An IT governance matrix built for boards
IT and cyber risk oversight is now a standing board responsibility. Most boards have still never seen an independent view of what their organisation’s IT provider actually covers.
The Lumenas IT check gives your board that view: an independent responsibility matrix built for board reporting, not for IT.
Make informed decisions about cyber and IT risk with three things
We comprehensively assess IT and cyber risk across eight domains.
Within each domain, every responsibility has a clear owner — or we highlight the gap.
A dated, independent record ready for auditors, insurers, and your next board meeting.
Cyber is now a standing board item
In ASIC v RI Advice Group Pty Ltd [2022] FCA 496,1 the Federal Court found a licensee breached its obligations by failing to have adequate systems to manage cybersecurity risk. It’s widely read as confirming that cyber and IT risk oversight sits squarely within existing director duties, not as a separate, optional layer of governance.
The difficulty is that most boards receive that reassurance from the same people who’d be responsible if something went wrong: the internal team or MSP delivering the service. The Lumenas IT check gives your board an independently produced view instead, without commissioning a $50K, multi-month cyber audit.
| Lumenas | Traditional audit | |
|---|---|---|
| Cost | $5K | $50K+ |
| Time to delivery | 2 weeks | 6–8 weeks |
| Written for | Your board | Your IT team |
| Independent of MSP | Yes | Yes |
FAQs
Whose job is it to commission this?+–
Our organisation already commissioned a cyber audit. Do we still need this?+–
How often should the board see this?+–
What does the board actually need to review?+–
Who sees the results — just the board, or the IT provider too?+–