Why Every Boardroom Needs A Bullhorn For Cybersecurity

ZTK04231 sq Edit

By Michelle Drolet

Founder & CEO

Michelle is a prominent leader in data security preparedness, renowned for her extensive expertise i

Read More
Thinking of cybersecurity purely through the lens of an “IT issue” is limiting. Cybersecurity impacts operational resilience, financial risk, regulatory exposure, brand trust and, in a worst-case scenario, business continuity. This makes a rock-solid case for a cybersecurity bullhorn in the boardroom.Unfortunately, cybersecurity is still treated as a technical dialog. Only 5% of companies have a cybersecurity expert in the boardroom. In most cases, the board hears cybersecurity updates, approves budgets and assumes that the technical experts have it all covered. That’s a cardinal misstep.Malicious actors move faster than annual planning cycles and scheduled tabletop exercises. Digital transformation expands the attack surface as third-party relationships multiply. AI introduces new uncertainty and new risk management challenges. And when something breaks, the impact lands squarely on the board’s shoulder: accountability, revenue, customers, regulators, reputation and shareholder value.

The High Cost Of Complacency

The global average cost of a data breach is $4.4 million, but this is not the worst case. Associated costs that give the board sleepless nights include downtime, customer churn, long remediation delays, contractual penalties and potential litigation. The infamous 2024 attack on Change Healthcare had a negative impact on hospital networks nationwide, including sacrifices to patient care, revenue and operations. Estimates and disclosures around the incident put costs in the billions.

This is why governing a top-tier enterprise without in-room expertise is not a good look for the board. In the U.S., the SEC now requires public companies to report cyber incidents within four business days of their designation as a “material” event. These companies must disclose annually how they manage and oversee cyber risk at the board level.

The board must transition from viewing cybersecurity strictly as an operational cost to recognizing it as a convergence of governance, disclosure and accountability.

How Cybersecurity Advocates Shape Boardroom Thinking

The job of a cybersecurity expert in the boardroom is not to sling technology talk per se, but to change the quality of board decisions around cybersecurity and work closely with the CISO for correct messaging. The focus should be on translating the various multiprong aspects of cybersecurity into enterprise trade-offs. For example, the need for a zero-trust framework should be positioned as, “Our current setup makes it easier for an attack to spread, and we can’t recover fast enough without taking a hit on revenue.”

The cyber advocate is also an expert in reframing budget discussions around downside risk and resilience, where the conversation shifts from cost to impact. And, above all, the advocate, along with the CISO, focuses on accountability, including who owns cyber risk, the level of the board’s risk appetite and, specifically, which business initiatives increase exposure (M&A, cloud migrations, AI deployments, new vendors).

What Boards Must Do Differently

If the board wants to reduce cyber risk, it has to move from passive oversight to active governance. Three shifts can make a measurable difference:

1. Cybersecurity expertise should be a must-have.

The board should have a security leader who has managed major incidents in the past and/or previously held a CSO, CISO or related chief risk officer position. If they are unable to find someone in-house with the requisite expertise, a standing external advisor should be tapped and given real, actionable authority.

2. Decision-grade transparency should be paramount.

Forgo adding additional metrics to evaluate the cybersecurity framework. Rather, tie the right metrics to business outcomes. In a sense, the board needs to be trained by asking questions such as: What could realistically bring operations to a halt, and how fast can we resume normal operations? Where is the company most vulnerable today regarding access controls, backups, key systems and third-party partners? What steps can we take in the next 90 days that will meaningfully reduce our risk?

Transparency means understanding the vulnerabilities before attackers do and having the discipline to fund the fixes/remediation.

3. Cybersecurity should always be on the agenda.

Cybersecurity should sit wherever strategy sits. Any decision that changes how the business operates should come with one salient check: What new risk exposure does this create, and how are we containing it? This applies to acquisitions, vendors, partners, AI rollouts, product launches, entering new markets and major operational changes.

A New Line Of Thinking For The Board

The question isn’t whether you have a security team. Most companies do. The question is whether the board is equipped to govern cyber risk with the same gravity as it applies to strategic directives, fiduciary oversight and legal/ethical compliance.

A cybersecurity advocate in the boardroom doesn’t guarantee you’ll avoid an incident. It makes it far more likely, though, that when the business does face a cyber incident, it won’t be caught flat-footed without a mitigation plan, or make high-stakes decisions blindly without context or counsel.

Cybersecurity is a business risk. Treating it as a purely technical matter is how breaches become crises, and crises bring lasting damage.

 

This article was originally posted on Forbes Technology Council >