Skip to main content
What Boards Are Actually Asking About RansomwareVendor & Third-Party Risk
4 min readFor C-Suite Executives

What Boards Are Actually Asking About Ransomware

Evolving Questions from the Boardroom

Boards, executive teams, and CISOs are increasingly focused on discussing ransomware beyond technical measures. The shift is clear: while endpoint detection was once the main concern, now the focus is on maintaining operations if a primary data center is compromised for an extended period.

The questions below reflect this evolution. They focus on the operational and strategic aspects of ransomware, which don't fit neatly into a security roadmap.

Q1: "We've invested heavily in security controls. Why is ransomware still a major risk?"

Attackers have changed tactics. While your security investments are important, the threat landscape has evolved.

Ransomware groups now combine operational disruption with data theft and reputational pressure. Some attacks skip encryption altogether, opting for extortion by threatening to publish stolen data. These attacks are swift and hard to detect because systems remain operational while data is already compromised.

Your security controls reduce the risk of compromise. Boards need to understand if your organization can continue operating during and after an incident. This requires offline backups, tested recovery procedures, executive decision-making protocols, and communication plans independent of potentially compromised systems.

Q2: "How does AI factor into this? Should we be more worried or less?"

Both. AI introduces new risks and opportunities.

AI increases the volume of valuable data and introduces new dependencies. Attackers use AI to enhance phishing, identify vulnerabilities, and craft convincing social engineering attacks.

Your organization is likely integrating AI into workflows, which adds identities, APIs, and permissions that need securing. Inventory AI use, understand data access, and ensure security controls evolve with these innovations. This isn't about blocking AI adoption; it's about ensuring identity management and data governance keep pace.

Q3: "Our vendors claim 'SOC 2 compliance.' Does this protect us from third-party ransomware risk?"

SOC 2 compliance indicates documented controls and an audit, but it doesn't guarantee rapid incident response.

With interconnected systems, cloud providers, software vendors, and AI platforms have varying access to your data. Attackers target these third parties as entry points.

Your vendor risk assessments should evaluate cybersecurity maturity and incident response capabilities. Understand how quickly partners can detect and report incidents, especially when shared systems are involved. Ask about recovery time objectives, tabletop exercises, and breach notification timelines. SOC 2 is a baseline; resilience requires deeper evaluation.

Q4: "What should we actually be testing in our incident response plan?"

Test areas that fail under pressure: executive decision-making, communication without email, and backup restoration.

Most organizations focus on technical recovery. Few test if executives can make coordinated decisions about ransom payments, customer notifications, and regulatory communication when systems are down.

Your incident response plan should define executive decision-making, communication protocols, legal coordination, and stakeholder responsibilities. Conduct tabletop exercises with leadership, not just IT. Simulate scenarios where primary communication channels are unavailable. Test backup restoration under pressure, not during scheduled maintenance.

Effective ransomware response comes from practiced decision-making and validated recovery procedures.

Q5: "How do we discuss this with the board without downplaying the risk or causing panic?"

Frame it as operational resilience, not security theater.

Boards don't need technical details of endpoint detection. They need to understand recovery capabilities, operational dependencies, and business continuity during an attack.

Translate cyber risk into business terms: What are our recovery time objectives? How long can we serve customers if our data center is compromised? What decisions are critical in the first hours of an incident, and who makes them?

This positions you as a strategic advisor, shifting the conversation from "Are we secure?" to "Can we maintain operations if security fails?"

Q6: "What's the single most important thing we're probably not doing?"

Regularly testing offline backup restoration.

Many organizations have backups but don't test restoration under realistic conditions. If ransomware hits and backups are incomplete, corrupted, or slow to restore, you've lost a key advantage against paying ransom.

Store critical data in encrypted, offline environments and test restoration quarterly. Include executives in these tests to understand actual recovery timelines. Validate that you can restore full operational capability, including system integrations and dependencies.

Where to Go for More

The NIST Cybersecurity Framework 2.0 integrates cyber resilience into enterprise risk management. For recovery planning, NIST SP 800-184 offers guidance on cybersecurity event recovery. ISO/IEC 27001:2022 addresses business continuity management within information security governance.

Shifting from prevention to resilience acknowledges that ransomware is a business disruption strategy, not just a technical problem. Build your response accordingly.

You Might Also Like