Skip to Content

Discover Our Newest Resources Resource Center

Dark teal and black gradient

Webinar

Board-Level Cybersecurity: Measuring and Communicating Risk to your Board

Join cybersecurity experts Anir Desai, Justin Graham, and Ashli Pfeiffer, along with Bryan Mitchell, former CISO of AutoZone, as they address one of the most critical challenges in cybersecurity leadership: communicating risk to Boards of Directors. Despite growing awareness of major cyberattacks, many board members and executives remain largely uneducated about the true risks their organizations face, often leading to underfunded security initiatives.

In this engaging session, the panel explores effective strategies to bridge the communication gap between technical and non-technical audiences, equipping CISOs and security leaders with actionable insights to drive better outcomes.

Key Takeaways:

  • Common challenges and communication gaps between CISOs and executives
  • Proven strategies to explain cybersecurity risks to non-technical Boards of Directors
  • How to leverage internal and external experts for impactful communication
  • If you’re looking to enhance your approach to risk communication and secure critical buy-in from leadership, this discussion is a must-watch.

Board-Level Cybersecurity: Measuring and Communicating Risk to your Board

An interview-style recap of Tevora’s panel discussion on board communication, cybersecurity leadership, and risk management

Cybersecurity has become a permanent boardroom issue.

From large-scale ransomware attacks and supply chain compromises to headline-grabbing outages and data breaches, cyber risk now directly impacts organizational performance, reputation, and shareholder value. Yet despite growing awareness, many organizations still struggle with one persistent challenge:

How do security leaders effectively communicate cyber risk to boards of directors and non-technical executives?

To explore that question, Ashli Pfeiffer (Managing Director, Tevora) moderated a discussion with:

  • Justin Graham 
  • Bryan Mitchell (Chief Information Security Officer, Group360)

The conversation focused on practical strategies for improving board communication, increasing cyber risk awareness, and helping security leaders secure executive support for their programs.

Why Cybersecurity Communication Remains Challenging

The session began with a discussion of research conducted by Brian Mitchell as part of his doctoral dissertation.

His research explored a fundamental question:

What do board members actually understand about cybersecurity risk?

Rather than approaching cybersecurity strictly through a technical lens, Brian examined cyber risk as a financial risk issue—using a language that boards are more accustomed to discussing.

The study included:

  • Current and former board members
  • CEOs
  • CFOs
  • CIOs
  • CISOs
  • Risk committee participants
  • Fortune 500 executives

One of the most striking findings was that many executive leaders lack a deep understanding of cybersecurity’s potential financial impact.

While boards do not need technical expertise, they do need reliable sources of information that help them understand cybersecurity risk in business terms.

Without that foundation, meaningful conversations about risk become difficult.

Understanding the Board’s Role in Cybersecurity

Before discussing how CISOs should communicate with boards, the panel emphasized the importance of understanding what boards are actually responsible for.

According to Justin, board responsibilities generally fall into three primary areas:

Governance

Boards provide oversight of the organization’s overall direction and strategy.

This includes ensuring cybersecurity initiatives support broader business objectives.

Risk Management

Boards are responsible for understanding and managing risks that can affect:

  • Financial performance
  • Reputation
  • Operations
  • Regulatory compliance

Cybersecurity increasingly falls into this category.

Oversight and Accountability

Boards help ensure management is implementing appropriate controls and initiatives to address cybersecurity threats.

They also establish accountability for cybersecurity outcomes across leadership teams.

As regulatory expectations continue to evolve—including SEC disclosure requirements—board involvement in cybersecurity oversight has become even more important.

The Value Boards Bring to Security Programs

While many discussions focus on educating the board, Justin emphasized that boards also provide significant value to security leaders.

Resource Allocation

Boards influence:

  • Budget approvals
  • Strategic investments
  • Security staffing decisions

Strong board support often determines whether critical initiatives receive funding.

Strategic Guidance

Board members frequently bring valuable experience from:

  • Other organizations
  • Different industries
  • Executive leadership roles

That diversity of perspective can strengthen cybersecurity strategies.

Organizational Influence

When boards actively support security initiatives, cybersecurity becomes a visible organizational priority.

That support often drives broader cultural change throughout the company.

Why CISOs and Boards Often Struggle to Align

One of the most common challenges discussed was the communication gap between security leaders and boards.

Brian noted that cybersecurity conversations frequently break down because participants are approaching risk from different perspectives.

Security professionals often focus on:

  • Threats
  • Controls
  • Vulnerabilities
  • Technical risks

Boards focus on:

  • Financial outcomes
  • Organizational performance
  • Strategic objectives
  • Business risk

The result is a disconnect.

Many boards understand financial risk exceptionally well but may not readily connect cybersecurity threats to those outcomes.

The Importance of a Shared Operating Picture

One of Brian’s key recommendations was to establish what he called a:

“Common operating picture.”

A common operating picture means that:

  • Security leaders
  • Executive teams
  • Board members

share a similar understanding of:

  • The threat landscape
  • Organizational risks
  • Priorities
  • Strategic objectives

Once everyone is aligned around the same understanding of risk, communication becomes significantly easier.

Without that alignment, conversations often result in confusion rather than action.

Translating Security Into Business Language

A recurring theme throughout the discussion was the need for security leaders to communicate in business terms.

Board members generally do not need information about:

  • CVSS scores
  • Technical vulnerabilities
  • Security tool configurations

Instead, they need to understand:

  • Business impact
  • Financial exposure
  • Operational consequences
  • Risk reduction strategies

Justin emphasized the importance of translating complex technical information into language that executives can easily understand and act on.

