2026: The Year of ‘Now What?’
As organizations move into 2026, cybersecurity and AI risk are firmly on the board’s radar, but competing priorities, limited time, and executive fatigue make meaningful engagement harder than ever. Budgets remain tight, automation and AI dominate conversations, and security leaders are under increasing pressure to cut through the noise and drive real impact. Cyber risk has attention, just not airtime. The challenge for CISOs and risk leaders is knowing what to elevate, how to frame it, and how to ensure their message resonates with decision makers who are focused on outcomes, tradeoffs, and business impact. So how do security leaders move from awareness to action when every conversation feels compressed? In this expert led discussion, Tevora brings together Executive Consultants Carlos Phoenix and Dr. Bryan Mitchell for a practical conversation on communicating evolving cyber and AI risk to the board. Moderated by Ashli Pfeiffer, Managing Director at Tevora, the session explores how CISOs can better align expectations, build allies, and drive meaningful outcomes at the executive level.
Key Takeaways:
- How to align board and executive expectations with today’s cybersecurity and AI risk reality
- Ways to bring AI risk into board conversations in clear and appropriate terms
- Proven engagement methods that lead to more meaningful board level impact
- Tactics to strengthen CISO relationships and reduce resistance
- Shared lessons learned to help de risk the CISO role
- How to optimize board time by centering discussions on decisions, tradeoffs, and business outcomes
Whether you are preparing for your next board discussion or refining your long term communication strategy, this session offers practical insight into navigating executive conversations with confidence in 2026.
2026: The Year of ‘Now What?’
As cybersecurity risk, regulatory scrutiny, and AI adoption accelerate, 2026 is shaping up to be what many leaders call “the year of now.” Expectations for Chief Information Security Officers (CISOs) have evolved rapidly—particularly in how they engage boards of directors.
To explore this dynamic, Tevora hosted a panel discussion featuring:
- Ashli Pfeiffer, Managing Director at Tevora (Moderator)
- Carlos Phoenix, Former Product CISO at VMware and cybersecurity executive
- Bryan Mitchell, Chief Information Security Officer at Groups360
The discussion focused on one central theme: How CISOs can effectively translate cybersecurity risk—especially in the age of AI—into board-level understanding and action.
Below is a curated, interview-style synthesis of the key insights.
The Role of the CISO in the Boardroom
Q: What is the CISO’s responsibility when it comes to the board of directors?
Bryan Mitchell:
At its core, the CISO’s role is to support the board’s fiduciary responsibilities—protecting shareholder interests while ensuring compliance with legal, regulatory, and ethical standards. This requires translating cybersecurity into a form the board understands: risk management.
Success depends heavily on alignment—between the CISO, executive leadership, and the board—and is shaped by company culture, reporting structures, and trust. Ultimately, the CISO must:
- Reduce organizational risk
- Communicate the value of security investments
- Establish a shared “common operating picture” with the board
Carlos Phoenix:
Many organizations focus heavily on risk and compliance, but often overlook governance. The CISO must balance all three pillars of GRC (Governance, Risk, and Compliance).
Importantly, cybersecurity accountability cannot sit solely with the CISO. The board must actively participate. A successful CISO ensures the board shares ownership of cybersecurity strategy and outcomes—not just oversight.
Why the Relationship Can Be Challenging
Q: Why is the CISO–board relationship often difficult?
Bryan Mitchell:
Several factors contribute to friction:
- Irregular communication or lack of standing agenda time for security
- Varying levels of board oversight and engagement
- Organizational history with cybersecurity leadership
- Accessibility of board members
- Trust—or lack thereof
Strong relationships are built through consistent, thoughtful engagement over time.
Carlos Phoenix:
In practice, the relationship varies widely. However, market trends show increasing pressure on CISOs, including higher turnover—often tied to board misalignment.
A common issue is a disconnect between perception and reality. Boards may believe certain outcomes are achievable, while CISOs present operational constraints. When expectations aren’t aligned, tension emerges.
However, when the relationship works well, it becomes highly productive—and even enjoyable. Boards bring significant experience and strategic perspective, which can elevate cybersecurity programs when aligned effectively.
What Boards Actually Want
Q: What are boards looking for from cybersecurity leaders?
Bryan Mitchell:
There is no universal answer—every board is unique. However, most boards seek:
- Clear, concise information to fulfill fiduciary duties
- Confidence that risks are being managed appropriately
- Visibility into how cybersecurity impacts business performance
Financial performance also plays a role. Boards tend to take a lighter approach when companies are performing well—and a more hands-on approach during periods of stress or after incidents.
Carlos Phoenix:
While formal cybersecurity research is limited, one consistent trend stands out: boards value peer insight.
They want to know:
- What are other companies doing?
- What are industry trends?
- How does our approach compare?
CISOs can add significant value by leveraging professional networks to bring back insights from peers and industry benchmarks. This helps validate strategy and builds board confidence.
Additionally, consistent engagement is critical. If cybersecurity is not regularly communicated, it quickly becomes “out of sight, out of mind.”
