InsightIQ GOVERNANCE ← THE MODEL
THE REASONABLE ALLOCATION MODEL · THE DIRECTOR’S VIEW

Nobody will ask whether you were secure.

They will ask what the Board did to satisfy itself that cyber risk was governed with reasonable care — and whether you can show it.

THE DAY THE QUESTION CHANGES

The cyber conversation directors prepare for is the scheduled one: twelve minutes on a Tuesday agenda, a posture update, a question or two, then on to the next item. The conversation that actually matters arrives without an agenda. It comes after an incident — and on any honest reading of the threat environment, there will eventually be an incident. Across the table sits a regulator’s investigator, or counsel for a shareholder action, or your own insurer’s lawyers.

On that day you will have exactly two things: what is in the record, and nothing else. Assurances you remember receiving but never minuted. A heat map that said amber. A certification that was current at the time. A budget that grew every year. None of these answers the question, because none of them is evidence of a reasoned decision — and reasoned decisions are the only currency that room accepts.

Qantas June 2025 — records of 5M+ customers taken through an offshore call centre, later published. Regulator closed its inquiry in July 2026 without opening a formal investigation: reasonable steps had been taken.
Optus 2022 breach. Defending civil penalty proceedings in the Federal Court.
Medibank 2022 breach. Defending civil penalty proceedings in the Federal Court.

Three household names, the same loss event and one test. The outcome was decided by what could be demonstrated.

WHY THE USUAL PACK LEAVES YOU EXPOSED

Hold your own board pack up against that examination and the problem is immediate: most cyber reporting cannot answer it, because it was never designed to. A heat map records an opinion, not a decision. A maturity score benchmarks activity, not reasoning. An audit result evidences a minimum, not an allocation. Beneath the reporting problem sit two deeper patterns — each of which looks like diligence in the minutes and reads as its absence under examination.

PATTERN 01

Compliance theatre

Letting a certification stand in for the reasoning. A retailer passed its PCI-DSS assessment two quarters before a card-data breach; the certification was real, the audit was clean, and the gap sat outside anything the standard tested for. A Board that accepted “we passed the audit” as its answer did not govern the risk. It borrowed someone else’s checklist and called it governance, and the record shows exactly that.

PATTERN 02

Unbounded spend

Funding every proposal that sounds prudent, because more security feels safer than less. It offers no coverage at all, because nobody can explain why spend stopped where it did. “We kept adding controls until the budget ran out” is an absence of reasoning with a large invoice attached. A growing security budget demonstrates nothing on its own without a rationale for its shape.

Both patterns end in the same place: money was spent, and the reasoning cannot be reconstructed. What closes the gap is not a bigger pack. It is a simple structure the Board can hold in its head, and demand.

EVERY DOLLAR NEEDS ONE OF THREE REASONS

Strip away the machinery and there are only three legitimate reasons a security dollar can be somewhere — and only three defensible answers to “why is this risk in the state it is in?”

REASON 01

We refuse to accept the consequence.

Some outcomes — a preventable safety incident, a regulator-scale breach of data held in trust — the Board has decided are not acceptable at any price. Spend addressing them is an obligation the Board itself created, and the rationale is the Board’s own recorded decision, not a business case.

REASON 02

The numbers justify it.

Everything outside a refusal is a choice, and a choice is defensible only when the risk reduction it buys stands in reasonable proportion to what it costs — with a stated reason why spending stopped where it did.

REASON 03

We examined the gap and chose to carry it.

Whatever the first two do not cover remains. The defensible response is a written, owned, dated decision to carry it — not silence, and not spending past the point the numbers support to avoid an uncomfortable conversation.

Every cyber risk the organisation carries should resolve into exactly one of these three positions, with evidence behind it. Notice that each is, at bottom, a Board-level act. A refusal is the Board’s decision. A stopping rule is the Board’s protection against unexaminable spend. A carried gap is the Board’s tolerance, exercised knowingly.

That is why this structure protects where conventional reporting does not: it turns cyber governance from receiving assurance into making and minuting decisions — and the minutes of a decision are worth more than any assurance ever received. Your management team will have internal names for the three positions. The labels belong to practitioners. What the Board governs, and what the record has to show, is the reasons.

SIX QUESTIONS FOR YOUR NEXT MEETING

Put these six questions to management, test what comes back, and have the exchange recorded. They will tell you most of what you need to know, including from the answers that do not come back cleanly.

  1. Which consequences have we, as a Board, refused to accept at any price — and where is that decision minuted?
  2. Is what those refusals oblige us to fund a finite, named list? When was each item on it last independently tested?
  3. For the last cyber funding request we approved: what risk reduction did it buy, at what cost, and who checked those numbers before we saw them?
  4. Why did our security spend stop at the level it did? What is our stated stopping rule?
  5. Which gaps are we knowingly carrying? For each: who owns it, which stated tolerance does it exceed, and when must it be re-examined?
  6. How much of our risk portfolio carries an evidenced probability, and how much is still, honestly, “not yet assessed”?

None of them asks whether the organisation is secure, and none requires you to learn a security vocabulary. Every one asks for a reason — and every answer, minuted, becomes part of the record that shows the Board asked, was answered, and acted. A management team operating this model will answer all six from the standing quarterly pack without preparation. A management team that cannot is not failing you; it is telling you where to direct them next. Either way, something is now in the minutes that was not there before, and that is about the only outcome in cyber governance anyone can guarantee.