Good questions are important tools The answers to the following questions can give the top management an indication of whether, and to what extent, appropriate security measures are in place. The top management and the rest of the organization should to be able to answer the questions within each category. The sequence of the questions does not reflect any prioritization of the questions. 8 questions that top management should ask themselves 1) Have we identified data and information that support critical business activities? 2) What are the consequences for the business, if data or information that support critical business activities is unavailable, manipulated or leaked? 3) Are we convinced that there is adequate protection of our information against known threats? 4) Have we defined the cyber and information security objectives, strategies, and policies that we are actively prioritizing and pursuing? 5) Do we have a security organization anchored at top management level? 6) Do we receive regular reporting on the status of our cyber and information security strategies and objectives? 7) Have we considered our organization’s security risk appetite? 8) Do we understand that we as members of the top management are obvious targets of cyberattacks (for example of CEO fraud and spear phishing)? 16 questions top management should ask their organizations 1) Which IT systems support our business critical activities? 2) Where do we store our most important data and information? 3) How do we keep ourselves updated on the cyber threat landscape and on the techniques used, among others, in cyber espionage and cybercrime? 4) How do we defend against phishing attacks and CEO fraud? 5) Are we obligated to comply with external cyber and information security requirements (for example standards or technical measures)? 6) Which methods do we use to control access to IT systems, data and information? 7) Which special precautions do we take when travelling? 8) How do we ensure that IT systems, computers and phones are updated? 9) How do we ensure the use of strong passwords to gain access to IT systems, computers and phones? 10) How do we supervise the use of user accounts with privileged rights? 11) Do we have the skills and resources needed to implement our strategies and objectives for cyber and information security? 5

Select target paragraph3