CISOs have made it to the boardroom. Now what? 

It may have taken some time but CISOs now firmly have a place at the boardroom table. But Thom Langford, CTO EMEA at Rapid7, questions whether the CISO’s message is getting across to the rest of the board. He explores how CISOs can translate cyber-risk into business value.  

Ever since the first CISO position was allegedly created by Citigroup in 1994, the holy grail of cybersecurity leadership has been a seat at the boardroom table. And now we’re there.  

Cybersecurity has become an important part of the business agenda for most companies and security heads are busy polishing up their slide decks stuffed with metrics to share in the boardroom. But many of those security leaders are realising a hard truth: simply being in the room isn’t the same as being understood. 

Getting a seat at the table was only the start. Phase one was access and now it’s time for phase two: articulation. It’s no longer about fighting for airtime; it’s about refining the message. 

The rise of the security-aware board 

The last few years have seen a substantial shift in the way cyber is handled by senior business leaders. Research has found that 91% of CISOs are now present to the full board or committee for their company to one degree or another. By now, most boards already know cybersecurity matters; what they want to know now is how it protects their bottom line.  

Added to that, Gartner found that around half of boards now have someone with genuine cybersecurity expertise or experience. That certainly leaves room for improvement, but it’s a huge leap from a decade ago, when you’d be lucky to find one or two in the whole FTSE 100. That’s progress. 

However, many cyber leaders have spent so long trying to be heard that they’re still talking about security the same way they did a decade ago.  

Risk isn’t the headline; cost and revenue are 

While a growing number of business leaders now understand that cyber-risks exist and believe that they need to be addressed, it’s important to remember that the board likely doesn’t care about risk in the same way security professionals do. 

Risk is on the agenda, but it’s still usually sitting somewhere in the middle. Revenue and cost will always be taking first and second place and cyber-risk is probably down at number eight of the top 10. It’s in the running, but it’s unlikely to be keeping anyone else up at night.  

Yet so many CISOs still walk into board meetings armed with risk registers, audit frameworks and traffic-light dashboards. Again, these are the same tools we used 10 years ago in a bid for attention.  

Instead of entering a meeting with the goal of moving cyber up from number eight to the top of the list, the goal should be to frame how it’s relevant to the things that are already heading the agenda.  

Cyber heads are well aware that security is deeply tied to revenue and cost, but they need to make sure this is properly conveyed to the rest of the board. That means translating every discussion about exposure or resilience into a conversation about cost avoidance and revenue protection. 

Gartner’s own data backs this up. When CEOs are asked what they truly prioritise, 53% cite growth and revenue, and 41% cite cost control. Only 35% put risk or resilience near the top. The message is clear: if we want their attention, we have to speak their language. 

Translating cyber-risk into business value 

Part of our problem is that we’ve become fluent in the wrong language. Cyber leaders talk risk confidently, residual versus inherent, threat surfaces, attack vectors, but that’s not the language of the boardroom. It’s like a foreign currency, until we provide the exchange rate into costs and revenue, it’s all just numbers on a page.  

What we need is an ‘abstraction layer’ between security metrics and business outcomes. The board doesn’t need to know about vulnerabilities patched or frameworks achieved; they need to know what they got for their investment.  

A report highlighting that patching processes were faster this quarter won’t get much attention. Instead, that report needs to say how this reduced cost, how it enabled growth and how it helped keep the customers happy. 

When we lead with outcomes, not operations, the conversation changes. We can still talk about risk, but we don’t go to bat with it.  

As the saying goes, the mountain isn’t going to come to Muhammad. We have to meet the board where they are; in the world of EBITDA, not IDS.  

Turning the board into a dialogue, not a download 

One of the biggest shifts in any board interaction is realising that success isn’t measured by how much you say, but by how many questions you get back. Gartner calls it the ‘golden ratio’: 45% of your time presenting, 55% in discussion. In other words, less show, more tell, less monologuing, more conversations.  

When they ask, ‘How secure are we?’ or ‘How do you know?’, that’s not a challenge to the CISO’s authority or competency, that’s the engagement they really want. It’s where understanding actually starts. 

Strong, collaborative governance is a great way of ensuring this happens. By having clear policies, defined risk tolerance and alignment with the board’s priorities, security decisions reflect real business needs.  

The CISO’s job is no longer to deliver a lecture, but to lead a dialogue. Continuous dialogue between the board and security teams keeps strategy aligned and reinforces that security supports the overall business mission. It also ensures the board are engaged, learning and aware of what the CISO and more importantly, their investment is doing for the business. 

The more we invite the board to test, probe and question, the more confidence we build. That’s when security stops being a compliance update and starts being a business conversation. Cybersecurity strategies then goes from being an IT directive to a business decision that supports the organisation’s broader strategy. 

We’ve spent years teaching the board to speak security, and now the situation is reversing. Risk might be the mother tongue of security, but revenue is the language of the boardroom and the next generation of CISOs must be bilingual to succeed.