Cybersecurity Advisory for Boards:
What Directors Must Own, Not Just Approve

Under NIS2 and SEC disclosure rules, board directors are personally accountable for cyber risk governance. Most boards don't know where their exposure starts. The work is helping them find out - and act.

Executive Answer

Boards are now personally accountable for cyber risk. Under NIS2, management bodies face personal liability for governance failures. Under SEC rules, material incidents must be disclosed within 4 business days. Most board directors don't know which of their organization's systems would trigger these obligations - or what a material incident looks like for their specific business. The CISO's job is to change that. The board's job is to ask the right questions.

Asaf's Perspective

I've sat across from board members after a major incident. The ones who struggled weren't unintelligent - they were unprepared. Nobody had ever walked them through what their organization's real exposure looked like, or what a breach would cost in regulatory terms, not just operational ones. The gap between a board that governs cyber risk well and one that doesn't isn't technical knowledge. It's structured access to the right information, asked in the right way. That's the work I do with boards: not briefing them on threat trends, but building the governance muscle they need to ask better questions and make better decisions.

What Boards Get Wrong About Cyber Risk

Three failures appear in nearly every board engagement I've seen:

1
Treating cyber as an IT problem

When a ransomware attack shuts down operations or a breach triggers a regulatory investigation, the board discovers it was accountable all along. Delegating cyber to IT without oversight is not a governance strategy - it is a governance gap with personal liability attached.

2
Receiving briefings, not making decisions

Most board cyber briefings are passive. The CISO presents slides. Directors nod. Nothing is decided. A board that is not making decisions about cyber risk - budget prioritization, risk acceptance, disclosure thresholds - is not governing it. It is just being informed about it.

3
Not knowing what "material" means for their business

SEC and NIS2 obligations hinge on materiality. Most boards have no agreed definition of what constitutes a material cybersecurity incident for their specific business - which means they cannot assess whether a disclosure obligation has been triggered until it is too late to act well.

What Board Oversight Actually Looks Like

Effective board cyber governance is built on four foundations:

Risk Briefing Framework

A structured four-quadrant briefing model: current exposure, recent incidents and near-misses, compliance status, and decisions required. 20 minutes. Business language. Actionable output.

Incident Response Governance

A clear board-level protocol for major incidents: who is notified, what the board authorizes, how disclosure obligations are assessed, and where the board steps back and lets management operate.

Regulatory Accountability

Board-level understanding of NIS2 management accountability obligations (and potential personal liability under national implementation laws), SEC 4-day disclosure requirements, and sector-specific regulations - mapped to the organization's actual footprint.

Strategic Questions

A standing set of questions that every director can ask: about unmitigated risk, IR testing, vendor security, and materiality thresholds. Questions that generate accountability, not passive updates.

The Regulatory Shift

The rules have changed. Two frameworks now place cyber governance accountability directly on board directors - not just on the CISO or CTO.

NIS2 (EU) - Personal Liability for Management Bodies

NIS2 explicitly holds management bodies - including board members - personally liable for cybersecurity governance failures at essential and important entities. Directors can face sanctions, temporary bans from management roles, and personal fines. The regulation came into force across EU member states in October 2024.

SEC Cybersecurity Disclosure Rules (US) - 4-Day Clock

Effective December 2023, US public companies must disclose material cybersecurity incidents within 4 business days of determining materiality. They must also disclose annually how the board oversees cybersecurity risk. Boards that cannot demonstrate active oversight are exposed to SEC enforcement and investor scrutiny.

These are not compliance checkbox exercises. They represent a structural shift in who is accountable when a breach occurs.

Frequently Asked Questions

What cyber risk responsibilities do board directors have?

Directors have a fiduciary duty to understand and oversee material cyber risk. Under SEC Cybersecurity Disclosure Rules (effective 2023), public companies must disclose material cybersecurity incidents within 4 days and describe the board's oversight of cybersecurity risk annually. Under NIS2 (EU), management bodies are personally liable for cybersecurity governance failures. Boards that delegate cyber risk entirely to IT - without understanding, questioning, or overseeing it - are exposed to regulatory sanction and personal liability.

How should a board be briefed on cybersecurity?

Board cyber briefings should follow a four-quadrant model: current risk posture (what we're exposed to), recent incidents and near-misses (what happened), compliance status (what we're obligated to), and strategic decisions required (what the board needs to decide or approve). Technical detail should be minimal. Business impact, regulatory exposure, and resource implications should be central. A good CISO-to-board briefing takes 20 minutes and generates decisions, not questions.

What questions should board directors ask about cybersecurity?

Five essential questions: (1) What is our most significant unmitigated cyber risk right now? (2) Have we tested our incident response plan in the last 12 months? (3) What is our regulatory exposure under GDPR, NIS2, or sector-specific rules? (4) Are our critical vendors and suppliers meeting our security requirements? (5) If we were breached tomorrow, who would make decisions, and what would we tell customers, regulators, and the public?

What is the board's role during a cyber incident?

During a cyber incident, the board's role is governance, not operations. Directors should ensure: the incident response plan is activated and the right people are in the room; legal, PR, and regulatory notification obligations are understood; material disclosure obligations (SEC, NIS2) are assessed; and that the CEO has the resources and authority needed. Boards that micro-manage the technical response slow it down. Boards that disappear create a governance vacuum. The right role is informed oversight and decision authorization.

How much cybersecurity knowledge does a board director need?

Directors don't need to be technical. They need to understand: what a material incident looks like for their specific business, what the organization's regulatory obligations are, what the key risks are and whether management has a credible plan to address them, and how to ask the right questions. A director who can ask "what is our most exploitable risk and what would it cost us?" is doing their job. A director who can't evaluate whether the CISO's answer is credible is a governance gap.

Is Your Board Ready for the Accountability Shift?

If your board is receiving cyber briefings but not making decisions - or if NIS2 and SEC disclosure obligations are unclear - let's talk about what governance-ready actually looks like.

Start a Conversation