Cybersecurity Teams and Boards Still Struggle to Find Common Ground in Face of Escalating Threats
The relationship between cybersecurity teams, led by Chief Information Security Officers (CISOs), and executive boards has long been plagued by miscommunication and conflicting priorities. While some may portray board members as apathetic towards security threats, the reality is more complex. In an effort to prioritize business growth and profits, boards often find themselves at odds with CISOs who want to disclose vulnerabilities and attacks in real-time.
This tension has its roots in the differing roles and responsibilities of the two groups. Boards are focused on driving business success and growth, while CISOs are tasked with protecting against increasingly sophisticated cyber threats. However, as the threat landscape continues to intensify, companies are beginning to recognize that cybersecurity cannot be ignored. Threat actors target operations, employees, customer data, and supply chains, making it essential for all stakeholders to work together.
A recent study by Checkmarx found that 95% of CISOs feel pressured by management and boards to suppress security issues within their organizations. This pressure can stem from a desire to avoid disclosing vulnerabilities or attacks, which can compromise business growth and reputation. However, some board members are pushing back against this narrative, arguing that transparency is essential for making informed decisions about investment and risk management.
Edna Conway, chief operating and risk officer at TPO group and former chief security and risk officer at Microsoft, notes that “strong directors care deeply not only about cyber risks but also about the business’s people, its mission, and what’s going on outside of the organization.” She attributes this shift in mindset to a growing recognition that cybersecurity is no longer a niche concern, but a core aspect of business operations.
While some board members still view security as a problem for the IT department to solve, there is a growing desire to see directors take a more enterprise-wide approach. As Chris Novak, partner and co-founder of Quadrum Advisors, notes, “directors generally do not expect to become cybersecurity practitioners… Their responsibility is to understand whether management has identified the organization’s most consequential risks, made deliberate decisions about those risks, and demonstrated that the company can respond and recover when preventive controls fail.”
As companies face more security challenges, it’s essential for both boards and CISOs to find common ground. By working together, they can ensure that cybersecurity is no longer seen as a barrier to growth, but rather an integral part of business strategy.
For those looking to improve their organization’s security posture, the takeaway is clear: transparency is key. While there may be legitimate concerns about disclosing vulnerabilities or attacks, the benefits of open communication far outweigh the risks. By working together and prioritizing cybersecurity, boards and CISOs can ensure that their organizations are better equipped to face the ever-evolving threat landscape.
Source: Dark Reading — 2026-07-24