Bridging the Knowledge Gap
One of the most consistent challenges identified: boards often lack a deep understanding of cybersecurity.
Bryan Mitchell:
Cybersecurity can be abstract—focused on technical concepts like systems, data, and threats. This makes it inherently difficult to grasp.
However, this gap presents an opportunity. CISOs who can effectively educate boards create stronger influence and alignment.
Carlos Phoenix:
The key is shifting from a technical to a business-focused narrative.
Effective CISOs:
- Avoid deep technical detail
- Focus on strategic implications
- Tie cybersecurity to business operations and outcomes
For example: Instead of discussing vulnerabilities, frame the conversation around business risk, operational disruption, or increased cost of doing business.
Boards are far more responsive to conversations about:
- Revenue impact
- Operational efficiency
- Strategic risk
Speaking the Board’s Language
Q: What frameworks or constructs resonate most with boards?
Bryan Mitchell:
Boards understand financial risk best. Converting cybersecurity risk into financial terms is one of the most effective strategies available.
This includes:
- Estimating potential financial loss
- Aligning risk with revenue impact or operational disruption
- Leveraging enterprise risk management frameworks
Ashli Pfeiffer:
Insurance is another powerful framework. Cyber insurance and coverage models help contextualize potential loss, even if they don’t fully capture exposure.
Carlos Phoenix:
Presentation style matters just as much as content. CISOs should leverage:
- Visuals (charts, graphs, trends) instead of text-heavy slides
- Comparative data over time (e.g., trends across quarters or years)
- Simple, emotionally resonant visuals
Boards are human. Effective communication taps into clarity and intuition—not complexity.
Building a Successful Relationship
Q: What are the conditions for success between CISOs and boards?
Bryan Mitchell:
- A clear, objective view of the current security state
- Shared understanding of risk (“common operating picture”)
- Executive and board support for risk reduction
Carlos Phoenix:
- Strong communication
- Shared responsibility across leadership
- Cultural fit between the CISO and board
Without alignment in these areas, the relationship will struggle
Developing Trust Over Time
Q: How can CISOs build lasting relationships with board members?
Bryan Mitchell:
Patience and consistency are key. Relationships are built over time and strengthened by leveraging internal stakeholders and allies.
Carlos Phoenix:
Take a tactical approach:
- Build relationships one board member at a time
- Find common ground (background, experience, interests)
- Expand influence gradually across the board
This creates a network of advocates rather than relying on a single supporter.
Addressing AI: Opportunity Meets Risk
Q: How should CISOs handle boards that are highly optimistic about AI?
Bryan Mitchell:
Leverage existing security programs—such as vendor risk, data protection, and governance—to demystify AI. At its core, AI still relies on foundational security principles.
Carlos Phoenix:
AI must be positioned realistically. While it offers significant upside, it also requires:
- Investment
- Organizational change
- New controls and risk management
Boards often seek benefits without fully understanding the associated costs. The CISO’s role is to clarify trade-offs and align expectations.
Communicating AI Risk Effectively
Q: How can AI risks be communicated without creating hype or fear?
Bryan Mitchell:
Frame AI within existing frameworks. Treat it as an extension of:
- Data protection
- Vendor risk
- Regulatory compliance
This makes it more understandable and manageable.
Carlos Phoenix:
Use existing risk management tools—like the risk register—to evaluate AI risks objectively.
Start with fundamental questions:
- Is AI being used?
- How is it being used?
- What data is involved?
Then:
- Document risks clearly
- Engage the business in accepting or mitigating those risks
- Participate early in AI initiatives to guide, not block, progress
Transparency is critical. CISOs must balance risk awareness with business enablement.
Is AI Risk a Cyber Issue or Enterprise Risk?
The consensus: both.
AI introduces:
- Cybersecurity risks (data exposure, model misuse)
- Enterprise risks (brand damage, regulatory exposure, societal impact)
Effective governance must address both dimensions simultaneously.
Quantifying Cyber Risk in Financial Terms
Q: What is the best way to convert cybersecurity risk into dollars?
Bryan Mitchell:
Collaboration with finance—particularly the CFO—is essential.
Successful approaches include:
- Linking assets to revenue impact
- Modeling risk based on probability and severity
- Incorporating insurance coverage scenarios
The key is mutual agreement on the model. When finance supports the methodology, board communication becomes far more effective.
Final Takeaways
This discussion reinforces several critical truths for modern CISOs:
- Cybersecurity is a business conversation—not a technical one.
- Board alignment depends on communication, trust, and shared ownership.
- Financial framing is the most effective translation of cyber risk.
- AI introduces both opportunity and complexity—requiring balanced governance.
- Strong relationships are built incrementally, not instantly.
As organizations navigate an increasingly complex threat landscape, the ability to connect cybersecurity strategy with board-level priorities has become a defining capability for today’s security leaders.
About Tevora
Tevora is a leading cybersecurity and compliance consulting firm, helping organizations manage risk, achieve compliance, and build resilient security programs. With deep expertise across frameworks such as SOC, PCI, FedRAMP, and more, Tevora partners with clients to deliver long-term, value-driven security solutions.




