Cyber risk reaches the board either because the board asked, or because an incident delivered it. The second route costs considerably more.

Cyber risk arrives at board level in one of two ways. Either the board asks for it, or an incident delivers it. The second route is considerably more expensive and far less comfortable.
Regulators, funders and insurers across the region are converging on the same expectation: that the board understood the risk, received regular reporting and made deliberate decisions about it.
What are our three largest cyber risks, stated in business terms. What would a serious incident cost us in revenue, penalties and reputation. Who decides during an incident, and have they ever practiced. What did our last assessment find, and what has been fixed since. Which vendors could take us offline. And how do we know staff awareness is improving rather than simply assumed to be.
A cyber risk register written in business language rather than technical findings. A tested incident response plan naming its decision makers. An improvement roadmap carrying owners and dates. And reporting at a fixed interval, so cyber risk becomes a standing item instead of a reaction.
Directors do not need technical expertise. They need to ask specific questions and decline vague answers. A surprising number of institutions improve simply because the board started asking.
Name your top three cyber risks
Quantify the cost of an incident
Identify incident decision makers
Track roadmap owners and dates
Review vendor concentration
Put cyber on every agenda
Nakawa, Kampala, Uganda
Uganda and East Africa
Onsite and remote
John Doe joined UHA
12 people registered today
ECG Interpretation Workshop