Compliance & Governance

Can Your Business Demonstrate Commercially Reasonable Cybersecurity? 169 Questions to Find Out.

Regulators, courts, and clients increasingly ask whether your security program meets the standard of commercially reasonable cybersecurity. Tom Brennan's 169-question framework helps you answer that question honestly.

By Tom Brennan

Featured image for Can Your Business Demonstrate Commercially Reasonable Cybersecurity? 169 Questions to Find Out.

The phrase "commercially reasonable cybersecurity" is appearing with increasing frequency in regulatory guidance, contract language, and litigation. The questions are organized across eight domains:

  1. Governance & Leadership — Does the organization have defined security ownership and board-level reporting?
  2. Risk Management — Is there a formal risk assessment process with tracked remediation?
  3. Asset Management — Does the organization know what assets it has and who is responsible for them?
  4. Access Control & Identity — Are privileged access rights managed, reviewed, and limited to need-to-know?
  5. Data Protection — Is sensitive data classified, encrypted, and subject to defined retention policies?
  6. Threat Detection & Response — Is there continuous monitoring and a tested incident response plan?
  7. Third-Party Risk — Are vendors assessed and contract provisions adequate?
  8. Business Continuity — Is there a tested backup and recovery capability?

Proactive Risk's MEASURERISK Framework Audit covers all 169 questions and delivers a prioritized remediation roadmap. Contact us to schedule your assessment.

Free Security Governance Resources

Accelerate your security program assessment with Proactive Risk's free resources, available in the Downloads library:

Explore Related Resources

Back to the Proactive Risk blog · Talk with Proactive Risk