Skip to content
← Insights

How to Talk to a Board About Cyber Risk (Without Losing the Room)

March 24, 2026 · 5 min read

AI Summary
Generating summary…

I have sat on both sides of this conversation. As an advisor briefing boards on cyber risk, and as someone who helped boards ask better questions of the CISOs briefing them. Here is what I learned from both angles.

The CISO board briefing is one of the most consistently mishandled conversations in corporate governance. It is not for lack of effort. CISOs spend enormous time preparing for these sessions. The problem is that the preparation is almost always optimized for the wrong thing.

Most board briefings on cyber risk are optimized to demonstrate technical competence. They answer the question: "Does our CISO understand the threat landscape?" What they rarely answer is the question the board actually needs answered: "Are we making the right decisions about cyber risk as an organization, and what decisions do we need to make today?"

Those are different questions. Bridging them requires a different kind of conversation.

What Boards Actually Need From a Cyber Briefing

Board directors are not cyber experts, and they should not need to be. Their job is to govern, which means they need to understand risk at a level that allows them to make informed resource allocation decisions and ask intelligent questions of management. They do not need to understand how a SIEM works.

What boards need from a cyber briefing is:

The Translation Problem

The most common failure mode I see is what I call the translation problem: the CISO presents technically accurate information that is not usable by non-technical directors.

"Our mean time to detect is 4.3 hours" is technically meaningful. Without context, it is not governable. Is 4.3 hours good? Relative to what benchmark? What does it mean for business risk? What would it cost to reduce it to 2 hours, and is that worth doing?

The metric is not the problem. The absence of context and consequence is. Every technical metric in a board briefing should be accompanied by: what does this mean for us, is this acceptable, and if not, what does fixing it require?

The same principle applies to maturity scores, vulnerability counts, penetration test findings, and every other technical output that finds its way into board materials. Numbers without narrative are not governance. They are performance.

How to Handle the "Are We Safe?" Question

At some point in almost every board briefing, someone asks a version of the question: "Are we safe?"

The honest answer — "no organization is fully safe, but here is our current risk posture relative to our risk appetite and here are the areas where we are most exposed" — is the right one. It is also the one that most CISOs are afraid to give because it sounds like an admission of inadequacy.

It is not. Boards that understand security understand that the goal is not to achieve perfect security but to make intelligent trade-offs in the face of persistent, evolving risk. A CISO who communicates with that clarity demonstrates sophisticated judgment. A CISO who implies the organization is safe — or who hedges so extensively that no clear picture emerges — undermines the trust the board relationship requires.

A Format That Works

After years of helping organizations improve their security governance, here is the briefing structure I recommend:

  • A clear articulation of the organization's current risk posture relative to its risk appetite.
  • An honest assessment of the most significant gaps, with the business consequences of those gaps described in business terms.
  • The decisions or resources required to address those gaps, with options and trade-offs.
  • Any decisions that require board-level authorization or awareness.
  • Opening: One slide, current risk posture in plain language. Are we better or worse than last quarter, and why?
  • Top three risks: Not a comprehensive catalog, but the three things that keep the security leadership team up at night, described in terms of business impact.
  • Decisions required: Explicit list of anything the board needs to decide, approve, or be aware of.
  • Progress update: Brief update on previously discussed initiatives — are they on track, and if not, why?
  • Appendix: Everything else for directors who want the detail.

The board's job is to govern. The CISO's job is to make that governable. The conversation works when both sides understand the distinction.

Next Step

Ready to strengthen your organization's resilience?

A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.