Audit committees are being asked to demonstrate technical competence
Regulators want named expertise, not a director who once ran an IT function.
Financial expertise on audit committees was codified two decades ago and changed board composition permanently. Technical and cyber competence is following the same path.
The early implementations are uneven. Some boards have recruited genuine practitioners; others have relabelled existing directors and hoped.
The distinction becomes visible under incident conditions, which is precisely when it is most expensive to discover.