Cyber Security for Directors: 4 Priorities You Must Oversee (According to the ASD)

In 2025, cyber security is no longer just an IT issue – it is a core director duty.

The landscape of cybersecurity in Australia has shifted. With ASIC increasingly focusing on personal liability and “reasonable steps,” Boards can no longer afford to be passive. But bridging the gap between high-level governance and technical reality remains a significant challenge for many Australian Directors.

To clarify these expectations, the Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) have released joint guidance. They have identified four priority areas for 2025-26 that every Board must address to build a defensible position.

If you are a Director, here is your executive briefing on these four priorities, along with the specific governance questions you must ask your management team today.

Priority 1: Event Logging and Threat Detection

The Risk: You cannot govern a crisis you cannot see. The ASD highlights that many organisations fail to detect intrusions until it is too late (often months after the breach) because they lack adequate visibility. If a breach occurs, you need accurate data to understand what happened and to meet mandatory reporting obligations.

The Board Question: “If a breach happened today, would we know immediately, or would we find out when the ransom note appears?”

The Operational Reality (What BitLOGIC Does):

To answer this, your organisation needs a Security Information and Event Management (SIEM) system. This tool acts as a “black box” recorder for your network.

  • Action Item: Ask your IT partner if your event logs are centralised (stored in a secure, separate location) and time-synchronised. This ensures that if a hacker deletes evidence on a server, the forensic record remains safe.

Priority 2: Management of Legacy IT Assets

The Risk: “If it ain’t broke, don’t fix it” is a dangerous philosophy in cyber governance. Old servers, outdated software, and applications that have reached their “End of Life” (EOL) are known as Legacy IT. These assets often stop receiving security patches from the manufacturer, leaving permanent, unfixable doors open for attackers. Identifying these assets is a critical component of a robust cyber security risk assessment.

The Board Question: “What systems are we currently running that are no longer supported by the manufacturer, and what is the funded roadmap to retire them?”

The Operational Reality (What BitLOGIC Does):

Your technical team must maintain a live Asset Register that flags the support status of every device. The Board must be willing to view the retirement of this “technical debt” not as an IT cost, but as a risk management necessity.

Priority 3: Cyber Supply Chain Risk Management

The Risk: Your internal firewall might be robust, but what about the vendors who hold the keys to your data? A breach in your payroll provider, managed service provider (MSP), or software vendor’s network can easily become a breach in yours. This is currently one of the blindest spots in cybersecurity in Australia. The new guidance explicitly prompts Boards to ask two types of questions: Governance (the strategy) and Technical (the proof).

The Governance Questions (Threshold Questions):

  1. “Have we categorised our suppliers by criticality and risk exposure?” (i.e., Do we know which vendors could shut us down?)
  2. “Have we assessed our suppliers’ cyber security posture using independent assessments or certifications?”

The Technical Questions (The Proof):

  • “Do we limit supplier access to only necessary systems and data?” (Least Privilege)
  • “Do we implement cyber security measures, such as network segmentation and multi-factor authentication (MFA), for supplier access?”
  • “Do we monitor and log exactly what our suppliers are doing while connected to our systems?”

The Operational Reality (What BitLOGIC Does):

We implement Zero Trust principles for supply chains. This means no vendor is trusted by default. We enforce MFA for every external connection and use network segmentation to ensure that even if a vendor is compromised, the attacker cannot move laterally into your core systems.Shutterstock

Priority 4: Preparation for Post-Quantum Cryptography

The Risk: It sounds like science fiction, but it is a looming reality. As quantum computing advances, the standard encryption methods used today to protect your long-term sensitive data (like health records, tax data, or trade secrets) will eventually become breakable.

Cyber criminals are already executing “Harvest Now, Decrypt Later” attacks – stealing encrypted data today to store it until the technology exists to unlock it.

The Board Question:

“Where is our most long-term sensitive data stored, and are we monitoring the transition to quantum-resistant encryption standards?”

The Operational Reality (What BitLOGIC Does):

This is a long-term strategic play. Preparation involves identifying your “Crown Jewel” data – information that must remain secure for 10+ years – and ensuring your software vendors are engaging with the new NIST post-quantum cryptography standards.

How Directors Can Oversee a Cyber Crisis

The overarching theme of the ASD and AICD guidance is oversight.

Directors do not need to be technical engineers, but they must ensure their management teams – and their IT partners – are not marking their own homework. You need independent verification that the “reasonable steps” required by law are actually being taken.

At BitLOGIC, we act as the strategic bridge between technical execution and Board-level assurance. Whether it’s conducting a comprehensive cyber security risk assessment, providing audit logs for supplier access, or building a roadmap to retire legacy assets, we provide the data Directors need to sleep soundly.

Is your Board asking the right questions? Contact BitLOGIC today to ensure you have the right answers.

Frequently Asked Questions (FAQs)

What are the top cyber security priorities for Australian Directors in 2025?

According to the ASD and AICD, the four key priorities are: Event Logging and Threat Detection, Management of Legacy IT Assets, Cyber Supply Chain Controls, and Preparation for Post-Quantum Cryptography.

Why is legacy IT a cyber security risk?

Legacy IT assets (software or hardware that is End-of-Life) no longer receive security patches from the manufacturer. This means if a new vulnerability is discovered, it cannot be fixed, leaving the system permanently exposed to attackers.

What questions should a Board ask about supply chain security?

Boards should ask “Threshold Governance” questions, such as: Have we categorised suppliers by risk? And technical questions, such as: Do we enforce Multi-Factor Authentication (MFA) for all vendor access? And do we log their activity?

How does a cyber security risk assessment help Directors?

A cyber security risk assessment provides an independent, fact-based view of an organisation’s security posture. It allows Directors to see where the gaps are (e.g., in legacy IT or supply chain) and allocate budget effectively to mitigate legal liability.

Tags:

Related news