latest version in late 2024). These five principles outline best-practice approaches for boards and directors to govern cyber risk effectively. 

In summary, the five AICD Cyber Security Governance Principles are: 

  • Set clear roles and responsibilities – Define who is accountable for cyber security at board and management levels. 
  • Develop, implement and evolve a comprehensive cyber strategy – Ensure a sound cyber security strategy is in place and aligned with business goals. 
  • Embed cyber security in risk management practices – Integrate cyber risks into enterprise risk management and oversight. 
  • Promote a culture of cyber resilience – Lead by example and cultivate organisation-wide awareness and accountability for security. 
  • Plan and prepare for significant cyber security incidents – Be ready for crises with robust incident response and recovery plans. 

Let’s break these down in plain language and discuss what they mean for boards: 

Principle 1: Set Clear Roles and Responsibilities

The board must establish clear accountability for cyber security. This means explicitly assigning a senior executive (often a Chief Information Security Officer or CIO) to be responsible for day-to-day cyber risk management, and deciding how the board will oversee their work (for example, via a dedicated board risk committee or a cyber-specific subcommittee). 

In practice, a clear division of responsibilities between board governance and management execution is key. For example: 

Board’s Governance Role  Management’s Role 
Set the strategic direction & risk appetite for cyber security (e.g., how much risk the company is willing to accept).  Develop and execute a detailed cyber security strategy and programme to meet the board’s risk appetite and objectives. 
Oversee and monitor the implementation of cyber security initiatives via regular reports and metrics.  Implement security controls, policies, and processes; report on progress and incidents to the board. 
Ensure adequate resources & budget for security and compliance with legal/regulatory obligations.  Manage the day-to-day operations of cyber defences, incident response, training, and compliance activities. 

By setting clear roles, the board signals that cyber security is a priority and prevents gaps or confusion about who is in charge of protecting the organisation. 

Principle 2: Develop, Implement and Evolve a Comprehensive Cyber Strategy

cyber security strategy is a formal plan that outlines how the organisation will protect its digital assets, including what threats it prioritises, which safeguards to implement, and how it aligns with business objectives. The board should ensure management has crafted such a strategy and regularly updates it. 

Board expectations include: 

  • Identifying the organisation’s key digital assets and data (the “crown jewels”), who can access them, and how they’re protected. 
  • Ensuring the strategy addresses external dependencies and third parties (like cloud services or vendors) that might affect security. 
  • Requiring periodic independent reviews or audits of the strategy and controls, so the plan is tested and updated against evolving threats. 

Boards should look for concrete strategic elements like an annual cyber security roadmap, a defined target maturity (e.g., achieving certain standards such as the ASD Essential Eight or ISO 27001), and alignment between the security program and overall business growth plans. 

Principle 3: Embed Cyber Security in Risk Management Practices

Cyber security risk should not live in a silo; it must be woven into all existing risk management processes. This means that within the company’s risk register and frameworks, cyber risks are clearly listed, assessed for likelihood and impact, and have controls and treatments in place. Boards should see evidence that management isn’t treating cyber as a one-off project but as an ongoing risk category, with risk appetite statements, regular risk assessments, and mitigation plans. 

As part of this, boards should insist on regular assessments of key cyber controls (e.g., through internal audits, penetration tests, and control self-assessments). Effective boards also ensure that reliance on external providers’ security (e.g., cloud platforms) doesn’t create blind spots – management should evaluate vendor security during procurement processes and not assume third-party tools are inherently secure without verification. 

Principle 4: Promote a Culture of Cyber Resilience

Cyber resilient culture starts at the top. Boards need to champion a culture where security is everyone’s responsibility and good cyber hygiene is part of day-to-day operations. This involves: 

  • Ensuring directors and executives themselves receive cyber security training and participate in initiatives like phishing simulations, to set an example. 
  • Including cyber security awareness and accountability in employee training and even in performance KPIs for relevant leadership roles. 
  • Reinforcing through internal communications that following security protocols is non-negotiable – avoiding any perception that senior leaders are exempt from policies (no “special treatment” like skipping security updates or bypassing processes). 

A strong culture means that even the best technical defenses are supported by vigilant people and effective processes. 

Principle 5: Plan and Prepare for Significant Cyber Security Incidents

No organisation can guarantee it won’t face a serious cyber incident, so boards must ensure robust incident response and recovery plans are in place. Directors should: 

  • Review and approve a formal cyber incident response plan that outlines actions, responsibilities, and communication strategies for various types of incidents (e.g., data breach, ransomware). 
  • Participate in or observe regular simulation exercises or tabletop drills to test the plan, so the board and senior management know their roles during a crisis. 
  • Have clarity on how the organisation will communicate with stakeholders – customers, regulators, media, and investors – if a major breach occurs, to manage reputational risk and maintain trust. 

