“Where Are We On Cyber?” – A Qualitative Study On Boards’ Cybersecurity Risk Decision Making
Jens Christian Opdenbusch
Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Phishing & Fraud 1 · Phishing & Fraud 1
Key moments
- 0:49 Understanding the UK Board of Directors structure
- 2:38 Study questions and approach to interviewing executives
- 4:48 Boards ask abstract questions, fear of looking uninformed
- 6:16 Regulation elevates cyber, but knowledge sharing is lacking
- 6:50 Boards and CISOs have different cyber risk perceptions
- 7:25 CFO's role in translating technical risks for the board
- 8:00 Cyber security risk isolated from traditional risk management
“Where Are We On Cyber?” – A Qualitative Study On Boards’ Cybersecurity Risk Decision Making
Speakers: Jens Christian Opdenbusch
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=JjhOMdXur5Q
Overview
In an increasingly digital world, cybersecurity risk has ascended to the highest levels of organizational concern. Yet, how Boards of Directors—the ultimate arbiters of corporate strategy and risk—grapple with this complex domain remains a significant, often opaque, challenge. The talk "Where Are We On Cyber?" presented by Jens Christian Opdenbusch at the NDSS Symposium, delves into this critical intersection, offering a qualitative study that uncovers the intricate dynamics of cybersecurity risk decision-making within UK boards. Conducted by Opdenbusch alongside Jonas Hilcha and Angela Zassasa from the University of Bhham, Germany, the research provides a rare glimpse into the perspectives of C-level executives, non-executive directors (NEDs), Chief Information Security Officers (CISOs), and consultants.
The study aims to demystify how cybersecurity information flows to the board, the nature of their decisions, and the execution of those decisions, while also exploring the influence of various stakeholders. This work is particularly pertinent given the board's inherent oversight role, their responsibility for long-term risk management, and their mandate to maximize shareholder value—all of which can be severely impacted by cybersecurity incidents. The findings reveal critical gaps in communication, perception, and integration of cybersecurity risks, offering invaluable insights for both security professionals striving to elevate their message and board members seeking to enhance their governance.
The importance of this research cannot be overstated. As digital transformation accelerates, so too does the attack surface, making robust cybersecurity governance a non-negotiable aspect of business resilience. By shedding light on the current state of board-level engagement with cyber risk, Opdenbusch and his team provide a foundational understanding that can inform better practices, foster more effective communication, and ultimately strengthen an organization's defensive posture from the top down. The study's focus on the UK board structure, which uniquely combines executives and non-executives, adds a specific lens to these universal challenges, making its insights broadly applicable to any organization navigating the complexities of modern cyber threats.
Background
▶ Watch: Understanding the UK Board of Directors structure (0:49)
The foundation of this study rests on understanding the unique structure and responsibilities of Boards of Directors, particularly within the UK context where the research was conducted. As Opdenbusch explained, a UK board is distinct in that it comprises both executive directors (e.g., CEO, CFO, CTO, CIO) who are part of the company's day-to-day management, and non-executive directors (NEDs), who typically hold executive positions in other companies or are retired, offering an external perspective without operational involvement. Crucially, the Chief Information Security Officer (CISO), despite their pivotal role in managing cyber risk, is typically positioned one or two levels below the board, reporting to an executive like the CFO, CTO, or CIO, rather than being a direct board member. This hierarchical distance immediately highlights a potential challenge in direct communication and influence at the highest strategic level.
The rationale for focusing on boards from a cybersecurity perspective is multifaceted. Boards hold a fundamental oversight role, tasked with maintaining a long-term view of emerging risks, including the rapidly evolving landscape of cybersecurity threats. Furthermore, NEDs are specifically mandated to maximize shareholder value, a metric demonstrably impacted by cybersecurity breaches, which can lead to significant financial losses and harm stock prices through negative disclosures. Therefore, understanding how these bodies perceive, discuss, and decide on cybersecurity risks is paramount for organizational resilience and investor confidence.
