Perspective · Board cyber governance

What boards should ask the CISO

Most board-level cyber updates fail in the same quiet way. The CISO presents diligently, the slides are full, everyone nods, and the directors leave no more certain than before whether the organization is actually safer than it was last quarter. The problem usually isn't the CISO. It's the questions.

Effort is not the same as risk

Boards are routinely handed activity: attacks blocked, patches applied, phishing-test pass rates, tickets closed, tools deployed. These are real numbers, but they measure how hard the security team is working, not how exposed the business is. A board cannot govern effort. It governs risk, the same way it governs credit, market, and operational risk: in terms of exposure, appetite, trend, and the cost of being wrong.

When cyber is discussed in a different language than the rest of the risk portfolio, directors are left to take it on faith that the effort is aimed at the right things. Good governance doesn't run on faith. It runs on a shared, comparable picture of risk, and the fastest way to get one is to change the questions the board asks.

Five questions that change the conversation

This is less about a new dashboard and more about what directors choose to ask. Five questions do most of the work:

  • What are our top cyber risks, in business terms, and are they inside or outside our risk appetite? Not “we blocked four million attacks,” but “a ransomware event on our core platform would halt settlement for three to five days, which exceeds the tolerance we set.”
  • Which way is our risk moving, and why? A single snapshot tells a board almost nothing. Direction (better or worse than last quarter, and the reason) tells it whether the current investment is actually working.
  • Where do we stand against what our regulators and examiners expect? Anchored to a recognized standard such as NIST CSF 2.0 and the specific expectations of your regulators, expressed as concrete maturity rather than a blanket “we're compliant.”
  • If we were hit today, how fast could we detect, respond, and recover, and when did we last actually prove it? Resilience is a claim until it is tested. The date of the last tabletop or recovery exercise is as revealing as any metric on the page.
  • What is our concentration and third-party exposure, who could take us down that we don't directly control? Most material incidents now arrive through a vendor, a platform, or a shared dependency. The board should know where the single points of failure sit.

A sixth, when time allows: are we funding the roadmap we approved, and what is the risk of the gap between the plan and the budget? The answer often explains more than any individual metric.

Directors can't govern effort. They can govern risk, but only if it arrives in the language of the business.

What a good answer sounds like

The value is in the quality of the answer, not just the sharpness of the question. Strong answers share three traits. They are specific: a number, a scenario, a named system, not an adjective. They are comparative: measured against last quarter, against appetite, against the standard, against peers. And they are honest: a CISO who only ever brings good news isn't protecting the board.

The most useful updates name the two or three things that keep the CISO awake at night, and what they would do about them with more resources. Directors should be quietly wary of a cyber update that contains no bad news and no asks; it usually means the hard parts aren't being surfaced.

Cadence is part of governance

Content matters, but so does rhythm. A board needs a consistent, one-page view that trends the same measures over time (not a differently shaped deck each quarter) together with a clear, pre-agreed path for escalating a material event between meetings. Governance is a discipline you keep, not an event you attend.

The organizations that handle a crisis well are almost always the ones that rehearsed the conversation before they needed it. The board's standing cyber discussion is where that rehearsal happens.

Helping boards and CISOs have exactly this conversation (translating technical posture into a board-ready picture of risk, readiness, and resilience) is core to what NorthBridge does. If your directors are getting activity when they need governance, let's talk.

Start a conversation

Want the one-page version? — a print-ready brief a director could take into the next meeting.

Related: see how this reads on a single page in our illustrative board cyber dashboard.