By planning ahead, boards help their organisation react quickly and effectively under pressure, minimising damage and ensuring lessons are learned after an incident. 

Cyber Security Governance Priorities for Boards in 2025–26

The ASD–AICD joint guidance for boards (2025–26) highlights some key focus areas that Australian boards should prioritise given the current threat landscape and emerging challenges. These priorities build on the AICD principles and give directors specific top-of-mind issues to address: 

1. Secure by Design and Secure by Default

Boards should ensure that any technology systems or products the organisation uses (or provides to customers) are built with security from the ground up. “Secure by design” means security features are embedded into systems during development, to prevent common vulnerabilities from the start. “Secure by default” means systems and software come with strong security settings enabled out of the box, rather than relying on users to turn them on. 

Board action: When reviewing new digital projects or acquisitions, ask management how they are implementing secure development practices (such as code security testing, secure architecture reviews) and whether default configurations for software/hardware are set to the most secure settings. Encourage a mindset that it’s easier and cheaper to bake security in upfront than to bolt it on later. 

2. Protect Critical Assets and Assume Compromise

Boards must push their organisations to identify the “crown jewels” – the most critical data, systems, and services – and apply the strongest safeguards around them. This means concentrating security investments and policies on assets that, if compromised, would be catastrophic (financially or operationally). Simultaneously, directors should encourage an “assume compromise” mindset: operate as if a threat actor could already be inside your network and design security accordingly (e.g., limiting lateral movement, using robust monitoring, and ensuring backups). 

Board action: Ensure management has a clear inventory of critical assets and is implementing extra layers of protection for those (like stricter access controls, encryption, 24/7 monitoring). Ask questions such as, “Which systems or data would pose the greatest risk if breached, and how are we locking those down?” Embracing assume-compromise means focusing on detecting intrusions quickly and having containment plans, not just trying to prevent every single attack. 

3. Strengthen Threat Detection and Modernise Legacy Systems

Even with great prevention, incidents can happen. That’s why rapid threat detection and response capabilities have become a priority. Boards should expect an enterprise-wide approach to event logging and monitoring, so that any malicious activity in the network is quickly identified. Meanwhile, outdated legacy IT systems often present vulnerabilities and should be retired or significantly hardened to avoid being weak links. 

Board action: Check that management has invested in modern detection tools (like security information and event management systems, or 24/7 security operations centre services) and the organisation isn’t flying blind when under attack. Ask, “How quickly would we detect a breach, and do we have the right logs to investigate incidents?” Additionally, get updates on any plans to replace or secure legacy systems – and if such systems must remain, ensure compensating security controls and concrete timelines to upgrade them. 

4. Manage Third-Party and Supply Chain Cyber Risk

Boards should not overlook the cyber risks stemming from third-party vendors and suppliers. When entrusting sensitive data or critical operations to external partners (like cloud providers, software vendors, or outsourced services), the organisation’s security is only as strong as that of its partners. Therefore, third-party risk management must be part of cyber governance. 

Board action: Ask management how they vet suppliers for security (for example, do service providers follow standards like ISO 27001 or IRAP for government work?). Ensure that contracts include cyber security requirements and incident notification clauses. It’s wise to include supplier risks in the regular risk reports to the board. A question to consider: “What are our most critical supplier relationships, and how are we confident those partners are managing cyber risks properly?”. 

5. Prepare for Emerging Threats (e.g. Post-Quantum Cryptography)

Forward-thinking boards look beyond today’s threats to tomorrow’s challenges. A notable emerging issue is the impact of quantum computing on cryptography – within the next decade, quantum computers could break today’s encryption. Australian Government guidance suggests that boards of organisations with long-lived sensitive data (like health or national security information) should start planning for a migration to post-quantum cryptography (encryption methods resistant to quantum attacks). 

Board action: Without getting into deep technical detail, directors should ensure someone in the organisation is responsible for tracking developments in post-quantum security and creating a transition plan. Ask if a cryptographic asset inventory has been done – identifying where and how your data is protected with current encryption – and whether relationships with vendors and partners consider future encryption standards. While not an urgent change for all, boards should incorporate it into their long-term technology risk discussions. 

Don’t Forget the Basics: All these areas should complement strong fundamental security practices. Boards should still verify that basic cyber hygiene (like up-to-date software patching, multifactor authentication on accounts, regular backups, and employee awareness training) is consistently maintained. These basics form the foundation on which advanced measures are built. 

