Cybersecurity has become a critical governance issue that demands strategic oversight from the board. While directors aren’t expected to be cybersecurity experts, they are still responsible for understanding and overseeing the organization’s cybersecurity program to:
- Understand the investments required to mitigate cyber risk;
- Comply with regulatory requirements, such as SEC cybersecurity reporting;
- Ensure the organization is prepared to respond to a breach; and
- Maintain effective business operations.
Most importantly, the board ensures that 1) the right tone is set from the top and 2) the Senior Management Team is driving information security actions throughout the organization. Therefore, choosing an expert cybersecurity advisor to help incorporate cyber risk oversight into your governance process can significantly improve the organization’s board-level awareness and preparedness against cyberattacks.
Drawing from insights shared by Howard Hoffmann and Christopher Hetner in their webinar, this blog post examines the benefits of establishing independent cyber risk reviews, the importance of setting the right tone at the top, and the need for strong risk governance and management oversight at the board level.
“Too often, cybersecurity gets lost in translation when board members engage the C-suite. This leaves the board unsure of precisely what the organization is funding and where residual gaps remain.” — Chris Hetner
The Board’s Role in Cyber Risk Management
Cybersecurity has evolved into a critical governance issue that demands strategic oversight from corporate boards. For example, the SEC’s cybersecurity disclosure rules, effective December 18, 2023, emphasize that boards must take responsibility for understanding the organization’s cybersecurity program, ensuring breach readiness, and maintaining secure business operations.
Unlike technical specialists, boards must assess cyber risks from a broader perspective, focusing on business, operational, and financial implications. This approach involves analyzing how cyber threats and vulnerabilities affect the company’s strategic objectives, competitive position, and long-term value creation.
In contrast, Chief Information Security Officers (CISOs) focus on the technical execution of the cybersecurity program. They typically communicate risk updates, challenges, and opportunities using specialized terminology and industry-specific language that reflects their operational focus.
The differing viewpoints and technical expertise of boards versus CISOs can lead to a communication divide. Board members, often lacking deep technical backgrounds, may struggle to fully grasp cyber risks or access the business-relevant information necessary for informed decision-making. This gap complicates effective risk oversight.
Despite these challenges, both groups share a common objective: building a cyber-resilient organization. They are driven by a mutual concern that, without proper preparation, a breach could expose vulnerabilities without a clear explanation. As a result, they aim to minimize the likelihood and severity of security incidents.
Bridging this divide requires boards to obtain clear, business-oriented insights into cyber risks and defenses. To fulfill their role effectively, boards should prioritize:
- Understanding the organization’s cyber defense strategy in a business context;
- Interpreting risk information presented to them through the lens of business impact;
- Confirming the risk management program’s effectiveness; and
- Ensuring cybersecurity initiatives and frameworks are implemented as planned and budgeted.
Translating well intentioned presentations, technical reports, data, and jargon from CISOs and CIOs to meet these goals can be both complex and time-intensive for boards. This challenge highlights the need for a specialized role to facilitate communication and alignment. Enter: the Cybersecurity Board Advisor.
How does a Cybersecurity Advisor assist Boards?
The ideal board advisors are trusted cybersecurity experts who have managed information security programs, led operational performance improvement initiatives, and served on corporate boards. They understand how to diagnose the effectiveness of a cybersecurity program, build a culture around security awareness, and close the gap in understanding between the board perspective and the CISO perspective.
The advisor’s job is to enrich the cybersecurity knowledge and governance capability of the existing board. They deliver a variety of benefits to help boards gain confidence in the organization’s information security posture, including:
- Enhancing knowledge of cyber risk management best practices;
- Providing support for cyber strategy & governance design;
- Developing a cyber risk governance charter;
- Delivering actionable insights on cyber security vulnerabilities and mitigation options/costs;
- Benchmarking the organization’s security posture against peers; and
- Leading a cybersecurity governance committee if desired.
Cybersecurity board advisors guide directors in asking the right questions of the CISO and management team to assess the effectiveness of the organization’s cybersecurity program. They explore the business impact of cyber risks, such as the potential financial loss from data breaches, ransomware attacks, and operational disruptions. For instance:
- Do we have a complete view of our cyber risks and the potential impact of threats?
- Are we aware of regulations that could impact us, and how?
- When we experience a breach, are we confident in our ability to recover?
- Does our company have cyber insurance, and is it adequate based on our security practices?
- Have we evaluated cyber risks that our vendors and third parties may introduce?
- Is our information security awareness training effective?
- Have our investments reduced the likelihood and severity of a security breach or incident?
- Will our documentation pass an internal or third-party cybersecurity audit?
- How do we determine if a security incident is material, and who makes that call?
It is worth noting that achieving 100% protection against security incidents and data breaches is impossible. Instead, boards and management teams must make their best effort to avoid attacks, be prepared to recover when an incident occurs, and continue operating with minimal disruption. Here is where an independent cyber risk review can be useful.
What is an Independent Cyber Risk Review?
