When a cyber incident strikes, your board needs to ask more than "Are we still operating?" The Manchester Airports Group breach, which exposed 8.7 million customer records while airports continued running, shows why. Operations stayed online, but customer data walked out the door. Both outcomes matter.
This checklist provides your board and audit committee with a practical tool to assess whether your organization's cyber resilience strategy covers the full scope of business impact, not just uptime.
Purpose of the Checklist
This tool helps boards and audit committees evaluate whether management's cyber resilience approach addresses both operational continuity and data protection across the entire business ecosystem. It's designed for quarterly risk reviews, annual strategy assessments, or post-incident evaluations.
The checklist reflects the UK National Cyber Security Centre definition of cyber resilience: an organization's ability to protect itself from, prepare for, respond to, and recover from cyber incidents, data breaches, and service outages. It translates that definition into specific oversight questions.
Use it to identify gaps in how your organization defines, measures, and demonstrates resilience before an incident forces the conversation.
Prerequisites
Before using this checklist effectively, your board should have:
- Current enterprise risk register access: You need visibility into how cyber risks connect to broader business risks, not just IT infrastructure diagrams.
- Third-party Risk Portfolio: A list of vendors, cloud platforms, and outsourced services that handle customer data or support business operations.
- Defined critical business services: Management should have identified which services are essential to organizational objectives (this goes beyond "critical systems").
- Incident response structure documentation: The plan for who does what when something goes wrong.
- Recent control testing results: Evidence that protective controls are working as designed.
If these don't exist or haven't been reviewed in the past year, that's your first finding.
The Checklist
Business Impact Definition
- Has management defined "cyber resilience" to include both operational continuity and data protection?
- Can management explain which business services depend on which systems, data stores, and third parties?
- Does the organization maintain a current inventory of where customer data lives, including third-party hosted databases?
- Are customer-facing applications (parking, WiFi, booking systems) included in cyber risk assessments even if they're not operationally critical?
- Can management demonstrate how a data breach would trigger privacy obligations, fraud exposure, and reputational consequences separately from operational impact?
Third-Party Risk Integration
- Does the organization know which third parties host customer data or provide services that collect personal information?
- Are third-party systems subject to the same dependency mapping as internal critical systems?
- Can management identify which controls protect third-party relationships and data flows?
- Is there a process for assessing whether a third-party compromise could expose customer information without affecting core operations?
- Do vendor contracts specify incident notification timeframes and breach response responsibilities?
Incident Response Readiness
- During an incident, can the team identify affected systems, connected services, involved suppliers, and applicable regulatory obligations within hours rather than days?
- Is cyber risk information connected to enterprise risks, controls, third parties, and business services in a way that supports rapid incident assessment?
- Does the incident response structure specify who assesses business impact beyond operational downtime?
- Can management explain containment capabilities: what an attacker can reach from a compromised system and which controls limit lateral movement?
- Are there defined severity levels that account for data exposure separately from service disruption?
Control Performance and Assurance
- Can management demonstrate that controls protecting customer data platforms receive the same scrutiny as controls protecting operationally critical systems?
- Is there evidence that segmentation, identity and access management, and monitoring controls are tested regularly?
- Does the organization track Key Control Indicators for data protection separately from availability metrics?
- Can management show which controls failed or were bypassed after an incident, and what changed as a result?
- Are control testing results available to the audit committee in a format that shows coverage across both operational and data protection domains?
Learning and Adaptation
- After an incident, does the organization update risk assessments to reflect what happened?
- Is there a process for identifying similar exposures elsewhere in the business based on incident findings?
- Can management track remediation actions from incident to control change to risk reassessment?
- Does the board receive post-incident reports that cover operational impact, data exposure, regulatory consequences, and control performance?
- Are lessons from incidents incorporated into future resilience planning and vendor risk assessments?
Measurement and Reporting
- Does management report cyber resilience using metrics beyond uptime and mean time to recovery?
- Are there measures for detection speed, containment effectiveness, data exposure scope, and customer impact?
- Can the board see trends in control performance across both operational continuity and data protection?
- Does the Cybersecurity Risk Register include risks to customer trust and regulatory standing, not just operational risks?
- Is the board receiving information that would allow it to assess whether a "successful" incident response (operations continued) still resulted in significant business harm (data exposed)?
Customizing the Checklist
Adjust this checklist based on your organization's risk profile and regulatory context:
For regulated industries (financial services, healthcare): Add questions about specific breach notification requirements, regulatory reporting timeframes, and whether incident response plans account for examiner inquiries.
For organizations with complex supply chains: Expand the third-party section to include questions about fourth-party risks (your vendors' vendors) and whether contracts allow you to audit third-party security controls.
For customer-facing businesses: Add questions about customer communication plans, fraud monitoring capabilities after a breach, and whether customer service teams are trained to handle breach-related inquiries.
For organizations using GRC platforms: Add questions about whether cyber incidents, controls, risks, and third-party relationships are connected in your system or maintained in separate tools that require manual reconciliation during an incident.
Remove questions that don't apply to your business model. A manufacturing company with minimal customer data collection doesn't need the same depth on breach notification as a travel or hospitality business.
Validation Steps
After completing the checklist:
Score the gaps: Count how many questions received "no" or "unclear" responses. More than five suggests your resilience strategy may be operationally focused but data-protection incomplete.
Test the connections: Pick one customer-facing application. Ask management to trace it from system to supplier to data store to applicable controls to incident response procedures. If this takes more than one meeting to assemble, you've identified a structural gap.
Review a past incident: If your organization has experienced any information security event in the past two years, use this checklist to evaluate the response. Did the assessment cover both operational and data protection dimensions? Were control failures identified and addressed?
Compare to regulatory expectations: Cross-reference your findings against applicable frameworks. The UK Cyber Governance Code of Practice asks boards to integrate cyber risks into enterprise risk management and build resilience to risks arising through suppliers. Can you demonstrate both?
Schedule follow-up: Set a date (30-60 days) for management to address priority gaps and report back. Cyber resilience isn't a one-time assessment; it requires ongoing visibility into how risks, controls, and business impact connect.
The Manchester Airports Group incident demonstrated that keeping operations running doesn't mean the incident was fully contained. Your board's oversight should reflect that reality.





