Skip to content
CISOteria

The Board Is Asking Cybersecurity Questions. But Can It Judge the Answers?

The Board Has the Answers. Does It Understand Them?

A board can review every cybersecurity report, ask every recommended question, approve more investment, and still fail to govern cyber risk properly.

Cybersecurity has quietly changed the job description of the board, not because directors are expected to understand malware, analyse attack techniques, or debate the merits of competing security technologies, but because cyber incidents increasingly determine whether an organisation can continue operating, comply with regulatory obligations, preserve stakeholder trust, and execute its strategy. 

The discussion has therefore moved from technology to governance. This raises an uncomfortable question that many boards still need to answer: what does real accountability for cybersecurity look like?

For years, the answer seemed simple. Cybersecurity became a regular board topic, the CISO gave quarterly updates, dashboards became more detailed, and directors approved more spending or asked for independent reviews. From the outside, this looked like strong governance.

Recent academic research suggests that the reality is more complicated.

When Oversight Becomes Theatre 

A Full Agenda Is Not Proof of Governance 

One of the most important findings from recent research is not simply that boards struggle with cybersecurity. It is that many directors believe they are providing effective oversight, while cybersecurity specialists looking at the same process disagree.

The researchers interviewed directors, cybersecurity executives, and senior consultants, while also reviewing 1,000 firms from the Russell 3000. Only 14.7% reported having at least one director with cybersecurity or closely related expertise. More than half of the non-expert directors interviewed believed that specific cybersecurity expertise was not necessary for effective oversight, while none of the expert directors agreed.

The difference was not about effort. Non-expert directors attended meetings, reviewed reports, completed training, and asked questions just as expert directors did. The problem was that these activities could still remain symbolic if directors did not have enough knowledge to understand which information was truly reassuring and which information should change the board’s view of risk.

Governance is not measured by how many meetings are held or how many reports are reviewed. It is measured by whether directors can challenge assumptions, influence important decisions, and recognise when positive metrics hide serious weaknesses.

The researchers describe this as the difference between symbolic and substantive oversight. Symbolic oversight looks like governance. Substantive oversight improves the decisions that follow.

More Dashboards, Same Blind Spot 

Reports Still Need Context

The natural response to weak oversight is often to give directors more information: more dashboards, more indicators, more reports, and more external reviews.

But the problem is often not a lack of information. It is a lack of context, interpretation, and challenge.

A lower number of critical vulnerabilities may mean security has improved, but it may also mean the organisation changed how it measures them or reduced the scope of its scanning. High compliance scores may show that processes are being followed, but they may say very little about whether the organisation can continue operating during an attack. A positive assurance report may confirm that a review took place without showing whether it covered the systems, suppliers, and dependencies that matter most.

Without context, information can create confidence instead of understanding.

The information gap may also be larger than boards realise. In a supporting survey, CISOs estimated that the median share of peers who filtered reports to make themselves or their managers look better was 40%. The study does not prove that 40% of board reports are false, but it does show that experienced security leaders see selective reporting as a real governance risk.

A board without enough expertise may not notice when information has been softened, simplified, or framed to highlight progress. More importantly, it may not realise that there is anything to notice.

Monitoring Does Not Mean Governing 

Another study offers a useful way to think about this issue. Instead of treating oversight as a regular reporting task, the authors argue that boards should approach cybersecurity as an ongoing process of strategic sensemaking.

They describe three activities: scanning, interpretation, and action. These should continue before an incident, during an attack, and throughout recovery.

The board’s role is not to manage cybersecurity operations. It is to make sure the organisation keeps identifying important risks, understands what they mean for the business, and makes decisions that improve long-term resilience.

Accountability Starts Before the Incident

Governance failures often begin long before a cyber incident reaches the boardroom.

They begin when ownership of important risks is unclear, when business leaders assume cybersecurity belongs only to the security team, when supplier risk is reviewed separately from business continuity, or when management’s confidence is not supported by evidence the board can examine.

By the time an incident happens, many of the decisions that shape its impact have already been made. The organisation has already decided which systems are most important, which risks it will accept, which remediation deadlines can move, and which recovery capabilities deserve funding.

Strategic oversight therefore starts with clear ownership, clear decision rights, reliable evidence, and a direct link between cyber risk and business priorities.