The research was driven by two primary questions:
- How does cybersecurity risk decision-making of boards even work? This encompassed understanding the information flow towards boards, the type and content of their decisions, and how these decisions are subsequently executed.
- How do other stakeholders influence those decisions? This involved exploring the impact of CISOs, other executives, regulators, and investors on board-level cybersecurity strategies.
To answer these questions, the research team employed a rigorous qualitative methodology. The process began with exploratory interviews with six pilot participants, comprising CISOs, NEDs, and consultants. Insights from these initial discussions were then used to develop tailored interview guides for each stakeholder group. The core of the study involved 18 semi-structured interviews with C-level executives, NEDs, CISOs, and C-level consultants. The collected data was then subjected to both inductive and deductive qualitative coding to identify key themes and learnings.
Recruitment, a significant challenge given the senior level of participants, was achieved through a snowballing approach. Initial access was gained via an advisory board for a research project partially funded by the UK's National Cyber Security Centre (NCSC), which included NEDs and CISOs. These initial contacts then referred the researchers to their peers and networks, ultimately leading to the 18 interviewees. The participant pool represented a broad range of industries, not limited to technology, and notably included individuals from very large companies, with some employing up to 260,000 people and an average of approximately 90,000 employees. This breadth and scale underscore the relevance of the findings to substantial and complex organizations. Despite the robust recruitment, it's worth noting that only two of the final 18 participants were female, indicating a potential gender imbalance within the studied demographic. This comprehensive background sets the stage for the nuanced findings that emerged from the study, revealing both systemic challenges and promising avenues for improvement in board-level cybersecurity governance.
Key Findings
▶ Watch: Boards ask abstract questions, fear of looking uninformed (4:48)
The qualitative study unearthed several critical insights into the dynamics of cybersecurity risk decision-making at the board level, highlighting significant gaps and areas for improvement.
Firstly, the research revealed a pervasive issue with the depth and nature of questions boards ask regarding cybersecurity. Participants reported that board questions often remain highly abstract, lacking the specificity required to genuinely challenge the organization's cybersecurity posture. An executive interviewee, for instance, cited being asked, "Are we giving you enough money?" as an example of a question that, while seemingly supportive, fails to probe the efficacy of spending or the actual risk landscape. This superficial questioning is compounded by a notable fear of losing face among some non-executive and executive directors. As one executive put it, they are "scared about losing face" and don't want to ask questions that might make them "look stupid" in a domain often perceived as a "dark art" or the exclusive realm of "a bunch of chaps in hoodies." This apprehension severely hinders effective oversight and critical inquiry.
Secondly, regulation emerged as a powerful force in elevating cybersecurity to the board's agenda. Participants acknowledged that regulatory mandates effectively bring the topic to the forefront. However, there was a strong desire for more knowledge sharing by regulatory bodies. Boards and executives expressed a need for anonymized incident reports and insights from regulators, who are often the first point of contact during crises or recipients of incident disclosures. Such shared intelligence could provide valuable context and learning opportunities, moving beyond mere compliance to genuine risk mitigation.
A third significant finding was the pronounced divergence in risk perceptions between board-level executives and CISOs. When discussing "risks," boards predominantly focused on financial risks—potential impacts on revenue, stock prices, or market value. In contrast, CISOs typically discussed more technical risks—vulnerabilities, threat vectors, or specific security controls. This disconnect means that even when both parties believe they are addressing cybersecurity risk, they are often operating on entirely different conceptual planes. The executive who noted that "if you've got a conversation where someone is talking about antivirus tools on a board level, you've got a problem because that's not something that should be discussed on a board level," perfectly encapsulates this gap.
Crucially, the study identified a promising mechanism for bridging this communication chasm: the Chief Financial Officer (CFO) as a translator. One CISO shared a successful approach where they prepared cybersecurity material specifically for their CFO, who would then present it to the board. The effectiveness stemmed from the CFO not being an IT person, which necessitated a collaborative effort to distill complex technical risks into board-relevant business and financial terms. This forced collaboration ensured that only truly pertinent information, stripped of "IT world and concepts," reached the board, framed in a language they understood and valued.
