Security Gaps Persist: Why Boards and CISOs Struggle to Get on the Same Page
A growing number of high-profile cyberattacks has forced executive boards to prioritize security, but despite this shift, communication gaps between boards and chief information security officers (CISOs) persist. These disparities are not due to a lack of concern for cybersecurity from board members, but rather a complex web of misunderstandings and miscommunications that can have devastating consequences.
At the heart of these issues lies a language barrier between the business and technical worlds. CISOs, responsible for tracking and responding to threats in real-time, often feel pressured by management and boards to suppress security issues found within their organizations. This can lead to a culture of silence, where vulnerabilities and attacks are kept hidden from board members who may view them as potential risks to business growth.
Edna Conway, chief operating and risk officer at TPO group and former chief security and risk officer at Microsoft, argues that this perception is misguided. “Strong directors care deeply not only about cyber risks but also about the business’s people, its mission, and what’s going on outside of the organization,” she says. This emphasis on transparency and communication is essential for making informed decisions about investment and growth.
Conway’s experience working with private equity firms who invest in cutting-edge technology companies has shown her that boards are not apathetic to security threats. In fact, they often recognize the importance of cybersecurity as a critical component of their business strategy. “Together, we live and die by transparency,” she says. “It’s how you make decisions on investment and wrap your arms around leadership to ensure growth for everyone.”
Despite this growing awareness, many directors still view security as a problem for the IT department to solve. Chris Novak, partner and co-founder of Quadrum Advisors, notes that there is a strong desire among board members to see cybersecurity as an enterprise risk and resilience issue. This involves understanding how security threats can impact operations, customers, revenue, regulatory obligations, reputation, and long-term strategy.
As companies face increasing security challenges, the lines between board members and CISOs are blurring. Novak emphasizes that directors do not expect to become cybersecurity practitioners, but rather they should understand whether management has identified the organization’s most consequential risks and made deliberate decisions about those risks.
Ultimately, bridging this gap requires a fundamental shift in communication and understanding between boards and CISOs. By acknowledging the complexities of cybersecurity and recognizing its impact on business operations, board members can work more effectively with their security teams to mitigate risks and ensure long-term growth.
Practical takeaway: Effective communication is key to bridging the divide between boards and CISOs. Boards should take an active interest in understanding cybersecurity risks and engage in open dialogue with their security teams to make informed decisions about investment and growth. By doing so, they can work together to mitigate threats and ensure the long-term success of their organization.
Source: Dark Reading — 2026-07-24