The Questions Have Changed

For many years, boards asked whether the organisation had the right controls, whether regulatory duties had been met, or whether audits had found serious weaknesses. Those questions still matter, but they are no longer enough.

A stronger governance discussion asks whether the board understands which cyber risks could affect the organisation’s strategy, who owns those risks outside the security team, what evidence supports management’s confidence, and how directors would know if their current view of risk was no longer correct.

These questions are harder because they do not only ask for information. They ask for understanding.

Smart Directors Can Still Ask the Wrong Questions 

The study does not say that every board must appoint a former CISO. It does show that boards without real cybersecurity knowledge face a greater risk of confusing visible governance activity with effective oversight.

Directors with cybersecurity expertise are more likely to notice gaps, challenge assumptions, test reports, and separate technical detail from business impact. Their value is not mainly in explaining technology. It is in improving the board’s judgement.

One of the most important findings is that directors without cybersecurity expertise often do not realise that their oversight may lack depth. This creates a serious blind spot because boards cannot easily fix a weakness they do not recognise.

That does not mean one expert should carry the responsibility for the whole board. All directors still need to understand how cyber risk affects strategy, operations, finance, compliance, and trust. Expertise should improve the board’s work, not replace shared responsibility.

If Everyone Owns Cyber Risk, No One Does

Both studies point to the same basic issue: effective cybersecurity governance depends on visibility.

Directors need to know who owns important risks, how decisions are made, what evidence supports management’s confidence, which dependencies affect resilience, and how risk is changing across the organisation. Without that visibility, accountability is difficult to test or prove, even when everyone is acting in good faith.

Technology cannot create board accountability, but it can make accountability easier to see, challenge, and support with evidence.

This is where a governance platform can help. Its value is not in creating another separate dashboard, but in connecting risks, ownership, controls, evidence, compliance duties, and third-party relationships in one place.

Conclusion

The Board Will Be Judged by What It Can Prove 

Regulators, investors, customers, and executive teams increasingly expect boards to show not only that cybersecurity appears on the agenda, but that directors understand how cyber risk is governed, challenged, and connected to strategy.

That expectation cannot be met through reporting alone. It requires boards that are willing to question their own assumptions, organisations that can prove accountability instead of only describing it, and governance processes that turn cybersecurity from a technical issue into a business decision.

The boards that govern cyber risk well will not necessarily be those that receive the most information. They will be those that can challenge what they are told, recognise what is missing, and connect cyber risk to the decisions that shape the organisation’s future.

For Further Reading

This blog post is based on insights and analysis from:

  • Lowry, Michelle R., Anthony Vance, and Marshall D. Vance. “Inexpert supervision: Field evidence on boards’ oversight of cybersecurity.” Management Science 72.2 (2026): 783-804. https://doi.org/10.1287/mnsc.2023.0414

The Policy Says One Thing. The Organisation Does Another. Why?

Approved on Paper. Ignored in Practice

Most organisations already have security policies.

They explain how employees should handle data, approve access, share files, use devices, and report incidents. On paper, the rules are clear. Responsibilities are assigned, controls are documented, and the organisation can point to a formal process.

Then the policy meets daily work.

An employee cannot complete a task quickly enough through the approved system, so they create a workaround. A manager uses a faster channel because the official process feels too slow. A team adopts an unauthorised tool because the approved one does not fit the work.

The problem is not always that employees do not know the rules. The policy describes how work is supposed to happen, while employees deal with how work actually happens.

On Paper, Everything Works

Knowing the Policy Is the Easy Part

Recent research on information security policy compliance shows that awareness alone is not enough. Employees may understand the rules and still behave differently when the approved process feels difficult, time-consuming, unclear, or disconnected from the pressures of their role. The research describes this as a “knowing-doing” gap: people may know what the organisation expects without consistently following it in practice.

Organisations often assess policy strength through formal evidence: an approved document, completed training records, and a successful audit review. Those signals show that the process exists, but they reveal far less about how employees behave under pressure.

Deadlines, slow systems, unclear instructions, and competing business demands often shape daily decisions more than the policy itself.

Green Checks Can Hide Grey Practices 

A policy may be formally approved, communicated across the organisation, included in training, and reviewed during an audit, yet still remain weakly connected to daily work. From a governance perspective, those visible signs can create a level of confidence that the organisation has not fully earned.

