CODY KELLER



There’s a version of board cybersecurity oversight that looks great on paper and doesn’t work at all in practice. The CISO presents to the board once a quarter. The slides have charts, metrics, and a risk heat map. The board nods, asks a few questions, and moves on to the next agenda item. Everyone checks the governance box.

The problem is that this model measures the wrong thing. And in 2026, with regulators explicitly evaluating board oversight quality — not just whether it happened — organizations running this version of cybersecurity governance are accumulating legal and fiduciary exposure they may not fully appreciate.

Here’s what the data actually shows, and what effective board cyber oversight looks like in practice.

The Reporting Gap Nobody Is Talking About

New benchmark research from IANS and Artico Search in 2026 found that while 95% of CISOs deliver regular updates to their boards — signaling a mature reporting cadence — only 30% of boards describe their relationship with the CISO as strong and collaborative.

Read that twice. Nearly every CISO is reporting to the board. Less than a third of boards describe that relationship as genuinely collaborative. The cadence is there. The substance isn’t.

When board directors rated the quality of their cybersecurity reporting across six key areas, a clear pattern emerged: reporting on current-state risk and program operations is working. Reporting on future risk is not. Only 29% of directors describe the updates they receive as very effective overall.

This is a structural problem, not a personnel one. Most cybersecurity reporting is optimized for demonstrating what the security team is doing — patches applied, alerts reviewed, incidents closed — rather than giving directors what they need to make governance decisions. Those are fundamentally different reports, and most organizations are only building one of them.

What Boards Are Actually Being Asked to Do

The legal landscape has moved faster than most board education programs have kept up with.

In 2026, cybersecurity has become a fundamental pillar of corporate strategy and fiduciary responsibility. Board members owe a Duty of Care and a Duty of Loyalty to the corporation, and regulators are now looking past the technical “how” of a breach to the organizational “why.” If a breach occurs, the first question from the SEC or the FTC is: what was the board doing to prevent this?

Regulators have shifted from policy-based expectations to outcome-based accountability. Boards are now directly responsible for cyber incidents, weak oversight, and failed recovery. Activity metrics are no longer enough.

That’s not a hypothetical future. It’s the current operating environment for any publicly traded company subject to SEC cybersecurity disclosure rules, and increasingly for private companies in regulated industries. The board’s governance record — what was discussed, what questions were asked, what decisions were made — is now a legal document. Boards that only ever record “the report was noted” have created a paper trail showing oversight didn’t happen. Most cybersecurity governance failures are reporting failures.

The Five Things Boards Consistently Get Wrong

1. Treating cybersecurity as an IT briefing rather than a risk governance conversation. When the CISO presents in the same format as an IT infrastructure update, the board receives it with the same level of engagement. Cybersecurity needs its own governance framing — risk appetite, exposure levels, cost-to-mitigate decisions, and progress against agreed tolerances. Reporting should be in business terms: exposure level, cost to mitigate, progress made. Not raw technical data. If your board can’t answer “what is our risk appetite for a ransomware event and is our program operating within it?” — the reporting model needs to change.

2. Annual or infrequent CISO engagement. Boards cannot oversee cyber risk effectively if they only interact with the CISO during annual presentations or after a crisis. Sustained, structured engagement helps directors treat cybersecurity as an enterprise-wide strategic concern, not a technical sidebar. Quarterly briefings are the baseline — but the structure matters as much as the frequency. Directors need to ask questions and push back, not just receive a presentation.

3. Confusing compliance with security. Passing an audit isn’t the same as managing risk. A company can be fully compliant with applicable frameworks and still carry significant unmitigated risk. Compliance tells you whether you met minimum documented standards as of a point in time. It doesn’t tell you whether your program is effective against the threats currently targeting your industry.

4. Siloed ownership of cyber, AI, and operational resilience. Governance breaks down when ownership scatters across functions with no single accountable party. The organizations most exposed right now are the ones where the cybersecurity committee owns one thing, the AI committee owns another, and nobody owns the intersection. As AI becomes embedded in operations, the risk surfaces of both domains merge — governance needs to reflect that.

5. No documented risk appetite statement. Name one accountable executive. Write a one-page risk appetite statement and have the board approve it in a minuted meeting. Put security on the agenda quarterly as a decision item, not an update. Keep a risk register the board actually sees, with owners and dates. That’s the difference between demonstrable governance and an organization whose only defense, after an incident, is that the security team was doing its best.

What Good Actually Looks Like

Effective board cyber oversight requires quarterly substantive engagement with the CISO, reporting framed around business risk rather than technical metrics, a documented and board-approved risk appetite, and a tested escalation protocol for material incidents.

Boards benefit from direct, recurring interaction with the CISO rather than filtered reporting through the CEO. Best practice includes periodic deep-dive sessions and a clear escalation protocol so the board receives timely notification of significant incidents without depending on management’s discretion to trigger it.

None of this requires the board to become technically sophisticated. It requires them to ask better questions, engage more consistently, and hold management accountable for reporting that actually informs decisions. That’s the governance role — and in 2026, it’s no longer optional.


Discussion Questions

  1. Does your board currently have a documented, board-approved cyber risk appetite statement? When was it last reviewed against the current threat environment?
  2. How is your CISO reporting structured — as a technical briefing or as a risk governance conversation framed in business terms? What would it take to shift that framing?
  3. Does your board’s governance record reflect substantive engagement with cyber risk — documented questions, decisions, and follow-up items — or would it read to a regulator as passive receipt of information?

Further Reading

  • NACD 2026 Director’s Handbook on Cyber-Risk Oversight: https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-handbooks/2026-cyber-risk-oversight/
  • IANS 2026 Benchmark Report: How Boards Are Partnering with CISOs: https://www.iansresearch.com/resources/press-releases/detail/new-report-reveals-key-gaps-in-board-ciso-strategic-dialogue-on-cyber-risks
  • SEC Cybersecurity Disclosure Rules: https://www.sec.gov/rules/final/2023/33-11216.pdf

Cody Keller is an Information Security Manager specializing in Governance, Risk, and Compliance with over ten years of experience in cybersecurity strategy, risk management, and regulatory compliance. He holds the CISSP, CISM, and CRISC certifications and is the author of The Parent’s Guide to Online Safety. Through CKCybersecurity.com, he writes and consults on practical security program management for organizations navigating an increasingly complex threat and regulatory landscape. Connect on LinkedIn at linkedin.com/in/codyjkeller or reach out at ckcyberconsulting@gmail.com.



Leave a Reply

Your email address will not be published. Required fields are marked *