Fifth, the research highlighted that cybersecurity risks are often managed in isolation, failing to be integrated with more traditional, mature risk management approaches that have existed for many years. Boards tend to look at cybersecurity and other operational risks "in a vacuum," rather than comparing them directly to established financial or market risks. This siloed approach prevents a holistic understanding of the company's overall risk profile and can lead to misallocation of resources or underestimation of interconnected threats.
Finally, the study debunked an initial hypothesis regarding investor influence. The researchers anticipated that investors, keen to protect their investments, would actively inquire about cybersecurity. However, almost all non-executive directors reported never encountering cybersecurity questions during investor presentations. Responses ranged from "I've never heard a question about cyber security" to "I would be amazed if an investor even asked questions about cyber security." This creates an awkward position for boards, who are tasked with representing shareholder interests and ensuring long-term company viability, yet receive no direct pressure from investors on a risk that profoundly impacts both.
These key findings collectively paint a picture of a board-level cybersecurity landscape characterized by abstract engagement, communication breakdowns, and a need for more integrated and informed decision-making.
Technical Deep Dive
▶ Watch: Regulation elevates cyber, but knowledge sharing is lacking (6:16)
While this qualitative study does not delve into traditional "technical" elements such such as code or network protocols, its technical deep dive focuses on the socio-technical architecture of cybersecurity decision-making within organizations, specifically at the board level. It scrutinizes the mechanisms of information flow, the nature of risk perception, and the organizational structures that either facilitate or impede effective governance.
At the heart of the challenge is the information flow from the CISO—typically positioned one or two hierarchical levels below the board—up to the decision-makers. This distance inherently introduces friction and potential loss of fidelity. The CISO, as the highest-ranking cybersecurity professional, possesses the most granular understanding of technical threats, vulnerabilities, and the operational security posture. However, directly presenting this highly technical information to a board comprising individuals with diverse, often non-technical, backgrounds proves ineffective. The study highlights that boards are not interested in "antivirus tools" but rather in the strategic implications and financial impacts of cyber risks.
The proposed translation mechanism involving the CFO is a crucial technical insight into bridging this gap. The CFO, by virtue of their role, operates at the intersection of operational activities and financial implications, making them an ideal intermediary. The "technical" aspect here lies in the process of translation itself. It's not merely simplifying language; it's about reframing technical risks into a business risk context that resonates with the board. This involves:
- Risk Quantification: Converting abstract technical vulnerabilities into potential financial losses, regulatory fines, reputational damage costs, or operational disruptions with clear monetary impacts.
- Strategic Alignment: Demonstrating how specific cybersecurity investments or deficiencies directly impact strategic business objectives, market competitiveness, or long-term growth.
- Prioritization: Helping the board understand which risks are most material to the business, allowing for informed resource allocation based on impact and likelihood, rather than purely technical severity.
The success of the CFO as a translator, as described by one CISO, stems from their lack of technical expertise. This forces a collaborative effort where the CISO must strip away "IT world and concepts" and articulate the essence of the risk in terms the CFO, and subsequently the board, can grasp. This collaborative filtering mechanism ensures that only the most critical, board-relevant information makes it through, effectively acting as a semantic gateway for cybersecurity intelligence.
Furthermore, the study implicitly highlights the power imbalance inherent in the CISO's position relative to the board. Without a robust mechanism for challenging and scrutinizing cybersecurity information, the CISO, as the "highest ranking person in cyber security in this company," could potentially control the narrative and decide "what to share with board members and what not to share." This lack of independent oversight and challenge can lead to a less informed board and, consequently, suboptimal risk decisions. The proposed solution of subcommittees acts as a technical architectural improvement, creating a dedicated forum where executives, NEDs, and CISOs can engage in more in-depth discussions, fostering mutual understanding and challenging assumptions from both technical and business perspectives. This structure aims to democratize the understanding of cyber risk and ensure more balanced information flow.
