{"id":20369,"date":"2026-09-16T12:37:09","date_gmt":"2026-09-16T09:37:09","guid":{"rendered":"https:\/\/lamdabroking.com\/?p=20369"},"modified":"2026-09-16T13:03:01","modified_gmt":"2026-09-16T10:03:01","slug":"repository-governance-board-risk","status":"publish","type":"post","link":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/","title":{"rendered":"Who Can Reach Our Production Code? Five Governance Questions for the Board"},"content":{"rendered":"<p dir=\"ltr\"><span style=\"font-weight: 400;\">The answers go into the minutes, and the minutes are the document that will be examined if an allegation is ever brought against the officers. Data from 2026 indicates an average cost of around 5 million dollars for a data breach, which puts this discussion firmly in the range that calls for a board-level decision.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Key Takeaways<\/span><\/h2>\n<ul dir=\"ltr\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access to production code is a governance question because it determines who can change the product the company sells. A board that receives a numerical answer, meaning how many people hold access and when the last review took place, is genuinely exercising oversight. A board that receives an answer along the lines of &#8220;only the relevant team&#8221; is relying on an assertion and recording it in the minutes as though it were evidence.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The 2023 SEC disclosure rules require public companies to describe the board&#8217;s oversight of cyber risk and to report a material cyber incident. The proposed requirement to disclose cyber expertise among board members was dropped from the final rule, so the surviving requirement concerns the oversight process rather than the composition of the board.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In Israel, an officer&#8217;s duty of care under the Companies Law extends to oversight of information risk. Amendment 13 to the Privacy Protection Law widened the enforcement powers of the Privacy Protection Authority and added a reporting duty, and the Privacy Protection Regulations (Data Security) set operational requirements the board is expected to confirm are in place.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directors and officers insurance is designed to respond to shareholder claims and regulatory proceedings, subject to the wording, the limits and the exclusions. A record of discussion, decision and follow-up strengthens an officer&#8217;s position against an allegation of breach of the duty of care. A documented absence of oversight works the other way, and produces exactly the evidence a claimant is looking for.<\/span><\/li>\n<\/ul>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Why Code Access Became a Board Question<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Production code is the asset that generates the revenue, and whoever can change it can change the product the customer bought. When a departed developer, a subcontractor or an old service account still holds access that has never been reviewed, the company is carrying a risk nobody decided to accept, and consciously accepting risk is precisely the kind of decision a board is expected to take and record.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Regulation is moving the same way. NIS2 in Europe established personal accountability for senior management on information security in the sectors within scope. The 2023 SEC disclosure rules require public companies to describe the board&#8217;s oversight of cyber risk, and to report a cyber incident of a scale that triggers disclosure, within a fixed timetable. In Israel, Amendment 13 and the widened powers of the Privacy Protection Authority create a similar effect on private companies holding databases. For a private company selling to enterprise clients and institutional investors the expectation is substantively identical, even without a direct statutory duty. The question left open in every one of these cases is what evidence the board is able to produce.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Oversight is measured by what goes into the minutes rather than by what was said in the room.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">The Five Questions and the Answer That Is Enough<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The questions below are short, and they generate a governance discussion inside ten minutes. The difference between a real discussion and a box-ticking exercise lies in the quality of the answer: an answer that points to a document, a date and a named owner allows follow-up next quarter.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Who Holds Access to Production Code<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The answer that suffices is a named list with an update date, a total count, and a breakdown into employees, contractors and service accounts. A number lets the board track the figure across quarters and ask why it grew, and the breakdown exposes the automated accounts and the contractors that most discussions skip over.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">When the Last Access Review Was Carried Out<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Permissions are created under pressure, on a release night or during an incident, and stay open long after the need has passed. A periodic review that records what was removed and who approved it is the evidence that the process is alive. An answer that suffices includes a date, a scope, the name of the person responsible, and the number of permissions revoked.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Whether the Incident Response Plan Has Been Exercised<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">An incident response document that was written and never exercised is an assumption. A tabletop exercise held within the past year is evidence. The board should ask when the exercise took place, who took part, which gaps emerged and what has been fixed since. In a real event, the reporting timetable towards the Privacy Protection Authority and under the SEC rules is too short to start learning the procedure then.