CYBERPLANZ
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Cyberplanz Board Governance Framework >
      • The Boardroom Guide to Cyber & AI Governance
      • Board Cyber & AI Governance Self-Assessment
  • About Us
  • Contact Us
  • Blogs
Picture
Picture
​There is in the act of preparing, the moment you start caring.  - Winston Churchill

Board Cyber & AI Governance Self-Assessment
​

Can your Board confidently answer these questions?
Cybersecurity and Artificial Intelligence are no longer just technology issues—they are Board responsibilities.

This five-minute self-assessment is designed to help Directors evaluate whether their organisation has appropriate governance, oversight and leadership in place to manage cyber and AI risks.

For each statement, select the score that best reflects your organisation today.
​
Score Description
1  Not in place
2  Significant improvement required
3  Developing
4  Well established
5  Leading practice


1. Cyber Governance
Our Board receives regular reporting on cyber risk, understands the organisation's key cyber risks, and cyber resilience is a standing agenda item at Board meetings.
☐ 1 ☐ 2 ☐ 3 ☐ 4 ☐ 5
Board Reflection
Can every Director confidently explain our organisation's three biggest cyber risks in plain English?


2. AI Governance
Our organisation has visibility over where Artificial Intelligence is being used, understands the associated risks, and has appropriate governance and policies for responsible AI use.
☐ 1 ☐ 2 ☐ 3 ☐ 4 ☐ 5
Board Reflection
Would the Board know if staff were entering confidential information into public AI tools today?


3. Cyber Culture & Staff Engagement
Cybersecurity is embedded within our organisational culture through leadership, continuous awareness, and staff engagement—not simply annual compliance training.
☐ 1 ☐ 2 ☐ 3 ☐ 4 ☐ 5
Board Reflection
Do employees feel comfortable reporting mistakes, suspicious activity, or potential cyber incidents without fear of blame?


4. Incident Preparedness & Organisational Resilience
Our Board has confidence that the organisation could effectively respond to and recover from a significant cyber or AI-related incident. Incident response plans are regularly tested and reviewed.
☐ 1 ☐ 2 ☐ 3 ☐ 4 ☐ 5
Board Reflection
Has the Board participated in a cyber incident or crisis simulation within the past 12 months?


5. Third-Party & Supply Chain Risk
Our organisation understands the cyber and AI risks presented by suppliers, contractors and service providers, and regularly reviews these risks.
☐ 1 ☐ 2 ☐ 3 ☐ 4 ☐ 5
Board Reflection
If one of our critical suppliers suffered a major cyber incident tomorrow, do we understand the potential impact on our organisation?


Your Board Governance Score
Add your five scores together.
Total Score: ______ / 25


What Your Score Means
5–10 | Immediate Action Required
Cyber and AI governance appear to be immature or largely unmanaged.
The Board should prioritise understanding its governance responsibilities and establish a structured improvement programme.


11–18 | Building Foundations
Some governance practices exist, but there are likely to be gaps in oversight, organisational culture, incident preparedness, or AI governance.
This is an ideal time to strengthen resilience before a significant incident occurs.


19–22 | Good Governance
The organisation demonstrates sound governance practices and Board engagement.
Continue improving cyber culture, AI governance, supplier oversight and resilience testing to remain ahead of emerging risks.


23–25 | Leading Practice
Your Board demonstrates strong governance and strategic oversight of cyber and AI risks.
Maintain momentum by regularly reviewing emerging technologies, evolving threats and organisational resilience.
Remember:
Cyber resilience is never finished.
It evolves alongside your organisation.


A Final Question Every Board Should Ask

If our organisation experienced a major cyber or AI-related incident tomorrow...
  • Would every Board member understand their role?
  • Would management know what decisions need to be made?
  • Would our staff know how to respond?
  • Would our customers continue to trust us?
  • Could we confidently explain our governance decisions to regulators, investors and stakeholders?
If the answer to any of these questions is "I'm not sure," your next Board discussion should begin there.

Download your copy here:

Your browser does not support viewing this document. Click here to download the document.

Human-Centric Cyber Governance & AI Security for NZ Organisations

Picture
A Corna Consulting Company
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Cyberplanz Board Governance Framework >
      • The Boardroom Guide to Cyber & AI Governance
      • Board Cyber & AI Governance Self-Assessment
  • About Us
  • Contact Us
  • Blogs