The Board Has the Answers. Does It Understand Them?
A board can review every cybersecurity report, ask every recommended question, approve more investment, and still fail to govern cyber risk properly.
Cybersecurity has quietly changed the job description of the board, not because directors are expected to understand malware, analyse attack techniques, or debate the merits of competing security technologies, but because cyber incidents increasingly determine whether an organisation can continue operating, comply with regulatory obligations, preserve stakeholder trust, and execute its strategy.
The discussion has therefore moved from technology to governance. This raises an uncomfortable question that many boards still need to answer: what does real accountability for cybersecurity look like?
For years, the answer seemed simple. Cybersecurity became a regular board topic, the CISO gave quarterly updates, dashboards became more detailed, and directors approved more spending or asked for independent reviews. From the outside, this looked like strong governance.
Recent academic research suggests that the reality is more complicated.
When Oversight Becomes Theatre
A Full Agenda Is Not Proof of Governance
One of the most important findings from recent research is not simply that boards struggle with cybersecurity. It is that many directors believe they are providing effective oversight, while cybersecurity specialists looking at the same process disagree.
The researchers interviewed directors, cybersecurity executives, and senior consultants, while also reviewing 1,000 firms from the Russell 3000. Only 14.7% reported having at least one director with cybersecurity or closely related expertise. More than half of the non-expert directors interviewed believed that specific cybersecurity expertise was not necessary for effective oversight, while none of the expert directors agreed.
The difference was not about effort. Non-expert directors attended meetings, reviewed reports, completed training, and asked questions just as expert directors did. The problem was that these activities could still remain symbolic if directors did not have enough knowledge to understand which information was truly reassuring and which information should change the board’s view of risk.
Governance is not measured by how many meetings are held or how many reports are reviewed. It is measured by whether directors can challenge assumptions, influence important decisions, and recognise when positive metrics hide serious weaknesses.
The researchers describe this as the difference between symbolic and substantive oversight. Symbolic oversight looks like governance. Substantive oversight improves the decisions that follow.
More Dashboards, Same Blind Spot
Reports Still Need Context
The natural response to weak oversight is often to give directors more information: more dashboards, more indicators, more reports, and more external reviews.
But the problem is often not a lack of information. It is a lack of context, interpretation, and challenge.
A lower number of critical vulnerabilities may mean security has improved, but it may also mean the organisation changed how it measures them or reduced the scope of its scanning. High compliance scores may show that processes are being followed, but they may say very little about whether the organisation can continue operating during an attack. A positive assurance report may confirm that a review took place without showing whether it covered the systems, suppliers, and dependencies that matter most.
Without context, information can create confidence instead of understanding.
The information gap may also be larger than boards realise. In a supporting survey, CISOs estimated that the median share of peers who filtered reports to make themselves or their managers look better was 40%. The study does not prove that 40% of board reports are false, but it does show that experienced security leaders see selective reporting as a real governance risk.
A board without enough expertise may not notice when information has been softened, simplified, or framed to highlight progress. More importantly, it may not realise that there is anything to notice.
Monitoring Does Not Mean Governing
Another study offers a useful way to think about this issue. Instead of treating oversight as a regular reporting task, the authors argue that boards should approach cybersecurity as an ongoing process of strategic sensemaking.
They describe three activities: scanning, interpretation, and action. These should continue before an incident, during an attack, and throughout recovery.
The board’s role is not to manage cybersecurity operations. It is to make sure the organisation keeps identifying important risks, understands what they mean for the business, and makes decisions that improve long-term resilience.
Accountability Starts Before the Incident
Governance failures often begin long before a cyber incident reaches the boardroom.
They begin when ownership of important risks is unclear, when business leaders assume cybersecurity belongs only to the security team, when supplier risk is reviewed separately from business continuity, or when management’s confidence is not supported by evidence the board can examine.
By the time an incident happens, many of the decisions that shape its impact have already been made. The organisation has already decided which systems are most important, which risks it will accept, which remediation deadlines can move, and which recovery capabilities deserve funding.
Strategic oversight therefore starts with clear ownership, clear decision rights, reliable evidence, and a direct link between cyber risk and business priorities.
The Questions Have Changed
For many years, boards asked whether the organisation had the right controls, whether regulatory duties had been met, or whether audits had found serious weaknesses. Those questions still matter, but they are no longer enough.
A stronger governance discussion asks whether the board understands which cyber risks could affect the organisation’s strategy, who owns those risks outside the security team, what evidence supports management’s confidence, and how directors would know if their current view of risk was no longer correct.
These questions are harder because they do not only ask for information. They ask for understanding.
Smart Directors Can Still Ask the Wrong Questions
The study does not say that every board must appoint a former CISO. It does show that boards without real cybersecurity knowledge face a greater risk of confusing visible governance activity with effective oversight.
Directors with cybersecurity expertise are more likely to notice gaps, challenge assumptions, test reports, and separate technical detail from business impact. Their value is not mainly in explaining technology. It is in improving the board’s judgement.
One of the most important findings is that directors without cybersecurity expertise often do not realise that their oversight may lack depth. This creates a serious blind spot because boards cannot easily fix a weakness they do not recognise.
That does not mean one expert should carry the responsibility for the whole board. All directors still need to understand how cyber risk affects strategy, operations, finance, compliance, and trust. Expertise should improve the board’s work, not replace shared responsibility.
If Everyone Owns Cyber Risk, No One Does
Both studies point to the same basic issue: effective cybersecurity governance depends on visibility.
Directors need to know who owns important risks, how decisions are made, what evidence supports management’s confidence, which dependencies affect resilience, and how risk is changing across the organisation. Without that visibility, accountability is difficult to test or prove, even when everyone is acting in good faith.
Technology cannot create board accountability, but it can make accountability easier to see, challenge, and support with evidence.
This is where a governance platform can help. Its value is not in creating another separate dashboard, but in connecting risks, ownership, controls, evidence, compliance duties, and third-party relationships in one place.
Conclusion
The Board Will Be Judged by What It Can Prove
Regulators, investors, customers, and executive teams increasingly expect boards to show not only that cybersecurity appears on the agenda, but that directors understand how cyber risk is governed, challenged, and connected to strategy.
That expectation cannot be met through reporting alone. It requires boards that are willing to question their own assumptions, organisations that can prove accountability instead of only describing it, and governance processes that turn cybersecurity from a technical issue into a business decision.
The boards that govern cyber risk well will not necessarily be those that receive the most information. They will be those that can challenge what they are told, recognise what is missing, and connect cyber risk to the decisions that shape the organisation’s future.
For Further Reading
This blog post is based on insights and analysis from:
- Harel, Yaniv, and Abraham Carmeli. “A strategic cybersecurity oversight framework: a board’s imperative.” Journal of Cybersecurity 11.1 (2025): tyaf021.
https://academic.oup.com/cybersecurity/article/11/1/tyaf021/8237280
- Lowry, Michelle R., Anthony Vance, and Marshall D. Vance. “Inexpert supervision: Field evidence on boards’ oversight of cybersecurity.” Management Science 72.2 (2026): 783-804. https://doi.org/10.1287/mnsc.2023.0414