Skip to main content

How to talk to board members about cyber

New guidance helps CISOs communicate with Boards to improve oversight of cyber risk.
Nadzeya_Dzivakova via Getty Images

Improving the management of cyber risks in organisations has been the central motivation behind our Cyber Security Toolkit for Boards, which helps boards to embed cyber resilience and risk management throughout their organisations, systems, technologies and staff.

However, for some time the NCSC has been aware of a ‘skills gap’ in how cyber security risk is overseen at the board level. To explore this more fully, we commissioned research specialists Social Machines to obtain a better understanding of this perceived ‘lack of board engagement with cyber security and cyber-related decision-making’. 

The research included interviews with board members, CISOs and other cyber security leaders in medium to large organisations. Whilst some of the key themes could perhaps have been predicted (such as how boards find the excessive use of technical language and jargon as barriers to understanding), other findings were more unexpected - and concerning.

For example, 80% of participants were unsure of where accountability for cyber resided. We found that in many organisations, the CISO (or equivalent role) thought that the Board was accountable, whilst the Board thought it was the CISO. This lack of clarity is compounded by a ‘lack of expertise’ reported by 60% of the participants. As a result of their limited understanding of the risks, Boards believed they were unable to offer the necessary oversight.

For their part, CISOs stated that they didn’t feel the need to involve the Board because they believed that the Board would struggle to understand their technical explanations.

Board-level cyber discussions: communicating clearly is new guidance from the NCSC that addresses head on the issues raised by the Social Machines research. It encourages CISOs and other cyber security leaders to ‘step up’ to this challenge, and offers practical tips to help you engage strategically with the board to improve the management of cyber security risk. 

As the authority for cyber security in your organisation, it’s up to CISOs to elevate their conversations with board members (and other senior decision makers) so that they connect ‘cyber’ with the overall business challenges and context. This means CISOs must engage with Boards on their terms and in their language to ensure the cyber risk is understood, managed and mitigated. The guidance explains that a crucial first step is to recognise that - rightly or wrongly - this is the CISO’s problem to solve, and they need to work with the audience as they find it (which may not be the audience they wish they had).

As the research underlines, most Board members do not have in-depth cyber security knowledge. That’s not their role. Cyber security leaders, on the other hand, do have detailed knowledge of the domain, but are less experienced in communicating technical matters to Board or senior executive teams. As cyber professionals, it the CISO’s job to bridge this gap to provide better cyber security outcomes. 

The new guidance forms the latest part of the Cyber Security Toolkit for Boards, and will help the CISO better understand the responsibilities and mindset of boards, and how to best explain this complex subject. By doing so, cyber security leaders are more likely to receive the investment and resources they need, ultimately reducing the cyber security risk and enabling the business to focus on its value-creating work.

We hope you find the new guidance useful. If you have any comments or questions, or have ideas about what else you’d like to see in the Cyber Security Toolkit for Boards, please get in touch using [email protected]


Sarah Lyons
Deputy Director, Economy and Society Resilience

Written by

Sarah Lyons Deputy Chief Operating Officer, NCSC