Advisory & assurance
Cyber risk belongs in the boardroom
Directors and senior leaders are increasingly expected to understand, oversee and report on cyber and privacy risk. “We left it to IT” is no longer a defensible position.
We help your board and leadership establish sound governance practices — setting clear direction, holding the right accountabilities, and making sure risks are properly mitigated, monitored and reported. This reflects the “Govern” function at the heart of the NIST Cybersecurity Framework, and aligns with the expectations set out in the New Zealand Information Security Manual (NZISM). Then we help you keep those practices current as your organisation and the threat landscape evolve.
Why it matters
Good governance protects more than data
Boards without formal cyber and privacy governance expose their organisation — and themselves — to real consequences: obligations under New Zealand’s Privacy Act 2020, cross-border rules such as the EU’s GDPR where they apply, financial loss, and lasting reputational damage. Strong governance turns all of that from a lurking worry into something you actively understand and control.
How we help
Clarity for the board, less load on your team
- Helping your board agree an acceptable level of cyber security risk — your risk appetite
- Formalising the cyber security and privacy policies that sit underneath it
- Producing clear, regular board reports that flag the areas of risk without burying your people in busywork
- Keeping it all current as things change