Boards caught up on cyber risk. Gartner's 2024 survey found 93% now see it as a threat to stakeholder value — a level of fluency they did not have three years ago. Yet in Trend Micro's study of 2,600 IT leaders, 79% still report boardroom pressure to downplay severity, and a third say cybersecurity is still treated as an IT issue.
Those two findings look contradictory until you read them together. The gap isn't that boards stopped caring. It's that the questions changed and the answers did not. Four questions now separate the leader who holds the room from the one who loses it — and losing it costs standing without a breach ever happening.
The shift is structural, not a matter of personality
Converging regulation gave boards a vocabulary they previously lacked: the SEC's four-business-day incident disclosure on Form 8-K, the NYDFS Part 500 certification a CEO and CISO must jointly sign, the EU's DORA fully applicable since January 2025, NIS 2 with personal liability for senior managers, the EU's AMLA operational since July 2025, and the FCA's Principle 11.
Enforcement made the cost concrete. NYDFS fined Gemini Trust $37 million in 2024, citing Part 500.11 third-party risk. It fined Block, Inc. $40 million in 2025, citing the board's own failure to review cyber policies alongside an inadequate business-continuity plan. Coinbase disclosed $180–400 million in remediation following a third-party support breach.
A board that has read those cases asks sharper questions — and can now tell a quantified answer from a qualitative one.
The four questions
Each is framed in the language regulated-sector boards now use, and anchors to the frameworks your own regulators and auditors work from. Read them as a benchmark to score yourself against before you are in the room.
1. What does our next incident cost us — and how do we know?
Required by SEC materiality on a four-day clock, DORA Article 18 classification, and NIS 2 Article 23 reporting. What holds the room: exposure quantified in currency, the methodology behind the number, and the disclosure threshold — mapped to SEC materiality, DORA, and Principle 11. What loses it: "high risk," or "significant exposure."
2. Who does what in the first 72 hours — and what slows the clock?
GDPR Article 33, DORA Article 19, and NYDFS Part 500.17(a) all converge at 72 hours, with a 24-hour window for ransom payments. The board wants names: who calls the regulator, who authorizes counsel, who approves the public statement, who decides on a ransom — and the tested escalation timeline in hours. An aspirational plan does not hold the room. Boards now ask whether it has been rehearsed.
3. Which third-party dependency could take us down with them?
A governance question now, not a procurement one — DORA Articles 28–44, NIS 2 Article 21, NYDFS Part 500.11 (the provision the $37 million Gemini fine cited). The 2025 Verizon DBIR found third-party involvement in breaches doubled to 30%. What holds the room: naming, by service, the three vendors whose failure triggers a material disclosure, with contractual, operational, and substitution controls documented for each. The outsourced support and operations layer is now one of those named dependencies.
4. What will regulators ask six months from now that we can't answer today?
Concrete in 2026: the first fully phased NYDFS Part 500 certification signed by the top executive and the CISO, DORA fully applicable, AMLA direct supervision arriving in 2028, and the GENIUS Act's federal stablecoin regime in force. What holds the room: a forward calendar mapped to specific regulatory dates, with gap-closure milestones and named accountable executives — not framework alignment in the abstract.
The four read as a single test of standing
Answer all four in board language and you compound your standing. Answer two, and you watch the board bring in outside advisors who will — EY's data shows external-advisor engagement for cyber oversight more than doubling in a single year. The replacement is rarely an event. It is a gradual transfer of the questions to someone else.
Common questions
Why would boards pressure leaders to downplay risk and still dismiss them?
Both come from the same root: risk communicated in qualitative, technical language that does not connect to the board's financial and regulatory frame. Boards are more fluent than ever (93%), so an answer that isn't quantified reads as evasive or as noise — which is why 79% feel pressure to soften it and a third still see it treated as an IT issue.
Is this only relevant to public companies?
No. The four questions are driven by supervisory frameworks that reach private crypto exchanges, fintechs, payment processors, iGaming operators, and DeFi protocols — NYDFS Part 500, DORA, NIS 2, AMLA, FCA Principle 11 — not only SEC disclosure rules.
Where does the support and operations layer fit?
Under question three. An outsourced support or operations layer is a third-party dependency a board now expects to see named, with its controls and substitution plan documented. Toeshee operates that layer for regulated crypto, iGaming, and fintech operators under the compliance discipline those frameworks require — a SOC 2 Type II examination across support operations is the control it shows for that dependency.
Toeshee is the specialized customer-support partner for iGaming, fintech, and digital-asset platforms, operating the support layer with risk management and compliance as the design principle of every workflow — SOC 2-compliant operations, risk-tiered escalation discipline, and Multi-Dimensional Security at every agent desktop.
We've got your back. Crypto-native.
