When a cyber incident occurs, technical teams carry much of the immediate operational workload. But oversight of material cyber risk cannot simply be delegated. Boards and executive leaders need to know whether the organisation can identify an incident, escalate it appropriately, understand affected systems and data, preserve evidence and meet applicable regulatory obligations.
Having an incident response plan is therefore not the same as being incident-ready. The real governance question is whether documented arrangements have been tested against the organisation’s actual technology environment, third-party dependencies and compliance obligations.
What Recent ANZ Incidents Reveal
Recent breaches across Australia and New Zealand demonstrate how quickly cyber risk can become a board-level issue. Mathspace confirmed that unauthorised parties accessed an internal reporting system and downloaded information relating to students, parents or guardians, teachers and staff, affecting more than one million people across Australia and New Zealand.
In New Zealand, Health New Zealand has also confirmed its involvement in supporting Zenith Technology following a cyber incident involving the clinical-research organisation. These incidents involve different circumstances and should not be treated as evidence of identical security or governance failures.
What they do demonstrate is the complexity organisations face when sensitive information, critical systems and third-party technologies are involved. Boards may suddenly require reliable answers about affected systems, data exposure, vendor dependencies, escalation decisions and regulatory obligations.
That is why cybersecurity testing should not be treated purely as a technical exercise. Testing can provide evidence about whether important controls and assumptions will withstand scrutiny when an incident occurs.
Incident Response Is a Governance Test
A capable cyber incident response team is an important part of organisational preparedness, but technical capability alone is not enough.
During a serious event, leadership may need to answer questions such as:
- Who has authority to declare a major incident?
- Who can approve isolation of critical systems?
- What information must reach the board, legal advisers and regulators?
- Which notification obligations have been triggered?
- Is evidence being preserved appropriately?
- Who owns the risk when an affected system is operated by a third party?
These are governance questions as much as cybersecurity questions.
In Australia, organisations covered by the Notifiable Data Breaches scheme may need to notify the Office of the Australian Information Commissioner and affected individuals where an eligible breach is likely to result in serious harm.
In New Zealand, organisations must notify the Privacy Commissioner and affected individuals when a privacy breach has caused, or is likely to cause, serious harm.
Sector-specific, contractual and other regulatory requirements may also apply. Boards therefore need confidence not simply that procedures exist, but that decision-making responsibilities and escalation pathways are understood.
Third-Party Risk Extends the Governance Perimeter
Modern organisations depend on cloud platforms, software providers, contractors, APIs and specialist vendors. These relationships expand the governance perimeter.
Outsourcing a service does not remove the need to understand the associated cyber risk.
Boards should have visibility into where sensitive information resides, which third parties can access it, how vulnerabilities are communicated and who is responsible when a supplier-related security issue emerges.
The organisation may not operate the underlying technology, but it still needs sufficient evidence to understand the exposure created by that dependency.
Why Paper Compliance Is Not Enough
Policies, registers and response plans remain necessary. But documents alone cannot prove that controls are operating effectively.
A policy may require critical vulnerabilities to be escalated immediately. Independent assessment can determine whether that process is actually understood and followed.
A data-classification framework may appear complete. Assessment may reveal whether sensitive information is consistently identified across internal and third-party environments.
An incident response procedure may define responsibilities. Testing may show whether those responsibilities remain clear when technical, legal, operational and communication decisions occur simultaneously.
Experienced ISO 27001 information security auditors can help assess whether documented controls are reflected in operational practice and supported by appropriate evidence. The objective is not more paperwork. It is to reduce the gap between what an organisation believes is happening and what the evidence demonstrates.
Independent Assurance: From Assumption to Evidence
Cybernetic Global Intelligence (Cybernetic GI) provides organisations across Australia and New Zealand with an independent view of cyber risk, governance and control effectiveness.
Its role is important to distinguish from remediation.
Cybernetic GI assesses digital environments and relevant third-party dependencies, examines controls and governance processes, identifies gaps, validates available evidence and reports findings and recommendations to boards and senior management.
The organisation itself remains responsible for deciding how those findings should be addressed. A targeted cyber security audit can determine whether expected controls exist, whether they are operating effectively and where governance or technical weaknesses require management attention.
For boards, the value is greater visibility. Independent assessment helps leadership understand where controls are effective, where assumptions require validation and where identified gaps should enter the organisation’s risk-management process.
The Board Needs Evidence Before the Incident
Cyber incidents cannot always be prevented.
The governance objective is therefore not to promise perfect security, but to ensure that boards have sufficient visibility over material cyber risk and can challenge whether claims of readiness are supported by evidence.
Boards should be asking:
- Are critical controls operating as intended?
- Are escalation responsibilities clear?
- Are third-party dependencies understood?
- Can management identify what information is exposed and where it resides?
- Have key assumptions been independently tested?
Cyber resilience becomes more credible when boards do not have to rely solely on statements such as “we have a policy” or “the system is secure.”
They should be able to ask:
What evidence supports that conclusion, and what gaps still require management attention?
Cybernetic GI helps organisations identify those gaps, validate the available evidence and provide boards with a clearer view of the cyber risks requiring attention. The findings inform the decision. The board and management determine what happens next.