The answers go into the minutes, and the minutes are the document that will be examined if an allegation is ever brought against the officers. Data from 2026 indicates an average cost of around 5 million dollars for a data breach, which puts this discussion firmly in the range that calls for a board-level decision.

Key Takeaways

  • Access to production code is a governance question because it determines who can change the product the company sells. A board that receives a numerical answer, meaning how many people hold access and when the last review took place, is genuinely exercising oversight. A board that receives an answer along the lines of “only the relevant team” is relying on an assertion and recording it in the minutes as though it were evidence.
  • The 2023 SEC disclosure rules require public companies to describe the board’s oversight of cyber risk and to report a material cyber incident. The proposed requirement to disclose cyber expertise among board members was dropped from the final rule, so the surviving requirement concerns the oversight process rather than the composition of the board.
  • In Israel, an officer’s duty of care under the Companies Law extends to oversight of information risk. Amendment 13 to the Privacy Protection Law widened the enforcement powers of the Privacy Protection Authority and added a reporting duty, and the Privacy Protection Regulations (Data Security) set operational requirements the board is expected to confirm are in place.
  • Directors and officers insurance is designed to respond to shareholder claims and regulatory proceedings, subject to the wording, the limits and the exclusions. A record of discussion, decision and follow-up strengthens an officer’s position against an allegation of breach of the duty of care. A documented absence of oversight works the other way, and produces exactly the evidence a claimant is looking for.

Why Code Access Became a Board Question

Production code is the asset that generates the revenue, and whoever can change it can change the product the customer bought. When a departed developer, a subcontractor or an old service account still holds access that has never been reviewed, the company is carrying a risk nobody decided to accept, and consciously accepting risk is precisely the kind of decision a board is expected to take and record.

Regulation is moving the same way. NIS2 in Europe established personal accountability for senior management on information security in the sectors within scope. The 2023 SEC disclosure rules require public companies to describe the board’s oversight of cyber risk, and to report a cyber incident of a scale that triggers disclosure, within a fixed timetable. In Israel, Amendment 13 and the widened powers of the Privacy Protection Authority create a similar effect on private companies holding databases. For a private company selling to enterprise clients and institutional investors the expectation is substantively identical, even without a direct statutory duty. The question left open in every one of these cases is what evidence the board is able to produce.

Oversight is measured by what goes into the minutes rather than by what was said in the room.

The Five Questions and the Answer That Is Enough

The questions below are short, and they generate a governance discussion inside ten minutes. The difference between a real discussion and a box-ticking exercise lies in the quality of the answer: an answer that points to a document, a date and a named owner allows follow-up next quarter.

Who Holds Access to Production Code

The answer that suffices is a named list with an update date, a total count, and a breakdown into employees, contractors and service accounts. A number lets the board track the figure across quarters and ask why it grew, and the breakdown exposes the automated accounts and the contractors that most discussions skip over.

When the Last Access Review Was Carried Out

Permissions are created under pressure, on a release night or during an incident, and stay open long after the need has passed. A periodic review that records what was removed and who approved it is the evidence that the process is alive. An answer that suffices includes a date, a scope, the name of the person responsible, and the number of permissions revoked.

Whether the Incident Response Plan Has Been Exercised

An incident response document that was written and never exercised is an assumption. A tabletop exercise held within the past year is evidence. The board should ask when the exercise took place, who took part, which gaps emerged and what has been fixed since. In a real event, the reporting timetable towards the Privacy Protection Authority and under the SEC rules is too short to start learning the procedure then.

Whether the Insurance Programme Matches the Risk Profile

The question here concerns the fit between the limits and the actual exposure. A programme built from cyber, technology professional liability and directors and officers cover needs limits that reflect revenue scale, data types and the requirements written into client contracts. Data from 2026 indicates an average cost of around 5 million dollars for a data breach, and according to 2026 data the cost of a data breach in the United States is more than double the global average. A company with United States operations carrying a limit set three years ago is sitting on a gap. That gap can be measured in a single meeting.

How Vendors With Environment Access Are Managed

An external vendor with access to a production environment extends the company’s attack surface, and the board should know how many such vendors exist and who approved each of them. An answer that suffices includes a vendor register with the level of access, the date of the last review and the security clauses in the contract. An incident originating with a vendor ends up at the company’s door, in front of the client and in front of the regulator.

