• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • Home
  • Resources
    • Calculators
      • ISO Certification Cost Calculator
      • Cost of Quality Calculator
    • Lowest Cost ISO Services Quote Program
    • Online Gap Checklists
      • ISO 9001 Gap Checklist
        • ISO 9001 Gap Checklist Overview
        • ISO 9001 Gap Checklist Sample
        • ISO 9001 Gap Checklist Dashboard
      • ISO 45001 Gap Checklist
        • 45001 Checklist Gap Checklist Overview
        • ISO 45001 Gap Checklist Sample
        • ISO 45001 Gap Checklist Dashboard
      • ISO 27001 Gap Checklist
        • ISO/IEC 27001 Gap Checklist Overview
        • ISO 27001 Gap Checklist Sample
        • ISO 27001 Gap Checklist Dashboard
    • White Papers
      • AI and Quality Management: Many Questions, Few Answers
      • A Guide to Quality Risk Management
      • ISO 9001 Updates FAQ
      • Integrating ISO 27001 and ISO 9001
    • Job Salary Reports
      • Quality Professionals Salary Report
    • Free Quality Ebook
    • Glossary
  • Articles
    • Environment
    • Cybersecurity
      • Artificial Intelligence
      • Automation
      • Career
      • Certification Management
      • Continuous Improvement
      • Documentation
      • ISO 27001
      • Information Security Mgt. Systems (ISMS)
      • Management
      • Regulatory
      • Risk Management
      • Software
      • Supplier Quality
      • Sustainability
    • Management Systems
    • Manufacturing
    • Quality
      • Artificial Intelligence
      • Automation
      • Career
      • Certification Management
      • Continuous Improvement
      • Cost of Quality
      • Documentation
      • ISO 9001
      • LEAN-6 Sigma
      • Product Safety
      • Quality Management
      • Regulatory
      • Risk Management
      • Root Cause
      • Skills
      • Software
      • Supplier Quality
      • Sustainability
    • Safety
      • Product Safety Certification
      • Risk Management
  • What We Do
    • About Conformance 1
    • Group Purchasing
    • Negotiated Discounts
    • Why Buy Through Us?
  • Products/Services
    • Name Your Fee Training
    • Registrar Directory
    • Software Directory
    • Consultant Directory
  • Online Gap Checklists
    • ISO 9001 Dashboard
    • ISO 45001 Dashboard
    • ISO 27001 Dashboard
  • Contact
    • General Inquiries
    • Ask an ISO Expert
  • Login
    • Login
    • Log Out
Conformance1

Conformance1

Tools for conforming to standards, goals and processes

“Where Are We On Cyber?” – A Qualitative Study On Boards’ Cybersecurity Risk Decision Making

Leave a Comment Filed Under: Cybersecurity-Risk Management

CISOs Survey
  • Board members often hesitate to ask critical cybersecurity questions due to a lack of technical expertise, weakening oversight and reinforcing dependence on CISOs and executives.
  • Cybersecurity is treated primarily as a budget issue rather than as a strategic risk requiring in-depth engagement and risk appetite alignment.
  • Effective oversight is hindered by communication gaps, limited board-level understanding of cyber risk, and a lack of formalized structures like cyber-specific subcommittees.

This qualitative study explored how cybersecurity risk is perceived and handled at the board level in some of the UK’s largest organizations. Through interviews with 18 C-level executives, CISOs, non-executive directors (NEDs), and consultants, researchers found that while cybersecurity is increasingly present on board agendas, it is commonly reduced to financial abstractions—mainly investment decisions—rather than being treated as a strategic risk. Boards rarely engage directly with the complexities of cybersecurity; instead, they rely heavily on reports from executives and CISOs, often without the knowledge or confidence to challenge the content. A fear of appearing uninformed causes many NEDs to refrain from asking deeper questions, ceding effective decision-making to CISOs and, in some cases, auditors.

The study highlights a troubling power imbalance between boards and cybersecurity leaders. CISOs shape both the agenda and the content of board-level cybersecurity conversations, effectively determining which risks and data are communicated. This undermines the board’s traditional oversight function. Compounding the issue is the failure to integrate cybersecurity into established risk management frameworks. Although “risk” is cited as a common language across business units, the translation of cyber threats into comparable risk metrics is often inadequate or overly simplified. In many organizations, risk appetite for cybersecurity remains undefined or poorly operationalized, further distancing cyber risk from traditional enterprise risk governance.

Participants emphasized the value of dedicated cybersecurity subcommittees, continuous board education, and third-party audits to improve board engagement. However, war-gaming exercises and regulatory pressures, while useful, were often seen as reactive or superficial. A few organizations had begun addressing these issues with targeted board training or by adding cyber-savvy NEDs, though the consensus was that a broader cultural shift is required. Regulatory bodies, while instrumental in surfacing cyber risk, typically lack the prescriptive detail needed to enforce meaningful board-level engagement.

Ultimately, the study calls for structural and regulatory changes to empower boards in their cybersecurity oversight roles. It suggests more standardized reporting requirements, industry benchmarking, and formal subcommittees to institutionalize cyber risk governance. The researchers also recommend improving communication channels between CISOs and boards by fostering a shared understanding of risk and bridging technical-business language divides. Without these changes, cybersecurity risk will continue to be managed in a reactive, fragmented manner, leaving organizations vulnerable despite growing awareness at the top.

Read the full article

Filed Under: Cybersecurity-Risk Management

Reader Interactions

Leave a Reply

You must be logged in to post a comment.

Primary Sidebar

Search

Email Newsletter

News delivered to your inbox

Name(Required)
Newsletter Preferences(Required)
This field is hidden when viewing the form
This field is for validation purposes and should be left unchanged.

Related Items

Help us improve our tool

Have a suggestion for improving our ISO Gap Analysis Checklist? Let us know.

Secondary Sidebar

Categories

Recent Posts

  • Information Security Measures for a Procrastination Combatting Digital Solution
  • Cybersecurity Governance Toolkit
  • Quick Start Guide to Security Compliance
  • Best Practices for Cybersecurity Compliance Monitoring
  • ISO 27001 certification: What happens in the certification audit?

Footer

Important Resources

Cost of Quality Calculator

ISO 9001 Online Gap Analysis

ISO Certification Cost Calculator

Free Quality Ebook

Process Improvement Survey

ISO 9001 Glossary

 

Recent Posts

  • Information Security Measures for a Procrastination Combatting Digital Solution
  • Cybersecurity Governance Toolkit
  • Quick Start Guide to Security Compliance
  • Best Practices for Cybersecurity Compliance Monitoring
  • ISO 27001 certification: What happens in the certification audit?

Search

Contact Us

About Us

Privacy Policy

 

Copyright © 2025 · Conformance1 · Log in