Executive cyber risk workshops for the people who govern the organisation.
F Creative Studio 360 briefs boards and leadership teams in any country on oversight, investment and crisis decisions, in language a board can use.
Directors are asked to oversee a risk they are rarely trained to discuss.
The session is built around the governance duties that apply to the entities in the room, and around the NIST Cybersecurity Framework where that is the language management already uses. When the board wants risk expressed in money, the discussion can use Factor Analysis of Information Risk.
F Creative Studio 360 does not change systems during a workshop, and does not replace your counsel.
- The board owns the decision
- A technical team can describe a weakness. The board still decides what risk the organisation will carry, what it will spend, and what it will tell people if something goes wrong.
- The duty follows the jurisdiction
- Directors are accountable under the law where the organisation is governed. The workshop uses that law. It does not assume one country’s statute applies everywhere.
- The language has to be usable
- A board minute needs a decision, not a list of product names. The session stays on impact, options and what the board will ask next.
- A workshop is not a legal opinion
- F Creative Studio 360 explains the governance questions. Your counsel interprets the statute. The session does not certify the board or the programme.
What the workshop covers
The agenda is set for the board in front of you. A bank, a listed company and a private group do not sit under the same rules, even when they face the same kind of incident.
- What the board is accountable for
- Oversight, the questions directors should ask, and what a reasonable record of that oversight looks like where you operate.
- Risk in business terms
- How a technical issue becomes a financial, operational or reputational one. Factor Analysis of Information Risk can be used when the board wants the discussion in money.
- A decision exercise
- A tabletop for leadership: who is told, what is said publicly, when a regulator is notified, and who can stop operations. It is a discussion. It is not an attack on your systems.
- Suppliers and insurance
- What the board should ask about suppliers, and what a cyber insurance policy does and does not cover. This is not insurance advice and not a recommendation to buy a policy.
- Where to spend
- A way to compare proposals when the budget cannot fund all of them, based on the risk the board has already accepted.
- The note you keep
- A short record of the decisions, the open questions, and what management was asked to bring back.
How a workshop runs
The same shape works in any country. It can be held in a boardroom or online, including when directors are in more than one place.
- 1
Confirm the room
Who will attend, which entities they govern, and which laws and listing rules apply to those entities.
- 2
Brief the duties
A non-technical session on oversight, the questions to ask management, and the record the board should keep.
- 3
Exercise a decision
If it is in scope, a scenario the leadership team works through together. No systems are touched.
- 4
Hand back the note
Decisions, open questions, and what to ask for next. Counsel and management own the actions that follow.
What you receive
- A session matched to the entities and the roles in the room.
- A short list of questions the board can keep using with management.
- Notes from the decision exercise, when one was in scope.
- A record of what was asked, without a claim that the board is compliant.
- A suggestion for what counsel or management should bring to the next meeting.
Rules the workshop can use
F Creative Studio 360 uses the references that apply where you are governed. Examples include the US Securities and Exchange Commission cybersecurity disclosure rules, NIS2 and DORA.
For an organisation that is actually subject to them, the session can use CPS 234, the Security of Critical Infrastructure Act, the Corporations Act, the ASX Corporate Governance Principles and the Information Security Manual. Naming a rule is not a statement that you comply with it.
Common questions
What is an executive cyber risk workshop?+
It is a session for directors and executives on cyber risk as a business decision: oversight, money, disclosure and what to do in a crisis. F Creative Studio 360 facilitates it. It does not certify the board, and it is not a legal opinion.
Where do you deliver this?+
For boards and leadership teams in any country, in person or online. The duties discussed are the ones that apply where that organisation is governed. A local rule, such as CPS 234, the SOCI Act or the Corporations Act, is used only when that organisation is actually subject to it.
How is this different from security awareness training?+
Awareness training is for staff who receive messages and calls. This workshop is for the people who govern the organisation. They can be scoped together, and they are not the same session.
Is the incident exercise a penetration test?+
No. It is a discussion of decisions: customers, regulators, insurers and operations. F Creative Studio 360 does not attack systems, send phishing mail, or change the environment as part of the workshop.
Do you tell us what the law requires?+
The workshop names the obligations that apply to the entities in the room and turns them into questions a board can ask. Interpretation of the statute, and any filing, stays with your counsel. F Creative Studio 360 does not file reports for you.
How much does it cost, and how long does it take?+
It depends on who is in the room, whether a decision exercise is included, and whether the session is in person. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Start with the board that has to decide.
F Creative Studio 360 will look at who governs the organisation and which rules apply, then say what a sensible workshop includes.