The goal is not to oversimplify cybersecurity—it is to make it relevant.

Building Strong Relationships with the Board

Several panelists highlighted that successful board communication starts long before a quarterly presentation.

Trust matters.

Justin stressed the importance of building relationships through:

  • Regular communication
  • Open dialogue
  • Ongoing engagement

The most successful CISOs are often those who become trusted advisors rather than occasional presenters.

Communication Should Be Proactive

One lesson highlighted repeatedly was the importance of proactive communication.

Security leaders should not wait until an incident occurs before engaging leadership.

Instead, organizations should regularly discuss:

  • Emerging threats
  • Program progress
  • Security metrics
  • Strategic risks

This creates familiarity and trust, making incident discussions significantly easier when they become necessary.

What Happens When Boards Don’t Understand Cyber Risk?

The panel discussed several consequences of poor board-level cybersecurity awareness.

Insufficient Budget Allocation

Perhaps the most common outcome is underinvestment.

When risks are not fully understood, boards may underfund:

  • Security initiatives
  • Staffing
  • Technology
  • Risk mitigation efforts

Slower Incident Response

Without prior awareness and preparedness, leadership decisions during incidents often take longer.

That delay can increase:

  • Business impact
  • Recovery costs
  • Reputational damage

Underestimating Insider Threats

Boards may also fail to appreciate the risks posed by:

  • Employees
  • Contractors
  • Privileged users

This can leave organizations vulnerable to insider-driven incidents.

Practical Ways to Educate the Board

When asked what security leaders can do to improve board understanding, the panel offered several practical recommendations.

Provide Cybersecurity Education

Many board members simply need foundational cybersecurity knowledge.

Topics may include:

  • Current threat trends
  • Ransomware risks
  • Third-party risks
  • Emerging technologies

The objective is not technical training but informed decision-making.

Use Metrics That Matter

Security reporting should focus on metrics that demonstrate:

  • Risk reduction
  • Program maturity
  • Improvement trends
  • Return on investment

Boards are often more interested in outcomes than technical details.

Clear, visual reporting can help maintain engagement.

Conduct Regular Risk Assessments

Ongoing risk assessments provide valuable opportunities to discuss:

  • New threats
  • Emerging risks
  • Priority initiatives

These conversations help boards understand where the organization faces the greatest exposure.

Include the Board in Incident Response Planning

Board members should understand:

  • Their role during an incident
  • Escalation procedures
  • Communication requirements
  • Business continuity expectations

Tabletop exercises can be particularly effective for building this understanding.

Security Culture Starts at the Top

Justin emphasized that board support plays a significant role in creating a security culture.

When executives and board members visibly support cybersecurity initiatives:

  • Employees pay attention.
  • Security becomes a business priority.
  • Organizational buy-in increases.

Culture is often one of the most underestimated elements of cybersecurity success.

The Importance of In-Person Engagement

One audience question focused on communication frequency and meeting formats.

While practices vary by organization, the panel agreed on two key points:

Communication Should Be Consistent

Whether monthly or quarterly, cybersecurity discussions should occur regularly.

Consistency matters more than specific frequency.

In-Person Interactions Are Highly Valuable

Both Justin and Brian expressed strong support for face-to-face board interactions whenever possible.

In-person meetings allow security leaders to:

  • Build trust
  • Read reactions
  • Clarify misunderstandings
  • Strengthen relationships

Those benefits can be difficult to replicate in virtual environments.

Risk Management Must Drive Prioritization

When discussing how security leaders maximize effectiveness, both panelists returned to a common theme:

Prioritize based on risk.

Organizations cannot solve every security challenge simultaneously.

Security leaders must identify:

  • Highest risks
  • Most impactful controls
  • Greatest business exposures

Those priorities become the foundation of:

  • Roadmaps
  • Budget requests
  • Board discussions

As Justin noted, risk management should drive security investments rather than compliance checklists alone.

Compliance Does Not Equal Security

One lesson learned from Justin’s experience as a virtual CISO was the distinction between compliance and security.

While compliance frameworks are valuable, organizations should avoid treating compliance as the ultimate objective.

True security often requires:

  • Going beyond minimum requirements
  • Understanding organizational risk
  • Implementing controls that address real-world threats

Checking boxes does not necessarily reduce risk.

An Unexpected Research Finding: The Role of Generational Perspectives

One of Brian’s most surprising research findings involved age and experience within boards.

He observed that board composition can vary dramatically:

  • Public company boards may include highly experienced senior executives.
  • Venture capital or private equity-backed boards may skew significantly younger.

Each group may bring different:

  • Technology experience
  • Risk perspectives
  • Decision-making styles

Understanding those dynamics can help security leaders tailor communication more effectively.

Final Takeaways

The discussion reinforced a simple but powerful message:

Cybersecurity communication is not primarily a technical challenge—it is a business communication challenge.

Successful CISOs and security leaders must:

  • Build trust
  • Speak the board’s language
  • Focus on business outcomes
  • Prioritize risk effectively
  • Educate continuously

Most importantly, they must help create a shared understanding of risk across the organization.

As Brian summarized, the goal is to establish a common operating picture—one where security leaders, executives, and board members all understand the threats facing the organization and can work together to address them effectively.

When that alignment exists, cybersecurity becomes not just a defensive function, but a true business enabler.