Security directors question whether risk protocols established a decade ago are adequate for today's threat environment.