In my years advising boards, I've seen the same pattern: the CISO presents a deck full of technical metrics, the board nods, and nothing changes. That is not a CISO problem. That is a governance problem. Boards that own cyber risk ask different questions - about business impact, about accountability structures, about what happens the day after a breach. My job is to help boards get from passive approval to active ownership.
What Regulators Now Expect from Boards
The SEC's 2023 cybersecurity disclosure rules require US public companies to disclose material incidents within four business days - and to describe their board's role in overseeing cyber risk. The EU AI Act creates organizational accountability for AI system failures that requires governance structures boards must own, not just delegate. NIS2, DORA, and sector-specific frameworks are following the same pattern.
The common thread: regulators are looking for named accountability, documented processes, and evidence that boards understand their exposure - not just that they were briefed on it. The organizations that will navigate this best are those where the board is an active participant in cyber governance, not a passive audience for quarterly CISO presentations.
The Five Questions Every Board Should Be Able to Answer
"What are our three most material cyber risks this quarter - and how do we know?"
Not a list of threats. A ranked, business-impact assessment with evidence.
"Who is accountable when an incident occurs - and have they exercised that accountability?"
Incident response plans exist everywhere. Boards that have rehearsed them are rare.
"What AI systems are we deploying, and which qualify as high-risk under the EU AI Act?"
Most boards cannot answer this. That is itself a governance gap.
"How long would it take us to detect a breach - and how do we know?"
According to the IBM Cost of a Data Breach Report 2024, the global average to identify a breach is 194 days. Most boards have never asked their CISO this question.
"What did we spend on cyber last year, and what did it protect?"
Budget without outcome measurement is not governance. It is hope.
What Board-Level Cyber Oversight Actually Looks Like
The boards I work with that handle cyber risk well share a few characteristics. They have at least one director with meaningful technical or security literacy - not necessarily a CISO background, but enough to ask the right questions. They receive business-impact reporting, not technical metrics. They have a clear escalation protocol. And they have tested their incident response plan in the last twelve months.
The boards that struggle have outsourced all of this to management. They receive dashboards they cannot interpret, approve budgets they cannot evaluate, and discover breaches through press coverage. The gap between those two groups is not technical sophistication. It is governance structure.
How I Work with Boards
I work directly with boards and audit committees to close the gap between what they are being told and what they need to know. That means reviewing how cyber risk is being presented, identifying the questions that are not being asked, stress-testing incident response plans, and translating technical exposure into the business and regulatory language that drives real governance decisions.