Questions for executive and supervisory boards

Digital resilience in the boardroom: questions for boards

A practical set of questions for executive and supervisory roles to connect digital risks with services, risk appetite, measures and demonstrable follow-up.

Digital resilience belongs in the boardroom because disruption directly affects services, continuity, safety, trust and board responsibility. Executive and supervisory boards do not need to perform the technical work. They do need a clear view of material risks, appropriate measures, residual risk and the quality of follow-up.

The questions on this page make that discussion concrete. They are designed for executive boards, management, audit committees and supervisory boards and can be connected with the relevant governance code and with NIS2 or the Dutch Cybersecurity Act.

Start with services and social impact

A useful discussion begins with what the organisation needs to protect. Disruption in healthcare or social work can immediately affect clients. Housing associations also consider tenant data and property processes. Childcare, culture and charities each have their own dependencies and relationships of trust.

  • Which services and processes have the highest recovery priority?
  • Which consequences for people, continuity, finance, privacy and reputation are unacceptable?
  • Which digital systems, data and physical facilities support those processes?
  • Which assumptions about availability and recovery have been tested?

Questions about risk and risk appetite

Risk management becomes useful to the board when scenario, impact, measure and decision are visibly connected.

  • Which material cyber scenarios are in the risk picture, and when were they last reviewed?
  • Which criteria do we use for likelihood, impact and risk acceptance?
  • Who may accept residual risk, and how is that decision recorded?
  • Which risks are outside the agreed tolerance and require a decision?
  • Which developments could materially change the risk picture this year?

Questions about measures and evidence of effectiveness

  • Which measures has the board approved, and which risks do they address?
  • Who owns policy, implementation, control and independent review?
  • Which tests, exercises, audits or reviews show that important measures work?
  • Which exceptions remain open, for how long and with which temporary safeguard?
  • Which improvement actions are delayed, and what does that require in capacity or budget?

Questions about suppliers and digital dependency

  • Which suppliers support critical services or process sensitive data?
  • Where do several services depend on the same provider, technology or infrastructure?
  • Which agreements cover incident notification, recovery, assurance, access and exit?
  • How do we verify that suppliers meet those agreements?
  • Which alternatives are available during prolonged failure of a critical supplier?

Questions about incidents and recovery

  • Who takes which executive and operational decisions during an incident?
  • When are executive and supervisory boards informed?
  • Have reporting duties, communication, privacy, continuity and recovery been exercised together?
  • Which maximum outage and data loss are acceptable for each critical process?
  • How are lessons from incidents and exercises followed until improvement is demonstrably complete?

Management information that leads to action

Useful board reporting shows developments and exceptions. It connects risk with services, ownership and decisions. A concise dashboard can cover material risks, incidents, supplier exceptions, test results, open improvements and residual risks requiring board attention.

Frequency should reflect risk and change. Clear escalation criteria ensure that urgent matters reach the agenda immediately.

Connecting governance codes and NIS2

Sector governance codes provide language for governance, supervision, continuity and accountability. Some explicitly address digital transformation, data, AI and cybersecurity; others connect indirectly through risk management and quality. The article Governance codes and NIS2 compares six sectors.

For essential and important entities, the Dutch Cybersecurity Act adds concrete duties. The board approves risk-management measures, oversees implementation and remains ultimately responsible. The questions above bring that responsibility into the existing governance cycle.

A practical approach for the next meeting

  1. Select one critical service or material scenario.
  2. Request the underlying risk assessment, measures and current evidence of effectiveness.
  3. Identify open uncertainties, dependencies and residual risks.
  4. Record the required decision, the owner and when the board will receive the next update.

This gives digital resilience a regular governance rhythm and clear follow-up.

Frequently asked questions about digital resilience in the boardroom

Which cyber questions belong on a board agenda?

Start with critical services, protected interests, material scenarios, supplier dependencies, residual risks, recovery capability and the quality of board reporting.

How often should digital resilience be discussed in the boardroom?

Choose a rhythm that reflects risk and change. Periodic reporting should be supplemented by direct escalation for significant incidents, major changes, new dependencies or risks outside the agreed tolerance.

What information does a supervisory board need?

Supervisory boards need a clear view of material risks, decisions, progress, exceptions, incidents, suppliers and evidence that important measures operate effectively.

Does the board need to assess technical details?

The board does not need to perform specialist work. It should be able to assess what the risk means, why measures are appropriate, which evidence is available and which decisions remain open.

How does NIS2 boardroom training support risk management?

Training gives executive and supervisory roles a shared language for impact, risk appetite, measures, residual risk and decisions. This makes reporting and follow-up more concrete.

Next meeting

Use these questions in a boardroom session

The NIS2 Boardroom Masterclass connects these questions with the Dutch Cybersecurity Act, risk management and recognisable sector cases. For an assessment, baseline review or implementation support, contact Kynexis Informatiebeveiliging BV.