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Whether the Insurance Programme Matches the Risk Profile<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The question here concerns the fit between the limits and the actual exposure. A programme built from cyber, technology professional liability and directors and officers cover needs limits that reflect revenue scale, data types and the requirements written into client contracts. Data from 2026 indicates an average cost of around 5 million dollars for a data breach, and according to 2026 data the cost of a data breach in the United States is more than double the global average. A company with United States operations carrying a limit set three years ago is sitting on a gap. That gap can be measured in a single meeting.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">How Vendors With Environment Access Are Managed<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">An external vendor with access to a production environment extends the company&#8217;s attack surface, and the board should know how many such vendors exist and who approved each of them. An answer that suffices includes a vendor register with the level of access, the date of the last review and the security clauses in the contract. An incident originating with a vendor ends up at the company&#8217;s door, in front of the client and in front of the regulator.<\/span><\/p>\n<p dir=\"ltr\"><b>The five board questions and the answer that is enough:<\/b><\/p>\n<table dir=\"ltr\">\n<tbody>\n<tr>\n<td><b>Board question<\/b><\/td>\n<td><b>Why it is a governance question rather than an IT question<\/b><\/td>\n<td><b>What constitutes a sufficient answer<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Who holds access to production code?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Access determines who can change the asset that generates revenue, which is a decision to accept risk<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A named list with an update date, a total count and a breakdown of employees, contractors and service accounts<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">When was the last access review carried out?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">The review cadence shows whether a continuing oversight process exists or a one-off exercise happened once<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Date, scope, named owner and the number of permissions revoked in the review<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Has the incident response plan been exercised?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">The ability to meet reporting deadlines is a duty of the company and of its officers alike<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A documented exercise within the past twelve months, participant list, gaps found and remediation dates<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Does the insurance programme match the risk profile?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Limits and terms of cover are a capital allocation decision that requires board approval<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A mapping of <a href=\"https:\/\/lamdabroking.com\/en\/cyber-insurance\/\">cyber<\/a>, <a href=\"https:\/\/lamdabroking.com\/en\/tech-eo-hi-tech-professional-liability-insurance\/\">technology professional liability<\/a> and <a href=\"https:\/\/lamdabroking.com\/en\/directors-and-officers-insurance\/\">directors and officers cover<\/a> against revenue, data types and contractual requirements<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">How are vendors with environment access managed?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">The company carries responsibility towards the client and the regulator even when the failure occurred at the vendor<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A vendor register with access level, date of last review and security and indemnity clauses in the contract<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Who is the executive owner of <a href=\"https:\/\/lamdabroking.com\/en\/cyber-risks\/\">cyber risk<\/a>?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Oversight requires a single address reporting to the board, and where responsibility is dispersed there is nobody to hold to account<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A senior officer named in the minutes, with fixed quarterly reporting and consistent metrics<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">What happens when a CEO asks to bypass a control?<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Departing from an approved procedure is a governance matter requiring documented approval rather than an operational call<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A written exception procedure, approval in writing, a record in the minutes and a date for review<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">The Personal Exposure of an Officer<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The Companies Law imposes a duty of care and a duty of loyalty on an officer, and oversight of information risk falls under the duty of care where the risk could damage the company&#8217;s operations. The typical allegation in such a proceeding is that the officer knew or ought to have known, and failed to act. A record of discussion, decision, follow-up and remediation is the practical defence against that allegation.