The Five Questions Every Director Must Answer: Professor Kai London on Board Cyber Risk
By the Ezeiza Times Business Desk
Cyber risk has moved decisively from the server room to the boardroom, and many directors are unsure what they are actually accountable for. Professor Kai London, a senior CISO and board advisor, offers a disarmingly simple test. “Every board should be able to walk into a room and answer five questions,” he says. “If they cannot, they are not governing cyber risk — they are hoping.”
“What could break, who owns it, what it would cost, which control holds it, and where the evidence is. Those five questions are the whole of board-level cyber governance.”
From delegation to accountability
London notes that modern regulation deliberately places cyber accountability on senior leadership, who can be held liable for failures. “It has moved cyber from something the board hears about to something the board answers for,” he says.
The five questions, unpacked
What could break? Know your critical services and their fault lines. Who owns it? Every critical risk needs a named owner. What would it cost? Quantify the impact so trade-offs are informed. Which control holds it? Know the specific control and whether it has been tested. Where is the evidence? Be able to prove, to a regulator, that the control worked.
Evidence over assertion
“The regulator's question has shifted from ‘do you have a policy?’ to ‘can you prove it worked?’” London says. Boards that can produce that evidence are in a fundamentally stronger position — commercially as well as legally.
For directors navigating rising personal accountability, London's message is clarifying: cyber governance is not about mastering technology. It is about being able to answer five questions with confidence and evidence.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
