01
Can you articulate your board's cyber risk appetite in plain English, and can you explain how that appetite was set, and by whom?
Most directors cannot explain their board's AI risk exposure, describe their cyber incident response obligations, or identify which IT controls they should be challenging. This engagement changes that with a formal, independent assessment built entirely around cyber risk, AI governance, and IT general controls.
Strictly confidential. Fixed fee. Delivered as a formal written report.
The Director's Dilemma
If any of these give you pause, that pause is worth addressing.
01
Can you articulate your board's cyber risk appetite in plain English, and can you explain how that appetite was set, and by whom?
02
If a breach occurred tomorrow, could you demonstrate to ASIC that you exercised due diligence, point to the evidence, and show when you last reviewed your organisation's incident response plan?
03
Do you know which AI tools your organisation is currently using, what data those tools are processing, and whether your board has formally approved their use?
04
Can you describe the IT general controls your organisation relies on, and when the board last received an independent assessment of them?
Your Obligations
Under the Corporations Act s180, directors owe a duty of care and diligence. ASIC has made that obligation explicit for technology risk. Its guidance confirms that cyber security is a governance matter requiring board-level attention, documented oversight, and active challenge of management reporting. The Cyber Security Act 2024 received Royal Assent in November 2024, with mandatory ransomware reporting obligations now in force and full enforcement from 1 January 2026. It adds further obligations for organisations meeting the responsible entity threshold. For directors of APRA-regulated entities, CPS 234 sets specific expectations for information security governance at board level. This engagement addresses how those obligations apply across three domains that now define director exposure: cyber risk, AI governance, and IT general controls. The question is not whether you are obligated. You are. The question is whether you can demonstrate informed, active oversight, and produce the evidence to prove it.
ASIC has made clear that cyber risk is a director-level obligation under s180. You are expected to understand exposure, challenge reporting quality, and ensure cyber governance decisions are documented. Boards that cannot show they actively questioned cyber reporting, not just received it, are exposed when a breach occurs.
Directors must understand what AI systems are being deployed, what data they process, and whether board oversight is real. AI has moved faster than governance in most organisations: tools are in operational use that the board has never formally reviewed, approved, or risk-assessed. That is a board accountability gap, not an IT problem.
IT general controls (access management, change control, backup and recovery, system availability) are the foundation beneath both cyber and AI risk. They are also the controls most commonly misrepresented in board reporting. If directors cannot identify what those controls are and when they were last independently tested, active oversight cannot be credibly claimed.
Personal Assessment
A formal, independent assessment of your personal readiness in cyber governance, AI governance, and IT general controls across your board appointments. The report is addressed to you, not your board, and is followed by a one-on-one debrief.
View the full engagement →Andrew Roberts Advisory does not sell software, resell vendor products, or take referral fees. I have no relationship with any technology vendor or managed service provider. My only obligation is to you.
My Commitment
No vendor relationships. No referral arrangements. My advice serves your interests, not a product, not a platform.
Every engagement is conducted under a formal NDA. What you share remains strictly between us.
I advise from the director's seat, not the IT department's. The framing, the language, and the output are designed for the boardroom, not the server room. My specialist focus is cyber risk oversight, AI governance, and IT general controls.
The directors who engage this practice are not those who have ignored cyber and AI risk. They are the ones who have decided that receiving a board paper is not the same as exercising oversight, and that when scrutiny arrives, the difference will matter. Every engagement begins with a confidential conversation. Obligation-free and on your terms.
Start a Confidential ConversationOr email: hello@aradvice.com.au