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">In Europe, NIS2 established personal accountability for senior management, including the possibility of personal fines and restrictions on holding management roles in the sectors within scope. In the United States, inaccurate or late disclosure of a material cyber incident may lead to enforcement proceedings against officers and to shareholder class actions alongside the claim against the company, and in Israel the Privacy Protection Authority has been exercising widened powers since Amendment 13, so a company that failed to meet the reporting duty stands in a weak position before the regulator and before its own clients.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Directors and officers insurance is designed to respond to claims of this kind, subject to the wording, the limits and the exclusions in the policy. Two conditions recur in almost every discussion: acting in good faith, and having a reasonable informational basis for the decision. Missing documentation of cyber risk oversight undermines both conditions at once. The board minutes therefore form part of the defence file before any claim is filed. The broker (LAMDA Broking) reviews the allocation of cover between the company and the officers, and the order of payments clause, to confirm that personal cover holds up even when the company is under cash flow pressure.<\/span><\/p>\n<p dir=\"ltr\"><b>Sources of duty, what is expected of the board, and the line that may respond:<\/b><\/p>\n<table dir=\"ltr\">\n<tbody>\n<tr>\n<td><b>Source of duty<\/b><\/td>\n<td><b>Who it applies to<\/b><\/td>\n<td><b>What is expected of the board<\/b><\/td>\n<td><b>Insurance line that may respond<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Companies Law<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Officers of an Israeli company<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Documented oversight of risk that could damage operations, including information risk<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Directors and officers, subject to the wording and to good faith conditions<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Privacy Protection Regulations (Data Security)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Every database owner in Israel<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Confirming that database mapping, permission management, logging and periodic review are in place<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Cyber for the privacy element, and directors and officers for an oversight failure allegation<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Amendment 13 to the Privacy Protection Law<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Companies holding databases<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A reporting procedure towards the Privacy Protection Authority with timelines and a named owner<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Cyber for response and mitigation costs, subject to the wording<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">2023 SEC disclosure rules<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Public companies in the United States<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Describing the board&#8217;s oversight of cyber risk and reporting a material incident<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Directors and officers, including defence costs in enforcement proceedings subject to the wording<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">NIS2<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Entities within scope in the European Union<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Personal accountability of senior management for security controls and vendor management<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Directors and officers, subject to fines exclusions and to applicable law<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">DORA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Financial entities and their technology service providers<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Technology risk governance, resilience testing and third-party provider management<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Cyber and technology professional liability, subject to the definitions in the wording<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Contractual requirements of enterprise clients<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Technology suppliers of every size<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Alignment between contractual undertakings, existing controls and insurance limits<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Technology professional liability and cyber, subject to limits and to the definition of services<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">What Investors and Clients Check Before They Sign<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Venture capital and private equity funds now put cyber governance questions into due diligence as a matter of routine. Ahead of a Series B the common expectation covers a written information security policy, an incident response plan that has been exercised, cyber and directors and officers cover at limits suited to the company&#8217;s stage, and evidence that basic governance exists. A SOC 2 report often appears on the same list, and a common misunderstanding enters here: it is an attestation report issued by an independent CPA firm against AICPA criteria for a defined period, and nobody holds such a certificate.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A further point often missed concerns the composition of the board. The proposed requirement to disclose cyber expertise among board members was dropped from the final version of the 2023 SEC rules, so the surviving requirement centres on the oversight process. A board that appoints a member with a technology background improves the quality of the discussion, but the evidence called for in a proceeding is the minutes, the metrics and the follow-up on closing gaps. Frameworks such as NIST and the ISO 27001 standard supply language that lets a board frame the questions without descending into engineering detail.