Boards & non-executive directors

For boards & non-executive directors

An IT governance matrix built for boards

IT and cyber risk oversight is now a standing board responsibility. Most boards have still never seen an independent view of what their organisation’s IT provider actually covers.

The Lumenas IT check gives your board that view: an independent responsibility matrix built for board reporting, not for IT.

Lumenas IT check, for boards and non-executive directors

20221
a Federal Court first found a licensee breached its duties by failing to manage cyber risk

$50M2
maximum Privacy Act penalty per serious contravention, or 30% of annual turnover

$5.8M3
first civil penalty under the Privacy Act, for systemic cybersecurity governance failures

Make informed decisions about cyber and IT risk with three things



Results by domain — all eight IT and cyber risk domains assessed

Visibility

We comprehensively assess IT and cyber risk across eight domains.

Responsibility detail — owner and status for each item

Accountability

Within each domain, every responsibility has a clear owner — or we highlight the gap.

End-to-end IT check results — alignment score and responsibility breakdown

Evidence

A dated, independent record ready for auditors, insurers, and your next board meeting.

Cyber is now a standing board item

In ASIC v RI Advice Group Pty Ltd [2022] FCA 496,1 the Federal Court found a licensee breached its obligations by failing to have adequate systems to manage cybersecurity risk. It’s widely read as confirming that cyber and IT risk oversight sits squarely within existing director duties, not as a separate, optional layer of governance.

The difficulty is that most boards receive that reassurance from the same people who’d be responsible if something went wrong: the internal team or MSP delivering the service. The Lumenas IT check gives your board an independently produced view instead, without commissioning a $50K, multi-month cyber audit.

Lumenas Traditional audit
Cost $5K $50K+
Time to delivery 2 weeks 6–8 weeks
Written for Your board Your IT team
Independent of MSP Yes Yes

FAQs

Whose job is it to commission this?+
Usually the CEO, COO, or whoever manages the MSP relationship. The board’s role is to ask for it and review the output, not to run it — it takes 30 minutes of one executive’s time, not the board’s.
Our organisation already commissioned a cyber audit. Do we still need this?+
A cyber audit tells you where the technical vulnerabilities are at a point in time. The IT check does something different: it documents who owns what, where management and the MSP agree, and where responsibilities have been assumed rather than agreed. The two are complementary, and most organisations find the check the more useful of the two for board reporting.
How often should the board see this?+
We suggest making that call after you’ve completed the check the first time. If it comes back clean, you probably don’t need to run it again for a while, or until something significant changes. But if the result leads to a change to your IT provider agreement or how you operate internally, it’s worth repeating the check sooner to make sure everything’s on track — for instance in 12 months.
What does the board actually need to review?+
Just the one-page executive summary and the alignment score. The full responsibility matrix and detailed findings sit behind it, for anyone who wants to go deeper.
Who sees the results — just the board, or the IT provider too?+
Whoever you choose. Most organisations share the summary with both the board and the IT provider, since it’s designed to prompt a conversation between them, not just a report to file away.

Ask your executive team if they’ve run the Lumenas check yet.