Leadership can see the document, the completion records, and the audit result. It has far less visibility into the small decisions employees make when the official process slows them down, creates extra work, or conflicts with an urgent business need. A team may use an unapproved tool, a manager may accept an informal exception, or an employee may skip a step that seems unnecessary in the moment. None of these actions may appear serious on their own, but together they can create a growing gap between the control environment described in policy and the one that actually exists.

The difficulty is that formal evidence usually records whether a process was designed, approved, or reviewed. It rarely shows how consistently that process is followed under pressure. As a result, an organisation may report strong compliance while the day-to-day reality depends on workarounds, local habits, and decisions that never reach the formal governance process.

Good Intentions Can Create Bad Security 

The Employee Followed Security – Just Not Yours 

A 2025 study examined what the researchers call shadow security practices – unofficial security-related workarounds created by employees who still believe they are protecting the organisation.

An employee may save important files on a personal device because the approved backup system is slow. The intention is protective, but the result is still outside the organisation’s control and may violate data-handling rules.

Shadow security is difficult to manage because the employee may still be trying to protect the organisation. They are balancing a business task with a security requirement, but doing so through a method the organisation cannot see or govern. 

Too Much Security Can Drive Work Underground 

The same study surveyed 433 office workers and found that information security overload increased employees’ intention to use unofficial security practices. When people felt that security duties added pressure, delayed their work, or made primary tasks harder, they were more likely to create their own solution.

This does not mean controls should disappear whenever they create friction. Some friction is necessary because the risk justifies it.

The problem begins when the organisation adds controls without understanding their combined effect. One approval, one authentication step, and one reporting requirement may each seem reasonable. Employees, however, experience the full process. When those requirements accumulate, the approved path may become harder to follow than the workaround.

Another Training Session Will Not Fix the Process 

Security Communication or Security Noise?

The shadow security study found that employees were less likely to create workarounds when they understood how security measures worked, why management required them, and what outcomes the measures were meant to achieve.

However, the study also found that excessive communication can increase overload. More emails, more warnings, and more training do not automatically create better behaviour. They can create confusion, fatigue, and pressure.

The goal should therefore not be maximum communication. It should be useful communication that explains the risk, the reason for the rule, and the practical way to follow it.

Culture Decides Which Rules Survive 

The 2025 systematic review found that policy compliance is influenced by employee attitudes, perceived effectiveness of security measures, management support, awareness, and organisational culture.

Employees notice whether leaders follow the same rules they promote. They notice whether managers reward speed while security demands caution, and whether reporting a problem leads to support or blame.

A policy may say that security is everyone’s responsibility, but the organisation teaches a different lesson when deadlines always win or exceptions are quietly ignored.

Training cannot fix that on its own. If the approved process is too slow, another awareness session will not make it faster. If employees are rewarded for speed and punished for delay, a reminder about compliance will not change the incentive.

Workarounds Are Also Evidence

A workaround should not be accepted simply because the employee had good intentions. Unapproved practices can still create serious risk.

But they should be studied.

A workaround shows where the official process and actual work have separated. It may reveal a missing tool, unclear ownership, a slow approval chain, or a policy that was written without enough operational input.

The organisation should examine both the employee’s decision and the conditions that made the approved process difficult to follow.

Approved, Published, Forgotten  

A policy becomes useful when the organisation can see how it is being applied.

That requires clear ownership, defined controls, evidence, exceptions, and regular review. It also requires visibility into where practice is moving away from policy.

For organisations using CISOteria, this means connecting policies to the controls, owners, evidence, risks, and compliance requirements they are meant to govern. The value is not simply in storing the policy. It is in showing whether the policy is active, who is responsible for it, what proves that it is being followed, and where gaps remain.

CISOteria does not enforce employee compliance. It gives the organisation visibility into whether policy and practice remain aligned.

Conclusion:

The Rules That Survive Pressure Are the Rules You Actually Have 

Every organisation has two versions of its security policy. One is written, approved, and presented during audits. The other is shaped by daily decisions, management behaviour, informal exceptions, and the pressure employees face when they try to get work done.

Good governance begins with recognising the gap between the two. The organisation needs to understand where practice has moved away from policy, why that happened, and whether the right response is stronger enforcement, clearer communication, a better process, or a revised policy.

Because the written policy shows what the organisation intends to do. Daily behaviour shows what it has actually made possible.

For Further Reading

This blog post is based on insights and analysis from: