Security News

Cybersecurity news aggregator

INFO News Dark Reading

CISOs vs. Boards: Myth or Misunderstanding?

  • What: Discussion on communication gaps between CISOs and boards
  • Impact: Organizations with security leadership challenges
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. CISOs vs. Boards: Myth or Misunderstanding? Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide. Arielle Waldman,Features Writer,Dark Reading July 24, 2026 5 Min Read SOURCE: DEEPBLUE4YOU VIA GETTY IMAGES The rumors are exaggerated. Executive boards aren't apathetic to security threats; they're often struggling with a cybersecurity language barrier. Increasingly disruptive cyberattacks require preventative and remediation efforts from positions across organizations, yet chief information security officers (CISOs) and IT teams feel unsupported by the powers that be. This adds pressure on the CISOs, as they fend off attacks and manage potentially devastating fallout. But attacks affect business operations, an organization's reputation, and can result in legal implications which require everyone to get on the same page. More companies are recognizing this, as the threat landscape intensifies and leadership is working to break down the stereotype that boards don't care about security. There is a misplaced perception that board directors sometimes deprioritize cybersecurity over speed and growth, says Edna Conway, chief operating and risk officer at TPO group and former chief security and risk officer at Microsoft. Related:Agentic AI: Taming the Unpredictable "In reality, strong directors care deeply; not only about cyber risks but about the business's people, its mission, and about what's going on 360 degrees outside of the organizations," Conway tells Dark Reading. Is Transparency Ever TMI? Transparency is one highly contentious point that has fueled claims that leadership doesn't prioritize security. A recent Checkmarx report found 95% of CISOs feel pressured by management and boards to suppress security issues found in their organizations. CISOs track and respond to threats in real time. The board's job is to focus on profits and growth. Disclosing a vulnerability or an attack, even an attempted one, can compromise business growth and that's often where the roles clash. CISOs want to get ahead of the unfortunate security news; boards may want to bury it. However, Conway observed the opposite while serving on boards of security and cutting-edge technology companies, and working with private equity firms who invest in their growth. "Together, we live and die by transparency," she says. "It's how you make decisions on investment and once you've made it, how you wrap your arms around the leadership to make sure they all grow – not just for your benefit, but for everyone's. There's no win if you have stasis." More companies have adopted this mindset because cybersecurity cannot be ignored. It's seeped its way into nearly every aspect of business and daily life. Threat actors target operations, individual employees, customer data, and supply chains. Related:Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? Many directors do still view security as a problem for the IT department to solve, says Chris Novak, partner and co-founder of Quadrum Advisors. However, there is a strong desire to see board members increasingly view cybersecurity as an enterprise risk and resilience issue, because it affects operations, customers, revenue, regulatory obligations, reputation, and long-term strategy, he adds. While board members and security teams maintain their distinct responsibilities, the lines between them are blurring as companies face more security challenges. "Directors generally do not expect to become cybersecurity practitioners, nor should they," he adds. "Their responsibility is to understand whether management has identified the organization’s most consequential risks, made deliberate decisions about those risks and demonstrated that the company can respond and recover when preventive controls fail." The Board, The Myth, The Legend Whether it’s a myth that board members do not care about or prioritize security is complicated, and that has changed over the years, as cybersecurity comes more into focus. Most board members would likely state openly that security is a priority, and Novak believes they mean what they are saying. Related:'Yellow Teams' Are Defining the Future of AI Security "The challenge most of them come to me with is not a lack of concern for security, rather they are looking for greater support," he says. The myth can stem from a lack of understanding, especially in the age of artificial intelligence. It is increasingly difficult to identify how to best to probe the organization's security posture, Novak explains. Communication between security teams and boards is a big hurdle for both sides because they essentially speak different languages. Cybersecurity professionals often speak in terms of threats and controls, while directors govern in terms of exposure, resilience, tradeoffs, and accountability, says Novak. CISO presentations contain dozens of metrics to highlight security standings, but leaders feel they aren't being told which key facts matter or what decision management needs from it, he adds. They may be looking for which business services could be interrupted, which risks are increasing, or what financial and reputational consequences threats pose. "Time and time again, the feedback I hear from both cohorts is that everyone assumed silence means agreement, or everyone assumed silence meant a lack of engagement," he adds. "That disconnect is wide enough to drive a tractor trailer through — which exposes everyone involved to unnecessary risk and litigation." How To Debug the Disconnect Filling communication gaps is essential as companies strive to unite board members and security teams. And they already have a lot in common: Both sides crave more support. For boards, that can look like periodic education on the threat environment, access to independent perspectives when they need to challenge or validate management’s assumptions, and opportunities to participate in realistic simulations that test how the organization would make decisions during a significant cyber incident, says Novak. Security teams can close the gap by beginning their board communications with business consequences, rather than technical activity, he recommends. Include a breakdown of which critical services could be disrupted, what the financial and reputational impact might be, and how quickly the organization could recover. "Boards and security leaders should agree on a small number of consistent, decision-useful measures," he says. "Stable reporting on critical exposures, recovery readiness, third-party risk, incident preparedness and changes in the organization’s risk profile is far more useful than a constantly changing collection of technical metrics." The goal is not to turn directors into cybersecurity experts or security leaders into corporate directors, he reiterates. Instead, each side needs to have enough understanding of the other's responsibilities to collaborate effectively. This shift in perspective is crucial for effective CISO-board communication, says Conway. "We seem to have forgotten that technology is here to support and enable us, the humans, not the other way around,” she says. “When we get to the point where we're working to support the technology, we've gone too far.” About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like CYBERSECURITY OPERATIONS Hand CVE Over to the Private Sector by Brian Martin JAN 27, 2026 CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi AUG 28, 2025 CYBERSECURITY OPERATIONS Critical Zero-Days Crack Open CyberArk Password Vaults by Nate Nelson AUG 06, 2025 Edge Picks APPLICATION SECURITY AI Agents in Browsers Light on Cybersecurity, Bypass Controls CYBER RISK Browser Extensions Pose Heightened, but

Share this article