Cyber Risk for Boards:
Own It, Don't Just Approve It

Regulators are no longer accepting "we were briefed" as a defense. SEC rules, the EU AI Act, and emerging liability frameworks are creating personal accountability for directors. The question boards need to ask is not "are we secure?" - it is "do we understand our exposure, and can we prove it?"

Asaf's Perspective

In my years advising boards, I've seen the same pattern: the CISO presents a deck full of technical metrics, the board nods, and nothing changes. That is not a CISO problem. That is a governance problem. Boards that own cyber risk ask different questions - about business impact, about accountability structures, about what happens the day after a breach. My job is to help boards get from passive approval to active ownership.

What Regulators Now Expect from Boards

The SEC's 2023 cybersecurity disclosure rules require US public companies to disclose material incidents within four business days - and to describe their board's role in overseeing cyber risk. The EU AI Act creates organizational accountability for AI system failures that requires governance structures boards must own, not just delegate. NIS2, DORA, and sector-specific frameworks are following the same pattern.

The common thread: regulators are looking for named accountability, documented processes, and evidence that boards understand their exposure - not just that they were briefed on it. The organizations that will navigate this best are those where the board is an active participant in cyber governance, not a passive audience for quarterly CISO presentations.

The Five Questions Every Board Should Be Able to Answer

"What are our three most material cyber risks this quarter - and how do we know?"

Not a list of threats. A ranked, business-impact assessment with evidence.

"Who is accountable when an incident occurs - and have they exercised that accountability?"

Incident response plans exist everywhere. Boards that have rehearsed them are rare.

"What AI systems are we deploying, and which qualify as high-risk under the EU AI Act?"

Most boards cannot answer this. That is itself a governance gap.

"How long would it take us to detect a breach - and how do we know?"

According to the IBM Cost of a Data Breach Report 2024, the global average to identify a breach is 194 days. Most boards have never asked their CISO this question.

"What did we spend on cyber last year, and what did it protect?"

Budget without outcome measurement is not governance. It is hope.

What Board-Level Cyber Oversight Actually Looks Like

The boards I work with that handle cyber risk well share a few characteristics. They have at least one director with meaningful technical or security literacy - not necessarily a CISO background, but enough to ask the right questions. They receive business-impact reporting, not technical metrics. They have a clear escalation protocol. And they have tested their incident response plan in the last twelve months.

The boards that struggle have outsourced all of this to management. They receive dashboards they cannot interpret, approve budgets they cannot evaluate, and discover breaches through press coverage. The gap between those two groups is not technical sophistication. It is governance structure.

How I Work with Boards

I work directly with boards and audit committees to close the gap between what they are being told and what they need to know. That means reviewing how cyber risk is being presented, identifying the questions that are not being asked, stress-testing incident response plans, and translating technical exposure into the business and regulatory language that drives real governance decisions.

Frequently Asked Questions

What cyber risk responsibilities do boards have?

Under regulations like NIS2, DORA, and SEC cybersecurity rules, boards are expected to have demonstrated cybersecurity literacy, oversee the organization's cyber risk management program, and ensure material incidents are reported appropriately. Board members can face personal liability for cybersecurity failures.

How should a board report on cybersecurity?

Effective board cybersecurity reporting focuses on business risk metrics - not technical vulnerability counts. Boards need to see: which critical assets are exposed, what the financial impact of a breach would be, how the organization compares to regulatory requirements, and what investments are reducing risk most effectively.

What should non-technical board members know about cyber risk?

Board members do not need to understand technical vulnerabilities. They need to understand: cyber risk as a business risk with financial and reputational impact, their oversight responsibilities under applicable regulations, what questions to ask management, and how to evaluate whether the CISO's report reflects reality.

How often should the board discuss cybersecurity?

Best practice is quarterly cybersecurity updates to the board, with immediate briefings after significant incidents or regulatory changes. Organizations subject to NIS2, DORA, or SEC rules should also ensure cybersecurity is integrated into regular risk committee agendas.

Sources & Further Reading

Last reviewed: July 2026

Does Your Board Own Your Cyber Risk?

If you're preparing for a board briefing, reviewing your governance structure, or responding to regulatory pressure around cyber accountability - let's talk.

Start a Conversation