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Common Mistakes<\/span><\/h2>\n<ul dir=\"ltr\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Receiving a cyber report once a year, and relying on a deck prepared specially for that meeting.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Approving a security budget without knowing how many people hold access to production code and how many of them are external contractors.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assuming an incident response plan exists because a file exists, without asking when it was exercised and what surfaced.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing policy limits once at purchase, and skipping the update after revenue growth, after entering the United States market, or after starting to handle health data.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Treating a SOC 2 report as a certificate that removes the need for internal oversight.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recording in the minutes that the subject was discussed, without recording what was decided, who owns it and by when.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discovering the allocation clause between the company and the officers only after a claim has been filed.<\/span><\/li>\n<\/ul>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Professional Checklist<\/span><\/h2>\n<ol dir=\"ltr\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Put a standing quarterly agenda item on cyber risk and code access, and record the discussion in the minutes.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ask for a numerical list of holders of production code access, split into employees, contractors and service accounts.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Require a periodic access review documenting what was removed and who approved the removal.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm the incident response plan was exercised within the past twelve months, and ask for the summary of gaps.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Appoint a single senior officer as owner of cyber risk, and record the name in the minutes.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ask for a vendor register covering environment access, including level of access and date of last review.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check the security, indemnity and incident notification clauses in vendor contracts against the actual exposure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compare policy limits against revenue scale, data types and the requirements written into client contracts.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review the allocation of cover between the company and the officers, and the order of payments clause.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Write a reporting procedure towards the Privacy Protection Authority with timelines, and set who is authorised to approve a report.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define fixed metrics presented to the board every quarter in the same format.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Record in the minutes what was decided, who owns it and the target date for every gap opened.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ask the broker for an annual review of the wordings against the company&#8217;s current risk profile.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bring these governance questions into your own due diligence before an acquisition or a partnership.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retain the documentation for at least three years, because it is called for in any proceeding that follows an incident.<\/span><\/li>\n<\/ol>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Frequently Asked Questions<\/span><\/h2>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Does a director need to understand technology in order to oversee cyber risk?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The practical requirement concerns process more than engineering knowledge. The proposed requirement to disclose cyber expertise among board members was dropped from the final version of the 2023 SEC rules, and the focus remained on describing how oversight is exercised. A director who asks for numbers, dates and a named owner is overseeing properly without any technology background.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">What does directors and officers cover address in a cyber incident?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A directors and officers policy is designed to respond to claims aimed at the officers themselves, for example a shareholder allegation of inadequate disclosure or a regulatory proceeding alleging an oversight failure, subject to the wording and the exclusions. The technical response costs, customer notification and restoration are generally examined under a cyber policy. Both policies may be engaged by the same event, so they are worth reviewing together.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">What counts as a sufficient answer to who can reach production code?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A named list with an update date, a total count and a breakdown into employees, contractors and service accounts. The number allows tracking across quarters, and the breakdown exposes the contractors and automated accounts most discussions skip over. An answer along the lines of &#8220;only the relevant team&#8221; leaves the board without a basis for a decision and without evidence of oversight.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">How long is there to report a security incident in Israel?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Amendment 13 to the Privacy Protection Law and the regulations made under it created a duty to report a severe security incident to the Privacy Protection Authority, and the timelines are short. Practical readiness means a written procedure setting out who identifies, who grades severity, who authorises the report and who speaks to clients. An organisation that starts building the procedure during the incident is almost always late.