Finally, the observation that cybersecurity risks are often viewed "in a vacuum" rather than integrated with existing, mature risk management approaches represents a significant technical deficiency in enterprise risk management (ERM). Traditional ERM frameworks, such as those for margin and credit risk, are well-established, with defined metrics, reporting structures, and decision protocols. The failure to integrate cybersecurity into these frameworks means that organizations lack a holistic view of their risk exposure, potentially leading to misallocation of resources or an underestimation of interconnected risks. The study implicitly calls for a "technical" integration of cybersecurity risk quantification and reporting into these established ERM systems, allowing for comparative analysis and more informed strategic decisions across all risk categories. This would involve developing standardized metrics and reporting mechanisms that align cyber risk with financial and operational risk parameters.
In essence, the "technical deep dive" here is not about the bits and bytes of cybersecurity, but about the organizational architecture, communication protocols, and risk quantification methodologies required to effectively govern cybersecurity at the strategic apex of an organization. It's about engineering better decision-making processes for a critical, complex domain.
Demo / Proof of Concept
▶ Watch: CFO's role in translating technical risks for the board (7:25)
As a qualitative study focused on interviewing senior executives and analyzing their perceptions and decision-making processes, this research did not involve a technical demonstration or a proof of concept. The methodology centered on gathering insights through semi-structured interviews and subsequent qualitative coding, rather than showcasing a functional system, tool, or exploit. The findings are derived from the rich narratives and experiences shared by the participants, illustrating organizational dynamics and communication challenges rather than technical vulnerabilities or defensive mechanisms.
Defensive Implications
▶ Watch: Cyber security risk isolated from traditional risk management (8:00)
The findings from "Where Are We On Cyber?" offer crucial insights that defenders, from CISOs to board members, can leverage to strengthen an organization's cybersecurity posture. The implications span communication strategies, organizational structure, and risk management practices.
For Chief Information Security Officers (CISOs) and Security Teams:
- Master the Art of Translation: The most significant implication for CISOs is the imperative to translate technical cybersecurity risks into business and financial terms. Stop discussing specific tools or vulnerabilities in isolation. Instead, frame risks in terms of potential revenue loss, regulatory fines, stock price impact, reputational damage, customer churn, or operational disruption. Provide quantifiable metrics where possible.
- Leverage Business-Savvy Intermediaries: Actively seek out and collaborate with business-minded executives, particularly the Chief Financial Officer (CFO), as a strategic partner to present cybersecurity matters to the board. The CFO's unique perspective, coupled with their financial acumen, can effectively bridge the communication gap, ensuring the message resonates with board members. Develop board materials collaboratively, focusing on strategic implications rather than technical minutiae.
- Anticipate and Address Board Concerns: Understand that boards are primarily concerned with strategic and financial risks. Tailor presentations to address these concerns directly. Provide clear, concise answers to questions like "What is the financial impact if X happens?" or "How does this risk compare to other business risks we face?"
- Advocate for Structured Engagement: Push for dedicated forums or subcommittees where in-depth discussions about cybersecurity can occur without the pressure of a full board meeting. This allows for a more comprehensive exchange of information and the opportunity to educate board members over time.
For Boards of Directors and Non-Executive Directors (NEDs):
- Overcome the "Fear of Losing Face": Board members must actively foster an environment where challenging, even seemingly basic, questions about cybersecurity are encouraged without fear of appearing uninformed. Recognize that robust questioning is essential for effective oversight. Consider pre-briefings or educational sessions to build foundational knowledge.
- Demand Business-Centric Metrics: Instead of asking abstract questions like "Are we giving you enough money?", demand metrics that directly link cybersecurity investments and risks to business outcomes. Ask for comparisons of cyber risk against other traditional business risks. Examples include "What is our estimated financial exposure to a ransomware attack?", "How does our cybersecurity maturity compare to industry peers?", or "What is the ROI of our recent security investments?"
