Can Your Business Demonstrate Commercially Reasonable Cybersecurity? 169 Questions to Find Out.
Regulators, courts, and clients increasingly ask whether your security program meets the standard of commercially reasonable cybersecurity. Tom Brennan's 169-question framework helps you answer that question honestly.
By Tom Brennan
The phrase "commercially reasonable cybersecurity" is appearing with increasing frequency in regulatory guidance, contract language, and litigation. The questions are organized across eight domains:
- Governance & Leadership — Does the organization have defined security ownership and board-level reporting?
- Risk Management — Is there a formal risk assessment process with tracked remediation?
- Asset Management — Does the organization know what assets it has and who is responsible for them?
- Access Control & Identity — Are privileged access rights managed, reviewed, and limited to need-to-know?
- Data Protection — Is sensitive data classified, encrypted, and subject to defined retention policies?
- Threat Detection & Response — Is there continuous monitoring and a tested incident response plan?
- Third-Party Risk — Are vendors assessed and contract provisions adequate?
- Business Continuity — Is there a tested backup and recovery capability?
Proactive Risk's MEASURERISK Framework Audit covers all 169 questions and delivers a prioritized remediation roadmap. Contact us to schedule your assessment.
Free Security Governance Resources
Accelerate your security program assessment with Proactive Risk's free resources, available in the Downloads library:
- Department Alignment Interview & Role Mapping Checklist — a structured intake tool mapping all 18 CIS v8.1 controls to the people who own them, surfacing accountability gaps and ownership overlaps
- Proactive Risk GitHub Repositories — open-source security policy templates, assessment scripts, and governance automation tools
Explore Related Resources