Board guides · Practical companion
What does good cyber evidence look like?
What to ask for, what it tells you and where its limits lie.
A board paper says the controls are effective, recovery has been tested and the major findings are closed. What gives you confidence those conclusions are justified? Use it alongside our other board guides, or on its own.

What's inside
Begin with the claim
Turn broad statements like “our recovery arrangements work” into specific conclusions the board can actually examine.
Look for a traceable basis
What a useful board paper summarises — results, limitations and a clear route to the supporting records, without raw technical logs.
Five familiar assurances
Practical examples of the evidence worth discussing behind common cyber assurances, as prompts for board judgement.
Make room for uncertainty
How to weigh what hasn’t been tested — and decide between further work, a temporary safeguard or explicit risk acceptance.
Claim · Evidence · Judgement
What are we being asked to accept? What was checked and what did it show? What can we reasonably conclude?
Get your free copy
Tell us where to send it and we'll email you the download link straight away.
