Boards approve significant spend on detection and response tools — the EDR and XDR platforms that are supposed to catch attackers inside the environment — and most boards have no way to judge whether that spend is buying real protection or expensive false comfort. The vendor acronyms (EDR, XDR, MDR) and the technical detail make it easy for a board to defer entirely to the security team, which is a mistake, because whether the firm can actually detect and respond to an attack is a governance question the board is accountable for. The board does not need to understand the technology; it needs to know which questions to ask to tell genuine detection capability from a dashboard that looks reassuring.
Why detection is the capability that matters
Prevention fails. Determined attackers get in, so the question is not only “can we keep them out?” but “if they are in, will we know, and how fast can we respond?” Endpoint detection and response, and its broader cousin extended detection and response, exist to answer that — to spot the attacker’s activity inside the environment and enable a response before the damage is done. But buying the tool is not the same as having the capability. A platform can be deployed, generating alerts no one investigates, tuned so poorly it is ignored, or covering only part of the estate — and the firm has the expensive tool and not the protection. The board’s job is to probe whether the capability is real.
The questions a board should ask
- What can we actually detect, and what would we miss? Every detection capability has gaps; a security team that claims to catch everything is not being straight. Understanding the coverage and the blind spots is more useful than a green dashboard.
- How fast could we detect and respond to a real attack? The measure that matters is time — how long between an attacker acting and the firm knowing and containing it. Has this been tested against a realistic scenario?
- Who watches this, and when? Detection is worthless without response; is someone actually monitoring and able to act around the clock, in-house or through a managed service, or do alerts pile up unattended?
- Does coverage match the estate? Detection that covers the corporate laptops but not the cloud workloads or the critical servers leaves the important ground unwatched; the board should know the coverage matches where the risk is.
Governing the capability, not just the spend
- Ask for the honest gaps, not the reassurance. A CISO who can articulate what the firm cannot detect is giving you a truer picture than one who claims total coverage.
- Insist on tested response times. A capability that has never been exercised against a realistic attack is unproven; testing turns a claim into evidence.
- Confirm someone is actually watching. The tool is the smaller part; the monitoring and response capability behind it is what determines whether detection happens.
- Match coverage to risk. Ensure the detection covers the parts of the estate where a compromise would actually hurt.
EDR and XDR are important capabilities, and the spend on them is usually justified — but only if the capability behind the tool is real, tested and watched. A board discharges its cyber-oversight duty here not by understanding the technology but by asking the questions that reveal whether the firm can genuinely detect and respond to an attack, or has merely bought a platform that produces alerts into the void. The difference is the whole point, and it is exactly the kind of thing a board is well placed to probe.
Free · 4 minutes
Do you actually know what you are running — and what it is about to cost you?
Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.
Who this is for
This reading is for:
- Board members who approve security spend but cannot assess it
- CISOs who need the board to understand detection, not just fund it
- Audit committees accountable for cyber oversight
- Firms choosing or reviewing an EDR/XDR platform
Sixteen Pillars gives boards the questions that reveal whether the firm can genuinely detect and respond to an attack, rather than having merely bought a platform. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming