Board advisory guide
Can You Defend the Declaration?
Cyber risk, critical dependencies and Provision 29 — a practical guide for non-executive directors.
This short guide helps NEDs move the conversation from reassurance to evidence, without turning the board into the security operations centre.

What's inside
The governance trigger
Provision 29 in two minutes — what changes, the declaration, and the implementation timeline.
The cyber question
Five practical tests for when a cyber control becomes material — and why a critical supplier isn't automatically a critical dependency.
The board conversation
Nine evidence-led questions for your next cyber discussion, designed to reveal where confidence is assumed.
The boardroom test
Can the board demonstrate why its cyber controls are material, how it knows they are operating effectively, and what would happen if a critical dependency failed?
Get your free copy
Tell us where to send it and the download will appear straight away.