Boardroom Questions: How Directors Can Gauge Cyber Resilience

As part of their oversight, boards need to probe management with smart questions. These questions help directors test the organisation’s cyber posture and focus discussions on key governance areas. Here are some examples: 

  • Clarifying Accountability: Who is our designated executive accountable for cyber security, and how often do they report to the board? 
  • Resourcing & Strategy: Do we have a board-approved cyber security strategy, and is our spending on cyber security aligned with the level of risk we face? 
  • Risk Integration: Is cyber risk integrated into our enterprise risk management, with clear metrics and regular assessments? 
  • Critical Asset Protection: What are our most critical digital assets, and what extra protections do we have in place for them? 
  • Incident Preparedness: Do we have a tested cyber incident response plan, and has the board been involved in simulation exercises? 
  • Third-Party Risk: How do we ensure our key suppliers and partners (especially cloud providers) meet robust cyber security standards? 
  • Continuous Improvement: How are we monitoring new cyber threats and adapting our controls (e.g., addressing emerging risks like quantum computers affecting encryption)? 

Encouraging candid answers to these questions will give the board a clearer view of the organisation’s cyber resilience and highlight areas where improvements are needed. 

Additional Cyber Security Resources

Protecting Australian Businesses from Evolving Digital Threats

At KMTech, we understand the unique cybersecurity challenges facing Australian organisations. Our expert team delivers proactive, scalable solutions to safeguard your data, infrastructure, and reputation so you can focus on growth with confidence.

Conclusion: Strong Cyber Governance is Smart Business

In the digital era, cyber security governance has become synonymous with good corporate governance. For Australian boards and directors, taking charge of cyber security oversight means protecting the company’s value, fulfilling regulatory obligations, and maintaining stakeholder trust. By adhering to the AICD’s principles and focusing on the critical priorities for 2025–26, boards can help their organisations stay ahead of threats and foster a resilient, secure environment. 

As a next step, some boards opt for an independent cyber governance review or expert-led workshop. This can benchmark current practices against industry best standards and bring further clarity to the board’s role in cyber oversight. For more information or a tailored board-level cyber governance assessment, please contact us – we’re here to help directors navigate the complexities of cyber risk with confidence. 

Frequently Asked Questions

What is cyber security governance?

Cyber security governance is the set of responsibilities and practices by which a company’s board and executive leadership direct and control the organisation’s management of cyber risks. It ensures that cyber security measures align with business goals and legal requirements, and that the organisation is prepared to prevent, detect and respond to cyber threats at a strategic level.

Why is cyber security governance important for boards?

Boards are accountable for overseeing all major risks to the organisation, including cyber threats. Effective cyber security governance helps protect critical assets, maintain customer trust, comply with regulations, and reduce the impact of incidents. It ensures that directors fulfil their fiduciary duties by proactively managing cyber risk – a major business risk in today’s digital world – and avoid potential legal or reputational consequences of inaction.

What are the AICD Cyber Security Governance Principles?

The Australian Institute of Company Directors (AICD), together with industry partners, has defined five Cyber Security Governance Principles to guide boards. These are: (1) Set clear roles and responsibilities; (2) Develop, implement and evolve a comprehensive cyber strategy; (3) Embed cyber security in risk management; (4) Promote a culture of cyber resilience; and (5) Plan and prepare for significant cyber incidents. These principles help boards structure their oversight of cyber risk. 

What should boards focus on in 2025–26 regarding cyber security?

According to joint guidance by the ASD and AICD, key board focus areas for cyber security in 2025–26 include: ensuring systems are secure by design and default; prioritising protection of critical assets (with an “assume compromise” approach); improving threat detection capabilities; modernising legacy IT; managing third-party (supply chain) cyber risks; and beginning to plan for long-term risks like the impact of quantum computing on encryption. All of this is in addition to maintaining strong basic cyber hygiene across the organisation.

How can a board improve its cyber security governance today?

Boards can start by educating themselves on the threat landscape and best practices. They should establish clear oversight structures (such as a board committee or advisor for cyber), insist on a formal cyber security strategy, set a suitable risk appetite, and integrate cyber risk into enterprise risk management. Conducting a cyber governance workshop or independent assessment can help identify gaps. Most importantly, boards should create a culture where cybersecurity is a priority and ensure that incident response plans are in place and tested regularly.

Related Stories

IT professional working in a security operations environment, representing the transition and ongoing evolution of the ACSC Essential Eight framework.

The Essential Eight Is Evolving, Not Disappearing

Around mid-2028: full retirement. The Essential Eight is expected to be retired as a whole at roughly the 24-month mark, with the cloud and operational technology chapters landing before then.

Person seated at a desk facing a large screen during a video conference, with text overlay reading “AI Compliance Frameworks.”

AI Compliance Frameworks

AI adoption is accelerating across Australian businesses, but so is regulatory scrutiny. From ethical use and data integrity to accountability and transparency, organisations can no longer afford a “move fast and hope for the best” approach to artificial intelligence.

The Evolution of Web Filtering | Modern Cyber Security Solutions

The Evolution of Web Filtering & Shadow AI Governance

This article explores how web filtering has changed, why older DNS‑based models are no longer sufficient, and what modern organisations need to control web, cloud, and AI‑driven risk effectively.

Want to be part of the crowd?

html