Board oversight of build-versus-buy decisions should require a total-cost view before approval, not a post-mortem after the budget has already run over.
Cyber claims data too inconsistent for pricing creates a real, quantifiable balance-sheet exposure that boards should ask to see measured directly.
Incident response capacity as a severity driver deserves its own board-level scenario test, not just a mention in the annual cyber risk report.
Board oversight of legacy core systems that can't support new treaty structures should focus on what business is being turned away, not just whether the system is still running.
Board oversight of technology investments should extend past the purchase decision to whether adoption actually stuck, since a stalled rollout after the demo is where much of the promised value quietly disappears.