How Can CISOs Improve Board Governance Around Cyber Risk Management?

The pressure is on for corporate leadership to get a better handle on cybersecurity. But unlike other board governance processes that are a lot more mature (e.g., financial risks, market pressures), when it comes to cyber risks, boards need help — help that the chief information security officer (CISO) is uniquely positioned to deliver.
Boards want better insights into how cybersecurity management decisions are made and often complain of getting briefed with techno-babble and operational security metrics instead. How can CISOs better bridge the communications divide and improve the board’s ability to provide adequate oversight of cyber risks?
A recent report titled “Leveraging Board Governance for Cybersecurity,” issued by the Advanced Cyber Security Center (ACSC), a nonprofit effort to enhance cyberdefense and informed policymaking, helps shed light on the disconnect. Boards have a strategic role to play regarding cybersecurity, but are hampered by their limited understanding of cyber issues, the quality and frequency of the reporting they receive from management, and inadequate board governance structures that often hold back key information from the full board.
While some organizations have improved their board governance processes on cybersecurity issues, much of the work to drive progress falls on the shoulders of the CISO. The good news is that, unlike a decade ago, there is now a lot more information available to guide CISOs on key cybersecurity issues to take up with boards and, where appropriate, resources designed specifically for board directors — such as the National Association of Corporate Directors (NACD)’s “Director’s Handbook on Cyber-Risk Oversight.”
A key finding from the ACSC report is that only 21 percent of boards said they had what can be described as a “full partnership” level of engagement regarding cybersecurity and digital transformation. What does a full partnership look like? It includes getting regular updates, engagement around cyber risk priorities, and actual discussions with feedback and consideration of cyber risks in both strategic and operational decision-making. Even when boards viewed security as an important issue, it was often given more of a cursory review; 53 percent of respondents reported that very few — 5 percent or less — full-board meetings focus on cybersecurity.
For CISOs, this provides an opportunity to ask just how well the board is able to provide strategic guidance for management’s risk decisions. Consider:
Both the ACSC report and the NACD handbook advocate for these improvements to board governance processes, and CISOs should leverage these resources fully.
The report echoed a common complaint among CISOs: “Most boards do not yet have sufficient expertise in technology or cybersecurity to serve as strategic thought partners on cyber risk.” Furthermore, 38 percent of respondents said their board viewed cyber risks as just “somewhat significant,” a dangerous indifference that, as recent breaches and ransomware attacks have shown, can bring an organization to its knees in the blink of an eye.