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Does the absence of an incident response exercise affect cover?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The underwriting questionnaire nearly always asks about it, and a negative answer affects pricing and sometimes renewal terms. Beyond underwriting, the absence of a documented exercise weakens the officers&#8217; position against an allegation of poor oversight, because it points to a document that was never tested. A two-hour tabletop exercise once a year, with a written summary, closes that gap at low cost.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">What do investors expect to see before a Series B?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A written information security policy, an incident response plan that has been exercised, cyber and directors and officers cover at limits suited to the company&#8217;s stage, and evidence that basic governance exists. A SOC 2 report sometimes appears on the same list, and the correct distinction there is that it is an attestation report by an independent CPA firm against AICPA criteria for a defined period.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">How should a vendor with production environment access be managed?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A register bringing together every vendor with access, the permission level of each, and the date of the last review. Alongside it you need security, indemnity and incident notification clauses in the contract, and time-limited access instead of a standing permission. An incident originating with a vendor ends up at the company&#8217;s door before the client and the regulator, so vendor control is part of the board&#8217;s oversight.<\/span><\/p>\n<p dir=\"ltr\"><b>Oversight of <a href=\"https:\/\/lamdabroking.com\/en\/cyber-risks\/\">cyber risk<\/a> is measured by what goes into the minutes, which makes a simple question about who can reach production code the most efficient governance tool available to a board.<\/b><\/p>\n<p dir=\"ltr\"><i><span style=\"font-weight: 400;\">The above is general information only and does not constitute insurance, legal or other professional advice. Terms of cover, exclusions and duties are set by the specific policy wording and by applicable law. Each case should be assessed on its own facts against the policy wording and with a qualified adviser.<\/span><\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A board that approves a security budget without knowing who can reach production code today is overseeing a number instead of a risk. Five short questions are enough to lift the discussion from IT level to governance level: who holds access to production code, when the last access review was carried out, whether the incident response plan has been exercised, whether the insurance programme matches the actual risk profile, and how third-party vendors with access to environments are managed. <\/p>\n","protected":false},"author":9,"featured_media":20299,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[38],"tags":[],"class_list":["post-20369","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Who Can Reach Our Production Code? Five Governance...<\/title>\n<meta name=\"description\" content=\"Who can reach production code, when access was last reviewed, whether the incident plan was exercised. A governance guide for boards and...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Who Can Reach Our Production Code? Five Governance...\" \/>\n<meta property=\"og:description\" content=\"Who can reach production code, when access was last reviewed, whether the incident plan was exercised. A governance guide for boards and...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Lamda - High Tech Insurance\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/lamda.ins\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-16T09:37:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-16T10:03:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1916\" \/>\n\t<meta property=\"og:image:height\" content=\"821\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Oded Oded\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Oded Oded\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/\"},\"author\":{\"name\":\"Oded Oded\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/person\\\/a5b8f4894f9fd6a7a2f3742ba5688174\"},\"headline\":\"Who Can Reach Our Production Code? Five Governance Questions for the Board\",\"datePublished\":\"2026-09-16T09:37:09+00:00\",\"dateModified\":\"2026-09-16T10:03:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/\"},\"wordCount\":3049,\"publisher\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design.jpg\",\"articleSection\":[\"Articles\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/\",\"name\":\"Who Can Reach Our Production Code? Five Governance...\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design.jpg\",\"datePublished\":\"2026-09-16T09:37:09+00:00\",\"dateModified\":\"2026-09-16T10:03:01+00:00\",\"description\":\"Who can reach production code, when access was last reviewed, whether the incident plan was exercised. A governance guide for boards and...