Boards need a clear answer to what would break first if cyber event definitions across multiple treaties stayed ambiguous through the next systemic event.