The most useless sentence I have heard in a leadership and board briefing, and I have heard it many times, is that we take security very seriously. It cannot be checked. It cannot be wrong. Everyone nods, the deck advances, and precisely nothing has been transferred from one side of the table to the other.

What makes it useless is not insincerity. The people saying it usually mean it. What makes it useless is that no possible state of the world would have produced a different answer.

The volume is not the problem

Start with the part nobody disputes. Boards are more engaged with cyber risk than they were five years ago, disclosure obligations have sharpened, and CISOs are in the room far more often. That is real progress and it happened quickly.

What has not improved is what happens in the room. IANS Research, surveying more than 660 CISOs and board directors in 2026, found that 95 percent of CISOs brief the board regularly, in the survey's own framing, while only 29 percent of directors rated those updates as very effective. Just over half described them as somewhat effective. Separately, only 15 percent of CISOs reported helping shape organisational strategy.

Read those together and the gap is not one of access or frequency. Nearly everyone is briefing, nearly everyone is showing up, and most of the receiving end finds the result mediocre. More meetings will not fix a problem that more meetings created.

The failure is in the questions, and it has a specific shape. A governance question is only doing work if the answer could turn out to be false.

Three properties of a question that works

A question worth asking has three characteristics, and every one of them is testable before the meeting.

The answer is a fact rather than a posture. A date, a count, a name, a duration. Something that has a value, not something that has a tone.

The answer has a source outside the person giving it. If the only evidence for the answer is the credibility of the person speaking, no information has moved. You have received a character reference.

And a wrong answer would be visible later. This is the property that does the actual work, and I will come back to it.

The difference shows up immediately when you write questions in pairs. Are we protected against ransomware becomes when did we last restore our largest production database from backup, and how long did it take. Is third party risk under control becomes how many external parties can currently authenticate into our environment, and who was the last one removed. Do we follow the framework becomes which two controls did we deliberately decide not to implement, and who signed that decision.

My favourite is the shortest. What is the oldest open finding, and on what date was it first raised. The answer is a single date. It cannot be softened, contextualised or presented as a journey. Ask it four quarters running and you will learn more about a security program than any maturity assessment will tell you.

Where the value is actually created

Here is the part that gets missed, and it is the whole argument.

The value of a good oversight question is not the answer delivered in the meeting. It is the work that happens in the three weeks before it, when somebody has to go and find out.

Nobody knows the oldest open finding off the top of their head. Somebody has to pull the register, reconcile it, discover that two systems disagree, and settle which one is right. That reconciliation is worth more to the organisation than the number it produces, and it would not have happened without a question that could be answered wrongly.

A governance question is a forcing function, not an information channel. Its value is created before it is asked. Which means the question set matters far more than the meeting, and the meeting is mostly where you confirm the work got done.

I watched a company replace a colour-coded dashboard with five standing questions of this type, agreed by leadership and the board together. In the first quarter, three of the five answers were we do not know yet. That was not a failure of the exercise. That was the exercise working, immediately, and the three unknowns became the security program's actual priorities for the following six months.

The objection that deserves an answer

There is a serious argument against everything above, and it is not the one about directors lacking technical depth.

It is that this turns oversight into interrogation. Security requires trust between the people overseeing it and the executive who runs it. Firing falsifiable questions at a CISO in front of their peers looks less like governance and more like a deposition, and a CISO who feels cross-examined every quarter starts managing the questions rather than the risk. That is a real failure mode and I have seen it produce genuinely worse security.

The objection is correct about the risk and wrong about the cause. What makes a question adversarial is surprise, not difficulty.

Publish the question set a full quarter in advance. Make it standing rather than novel. The same five questions, every quarter, known to everyone, with the answers expected to change over time. A surprise question is a gotcha. A published standing question is an agenda, and the difference in how it lands is total.

There is a second reason the objection dissolves in practice. Most CISOs want this. The single most reliable way to unlock security budget in any organisation is the sentence leadership and the board asked. A published question set that requires real answers hands the CISO a mandate they cannot generate on their own authority. Framed correctly, this is not something done to the security leader. It is the most useful thing leadership and the board can hand them.

Ask your CISO whether they would rather be asked whether the company is secure or be asked for the date of the oldest open finding. In my experience the answer is not close.

How to start without changing anything else

Keep the existing reporting exactly as it is. Add five standing questions to the end of the cyber agenda, and constrain every one of them so the answer must be a date, a count, a name or a duration. Publish them one quarter ahead. Change nothing else for a year.

Three things to do before the next meeting. Take the last cyber deck and, for each claim it makes, write down what evidence outside the security team would confirm it. Count how many claims have none. Then take the five questions you plan to ask and check whether any of them could produce an answer that later turns out to be wrong.

If most of your deck's claims have no external evidence, that is normal and it is also the finding. If none of your questions could be answered incorrectly, you are holding a meeting rather than exercising oversight, and the distinction matters more the closer you get to an incident.

What this changes

Leadership and the board stop receiving reassurance and start receiving facts, which is a less comfortable experience and a far more useful one. The security team gets a clear standing definition of what will be asked, which is the closest thing to a mandate most of them will ever get.

And when something does go wrong, and eventually something will, the record shows an oversight process that asked questions with checkable answers rather than one that accepted assurances. That distinction is not only about better security. It is increasingly the distinction regulators and plaintiffs' lawyers care about too.

Every question you ask that cannot be answered wrongly is a question you asked instead of a real one.