12) How do we educate our employees on cyber and information security practices? 13) Do we encourage relevant staff members to share cyber security knowledge and experience with staff members from other organizations? 14) When did we last test the effectiveness of our crisis management? 15) Do we regularly carry out internal controls, audits or revisions within cyber and information security? 16) How do we ensure that business partners and suppliers protect data and information that we share with them? The answers to these questions will enable the top management to identify areas that need increased focus and efforts. In this way, the questions work as a tool to help the top management oversee cyber and information security in the organization. You can find further guidance on understanding and answering these questions at the website sikkerdigital.dk, where a number of guides and templates, etc. are freely available to public authorities, private companies and citizens. 6

Select target paragraph3