Boards Do Care About Cybersecurity. They Just Don't Understand It.
Security chiefs and company directors want the same thing. A language gap between them is leaving organisations dangerously exposed.

Key points
- A 2024 Checkmarx report found 95% of chief information security officers (CISOs) feel pressured by management or boards to suppress security problems found inside their organisations.
- Experts say the core problem is not indifference but a communication gap: security teams speak in technical threats, while board directors speak in business risk and financial consequences.
- Chris Novak of Quadrum Advisors says silence from board members is routinely misread as agreement or disengagement, creating a gap "wide enough to drive a tractor trailer through."
- Security leaders can close that gap by leading board presentations with business consequences, not technical activity.
- Both sides are looking for more support, not less involvement.
Boards of directors are not ignoring cybersecurity. They are, in many cases, simply lost in translation.
That is the picture drawn by security leaders and governance advisers in a feature first reported by Dark Reading, and the implications matter for every company that handles customer data, processes payments, or runs any service online.
So why does it feel like boards don't care?
The feeling is real, even if the cause is misdiagnosed. A 2024 Checkmarx report found 95% of CISOs, the executives responsible for an organisation's security, felt pushed by management or boards to keep quiet about security problems. That pressure breeds distrust.
But Edna Conway, chief operating and risk officer at TPO Group and a former chief security and risk officer at Microsoft, says the tension usually comes from different priorities rather than deliberate negligence. "Strong directors care deeply," she says, "not only about cyber risks but about the business's people, its mission, and about what's going on 360 degrees outside of the organisations."
The real friction point is disclosure. Reporting a vulnerability (a weakness in a system that criminals could exploit) or a breach can alarm investors, hurt share prices, and invite regulatory scrutiny. Some boards prefer quiet. Most security chiefs want the problem on the table fast.
What does the gap actually look like in practice?
Chris Novak, partner and co-founder of Quadrum Advisors, puts it plainly: security professionals talk about threats and controls, while directors think in terms of exposure, resilience, and accountability. Neither group is speaking nonsense. They are using different vocabularies for the same underlying risk.
CISO presentations typically arrive packed with dozens of technical metrics. Board members sit through them unsure which numbers should prompt a decision. The questions they actually want answered are concrete ones: which of our services could go offline, how fast could we recover, and what would a serious attack cost us?
| What security teams present | What boards need to know |
|---|---|
| Number of detected threats | Which critical services could be disrupted |
| Patch compliance rates | Financial and reputational cost of an attack |
| Technical control status | How quickly the organisation could recover |
| Vulnerability counts | Whether risk is increasing or decreasing |
Novak says both sides routinely mistake silence for agreement. Nobody flags the gap. The gap widens.
What should organisations actually do?
Fix the meeting format, not the people in the room.
Novak recommends that security teams open every board presentation with business consequences first. Start with which services face the greatest risk of disruption. Follow with financial and reputational impact. End with recovery speed. Technical detail belongs in the appendix.
Boards, for their part, should receive regular briefings on the threat environment in plain terms, access to independent outside opinions, and chances to practise decision-making through realistic incident simulations. Think of it as a fire drill, but for a ransomware attack (ransomware being malicious software that locks a company's files until a payment is made).
Conway frames it simply: "We seem to have forgotten that technology is here to support and enable us, the humans, not the other way around."
For customers and employees, the practical upshot is this: organisations where security teams and boards communicate clearly respond to breaches faster, contain damage more effectively, and recover sooner. Ask your bank, your insurer, or your employer whether its board receives regular security briefings. The answer tells you something.



