Board members are asking better questions about cyber risk than they were five years ago. The answers they are receiving have not kept pace. That gap is not primarily a knowledge problem. It is a structural one, and it produces consequences that extend well beyond uncomfortable boardroom conversations.
The mismatch between what boards need to understand and what security functions are equipped to communicate reflects a deeper failure to treat cyber risk as a business risk. Until that treatment changes, boards will continue to approve security investments without understanding what they are buying, and security functions will continue to operate without the organisational authority their responsibilities require.
What boards are actually asking
Board-level questions about cyber risk have become more substantive. Directors ask whether the organisation’s risk exposure is within tolerance. They ask what a material incident would cost, operationally and reputationally. They ask whether the controls in place are proportionate to the risks the organisation actually carries. They ask, following every significant industry incident, whether the organisation is vulnerable to the same failure.
These are reasonable questions. They are also questions that most security functions are not structured to answer in the terms boards use. Security reporting tends to be operational: metrics on incidents detected, vulnerabilities remediated, controls passing or failing. This information is accurate. It does not answer the questions being asked.
A board asking whether cyber risk is within tolerance needs an answer framed in risk appetite terms, with a clear view of what the residual risk is, what it would take to change it, and what the organisation has consciously decided to accept. What it typically receives instead is a summary of security activities and a dashboard of operational indicators that describe what the security team has been doing, not what the organisation is exposed to.
Why the translation fails
The translation between security practice and board-level risk governance fails for structural reasons that are not resolved by better communication skills or clearer slide decks.
The first is that cyber risk quantification remains underdeveloped in most organisations. Without a credible method for expressing cyber exposure in financial or operational terms, security functions default to qualitative assessments that boards cannot easily compare against other risk categories or against risk appetite statements that are expressed in business language.
The second is that ownership of cyber risk at the executive level is frequently ambiguous. The CISO reports somewhere in the organisation. That reporting line is rarely the risk function. The risk function owns the risk framework. The disconnect between the two creates a situation where cyber risk is managed in one part of the organisation and governed in another, with no reliable mechanism for the two to produce a coherent picture.
The third is that boards receive cyber risk information episodically. Quarterly reporting, annual reviews, post-incident briefings. Cyber risk does not move on a quarterly cycle. The governance cadence creates a structural lag between the organisation’s actual risk position and the board’s awareness of it.
What regulators make of this
Regulators have noticed. DORA, NIS2, and the FCA’s operational resilience framework all contain provisions that push cyber and operational risk governance explicitly to board level. The expectation is not that directors become security experts. It is that boards can demonstrate active engagement with cyber risk, that they understand the organisation’s exposure, that they have approved an appropriate response, and that they exercise meaningful oversight of how that response is executed.
What regulators find when they examine board-level governance of cyber risk is often a gap between what the documentation says and what the board can actually articulate. Minutes that record that cyber risk was discussed are not evidence that the board understood what it was approving. Regulators ask follow-up questions. The answers tend to reveal whether the governance was substantive or performative.
The structural changes required
Boards that want to govern cyber risk effectively need two things that are currently absent in most organisations.
The first is a risk language that connects security practice to business outcomes. This requires investment in cyber risk quantification, not necessarily precise financial modelling, but a credible framework for expressing exposure in terms that sit alongside other enterprise risks. Without this, board oversight of cyber risk will remain structurally separated from board oversight of the rest of the organisation’s risk profile.
The second is clarity about where accountability sits. Someone at executive level must own cyber risk as a risk, not just as a security function. That ownership must carry with it the authority to make risk decisions and the accountability to answer for outcomes. Without this, the board has no single point of accountability to engage with, and the governance structure produces the appearance of oversight without the substance.
The question the board asked about cyber risk deserved a better answer. Building the capacity to provide one is not a communications exercise. It requires governance structures that most organisations have not yet built.


