ASD Essential Eight & AICD Director Cyber Standards
Cyber Governance Literacy Checker
Measure your board's cyber governance literacy across oversight structures, incident readiness, and regulatory compliance. Benchmark against the ASD Essential Eight and AICD cyber governance expectations.
58%
of directors report insufficient board-level cyber literacy
#2
Risk theme for Australian boards — Cyber (AICD DSI 2026)
E8
ASD Essential Eight — the Australian board cyber benchmark
Survey Evidence: AICD Director Sentiment Index 2026 — cyber risk ranked the #2 board risk theme, with 58% of directors reporting insufficient cyber literacy at board level.
Cyber Governance Literacy Checker — Assessment
Answer 8 questions to assess your board's cyber governance literacy and oversight maturity. Results are benchmarked against ASD Essential Eight, the AICD Cyber Risk Governance Guide, and current ASIC enforcement priorities.
Question 1 of 8 — Board Cyber Literacy
How would you rate your board's collective cyber governance literacy?
Question 2 of 8 — Independent Briefing
How frequently does your board receive a cyber risk briefing from an independent expert (not the CISO)?
Question 3 of 8 — Incident Response
Does your board have a cyber incident response plan with defined board-level roles and decision authority?
Question 4 of 8 — Cyber Risk Oversight
How does your board receive and act on cyber risk information?
Question 5 of 8 — Third-Party Cyber Risk
How does your organisation manage cyber risk across third-party vendors and supply chain?
Question 6 of 8 — Cyber Insurance
Does your board have visibility of the organisation's cyber insurance coverage and its adequacy?
Question 7 of 8 — Regulatory Compliance
How prepared is your organisation for Australian cyber reporting obligations (e.g., notifiable data breaches, CPS 234, SOCI Act)?
Question 8 of 8 — Director Skills Matrix
Does your board skills matrix include cyber expertise as a defined capability requirement?
Noventum Advisory is analysing your governance posture…
Board literacy self-assessed as moderate to low. No dedicated cyber expertise. Skills gap uplift is a priority.
Oversight Structures50%
Cyber risk reported to board but not through a formal committee structure. Reporting is irregular.
Incident Response45%
Incident plan exists but board roles not defined and plan untested. Significant resilience gap.
Third-Party Risk40%
Contractual protections only. No active monitoring of third-party cyber posture. Supply chain exposure high.
Regulatory Compliance55%
Aware of obligations but readiness uncertain. Notifiable data breach framework requires urgent review.
Skills & Succession40%
Cyber not formally included in board skills matrix. Recruitment brief for next board appointment should include cyber.
Recommended Governance Frameworks
Immediate
ASD Essential Eight — Board Alignment
Map your organisation's posture against the ASD Essential Eight. Prioritise Maturity Level 2 for patch management, multi-factor authentication, and application control.
30 Days
AICD Cyber Risk Governance Guide
The AICD guide provides a director-focused framework for cyber oversight. Use it to structure board reporting and define minimum literacy expectations for directors.
60 Days
ASIC Cyber Regulatory Obligations Review
Engage external legal counsel to map all applicable cyber reporting obligations: Notifiable Data Breaches scheme, CPS 234 (if applicable), SOCI Act critical infrastructure obligations.
Prioritised Action Roadmap
1
Commission an independent board cyber briefing
Engage an independent cyber advisor (separate from your CISO) to brief the full board on the current threat landscape, sector-specific risks, and your organisation's posture vs. peers.
Define and test a board-level cyber incident response plan
Update your cyber incident response plan to include specific board decision nodes. Run a tabletop exercise with board participation simulating a ransomware event or data breach.
⏱ Target: 45 days · Owner: CISO + Board Chair
3
Add cyber expertise to the board skills matrix
Formally include cyber/technology governance as a required board skill. Assess each director against the criteria and incorporate into the next board recruitment brief.
⏱ Target: 60 days · Owner: Nominations & Governance Committee
4
Establish a vendor cyber risk monitoring program
Implement formal third-party cyber risk assessment for all critical vendors. Require contractual cyber standards and annual attestation. Report results to the board.
⏱ Target: 60 days · Owner: CRO + Procurement
5
Map and remediate regulatory compliance gaps
Engage external legal counsel to assess obligations under NDB scheme, CPS 234, SOCI Act, and Privacy Act reforms. Develop a compliance roadmap with board oversight.
⏱ Target: 90 days · Owner: General Counsel + Audit Committee
Want expert help actioning these results?
Book a free 30-minute strategy call — no obligation, no pitch, just actionable advice.