* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* Cyber Due Diligence: Boards Top Questions for CISOs

English

* [English](https://www.paloaltonetworks.com/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence)
* [Français (French)](https://www.paloaltonetworks.fr/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)
* [日本語 (Japanese)](https://www.paloaltonetworks.jp/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)
* [简体中文 (Chinese -Simplified)](https://www.paloaltonetworks.cn/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)
* [繁體中文 (Chinese -Traditional)](https://www.paloaltonetworks.tw/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)
* [Deutsch (German)](https://www.paloaltonetworks.de/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)
* [한국어 (Korean)](https://www.paloaltonetworks.co.kr/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)
* [Español (Spanish)](https://www.paloaltonetworks.es/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/)

# Cyber Due Diligence: Boards Top Questions for CISOs

![Cyber Due Diligence: Boards Top Questions for CISOs](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2023/09/perspectives-unit42-panw-banner.png)  
**By [Tim Erridge](https://www.paloaltonetworks.com/perspectives/author/tim-erridge/ "Posts by Tim Erridge")** | **4 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Cyber Due Diligence: Boards Top Questions for CISOs\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fanswering-board-top-cybersecurity-questions-3-cyber-due-diligence%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/answering-board-top-cybersecurity-questions-3-cyber-due-diligence/?pdf=download&lg=en&_wpnonce=db3407a5a9 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/Erridge_Tim-min-scaled.jpg)

[Learn more](https://www.paloaltonetworks.com/perspectives/author/tim-erridge/)

## IN THIS ARTICLE

In the event of a cyberattack, your board will look to you for answers and insights. It can be a lonely position, but it doesn't mean you're all alone. In fact, if you can demonstrate that your plans and actions are backed by industry best practices and follow all applicable guidelines and requirements, you can put yourself in good company. Better yet, having third-party experts validate what you've done can go a long way to reassure stakeholders that you have covered your bases and done the work expected to protect the business.

Once the board has understood your cyber risk exposure and cyber risk mitigation, they are likely to inquire, "[What cybersecurity due diligence and assurances have we conducted?](https://www.paloaltonetworks.com/engage/communicate-cybersecurity-risks-with-your-board/due-diligence-and-assurances)"

*Subtext questions to consider:*

* Have we undertaken any independent validation of the work?
* Who delivered it, and what was the nature and extent of validation (e.g., threat hunting, compromise assessment, etc.)?
* If we did work internally, how did we ensure we were robust in our approach?

## Cybersecurity Due Diligence: How Do We Know We Did It Right?

The key here is to provide the board and other key stakeholders assurance that there is objectivity in previously conducted analysis. This analysis should not only prove that the vulnerability or attack has been mitigated but also that the operating environment is not open to follow-up exploits that have subsequently been created in the wild.

Organizations that frequently utilize open source software and span geographic borders are under increased regulatory scrutiny (e.g., CCPA, GDPR, etc.). For these organizations, it's recommended to engage a second set of objective eyes to confirm that risks have been mitigated and that the environment is not susceptible to a subsequent follow-up attack.

There are tools and services (e.g., breach simulation platforms, independent experts) that enable organizations to replicate exploits and validate that their environment is not open to a particular vulnerability. These tools can help provide additional assurance to the board by demonstrating extra due diligence and validating a "clean bill of health."

## Why Is It Important in Cybersecurity?

The concepts of SASE, much like the principles of Zero Trust, look to move security closer to the actual assets being protected.

SASE calls for delivering services from a single platform. It simplifies the tech stack, administration,  
and policies while ensuring consistency for all access. This simply can't be achieved with an approach  
using several disparate products, even from the same vendor.

As companies start to adopt a SASE strategy, particularly during the current vast shift we've seen to a  
remote/hybrid workforce, many organizations are encountering a gap in understanding their workers'  
day-to-day experiences. Complaints of slowness or bad connectivity have grown exponentially, leading  
to more need for in-depth visibility at every step along the path. This is typically referred to as digital  
experience management or user experience management.

## Managing the Risk Assessment Data: It's a Lot to Unpack

Being able to unpack your answers with solid data sources and insights can help you demonstrate that you've done the right things.  
It's critically important but no easy feat. Think about something as simple as a [compromise assessment](https://www.paloaltonetworks.com/unit42/assess/compromise-assessment?ts=markdown). How do you show that you've undertaken a compromise assessment across the right scope for the enterprise? You may have to describe the way you prioritized assets, which could be based on certain criticality levels, which in turn may be based on a robust business impact analysis and data classification scheme---it's easy to fall down a rabbit hole.

The key is to have clear ties to the decision hierarchy that you followed, so you can demonstrate due diligence and provide evidence for why you chose to embark down a certain security roadmap path. For instance, you will need to be able to show why you scoped tasks in a certain way and what work was actually completed.

Check out [part four of this series](https://www.paloaltonetworks.com/cxo-perspectives/answering-board-top-cybersecurity-questions-4-regulatory-compliance-requirements), which looks at how to answer the question, "How are we going to reply to regulatory or other compliance inquiries?"

Learn more about how to talk to your board about cybersecurity due diligence by watching this video:

## Get in Touch

*Remember to ask for Unit 42® by name with your cyber insurance carriers if you need
[incident response services](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown).*

*If you think you may have been impacted by the Log4j vulnerability or any other major attacks, please [contact Unit 42](https://start.paloaltonetworks.com/contact-unit42.html)
to connect with a team member. The Unit 42 Incident Response team is available 24/7/365. You can also take preventative steps by requesting a
[Proactive Assessment](https://www.paloaltonetworks.com/unit42/assess?ts=markdown).*

* [Addressing Regulatory Issues](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=addressing-regulatory-issues)
* [Third Party Risk Assessment](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=third-party-risk-assessment)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/08/CtrlAltDelusion-Header-WarGames2.png) BLOG

### Addressing Regulatory Issues

**Ctrl + Alt + Delusion: Revisiting "WarGames" 42 Years Later**

Shall we play a game? Auditing the classic cyber-thriller "WarGames."...

[Ben Hasskamp](https://www.paloaltonetworks.com/perspectives/author/ben-hasskamp/ "Posts by Ben Hasskamp")
[](https://www.paloaltonetworks.com/perspectives/ctrl-alt-delusion-revisiting-wargames-42-years-later/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/06/third-party-risks-are-rising-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**The Weakest Link in Your Cybersecurity Isn't What You Think**

Third-party risks are rising --- is your supply chain prepared?...

[Michael Sikorski](https://www.paloaltonetworks.com/perspectives/author/michael-sikorski/ "Posts by Michael Sikorski")
[](https://www.paloaltonetworks.com/perspectives/the-weakest-link-in-your-cybersecurity-isnt-what-you-think/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/05/nation-states-are-reshaping-threat-landscape.jpg) BLOG

### Addressing Regulatory Issues

**Is There a Cyber Cold War? How Nation-States Are Reshaping the Threat Landscape**

Why today's geopolitical risks are every CIO's security problem....

[Wendi Whitmore](https://www.paloaltonetworks.com/perspectives/author/wendi-whitmore/ "Posts by Wendi Whitmore")
[](https://www.paloaltonetworks.com/perspectives/is-there-a-cyber-cold-war-how-nation-states-are-reshaping-the-threat-landscape/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
