How to create better cybersecurity conversations with the board

Information security officers could try three perspectives when framing cybersecurity discussions. Image: Unsplash+/Getty Images
- An underestimated challenge facing many organizations is how to turn cybersecurity concerns into meaningful governance discussions and board decisions.
- Three complementary perspectives that help shape cybersecurity discussions include cybersecurity maturity, cyber risk appetite and present-day cybersecurity risks.
- A goal is to create a conversation where the board’s experience, perspective and judgment can shape what happens next.
I recently presented the cyber security status to our board. The discussion that followed confirmed that the approach had achieved what I hoped: it enabled a productive conversation about the risks that mattered most and where the board could add value.
In the weeks that followed, I shared the approach with dozens of chief information security officers (CISOs). Their feedback encouraged me to write about the same challenge facing many organizations regarding how to turn a board update into a meaningful governance discussion.
What follows is the approach that worked well for us – it is not the only way to engage a board but it helped create the kind of discussion every CISO hopes for.
Start with the company's risk environment
For a cybersecurity company, context matters. We are part of our customers' supply chains. We hold sensitive threat intelligence. Our source code is strategic intellectual property. Most importantly, our customers trust us to help protect their businesses.
A successful attack against a cybersecurity company could, therefore, affect not only the organization itself but confidence across the wider ecosystem.
That environment is also becoming more challenging. Geopolitical tensions continue to reshape cyber activity, while artificial intelligence (AI) is dramatically reducing the time, expertise and resources required to conduct sophisticated attacks.
Check Point Research's Annual AI Security Report 2026 shows how far this has already progressed: AI has moved from merely assisting attackers to directly operating intrusions, in some documented cases executing exploitation steps with little human direction.
Meanwhile, the gap between a vulnerability's disclosure and its exploitation has compressed from days to hours. Together, these developments are changing both the scale and the speed of cyber risk.
Starting the discussion with this context created a shared understanding of the environment before discussing how we were managing the risks.
3 ways to discuss cybersecurity governance
I found it useful to build the discussion around three complementary perspectives: cybersecurity maturity, cyber risk appetite and the cybersecurity risks that required the board's attention at that point in time.
These are not competing approaches. Each contributes something different to the board discussion.
1. Cybersecurity maturity
A maturity assessment, often based on the National Institute of Standards and Technology, demonstrates whether foundational capabilities across governance, protection, detection, response and recovery are in place and continuing to improve.
I believe this is an essential part of every board discussion. However, maturity is an indicator, not a conclusion.
A strong maturity assessment gives the board confidence that the organization is building the right cyber security foundations. At the same time, it does not necessarily answer a different question the board also needs to understand: whether those capabilities are adequately addressing the cyber security risks facing the business today.
2. Cyber risk appetite
Cyber risk appetite is another valuable governance concept.
For some organizations, particularly those with mature financial risk disciplines, it provides an effective way to express cyber exposure and support investment decisions.
In our case, however, some of our most important assets – source code, customer trust and strategic reputation – cannot be meaningfully reduced to a precise financial value.
I found risk appetite most useful as a way to frame discussions about acceptable and unacceptable risk, rather than as the organizing principle for the presentation.
3. Current cybersecurity risks
The discussion itself was organized around the cyber security risks that needed the board's attention at the time.
Unlike maturity, which evolves steadily over time, the cyber security risks that deserve the board's attention change continuously. New technologies, new attack techniques and changes in the business constantly reshape where management and the board should focus.
One clear example of this came earlier in our AI transformation, once the risks involved were better understood. Rather than using that clearer picture to pull back, several board members pushed the conversation in a different direction: they asked us to accelerate the transformation, provided we could do it securely.
That shift, from containing a risk to actively enabling a strategic priority, shaped how we approached the initiative from that point on.
For each risk, we answered seven consistent questions:
- What is the risk?
- Why does it matter to our business?
- What could the business impact be?
- What are we doing to reduce the exposure?
- What progress have we made?
- What uncertainty or residual risk remains?
- Where would the board's perspective, challenge or support be most valuable?
Focusing the discussion in this way changed its nature. Instead of spending time reviewing controls or security projects, the conversation honed in on priorities, assumptions, execution speed and trade-offs. The board challenged our thinking, tested our priorities and helped ensure we were focusing on the risks that mattered most.
Measure success by the quality of the discussion
The clearest sign this worked was the AI transformation moment above: the board didn't just react to the risks we presented; it reshaped the question entirely.
By grounding the conversation in the company's risk environment, demonstrating confidence in the cybersecurity foundations and focusing on the risks that required attention in the moment, the discussion became more relevant to both management and the board.
That was the approach that worked for us. The best measure of a board presentation is not how much it covers but how much it moves the conversation from reporting to judgment – where the board's experience and perspective can genuinely shape what happens next.
Have you read?
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Cybersecurity
Related topics:
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on CybersecuritySee all
Thomas Reagan and Luna Rohland
July 24, 2026



