* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* Cyber Risk Mitigation: Boards Top Questions for CISOs

English

* [English](https://www.paloaltonetworks.com/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan)
* [Français (French)](https://www.paloaltonetworks.fr/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)
* [日本語 (Japanese)](https://www.paloaltonetworks.jp/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)
* [简体中文 (Chinese -Simplified)](https://www.paloaltonetworks.cn/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)
* [繁體中文 (Chinese -Traditional)](https://www.paloaltonetworks.tw/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)
* [Deutsch (German)](https://www.paloaltonetworks.de/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)
* [한국어 (Korean)](https://www.paloaltonetworks.co.kr/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)
* [Español (Spanish)](https://www.paloaltonetworks.es/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/)

# Cyber Risk Mitigation: Boards Top Questions for CISOs

![Cyber Risk Mitigation: Boards Top Questions for CISOs](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2023/09/perspectives-unit42-panw-banner.png)  
**By [Tim Erridge](https://www.paloaltonetworks.com/perspectives/author/tim-erridge/ "Posts by Tim Erridge")** | **4 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Cyber Risk Mitigation: Boards Top Questions for CISOs\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fanswering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/answering-board-top-cybersecurity-questions-2-cyber-risk-mitigation-plan/?pdf=download&lg=en&_wpnonce=8c35f4dfea "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/Erridge_Tim-min-scaled.jpg)

[Learn more](https://www.paloaltonetworks.com/perspectives/author/tim-erridge/)

## IN THIS ARTICLE

When there is a cybersecurity incident, your board of directors wants to know if there is a plan. They want assurances that your organization is prepared to deal with the incident swiftly, efficiently, and thoroughly to minimize its impact on the business. That's why, after communicating about your cyber risk exposure, the next burning question you will likely need to answer will be around your cyber risk mitigation plan. You will need to be prepared to respond to the question, "[Has the situation been contained and have we dealt with it adequately?](https://www.paloaltonetworks.com/engage/communicate-cybersecurity-risks-with-your-board/situation-contained-adequately)"

*Subtext questions to consider:*

* What was our response plan?
* How did we prioritize efforts and resource allocation?
* What is left to do?
* Were there any surprises and/or lessons learned?

## Cyber Risk Mitigation: Are We Done?

What your executives and board really want to know is if the situation has been contained and what assurances you can provide that the risk has been dealt with appropriately.

To have a defensible position to answer questions like these from the board (or the audit committee in the future), you'll need documentation, documentation, and more documentation! Your incident response, patch management, and zero-day vulnerability plans will likely all be required to capture all the processes, communications, and steps taken to address and validate that the risk has been mitigated.

This documentation should be comprehensive, including not only the plans but also:

* The emergency change processes that you executed
* The people who were involved
* Patching and segmentation details (how and when systems were prioritized and patched/segmented)
* How systems related to critical processes
* How processes were stratified
* How enforcement rules were altered and deployed

The goal is to show exactly what was done, when, and how, so you can demonstrate due care and report the elements that your board, as well as regulators and auditors, are looking to understand.

## Keeping Executives Informed: Recovery Is a Journey Not a Moment

If the board asks, "Are you done? Is it contained? Did you finish up?" it's important to frame recovery as a journey, not a point-in-time experience. Recovery is an ongoing process that's about coming back stronger and faster.

This means you need to sit down and have the recap meetings that help you uncover lessons learned and figure out where you could have saved time or done something differently or better. When time is of the essence, the documentation that we've discussed is critical to making sure that nothing is missed, no stone left unturned, and no step left out. But it's also important to identify and then take care of the small stuff that can make a big difference in the efficiency of your operations.

For example, having easy-to-follow call trees for certain circumstances and business impact reports that tell you where your key assets are can save you a lot of time and effort when you're having the most stressful day of your life. Hindsight's 20/20, so take the time to figure out what would have been useful and then explain to the board what you are doing to come back stronger.

By framing your answers to the board's questions as a journey, you can remind them that security is never finished and never perfect, but it can keep getting stronger and more effective. Remember, "**the day of the dance is not the day to learn to dance,**" so, in addition to documenting everything meticulously, don't forget to rehearse, rehearse, rehearse/practice, practice, practice, rinse and repeat. Let the board know how you are using every single opportunity to prepare and bolster your capabilities and what you are doing to make sure the next time will be even better (because, as we all know, there will always be a next time).

Check out [part three of the series](https://www.paloaltonetworks.com/cybersecurity-perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence?ts=markdown), which looks at how to answer, "What due diligence and assurances have we conducted?"

Learn more about how to talk to your board about cyber risk mitigation by watching this video:Learn more about how to talk to your board about cyber risk mitigation by watching this video:

## Get in Touch

*Remember to ask for Unit 42® by name with your cyber insurance carriers if you need
[incident response services](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown).*

*If you think you may have been impacted by the Log4j vulnerability or any other major attacks, please [contact Unit 42](https://start.paloaltonetworks.com/contact-unit42.html)
to connect with a team member. The Unit 42 Incident Response team is available 24/7/365. You can also take preventative steps by requesting a
[Proactive Assessment](https://www.paloaltonetworks.com/unit42/assess?ts=markdown).*

* [Staying Ahead of Evolving Threats](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)
* [Third Party Risk Assessment](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=third-party-risk-assessment)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://www.paloaltonetworks.com/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://www.paloaltonetworks.com/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/02/Discover.png) BLOG

### Secure AI Usage

**The Pilot Trap: Why Scaling AI is Impossible With Legacy AppSec Tools**

Bridging the gap between AI innovation and AI control....

[Ian Swanson](https://www.paloaltonetworks.com/perspectives/author/ian-swanson/ "Posts by Ian Swanson")
[](https://www.paloaltonetworks.com/perspectives/the-pilot-trap-why-scaling-ai-is-impossible-with-legacy-appsec-tools/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/01/Dawn-of-the-Autonomous-Agent-featured.jpg) BLOG

### AI

**The Dawn of the Autonomous Agent: When AI Starts Attacking**

How to fight back when the adversary moves at machine speed....

[Dr. Nicole Nichols](https://www.paloaltonetworks.com/perspectives/author/dr-nicole-nichols/ "Posts by Dr. Nicole Nichols")
[](https://www.paloaltonetworks.com/perspectives/the-dawn-of-the-autonomous-agent-when-ai-starts-attacking/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