The five board questions and the answer that is enough:

Board question Why it is a governance question rather than an IT question What constitutes a sufficient answer
Who holds access to production code? Access determines who can change the asset that generates revenue, which is a decision to accept risk A named list with an update date, a total count and a breakdown of employees, contractors and service accounts
When was the last access review carried out? The review cadence shows whether a continuing oversight process exists or a one-off exercise happened once Date, scope, named owner and the number of permissions revoked in the review
Has the incident response plan been exercised? The ability to meet reporting deadlines is a duty of the company and of its officers alike A documented exercise within the past twelve months, participant list, gaps found and remediation dates
Does the insurance programme match the risk profile? Limits and terms of cover are a capital allocation decision that requires board approval A mapping of cyber, technology professional liability and directors and officers cover against revenue, data types and contractual requirements
How are vendors with environment access managed? The company carries responsibility towards the client and the regulator even when the failure occurred at the vendor A vendor register with access level, date of last review and security and indemnity clauses in the contract
Who is the executive owner of cyber risk? Oversight requires a single address reporting to the board, and where responsibility is dispersed there is nobody to hold to account A senior officer named in the minutes, with fixed quarterly reporting and consistent metrics
What happens when a CEO asks to bypass a control? Departing from an approved procedure is a governance matter requiring documented approval rather than an operational call A written exception procedure, approval in writing, a record in the minutes and a date for review

The Personal Exposure of an Officer

The Companies Law imposes a duty of care and a duty of loyalty on an officer, and oversight of information risk falls under the duty of care where the risk could damage the company’s operations. The typical allegation in such a proceeding is that the officer knew or ought to have known, and failed to act. A record of discussion, decision, follow-up and remediation is the practical defence against that allegation.

In Europe, NIS2 established personal accountability for senior management, including the possibility of personal fines and restrictions on holding management roles in the sectors within scope. In the United States, inaccurate or late disclosure of a material cyber incident may lead to enforcement proceedings against officers and to shareholder class actions alongside the claim against the company, and in Israel the Privacy Protection Authority has been exercising widened powers since Amendment 13, so a company that failed to meet the reporting duty stands in a weak position before the regulator and before its own clients.

Directors and officers insurance is designed to respond to claims of this kind, subject to the wording, the limits and the exclusions in the policy. Two conditions recur in almost every discussion: acting in good faith, and having a reasonable informational basis for the decision. Missing documentation of cyber risk oversight undermines both conditions at once. The board minutes therefore form part of the defence file before any claim is filed. The broker (LAMDA Broking) reviews the allocation of cover between the company and the officers, and the order of payments clause, to confirm that personal cover holds up even when the company is under cash flow pressure.

Sources of duty, what is expected of the board, and the line that may respond:

Source of duty Who it applies to What is expected of the board Insurance line that may respond
Companies Law Officers of an Israeli company Documented oversight of risk that could damage operations, including information risk Directors and officers, subject to the wording and to good faith conditions
Privacy Protection Regulations (Data Security) Every database owner in Israel Confirming that database mapping, permission management, logging and periodic review are in place Cyber for the privacy element, and directors and officers for an oversight failure allegation
Amendment 13 to the Privacy Protection Law Companies holding databases A reporting procedure towards the Privacy Protection Authority with timelines and a named owner Cyber for response and mitigation costs, subject to the wording
2023 SEC disclosure rules Public companies in the United States Describing the board’s oversight of cyber risk and reporting a material incident Directors and officers, including defence costs in enforcement proceedings subject to the wording
NIS2 Entities within scope in the European Union Personal accountability of senior management for security controls and vendor management Directors and officers, subject to fines exclusions and to applicable law
DORA Financial entities and their technology service providers Technology risk governance, resilience testing and third-party provider management Cyber and technology professional liability, subject to the definitions in the wording
Contractual requirements of enterprise clients Technology suppliers of every size Alignment between contractual undertakings, existing controls and insurance limits Technology professional liability and cyber, subject to limits and to the definition of services

What Investors and Clients Check Before They Sign

Venture capital and private equity funds now put cyber governance questions into due diligence as a matter of routine. Ahead of a Series B the common expectation covers a written information security policy, an incident response plan that has been exercised, cyber and directors and officers cover at limits suited to the company’s stage, and evidence that basic governance exists. A SOC 2 report often appears on the same list, and a common misunderstanding enters here: it is an attestation report issued by an independent CPA firm against AICPA criteria for a defined period, and nobody holds such a certificate.

A further point often missed concerns the composition of the board. The proposed requirement to disclose cyber expertise among board members was dropped from the final version of the 2023 SEC rules, so the surviving requirement centres on the oversight process. A board that appoints a member with a technology background improves the quality of the discussion, but the evidence called for in a proceeding is the minutes, the metrics and the follow-up on closing gaps. Frameworks such as NIST and the ISO 27001 standard supply language that lets a board frame the questions without descending into engineering detail.