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design.jpg\",\"contentUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design.jpg\",\"width\":1916,\"height\":821,\"caption\":\"5 \u05e9\u05d0\u05dc\u05d5\u05ea \u05de\u05de\u05e9\u05dc \u05e9\u05db\u05dc \u05d3\u05d9\u05e8\u05e7\u05d8\u05d5\u05e8\u05d9\u05d5\u05df \u05e6\u05e8\u05d9\u05da \u05dc\u05e9\u05d0\u05d5\u05dc\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/repository-governance-board-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber insurance\",\"item\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Who Can Reach Our Production Code? Five Governance Questions for the Board\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/\",\"name\":\"Lamda - High Tech Insurance\",\"description\":\"Risk and Finance Management\",\"publisher\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#organization\",\"name\":\"Lamda - High Tech Insurance\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/lamdaLogo-2.svg\",\"contentUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/lamdaLogo-2.svg\",\"width\":237,\"height\":102,\"caption\":\"Lamda - High Tech Insurance\"},\"image\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/lamda.ins\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/lamda-risk-and-capital-management\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/person\\\/a5b8f4894f9fd6a7a2f3742ba5688174\",\"name\":\"Oded Oded\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g\",\"caption\":\"Oded Oded\"},\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/author\\\/oded\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Who Can Reach Our Production Code? Five Governance...","description":"Who can reach production code, when access was last reviewed, whether the incident plan was exercised. A governance guide for boards and...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/","og_locale":"en_US","og_type":"article","og_title":"Who Can Reach Our Production Code? Five Governance...","og_description":"Who can reach production code, when access was last reviewed, whether the incident plan was exercised. A governance guide for boards and...","og_url":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/","og_site_name":"Lamda - High Tech Insurance","article_publisher":"https:\/\/www.facebook.com\/lamda.ins","article_published_time":"2026-09-16T09:37:09+00:00","article_modified_time":"2026-09-16T10:03:01+00:00","og_image":[{"width":1916,"height":821,"url":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design.jpg","type":"image\/jpeg"}],"author":"Oded Oded","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Oded Oded","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#article","isPartOf":{"@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/"},"author":{"name":"Oded Oded","@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/person\/a5b8f4894f9fd6a7a2f3742ba5688174"},"headline":"Who Can Reach Our Production Code? Five Governance Questions for the Board","datePublished":"2026-09-16T09:37:09+00:00","dateModified":"2026-09-16T10:03:01+00:00","mainEntityOfPage":{"@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/"},"wordCount":3049,"publisher":{"@id":"https:\/\/lamdabroking.com\/en\/#organization"},"image":{"@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design.jpg","articleSection":["Articles"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/","url":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/","name":"Who Can Reach Our Production Code? Five Governance...","isPartOf":{"@id":"https:\/\/lamdabroking.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#primaryimage"},"image":{"@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design.jpg","datePublished":"2026-09-16T09:37:09+00:00","dateModified":"2026-09-16T10:03:01+00:00","description":"Who can reach production code, when access was last reviewed, whether the incident plan was exercised. A governance guide for boards and...","breadcrumb":{"@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#primaryimage","url":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design.jpg","contentUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design.jpg","width":1916,"height":821,"caption":"5 \u05e9\u05d0\u05dc\u05d5\u05ea \u05de\u05de\u05e9\u05dc \u05e9\u05db\u05dc \u05d3\u05d9\u05e8\u05e7\u05d8\u05d5\u05e8\u05d9\u05d5\u05df \u05e6\u05e8\u05d9\u05da \u05dc\u05e9\u05d0\u05d5\u05dc"},{"@type":"BreadcrumbList","@id":"https:\/\/lamdabroking.com\/en\/repository-governance-board-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lamdabroking.com\/en\/"},{"@type":"ListItem","position":2,"name":"Cyber insurance","item":"https:\/\/lamdabroking.com\/en\/cyber-insurance\/"},{"@type":"ListItem","position":3,"name":"Who Can Reach Our Production Code? Five Governance Questions for the Board"}]},{"@type":"WebSite","@id":"https:\/\/lamdabroking.com\/en\/#website","url":"https:\/\/lamdabroking.com\/en\/","name":"Lamda - High Tech Insurance","description":"Risk and Finance Management","publisher":{"@id":"https:\/\/lamdabroking.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lamdabroking.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lamdabroking.com\/en\/#organization","name":"Lamda - High Tech Insurance","url":"https:\/\/lamdabroking.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2022\/12\/lamdaLogo-2.svg","contentUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2022\/12\/lamdaLogo-2.svg","width":237,"height":102,"caption":"Lamda - High Tech Insurance"},"image":{"@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/lamda.ins","https:\/\/www.linkedin.com\/company\/lamda-risk-and-capital-management\/"]},{"@type":"Person","@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/person\/a5b8f4894f9fd6a7a2f3742ba5688174","name":"Oded Oded","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g","caption":"Oded Oded"},"url":"https:\/\/lamdabroking.com\/en\/author\/oded\/"}]}},"_links":{"self":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts\/20369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/comments?post=20369"}],"version-history":[{"count":4,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts\/20369\/revisions"}],"predecessor-version":[{"id":20373,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts\/20369\/revisions\/20373"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/media\/20299"}],"wp:attachment":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/media?parent=20369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/categories?post=20369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/tags?post=20369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}