An independent cybersecurity risk review is a third-party assessment that provides an objective evaluation of an organization’s cyber defense posture, offering boards an unbiased lens to assess management’s claims and align cybersecurity strategies with business goals.
As explained in EXTEND’s Board Member Briefing webinar, the gap between cybersecurity technicalities and business priorities can overwhelm board members. Independent reviews by a team experienced in working with boards can, among other things, help close this gap, providing clarity by translating technical jargon into valuable insights.
Unlike internal assessments, one benefit to having independent reviews is going through unfiltered evaluations of an organization’s risk exposure, vulnerabilities, and areas for improvement. These reviews help the board determine if the cybersecurity program is comprehensive, effective, and aligned with evolving risks, such as ransomware, supply chain vulnerabilities, or geopolitical risks on the 2025 Board Agenda.
How is a Cyber Risk Review Conducted?
- Current Program Review: The independent firm reviews and documents the organization’s cybersecurity goals and the current state of its cybersecurity program.
- Risk Identification: The independent firm assesses the company’s business activities, the core processes (including data flows) that support the company’s business activities, and the assets (hardware, software, IP, people, etc.) that support the core processes to identify vulnerabilities, third-party risks, and potential cyber threats.
- Controls Evaluation: The review evaluates existing information security controls and any associated frameworks, such as incident and disaster recovery response plans, vulnerability management processes, vendor management, and team member training, to assess their effectiveness.
- Business Context Mapping: Cyber risks are translated into business terms, such as financial impact, operational disruptions, and reputational damage.
- Recommendations and Reporting: The review concludes with a detailed report outlining actionable recommendations to achieve the program goals, prioritized by their potential business impact.
Key Takeaways for Effective Cybersecurity Board Oversight
1. The Board Sets the Tone at the Top
Strong leadership starts with setting a clear, transparent tone from the top. Boards must prioritize open discussions around cyber risks, regularly assess risk and establish mitigation priorities, and ensure adequate resources are allocated toward security initiatives. When leadership engages proactively and sends a message that cybersecurity risks are manageable and essential to the business, it creates a culture of accountability throughout the organization.
2. Use Financial & Operational Metrics to Inform Decision-Making
Effective cybersecurity oversight requires translating cyber risks into business terms. Boards can only make informed decisions when cybersecurity risks are measured by their impact on the organization. To reinforce this point, the need for clear oversight becomes even more apparent given that global annual losses from cybercrime are projected to increase to $11.9 trillion in 2026.
Relevant metrics to consider:
- Annual Loss Expectancy (ALE): Predicts the potential financial impact of a cyber incident.
- Cost of Downtime: Quantifies the losses resulting from business disruptions caused by ransomware or system outages.
- Return on Investment (ROI) of Security Initiatives: Measures how effectively cybersecurity investments reduce risk exposure.
3. Form a Dedicated Risk Management Committee
A dedicated risk committee strengthens advocacy for security initiatives and prevents cyber risk oversight from becoming lost among broader audit or operational discussions. This committee should work closely with the cybersecurity team, providing oversight and acting as a bridge between management and the board. Certainly, the board plays a key role in choosing trusted advisors, as board members can bring a wealth of experience and valuable contacts from their own personal networks who could assist with cybersecurity guidance.
Hiring an External Firm for Board Advisory Services
IT and cybersecurity teams often take the fall when a data breach or security incident occurs. Yet, who is ultimately responsible when cyber criminals infiltrate an organization and access its data? The board. Therefore, boards should select a firm with industry expertise, proven independence, board-level experience, and a commitment to transparency and ongoing support.
If your organization is looking for cybersecurity board advisory services, EXTEND Resources advises boards to help them improve their understanding of cyber risk management, facilitate effective oversight of risk assessment and mitigation tactics and costs, boost cyber resilience, and mitigate the risk of regulatory penalties.
EXTEND brings cybersecurity expertise and an independent, unvarnished view of an organization’s security posture directly to your boardroom, enabling you to:
- Understand your changing role and cybersecurity responsibilities;
- Prioritize security investments based on a clear view of cyber risk;
- Evaluate the efficacy of your organization’s disaster recovery and business continuity plans;
- Set the tone for a culture of information security & data privacy;
- Be prepared for internal and third-party audits;
- Evaluate the effectiveness of your cyber insurance policy in relation to your organization’s risk mitigation strategy;
- Assess and manage cyber risks introduced by vendors and other third parties;
- Accurately disclose material incidents in a timely manner.
Contact EXTEND to inquire about board advisory and cybersecurity consulting services.
Howard Hoffmann, the CEO of EXTEND Resources, is a highly experienced cybersecurity executive who has served as a Board Member or Chairman of the Board for 10+ public and privately held companies, participating in audit and cybersecurity subcommittees. In addition, Chris Hetner is the Chair of the Nasdaq Center for Board Excellence Insights Council and the former Senior Cybersecurity Advisor to the SEC Chair, with 25+ years of industry experience in cybersecurity, risk management, and regulatory compliance.