Common Mistakes

  • Receiving a cyber report once a year, and relying on a deck prepared specially for that meeting.
  • Approving a security budget without knowing how many people hold access to production code and how many of them are external contractors.
  • Assuming an incident response plan exists because a file exists, without asking when it was exercised and what surfaced.
  • Reviewing policy limits once at purchase, and skipping the update after revenue growth, after entering the United States market, or after starting to handle health data.
  • Treating a SOC 2 report as a certificate that removes the need for internal oversight.
  • Recording in the minutes that the subject was discussed, without recording what was decided, who owns it and by when.
  • Discovering the allocation clause between the company and the officers only after a claim has been filed.

Professional Checklist

  1. Put a standing quarterly agenda item on cyber risk and code access, and record the discussion in the minutes.
  2. Ask for a numerical list of holders of production code access, split into employees, contractors and service accounts.
  3. Require a periodic access review documenting what was removed and who approved the removal.
  4. Confirm the incident response plan was exercised within the past twelve months, and ask for the summary of gaps.
  5. Appoint a single senior officer as owner of cyber risk, and record the name in the minutes.
  6. Ask for a vendor register covering environment access, including level of access and date of last review.
  7. Check the security, indemnity and incident notification clauses in vendor contracts against the actual exposure.
  8. Compare policy limits against revenue scale, data types and the requirements written into client contracts.
  9. Review the allocation of cover between the company and the officers, and the order of payments clause.
  10. Write a reporting procedure towards the Privacy Protection Authority with timelines, and set who is authorised to approve a report.
  11. Define fixed metrics presented to the board every quarter in the same format.
  12. Record in the minutes what was decided, who owns it and the target date for every gap opened.
  13. Ask the broker for an annual review of the wordings against the company’s current risk profile.
  14. Bring these governance questions into your own due diligence before an acquisition or a partnership.
  15. Retain the documentation for at least three years, because it is called for in any proceeding that follows an incident.

Frequently Asked Questions

Does a director need to understand technology in order to oversee cyber risk?

The practical requirement concerns process more than engineering knowledge. The proposed requirement to disclose cyber expertise among board members was dropped from the final version of the 2023 SEC rules, and the focus remained on describing how oversight is exercised. A director who asks for numbers, dates and a named owner is overseeing properly without any technology background.

What does directors and officers cover address in a cyber incident?

A directors and officers policy is designed to respond to claims aimed at the officers themselves, for example a shareholder allegation of inadequate disclosure or a regulatory proceeding alleging an oversight failure, subject to the wording and the exclusions. The technical response costs, customer notification and restoration are generally examined under a cyber policy. Both policies may be engaged by the same event, so they are worth reviewing together.

What counts as a sufficient answer to who can reach production code?

A named list with an update date, a total count and a breakdown into employees, contractors and service accounts. The number allows tracking across quarters, and the breakdown exposes the contractors and automated accounts most discussions skip over. An answer along the lines of “only the relevant team” leaves the board without a basis for a decision and without evidence of oversight.

How long is there to report a security incident in Israel?

Amendment 13 to the Privacy Protection Law and the regulations made under it created a duty to report a severe security incident to the Privacy Protection Authority, and the timelines are short. Practical readiness means a written procedure setting out who identifies, who grades severity, who authorises the report and who speaks to clients. An organisation that starts building the procedure during the incident is almost always late.

Does the absence of an incident response exercise affect cover?

The underwriting questionnaire nearly always asks about it, and a negative answer affects pricing and sometimes renewal terms. Beyond underwriting, the absence of a documented exercise weakens the officers’ position against an allegation of poor oversight, because it points to a document that was never tested. A two-hour tabletop exercise once a year, with a written summary, closes that gap at low cost.

What do investors expect to see before a Series B?

A written information security policy, an incident response plan that has been exercised, cyber and directors and officers cover at limits suited to the company’s stage, and evidence that basic governance exists. A SOC 2 report sometimes appears on the same list, and the correct distinction there is that it is an attestation report by an independent CPA firm against AICPA criteria for a defined period.

How should a vendor with production environment access be managed?

A register bringing together every vendor with access, the permission level of each, and the date of the last review. Alongside it you need security, indemnity and incident notification clauses in the contract, and time-limited access instead of a standing permission. An incident originating with a vendor ends up at the company’s door before the client and the regulator, so vendor control is part of the board’s oversight.

Oversight of cyber risk is measured by what goes into the minutes, which makes a simple question about who can reach production code the most efficient governance tool available to a board.

The above is general information only and does not constitute insurance, legal or other professional advice. Terms of cover, exclusions and duties are set by the specific policy wording and by applicable law. Each case should be assessed on its own facts against the policy wording and with a qualified adviser.