ASD Essential Eight & AICD Director Cyber Standards

Cyber Governance
Literacy Checker

Measure your board's cyber governance literacy across oversight structures, incident readiness, and regulatory compliance. Benchmark against the ASD Essential Eight and AICD cyber governance expectations.

58%
of directors report insufficient board-level cyber literacy
#2
Risk theme for Australian boards — Cyber (AICD DSI 2026)
E8
ASD Essential Eight — the Australian board cyber benchmark
Survey Evidence: AICD Director Sentiment Index 2026 — cyber risk ranked the #2 board risk theme, with 58% of directors reporting insufficient cyber literacy at board level.
Cyber Governance Literacy Checker — Assessment

Answer 8 questions to assess your board's cyber governance literacy and oversight maturity. Results are benchmarked against ASD Essential Eight, the AICD Cyber Risk Governance Guide, and current ASIC enforcement priorities.

Question 1 of 8 — Board Cyber Literacy

How would you rate your board's collective cyber governance literacy?

Question 2 of 8 — Independent Briefing

How frequently does your board receive a cyber risk briefing from an independent expert (not the CISO)?

Question 3 of 8 — Incident Response

Does your board have a cyber incident response plan with defined board-level roles and decision authority?

Question 4 of 8 — Cyber Risk Oversight

How does your board receive and act on cyber risk information?

Question 5 of 8 — Third-Party Cyber Risk

How does your organisation manage cyber risk across third-party vendors and supply chain?

Question 6 of 8 — Cyber Insurance

Does your board have visibility of the organisation's cyber insurance coverage and its adequacy?

Question 7 of 8 — Regulatory Compliance

How prepared is your organisation for Australian cyber reporting obligations (e.g., notifiable data breaches, CPS 234, SOCI Act)?

Question 8 of 8 — Director Skills Matrix

Does your board skills matrix include cyber expertise as a defined capability requirement?

Noventum Advisory is analysing your governance posture…
Analysing board cyber literacy…

Cyber Governance Literacy Report

Overall Governance Maturity Score
44 / 100
Based on your 8-question assessment
DEVELOPING — Critical cyber oversight gaps identified
Domain Scores
Board Cyber Literacy35%
Board literacy self-assessed as moderate to low. No dedicated cyber expertise. Skills gap uplift is a priority.
Oversight Structures50%
Cyber risk reported to board but not through a formal committee structure. Reporting is irregular.
Incident Response45%
Incident plan exists but board roles not defined and plan untested. Significant resilience gap.
Third-Party Risk40%
Contractual protections only. No active monitoring of third-party cyber posture. Supply chain exposure high.
Regulatory Compliance55%
Aware of obligations but readiness uncertain. Notifiable data breach framework requires urgent review.
Skills & Succession40%
Cyber not formally included in board skills matrix. Recruitment brief for next board appointment should include cyber.

Recommended Governance Frameworks

Immediate

ASD Essential Eight — Board Alignment

Map your organisation's posture against the ASD Essential Eight. Prioritise Maturity Level 2 for patch management, multi-factor authentication, and application control.

30 Days

AICD Cyber Risk Governance Guide

The AICD guide provides a director-focused framework for cyber oversight. Use it to structure board reporting and define minimum literacy expectations for directors.

60 Days

ASIC Cyber Regulatory Obligations Review

Engage external legal counsel to map all applicable cyber reporting obligations: Notifiable Data Breaches scheme, CPS 234 (if applicable), SOCI Act critical infrastructure obligations.

Prioritised Action Roadmap

1

Commission an independent board cyber briefing

Engage an independent cyber advisor (separate from your CISO) to brief the full board on the current threat landscape, sector-specific risks, and your organisation's posture vs. peers.

⏱ Target: 30 days · Owner: Board Chair + Risk Committee
2

Define and test a board-level cyber incident response plan

Update your cyber incident response plan to include specific board decision nodes. Run a tabletop exercise with board participation simulating a ransomware event or data breach.

⏱ Target: 45 days · Owner: CISO + Board Chair
3

Add cyber expertise to the board skills matrix

Formally include cyber/technology governance as a required board skill. Assess each director against the criteria and incorporate into the next board recruitment brief.

⏱ Target: 60 days · Owner: Nominations & Governance Committee
4

Establish a vendor cyber risk monitoring program

Implement formal third-party cyber risk assessment for all critical vendors. Require contractual cyber standards and annual attestation. Report results to the board.

⏱ Target: 60 days · Owner: CRO + Procurement
5

Map and remediate regulatory compliance gaps

Engage external legal counsel to assess obligations under NDB scheme, CPS 234, SOCI Act, and Privacy Act reforms. Develop a compliance roadmap with board oversight.

⏱ Target: 90 days · Owner: General Counsel + Audit Committee
Want expert help actioning these results?

Book a free 30-minute strategy call — no obligation, no pitch, just actionable advice.

📅 Book a Free Consultation
Get our monthly strategy toolkit

Free frameworks, benchmarks & tools delivered to directors and executives each month.