71% of CISOs spend 10+ hours on board reports - Help Net Security
Help Net Security newsletters : Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!
Please turn on your JavaScript for this page to function normally.
Anamarija Pogorelec, Senior Staff Writer, Help Net Security
August 10, 2026
Share
71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data delivery, better frameworks, and better context.
Pulse Security AI’s The CISO-Board Communication Gap report found that board members bring external information into discussions while many organizations still lack a formally defined cyber risk appetite. Over the past 12 months, 42% of security leaders had to defend a third-party security score.
"For a decade, the industry has told security leaders to communicate better with the board," said Mike Armistead, CEO of Pulse Security AI. "Our data says the problem is upstream of that. You cannot report status against a baseline that was never set."
Confidence in board reporting remains low
Only 12.5% of CISOs are very confident that their board accurately understands the true state of the security program after a presentation. Most people responsible for cyber risk governance therefore operate with an incomplete understanding, and the leaders presenting to them are aware of the gap. Most respondents said they were somewhat confident or neutral.
Respondents said material security incidents increased board trust, while tabletop exercises with security teams strengthened leadership credibility in ways presentations alone could not.
Seventy-one percent of respondents spend 10 or more hours preparing each board or audit committee presentation cycle, with most presenting quarterly. Organizations involve three or more people in assembling the supporting material, and fragmented preparation makes it harder to present a coherent view of business risk, resilience, and control effectiveness. Automated threat and vulnerability analysis, automated data aggregation, and better tools for translating findings into business impact would reduce the workload.
Armistead added, "You cannot assemble a clear picture of the business when the underlying information lives in a dozen disconnected places. Security leaders have earned the room. What they need now is the operating layer underneath it."
Governance gaps limit board oversight
Security oversight still relies more on instinct than measurement. Many CISOs do not have access to private sessions with the board or audit committee, limiting candid discussions about cyber risk.
Half of boards did not explicitly accept, mitigate, or transfer cyber risk last year. Some security leaders said concerns about personal legal exposure influence how they communicate with the board.
Many organizations still describe cyber risk using qualitative categories instead of financial impact, and many lack predefined board-level cyber incident escalation thresholds. Board discussions remain divided between reviewing past events and planning for future cyber risks.
More about
boardroom
CISO
communication
cyber resilience
cybersecurity
report
security controls
Share
Featured<br>news
AI agent deception moves from theory to reality in UK cyber tests
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
Future AGI: Open-source platform for shipping self-improving AI agents
Resources
Download: The High-Performance Team Playbook
Simplify security management with CIS SecureSuite Platform
Download: The IT and security field guide to AI adoption
Don't miss
Who will be the Stanislav Petrov in your organization?
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Metabase zero-day exploited to access Framework customer data
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
OpenAI locks down Astra over potential critical cyber capabilities
Cybersecurity news
HNS Daily
Daily newsletter sent Monday-Friday
HNS Newsletter
Weekly newsletter sent on Mondays
InSecure Newsletter
Editor's choice newsletter sent twice a month
Cybersecurity news alerts
Periodical newsletter released for important security events and breaking news
Cybersecurity jobs
Weekly newsletter listing new cybersecurity job positions
Open source
Monthly newsletter focusing on open source cybersecurity tools
Subscribe
I have read and agree to the<br>terms & conditions
×