Your CFO is going to be asked about cyber risk at the next board meeting.
Regulators now expect financial services leaders to articulate cyber risk the same way they articulate credit risk — with quantified controls, tested playbooks, and audit trails. "We have antivirus" is not an answer anyone will accept twice.

