Aug 10 / Latest News

CISOs Struggle to Give Boards Clear Cyber Risk Insight as Governance Gaps Persist

Boards increasingly want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. But translating technical findings into business language remains a major time burden for CISOs, who say they need simpler data delivery, better frameworks, and clearer context.

Pulse Security AI’s new report, The CISO-Board Communication Gap, found that board members frequently bring external information into discussions while many organizations still lack a formally defined cyber risk appetite. Over the past year, 42% of security leaders had to defend a third‑party security score during board conversations.

Only 12.5% of CISOs are very confident that their board accurately understands the true state of the security program after a presentation. Most respondents said they were only somewhat confident or neutral. Material security incidents tended to increase board trust, while tabletop exercises strengthened leadership credibility more effectively than presentations alone.

Seventy‑one percent of respondents spend 10 or more hours preparing each board or audit committee presentation, with most presenting quarterly. Multiple people contribute to the supporting material, and fragmented preparation makes it harder to present a coherent view of business risk, resilience, and control effectiveness. CISOs say automated threat and vulnerability analysis, automated data aggregation, and better tools for translating findings into business impact would significantly reduce the workload.

“You cannot assemble a clear picture of the business when the underlying information lives in a dozen disconnected places,” said Mike Armistead, CEO of Pulse Security AI. “Security leaders have earned the room. What they need now is the operating layer underneath it.”

Governance gaps continue to limit board oversight. Many CISOs do not have access to private sessions with the board or audit committee, reducing opportunities for candid discussions about cyber risk. Half of boards did not explicitly accept, mitigate, or transfer cyber risk last year. Some leaders said concerns about personal legal exposure influence how they communicate with directors.

Many organizations still describe cyber risk using qualitative categories instead of financial impact, and many lack predefined board‑level escalation thresholds for cyber incidents. Board discussions remain split between reviewing past events and planning for future risks, leaving decision‑makers without a consistent baseline for evaluating the organization’s true security posture.