- Integrate Cybersecurity into Enterprise Risk Management (ERM): Do not view cybersecurity in isolation. Insist on its integration into the broader ERM framework, comparing cyber risks alongside financial, operational, and market risks. This provides a holistic view and allows for more informed resource allocation and strategic decision-making.
- Form Dedicated Cybersecurity Subcommittees: Actively consider establishing a dedicated cybersecurity subcommittee. This provides a focused forum for deeper dives into complex cyber issues, allowing for more detailed discussions between CISOs, executives, and NEDs, and fostering a shared understanding that is often difficult to achieve in general board meetings. This also creates a mechanism for challenging the CISO and ensuring robust oversight.
- Seek External Expertise and Knowledge Sharing: Leverage regulatory bodies and industry peers for anonymized incident data and best practices. Regulators should be encouraged to facilitate this knowledge sharing, providing valuable context that can inform proactive defensive strategies.
- Prioritize Cyber Due Diligence: Despite current investor apathy, boards have a fiduciary duty to protect shareholder value. This means proactively understanding and mitigating cyber risks, even without direct investor pressure. This foresight will be crucial as investor awareness of cyber risk inevitably grows.
For Regulators:
- Enhance Knowledge Sharing: Regulators are uniquely positioned to collect incident data. Anonymized sharing of this data, including common attack vectors, financial impacts, and defensive strategies, would be invaluable for boards to learn from the experiences of others and enhance their defensive strategies. This moves beyond compliance to fostering collective resilience.
By implementing these defensive implications, organizations can move towards a more mature and integrated approach to cybersecurity governance, ensuring that strategic decisions at the highest level are informed, effective, and resilient against evolving threats.
Key Takeaways
- Communication Gap: Boards often struggle with effective cybersecurity oversight due to abstract questions and a "fear of losing face" when discussing technical topics, leading to a lack of depth in their engagement.
- Divergent Risk Perceptions: A significant disconnect exists between boards, which focus on financial risks, and CISOs, who emphasize technical risks, hindering effective dialogue and shared understanding.
- CFO as Translator: The Chief Financial Officer (CFO) can serve as a highly effective intermediary, translating complex technical cybersecurity risks into business and financial impacts that resonate with board members.
- Isolated Risk Management: Cybersecurity risks are frequently managed in isolation, rather than being integrated into traditional, mature enterprise risk management frameworks, preventing a holistic view of organizational risk.
- Investor Apathy: Despite the significant financial impact of cyber incidents, investors currently exhibit minimal interest in cybersecurity during board presentations, creating a potential blind spot for boards regarding shareholder interests.
- Subcommittees for Enhanced Governance: Establishing dedicated cybersecurity subcommittees is proposed as a promising long-term solution to foster deeper engagement, bridge communication gaps, and provide a more robust challenge mechanism for board-level cybersecurity oversight.
About the Speaker(s)
The presentation was delivered by Jens Christian Opdenbusch, who is part of a larger interdisciplinary research team based at the University of Bhham in Germany. The project was a collaborative effort with Jonas Hilcha, described as a freshly minted PhD, and Professor Angela Zassasa. The team brings together diverse academic backgrounds, including psychology, anthropology, and more technical fields such as cyber security and computer science, from which Jens Christian Opdenbusch and Jonas Hilcha originate. This interdisciplinary approach is reflected in the study's qualitative methodology, which examines not just technical aspects but also the human and organizational factors influencing decision-making at the highest corporate levels.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate academic research on a real and underexplored problem — board-level cyber governance dysfunction — with a credible methodology (18 semi-structured interviews, NCSC-affiliated access, inductive/deductive coding). The findings are coherent and the CFO-as-translator insight is practically useful, but nothing here will surprise a seasoned CISO or governance practitioner, and the sample size and UK-specific scope limit generalizability.
Heather Calloway (CISO) — SOLID
Legitimate qualitative research on a real governance problem — board-level cyber decision-making is under-studied and the findings are credible. But 18 interviews from UK boards, presented at an academic conference, leaves the practitioner asking what to do Monday morning that they didn't already know.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025