top of page

CISOs Are Briefing Boards Regularly, but Cyber Risk Is Still Getting Lost in Translation

  • 2 hours ago
  • 2 min read

Corporate boards are hearing from cybersecurity leaders on a predictable schedule, yet many may still lack a clear picture of the threats facing their businesses.


New research from Pulse Security AI found that only 12.5 percent of chief information security officers are “very confident” their board understands the true state of the cybersecurity program after a presentation. The findings point to a deeper governance problem that cannot be solved by polishing slides or removing technical jargon.


The study draws on a survey of 42 security leaders and corporate directors, more than 20 in-depth interviews, and two workshops involving roughly 22 CISOs. Pulse Security cautions that the sample is not nationally representative, but says the same themes appeared across each research method.


Boards Have Not Defined Their Cyber Risk Appetite


The most significant gap begins before a CISO enters the boardroom. According to the report, 55 percent of boards have not formally defined how much cyber risk their organization is willing to accept.


Without an agreed risk appetite, security teams have no stable benchmark for explaining whether the company is adequately protected. Board discussions can instead become shaped by external security ratings, recent headlines or isolated technical metrics.

About 70 percent of respondents said board members bring external information into cybersecurity discussions. Another 42 percent had been required to defend a third-party security score during the previous year.


Attempts to express cyber risk financially also appear limited. Only 16 percent of respondents said they successfully use a quantitative risk model such as FAIR, while just 3 percent regularly present risk using dollar figures.


Cybersecurity Board Reporting Creates an Operational Burden


Preparing for board meetings is also consuming significant security resources. Seventy-one percent of respondents spend at least 10 hours preparing for each board or audit committee cycle, and 39 percent involve four or more contributors.


Much of that work involves collecting information from disconnected security tools, building visualizations and translating technical findings into business terms. Sixty percent of respondents said they have no dedicated board-preparation or cybersecurity chief-of-staff role.


That manual process can make board reporting less consistent while diverting security personnel from operational work.


The study recommends defining cyber risk appetite before measuring against it, framing updates around revenue, resilience and regulatory obligations, and automating the aggregation of security data. It also calls for predefined incident-escalation thresholds and recurring private sessions between CISOs and directors.


One counterintuitive finding offers a clue about what works: 53 percent of respondents who experienced a material cybersecurity incident said board trust increased afterward. Real incidents create a shared understanding of risk that quarterly presentations often fail to produce.


The challenge for CISOs is to create that clarity before a breach forces the conversation.

bottom of page