Boardroom breach: The questions every leadership team needs to ask
Tue, 28th Jul 2026 (Today)
At a recent Boardroom Breach simulation hosted by Shakespeare Martineau, CSS Assure and the PrivacyRules alliance, powered by Polpeo's crisis simulation platform, participants worked through a realistic cyber incident as it unfolded in real time.
As the scenario evolved, leaders were forced to navigate operational disruption, stakeholder pressure, legal obligations, regulatory scrutiny and rapidly changing information. The exercise quickly demonstrated that while cyber incidents begin as technical events, they soon become business-wide challenges requiring decisions under pressure.
One thing became clear very quickly - the organisations that navigate cyber incidents best are those that have already considered how they would respond before a crisis occurs. The simulation highlighted six questions every leadership team should be asking.
What business value are we protecting and what happens if it is compromised?
For most organisations, the most important assets are not purely technical. They are commercial - revenue streams, customer relationships, intellectual property, operational capability and brand trust.
When a cyber incident occurs, attention often shifts quickly from the technical cause to the business impact. Customers, investors, regulators and employees will all form judgements on how the organisation responds.
Understanding which assets truly drive business value and what the impact would be if they were compromised is essential to prioritising protection and response.
Without that clarity, organisations risk spreading effort too thinly across areas that are not equally critical.
Is our cyber readiness aligned with today's threat reality?
Cyber threats have changed significantly in both scale and sophistication.
Many cyber criminal groups now operate with structured roles, specialist expertise and clearly defined commercial objectives. Their methods continue to evolve rapidly, and their ability to identify and exploit weaknesses is highly developed.
Against this backdrop, the question for leadership teams is whether their current level of preparedness still reflects reality.
Governance structures, response plans and risk assumptions that were appropriate even a few years ago may no longer be sufficient.
Cyber readiness should not be a static position - it requires continuous reassessment against an evolving threat landscape.
Could we maintain critical operations if systems went down?
A cyber incident is ultimately a test of operational resilience.
While technical teams focus on containment and recovery, leadership attention quickly shifts to continuity - which services must remain available, how long disruption can be tolerated and what the knock-on effects will be across the organisation.
Critical dependencies often become most visible under pressure. Organisations that have clearly mapped their essential processes, tested recovery pathways and identified alternative arrangements are better placed to maintain stability during disruption.
In many cases, resilience is less about avoiding downtime entirely and more about limiting its impact on core business functions.
Can we make decisions without full information?
Uncertainty is one of the defining features of any cyber incident.
In the early stages, information is incomplete and, in some cases, contradictory. Yet decisions around containment, communications, legal obligations and operational continuity cannot wait for certainty.
This is where governance structures become critical. Clear decision-making authority, defined escalation routes and agreed roles allow organisations to act decisively even when the full picture is not yet available.
Where these structures are unclear, uncertainty in the incident itself is often compounded by uncertainty in leadership response.
Are we ready to meet stakeholder expectations in a crisis?
Communication is one of the most sensitive aspects of any cyber incident response.
Stakeholders, such as customers, regulators, employees and partners, expect timely and credible updates.
Balancing transparency with accuracy is rarely straightforward. The organisations that manage this most effectively are those where communications, legal, operational and technical teams are aligned from the outset, with a shared understanding of objectives and constraints.
In a crisis, confidence is shaped by how consistently and coherently communication is delivered.
Are we prepared for what happens in practice?
Most organisations already have incident response plans, insurance arrangements, supplier contracts and governance frameworks in place.
The more important question is whether those arrangements hold up under real-world pressure.
Do decision-makers know their roles instinctively? Are critical documents and contracts easily accessible? Can cross-functional teams operate effectively under time pressure and incomplete information?
Preparedness is rarely demonstrated by the existence of documentation. It is demonstrated in execution when uncertainty is high, scrutiny is increasing and the stakes are significant.
The Boardroom Breach simulation reinforced a simple but important point - cyber resilience is both a technical discipline and a leadership capability.
The organisations best positioned to navigate future incidents will be those with a clear understanding of what matters most, strong decision-making structures and the confidence to act decisively when it counts.